Sony Settles With FTC Over Rootkits 133
The FTC has struck a deal with Sony punishing Sony for the rootkits it included on millions of CDs in 2005. The deal is exactly like the Texas and California settlements — $150 a rootkit. The settlement isn't final yet. There will be a 30-day public consultation. American citizens who read Slashdot might want to put in their two cents. Comments will be accepted through March 1 at: FTC, Office of the Secretary, Room H-135, 600 Pennsylvania Avenue, N.W., Washington, D.C. 20580 (snail mail only). Here is the FTC page announcing the settlement.
What about OS????/ (Score:3, Informative)
Re: (Score:1)
Re: (Score:2, Interesting)
Re: (Score:3, Informative)
This gives me an idea! (Score:2)
If nothing else, it would make for pretty pictures to show in court.
150? If by 150 you mean 150ml (Score:5, Funny)
How About... (Score:3, Interesting)
How About you realise that this is Sony BMG - e.g. a partnership between Sony and Bertelssman. The rootkit would have been 100% BMG's idea. The CEO of Sony has gone on the record as saying he thinks online music sales are too expensive and should be close to the 25c mark.
Re:How About... (Score:5, Insightful)
Why are they even paying this man?
Re: (Score:1, Insightful)
If he did, the shareholders would fire him. That, incidentally, is why corporations are more evil than any individual.
Re: (Score:2)
He does this because Sony does not have an on-line music retail business and therefore he has nothing he could act on. He is simply trying to smear iTunes and music selling mobile operators.
Re: (Score:3, Insightful)
Listen.... it doesn't matter that they're separate departments. Its. The. Same. Company. Saying "Oh its just the music department, all those other departments are ok," is just a cop-out. At least be honest that you don't really care.
Re: (Score:2, Informative)
You seemed have missed some fundamental facts. IT'S NOT THE SAME COMPANY! IT"S NOT A DEPARTMENT! IT'S A SEPARATE COMPANY! There's a *reason* it's called "Sony BMG" instead of "Sony Music Entertainment" (here's a hint, Sony doesn't own all of i
BS (Score:2)
If Wal-Mart split off the shoe department as Wal-Mart Shoe Company but still controlled it, it would still just be the shoe department.
Re: (Score:1)
Rookits take YOUR blood.
Re: (Score:2)
Since Sony are ment to be in the entertainment business how about a "reality show" where viewers can vote for which executive gets fed to the vampire...
Re: (Score:1)
Re: (Score:2, Informative)
Originally, the only symbol for the litre was l (lowercase letter l), following the SI convention that only those unit symbols that abbreviate the name of a person start with a capital letter.
In many English-speaking countries, the most common shape of a handwritten Arabic digit 1 is just a vertical stroke, that is it lacks the upstroke added in many other cultures. Therefore, the digit 1 may easily be confused with the letter l. On some typewriters, particularly older ones, the l key had to be used to type the numeral 1. Further, in some typefaces the two characters are nearly indistinguishable. This caused some concern, especially in the medical community. As a result, L (uppercase letter L) was accepted as an alternative symbol for litre in 1979. The United States National Institute of Standards and Technology now recommends the use of the uppercase letter L, a practice that is also widely followed in Canada and Australia. In these countries, the symbol L is also used with prefixes, as in mL and L, instead of the traditional ml and l used in Europe. In Britain and Ireland, lowercase l is used with prefixes, though whole litres are often written in full (so, "750 ml" on a wine bottle, but often "1 litre" on a juice carton).
Prior to 1979, the symbol (script small l, U+2113), came into common use in some countries; for example, it was recommended by South African Bureau of Standards publication M33 in the 1970s. This symbol can still be encountered occasionally in some English-speaking countries, but it is not used in most countries and not officially recognised by the BIPM, the International Organization for Standardization, or any national standards body.
so Europeans that use "l" instead if "L" are American, you say ...
Re: (Score:2)
On 2-liter bottles, and on products that we hope to export to Canada or Mexico. You'd be surprised.
Re: (Score:1)
I deny that that is the case! I bash Apple and Nintendo as vigorously as the others!
Now if you'd said Google...
----
(This, for the unaware, was an attempt to be +1 Funny, not -1 Moron.)
Drawing parallels (Score:4, Insightful)
Re: (Score:3, Insightful)
Could malware use Vista's DRM functionality? (Score:2, Interesting)
Re: (Score:1, Interesting)
Save your reciept ? (Score:5, Interesting)
I understand why stores require reciepts to return stuff, but when it comes to CDs which are non-returnable once that plastic wrap is taken off, who the hell bothers to save the reciept ?
