Silicon Valley Sleuth, an insider's view from Silicon Valley
A blog from vnunet.com



Other blogs
PCW Inter@ctive
Your views, your comments, your say

Security Watchdog
Sniffing out IT security
issues

The test bed
The hottest products, news and gossip from PCW's
Labs.

IT Sneak
IT Sneak Blog rummages in the dustbin of IT events.

Backbytes
An irreverent and offbeat look at the lighter side of technology

InterActive Home
Your complete guide to home entertainment technology

Taking Stock
Gags and Gossip from Accountancy Age.

Gizmodo
The gadgets weblog.



« Are we being hacked by aliens? | Main | Google stock takes a sanity break »

How long did Sony have to screw up the XCP?

As F-Secure already published when the Sony BMG XCP controversy first started spinning out of control, the company was already on Sony's tail before Mark Russinovich informed the world about this evil technology.

The difference being that F-Secure reported the issue quietly to Sony BMG to drive its consultancy business (helping fix the flaw before taking credit) where Russinovich was out to give Sony BMG a public whipping.

This story went back in time to seek out what exactly happened prior to the Russinovich blog posting. Most importantly it even further shows the level of incompetence that First 4 Internet showed in dealing with its own flawed code. The firm not only failed to act when it was first told about the security flaws in its software, it also derailed attempts to bring in F-Secure to help fix the issue (the parties couldn't agree on the terms of the non disclosure agreement). Given that First 4 Internet had created a patchwork of proprietary code combined with stolen GPL components, this isn't a big surprise.

First 4 Internet still won't comment on the mess it created. With lawsuits popping up against its technology all over the world, that's no big surprise. But the report in BusinessWeek only seems to make matters worse for both Sony BMG and First 4 Internet.

Creating insecure code is one thing. Knowing its bad nature and failing to act is even worse.

Incompetence

Tags: Sony BMG, first 4 internet, XCP, DRM, trojan

November 29, 2005 at 10:16 PM | Permalink

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d83451b07469e200d83522b75553ef

Listed below are links to weblogs that reference How long did Sony have to screw up the XCP?:

Comments

Post a comment






 

Useful links: About | Privacy policy | Terms & conditions | Top of the page
© Incisive Media Ltd. 2008
Incisive Media Limited, Haymarket House, 28-29 Haymarket, London SW1Y 4RX, is a company registered in the United Kingdom with company registration number 04038503