November 2005 Entries

Followup on Sony Rootkit Story

The issue of Sony's CD-borne rootkit software just keeps getting weirder: Over the weekend a Finnish researcher named Muzzy noticed a potential vulnerability in the web-based uninstaller that Sony offers to users who want to remove the First4Internet XCP copy protection software. We took a detailed look at the software and discovered that it is indeed possible for an attacker to exploit this weakness. For affected users, this represents a far greater security risk than even the original Sony rootkit. The consequences of the flaw are severe. It allows any web page you visit to download, install, and run any code it...

Hydrogen powered Mazda coming soon to a dealer near you

2 years ago, Mazda rocked the car world when it unveiled a hydrogen-powered version of its legendary rotary engine. In the spring, you'll be able to lease a Mazda RX-8 equipped with that engine. Hydrogen is one of the most exciting developments in the global effort to reduce our consumption of fossil fuels.  Not only does it burn cleanly, but it takes practically no electricity to produce, and it's cheap and plentiful.  Other auto makers are pursuing fuel cell technology, which is still years off and the energy they store still ultimately comes from burning fossil fuels like coal and oil. Very exciting...

That didn't take long

A new wave of bots exploiting Sony's ill-conceived DRM rootkit has been found in the wild. If you've been living in a cave the past week, you might have missed the discovery by security superhero Mark Russinovich of a rootkit that had been surreptitiously installed on his system when he played a Sony copy-protected music CD in his computer.  Seems Sony considers their right to protect their digital rights trumps your right to a properly functioning, and safe, computer, and has been shipping this rootkit software on its CDs since April.  The software can disable other music players on your system, has no discernible...

Rosa Parks, rest in peace

I don't know much about Rosa Parks, beyond what she's famous for.  I regret that.  There are a whole lot of people in this world, some now gone, that deserve the world to know them better. Regardless, I can't imagine a world that had gone without Ms. Parks and her famous deed so long ago.  I can't think of a single person in the modern age that has made such an impact on a country as that woman did.  What would the world be like if she had never come to be?  If she had said “Screw it”, and got up...

The Secure World Panel

So if you remember a couple weeks ago I was shanghai'd into moderating a panel on Identity Management at SecureWorld Expo in Seattle. This was my first major speaking role at a conference, so I was a bit stressed to say the least.  I just *knew* we'd be 20 minutes into the talk when I ran out of questions, and pictured myself saying something like “So.  Um.  How about those Mariners?” So I spent a lot of time researching the topic, and finding out what issues people were running into, and came up with about a dozen solid questions to ask.  I figured that...