How are they going to know when the CD was purchased ?
Re: (Score:2, Insightful)
Re: (Score:1)
Re: (Score:2)
The biggest problems I've had returning things have been when the item was technically fine - it met the manufacturer's spec
Re: (Score:2)
Well, considering these CDs were pulled from the shelves quite some time back, I think it's safe enough for them to assume that if you have a rootkit version of a CD, you bought it before that date.
Re: (Score:2)
Re: (Score:2)
If you did not legally purchase a shiny plastic disc, and it was not given to you by someone who did, then either you shoplifted--in which case it's a case for the cops--or the person you bought it from is a "pirate"/bootlegger, and the RIAA should go after him & his presses.
Re: (Score:2)
It's more than just silly, it's deceptive. The BSA won't accept COE's as proof of authenticity. If you read the paperwork that comes with the software carefully, it will tell you what you need to preserve as proof, and it's not always the same. (Sometimes it actually is just the COE and the sheet of paper it comes on, other times it's something else, or some combination of items.)
What le
how does this multiply out? (Score:4, Informative)
Is that $150 per cd "sold through" or $150 per customer who is aware of the lawsuit and actually files to get their cheque? Because I imagine those are entirely different numbers. Also, for those who would like to see Sony hurt worse for this, do remember that that this is more than enough. Any company pulling a stunt like that again will be ignorant, not unconcerned.
So when are desktop OS's going to come installed inside a secure virtual machine OS that is capable of detecting rootkits and possibly doing a little extra scanning on the side? That is long overdue.
Re:how does this multiply out? (Score:5, Insightful)
Wouldn't a better punishment be that Sony is made to stand up and publicize (using such mediums as MTV) the particular CDs that were infected and educate people as to how they can protect against malware. - It openly damages them to those who aren't aware about this (thereby acting as a deterant for anyone else thinking about doing somthing like this), informs the masses as to the lengths DRM goes to (generating more widespread disapproval for DRM) and helps to fight malware through educating the yoot.
Re: (Score:1)
Instructions for uninstalling [sonybmg.com] the rootkits are also on the internet.
I think most people who would really care about DRM issues already know about the Sony rootkit incident.
Re: (Score:2)
Re: (Score:2)
They might begin to care if they realise how far this can go.
Re: (Score:1)
Only it comes with its own Rootkit called DRM...
Re: (Score:2)
Re:how does this multiply out? (Score:5, Funny)
Re: (Score:2)
The number of infected PCs may well not tally well with the number of customers or the number of CDs. Some customers may have bought more than one infected CD and each CD can infect an arbitraty number of PCs. e.g. if it was bought by a lending library a single CD could have infected hundreds...
Re:how does this multiply out? (Score:5, Interesting)
Meanwhile, RIAA wants $750 per song... (Score:5, Insightful)
Re: (Score:2)
Re: (Score:2)
Doesn't this set some kind of precedent, so users now can get away with $150 per rootkit too?
IANAL, so I'm asking seriously.
Re: (Score:1)
Probably not, the $150 is likely based on the estimated cost of repairing the damage done by the rootkit, or the cost for removal by a professional at any rate. If you were to rootkit a server then the potential for damage and cost of removal are likely to be much higher. If you were to rootkit individual machines then this would probably be assessed on the basis of the machines in question.
What is most annoying about this is that it requires the injured party to be pro-active in claiming the money, and f
Re: (Score:1)
What makes Sony say they can pay only $175/-? Who estimates it would take only that much?
FTC Should not have settled at all. They should have charged Sony with criminal trespass, and jailed the CEO.
if i write a rootkit and distribute it inadvertently (because my GF burned it to CD??), would FTC settle? Heck, i would be in Gitmo after being "renditioned" to Syria!
So if you are a corporate, all you get is a se
Re: (Score:2)
The "inadvertently" bit would be tricky, in order for things to work the CD has to be mastered such that Windows automatically executes the malware when someone trys to play the disk. You need to do a few more things that just putting an executable on a data track.
Heck, i would be in Gitmo after being "renditioned" to Syria!
Or your GF or both of you...
Re: (Score:2)
[autorun]
open=myrootkit.exe
Re: (Score:2)
Re: (Score:2)
Actually, the $750 per song is for unintentional infringement. This action was obviously intentional and profit-motivated, the statutory damages in that case are $150,000 per infringement...which would be pretty good, I bet that would actually discourage them from doing this again, as opposed to this garbage settlement, which will have roughly the deterrent effect of fining you or me fifty cents.
