How long did Sony have to screw up the XCP? - Silicon Valley Sleuth

Silicon Valley Sleuth, an insider's view from Silicon Valley
A blog from V3.co.uk





Other blogs
Download Junkie
Your daily dose of download discussion

IT Sneak
V3.co.uk's under cover reporter offers odds and ends from the odd end of the technology

Mac Inspector
Drills to the core of the latest Mac rumours and news

Security Watchdog
Sniffing out IT security issues

The Frontline
Insight into the latest tech news from V3.co.uk's team of reporters

V3.co.uk Labs
The latest UK business technology: quick reviews and first impressions




« Are we being hacked by aliens? | Main | Google stock takes a sanity break »

How long did Sony have to screw up the XCP?

As F-Secure already published when the Sony BMG XCP controversy first started spinning out of control, the company was already on Sony's tail before Mark Russinovich informed the world about this evil technology.

The difference being that F-Secure reported the issue quietly to Sony BMG to drive its consultancy business (helping fix the flaw before taking credit) where Russinovich was out to give Sony BMG a public whipping.

This story went back in time to seek out what exactly happened prior to the Russinovich blog posting. Most importantly it even further shows the level of incompetence that First 4 Internet showed in dealing with its own flawed code. The firm not only failed to act when it was first told about the security flaws in its software, it also derailed attempts to bring in F-Secure to help fix the issue (the parties couldn't agree on the terms of the non disclosure agreement). Given that First 4 Internet had created a patchwork of proprietary code combined with stolen GPL components, this isn't a big surprise.

First 4 Internet still won't comment on the mess it created. With lawsuits popping up against its technology all over the world, that's no big surprise. But the report in BusinessWeek only seems to make matters worse for both Sony BMG and First 4 Internet.

Creating insecure code is one thing. Knowing its bad nature and failing to act is even worse.

Incompetence

Tags: Sony BMG, first 4 internet, XCP, DRM, trojan

Comments

Post a comment







Useful links: About | Privacy policy | Terms & conditions | Top of the page
© Incisive Media Investments Limited 2010, Published by Incisive Financial Publishing Limited, Haymarket House, 28-29 Haymarket, London SW1Y 4RX, are companies registered in England and Wales with company registration numbers 04252091 & 04252093