Techdirt:Sony: Rootkits Are Okay, Because No One Knows What They Are
Quote: Thomas Hesse, President of Sony’s Global Digital Business, literally says: “Most people, I think, don’t even know what a rootkit is, so why should they care about it?”
The gall.
The absolute gall.
Using this logic, we should throw out all the asbestos claims—at least, they could have, before people knew it was harming them. After all, people didn’t know asbestos was bad, so why should they care about it?
Ladies and gents, if you don’t know what a rootkit is, I’ll tell you why you should care: A rootkit is basically software you didn’t authorize (like a virus) that hides itself from the system.
I’m a geek. I can typically tell when a virus has infected a computer. And even if I can’t, typically anti-virus software eventually can.
But a rootkit is able to hide itself from the operating system. It’s a virus gone stealthy.
Now, let’s back up a moment, because many people associate “virus” with “destructive”. That’s simply not true. It’s like a gun—by its very existence, it has the possible capability to cause harm, but it might be innocuous—consider that a “toy gun” that fires no bullets is still technically a “gun”. For this analogy, that’s very much appropos. Not all virii necessarily cause harm. (Except that some might cause harm by their very existence, much like pointing a toy gun at a police officer might not have the most positive outcome)
So, not all rootkits themselves might cause harm. And, in fact, Sony’s rootkit is not designed to do harm.
However, it won’t be long, now that knowledge of it is trickling out, that real virus writers will be writing things to exploit the Sony rootkit—because it’s not even a well-designed rootkit: it’s very poorly written, and allows for exploits…
If you’re infected with Sony’s rootkit, if someone is able to write a file that starts with “$sys$” as the name (i.e. instead of somedocument.doc, they call it $sys$somedocument.doc), it is hidden from Windows. Which is how they hide the rootkit from you. But with something as simple as that, it means it’s very easy to write something that exploits it…
This is an outrage.
I am personally boycotting Sony until such time as they completely disavow this entire method, and offer true, complete, and workable solutions to systems they have infected.