Re: (Score:2)
Even that is a highly inflated figure. Actual "loses" are under 10USD, possibly under one.
This action was obviously intentional and profit-motivated, the statutory damages in that case are $150,000 per infringement
Part of the reason to have such massivly inflated figures is to ensure that the amount of money involved is high enough for law enforcement to take an interest. With something like spamming, even when it involves outright fraud, t
Re: (Score:2)
Yes, Sony is getting ripped off big time. Filesharers are simply getting $750 per title shared, not $750 per copy someone else recieved from him.
Sony is not getting charged $750 per song on the DRM CD. They are getting charged $150 for everyone who picked up a copy of the same set of songs from them. How unfair is that? I think they would love to have to pay $750/song for each of the CD titles they distributed regardless of how many copie
Not bad (Score:2, Insightful)
The only thing I'd like to see added onto there is a clause requiring So
Re: (Score:3, Interesting)
Sometimes the IT world just doesn't make its case clear in
Re: (Score:2, Insightful)
Also, their player program that shipped with the rootkit CDs had a 'phone-home' function that loaded a banner
Re: (Score:1)
This would be generous if Sony had damaged a CD. But Sony damaged a PC, something that generally costs 100 times the price of a CD.
While I don't think Sony should have to buy everyone a new PC, I do think Sony got off light.
Re: (Score:2)
Most people who got rooted don't know. Were I to guess at a percentage, I'd guess around 93% of those infected don't know, but I might be underestimating it. This means that any settlement that doesn't require Sony to actively track down those still infected is a poor settlement.
Imagine that a company created a disease organism, and planted it in
By that rationale... (Score:4, Insightful)
From TFA
Hmmm... no mention whether Vista or other Microsoft operating systems will come under fire of the same arguement.
Re: (Score:2)
Hmmm... no mention whether Vista or other Microsoft operating systems will come under fire of the same arguement.
I doubt it. Microsoft has made it pretty clear that their software will be monitoring and controlling its users activities.
Re: (Score:3, Insightful)
The proposed settlement requires Sony BMG to clearly disclose limitations on consumers' use of music CDs, bars it from using collected information for marketing, prohibits it from installing software without consumer consent, and requires it to provide a reasonable means of uninstalling that software.
From the summary, I thought this was about the rootkit, not the DRM functionality it was meant to protect. Why does the settlement require things tha
Banning things which are already illegal (Score:3, Interesting)
Re: (Score:2)
Re: (Score:2)
The settlement requires things that the law requires to prevent Sony from grandfathering this sort of thing in. Sony rootkits had been known to install even when you clicked "No."
This settlement is both better and worse than I thought:
On the one hand, apparently this will cost Sony $150 per proven wrecked computer + one non-rootkitted CD per rootkitted CD (when you consider how highly the RIAA valuies songs, that's a major price for them)+ "change your
Comment removed (Score:3, Interesting)
If someone in their basement pulled the exact..... (Score:5, Insightful)
Re:If someone in their basement pulled the exact.. (Score:5, Insightful)
All the rights of an individual with hardly any of the responsibilities.
How much per song can the RIAA get away with? (Score:1)
Karem
So if I'm reading the settlement site correctly... (Score:5, Interesting)
If you removed the unlawful hack yourself, no matter how much pain and suffering it caused, there is every probability that they will compensate you exactly nothing.
(I mean nothing but the opportunity to exchange your defective CD for a slightly less defective one or a DRM-laden download.)
I think the kicker is that this is one of those fancy federal consent-decrees -- like the one that was used to "break" the Microsoft monopoly way back when. They agree not to be such meanies and in exchange, they receive total immunity from prosecution on any related federal charges and all state laws that conflict with the federal decision are automatically superseded.
I'm so glad that the feds are looking out for me. With punishment like that, Sony surely KNOWS they've been naughty. It's certain that they won't do anything like THAT again.
The REAL point of a class action lawsuit (Score:3, Insightful)
-Eric
Re: (Score:2)
Suing lawyer gets $5 million
And that would make me happy in this case, seriously, Sony should burn for this who cares if people get reimbursed for damages. The victims of hackers rarely get reimbursed. The "damage" isn't the problem, they purposefully hacked into millions of people's computers to harvest personal information for profit. $5 million dollar fine would at least be a start regardless who saw the money. Far better people have gone to jail for doing much less.
