Skip to main content

Sony BMG Entertainment Spyware Suits

Just when the music recording industry was actually starting to show signs that it had finally learned some "digital media distribution savvy," one of the leading players does something foolish that raises questions again about the sector's collective inability to adapt to shifting business models.

The Electronic Frontier Foundation filed a class-action lawsuit against Sony BMG Entertainment through which it is demanding that the company further address problems related to the controversial "rootkit"-style copy-protection mechanism that it shipped on an estimated 24 million music CDs.

The suit, filed in Los Angeles County Superior court, alleges that two different types of rootkit DRM (digital rights management) software have been installed on the computers of "millions of unsuspecting music customers" when they played affected CDs on devices running Microsoft Corp.'s Windows operating system.

While the EFF lauds Sony for taking initial steps to fix issues related to one form of the rootkit, known as First4Internet XCP, the filing claims that a second variation of the software, labeled as SunnComm MediaMax, has not been addressed and affects 20 million of the involved CDs.

According to the EFF, the MediaMax software installs itself on computers even when users choose not to run the application, and the group contends that the application does not include any feature for deleting the program entirely.

The lawsuit claims that the rootkit software transmits information on individual usage habits back to Sony BMG, including details of what music people listen to, allowing the company to spy on customers and track their habits.

The State of Texas has also filed a civil law suit. Texas is seeking civil penalties of $100,000 per violation of the state's Consumer Protection Against Computer Spyware Act, which was enacted earlier this year.

Popular posts from this blog

The Impending GenAI Security Debt

Organizations that were experimenting with Applied-AI in isolated pilot programs just two years ago are now embedding it into core workflows, customer-facing products, and business-critical infrastructure. But as technology matures, a troubling pattern is emerging: speed of deployment is consistently outpacing the security discipline required to protect it. A new Gartner market study exposes the risk that many technology leaders have instinctively sensed but struggled to quantify. GenAI Security Market Development By 2028, 25 percent of all enterprise generative AI (GenAI) applications will experience at least five minor security incidents per year, that's up from just 9 percent in 2025. That represents nearly a threefold increase in less than three years, and the trend does not stop there. Gartner further projects that by 2029, 15 percent of all enterprise GenAI apps will experience at least one major security incident per year, compared to only 3 percent in 2025. Meanwhile, the d...