June 24, 2004
New Beastie Boys CD a Virus Threat?

UK's The Register: Beastie Boys CD installs virus

A new Beastie Boys' CD called "To the Five Boroughs" (Capitol Records), is raising hackles around the Web for reputedly infecting computers with a virus.

According to a recent thread at BugTraq, an executable file is automatically and silently installed on the user's machine when the CD is loaded. The file is said to be a driver that prevents users from ripping the CD (and perhaps others), and attacks both Windows boxen and Macs.

The infected CD is being distributed worldwide except in the USA and UK, which prevents us from giving a firsthand report. However, according to hearsay, we gather that the Windows version exploits the 'autorun' option, and that the Mac version affects the auto play option.

On Windows, when a CD is loaded, a text file called autorun.inf is read, and any instructions within it are executed. In this case, the machine is instructed to install some manner of DRM driver that prevents copying. We haven't seen either the .inf file or any of the executables, so we can't say how or at what level it accomplishes this - or if indeed it actually does accomplish this.

But assuming that the unconfirmed reports are accurate, we have here a media company infecting users' machines silently with a file that affects a computer's functionality, without first obtaining informed consent: a likely violation of pretty much every jurisdiction's anti-hacking laws. It's possible to foresee criminal charges being brought at some point: after all, having a good reason for spreading malware has never been much of a defence in court. And a file that alters a computer's functioning without the owner's informed consent is the very definition of malware. Because this malware can be transferred from machine to machine on a removable disk, and requires user interaction to spread, it is, quite simply, a computer virus. (A worm, on the other hand, is distinguished by its ability to spread without user interaction.)


There's an extended technical discussion in the rest of that link.

Further corroboration from Slashdot: Beastie Boys' New Album Silently Installs DRM Code

"After more than five years, the Beastie Boys have released a new album. It seems that the retail disc is bundled with a copy protection autoinstaller which silently silently puts itself onto the listener's computer. Many listeners are up in arms and some are venting their frustrations on the band's website."

Register link Via Radley Balko, on whose website a commenter says this was a Capitol Records decision and not the band's. A check of their message board apparently confirms this.

All I know is I wouldn't put up with it if I were in any position of power in the band.



Posted by Drizzten at June 24, 2004 03:00 PM

ATTENTION: Comments are closed. You are viewing my old blog, archived for search engine purposes.
To view the new blog, please go to the homepage. To find the current version of this entry, search here.

Comments

Sounds like fraud to me.

Posted by: BilLee Miller on June 25, 2004 04:55 AM
Post a comment
Name:


Email Address:


URL:


Comments:


ATTENTION: Comments are closed. You are viewing my old blog, archived for search engine purposes.
To view the new blog, please go to the homepage. To find the current version of this entry, search here.

HTML formatting is disabled. However, you may post a raw URL as it will show up as a clickable link.

Comments are the property and responsibilty of the commenter.

I reserve the right to delete any comment I wish as this is my property you are commenting upon, but I'm pretty laid-back so it isn't likely to happen unless you are some psycho idiot jerk. Oh, and unless you have my permission to promote your good or service, you are wasting your time: unsolicited advertisements will result in comment deletion and URL banning. This blog ain't for you spammers or the crap you want to sell.


Dislike the format, layout, color, or having a hard time reading the text? Comment here and let me know what you think.

Remember info?



Back to the top