Claim form help? (Score:5, Interesting)
One of the questions is as follows:
7. Briefly describe the type of harm / damage / problem you experienced and the steps that you
took in response:
What kinds of problems, other than the pain of removing it, did people have? Was any actual damage done? Did anyone's computer get taken over? I'm just curious what a valid response would be to this, for when I fill out the form.
Apparently some did get taken over (Score:2)
Plus, I don't know, I think the very act of installing a rootkit on someone's computer pretty much qualifies as "taking over" by itself. If someone installed a rootkit on your machine, I'm guessing you'd be a
Re: (Score:1)
Software relicensing costs (Score:1)
Total cost to him: $140 for the removal service and $200+ t
tell them (Score:2, Informative)
Understatement of the year... (Score:5, Insightful)
Huh? "Reasonably difficult"? This damned thing broke Russinovich's [technet.com] machine, and he had to use several utilities he developed himself to get rid of it by looking deeper into the Windows OS than I think Microsoft ever intended (or wanted) anyone to look. How many
"Difficult to uninstall"? Right...
Re: (Score:2)
I Chooose a Better Punishment (Score:5, Interesting)
Re: (Score:1)
Re: (Score:1)
Re: (Score:1)
Re: (Score:1)
Re: (Score:1)
Re: (Score:1)
Two cents (Score:3, Funny)
No, thats all wrong. Sony is supposed to pay out...
Wonder who really gets to pay... (Score:5, Insightful)
Artist monthly statement:
Sales: $$$
Gross royalties (tiny%): $
Deductions:
[ blah blah blah ] $$
DRM legal costs $$
[new this month]
Net Royalties: -$$$
[NB: you won't have to pay us because we're nice like that, we'll just carry it forward]
I have an idea for compensation (Score:2, Funny)
Re: (Score:2)
Naahh, if you got a free PS3 you'd just be induced to run out and buy a Sony HDTV so that in the end Sony would still make money on the deal [proliphus.com]. They wouldn't learn a thing!;)
Damn them anyway! (Score:3, Interesting)
After being yelled at for ruining my computer, she broke the CD and threw it away, and I've lost the receipts for the SB and XP.
I think a more fair settlement would have been to just have Sony give $500 to every man, woman, and child on the planet, and have its CEO spend as much time in a US federal assrape prison as anybody who would have done this to Sony's corporate computers would have, after being caned in Singapore. Then when he was released from US prison, have the Chinese execute him and bill his family for the bullet.
If you work for Sony in any capacity at all, I hate your fucking guts. Please die and take your God damned company with you.
Sorry for the rant.
Re:Damn them anyway! Don't be Sorry (Score:2)
Don't be. You earned the right to it.
Now if your computer is old enough to be running Win98 (mine is as well), consider it's time to upgrade. Try to get XP installed by the factory, since you'll likely like Vista even less, and give the old computer to the daughter. After that, if she stuffs it up, it's her problem, not yours.
How much they should actually pay (Score:1)
Sony BMG should have to pay each infected person the amount of money that it would take to replace their infected system plus the money they lost from not being able to pull all of their data out of the fire. For the average user, this malware probably made their computer totally unsalvagable, so this seems reasonable.
Grrrr Rrrrr Aaah-Oogah!!! (Score:2)
So it took them this much longer to achieve exactly the same settlement, lawyers billing their time all along the way. That's government in action for you.
Blame engineers, not just CEOs (Score:2)
I'm just happy to know that (Score:2)
So does this mean... (Score:2)
That if I get caught planting rootkits on peoples' computers that it's only going to cost me $150 per offense, with no jail time?
Some Sony executives should be serving time. Isn't planting a rootkit on someone's machine a felony in the US?
Re:Vaginas for Jesus: Nice real nice, REMOVE IT (Score:1, Insightful)
These are part of the answer why most internet publicists don't allow the public to comment the news. Which is a shame since some readers do have something interesting to say.
Re: (Score:2)
I know, offtopic.. just feeding the trolls.
Re: (Score:1)
Re: (Score:2)
I'll grant that it's a bit crude, but many teens, esp. geeks, have been treated rather roughtly in the name of J.C., and aren't clever about expressing their anger. Their JUSTIFIED anger.
Personally, I feel that church should be totally separated from state. Meaning NO TAX BREAKS!! I consider powerful organized religions to be socially harmful. I'm only against outlawing them because any law I can think of that would do the job would have even worse soci
Re: (Score:2, Informative)
Sad, but true.