Sony BMG's Copy-Protection Quagmire
文章来源: 文章作者: 发布时间:2007-04-02 02:51 字体: [ ]  进入论坛
(单词翻译:双击或拖选)
 

Sony BMG is the world's second largest music company, responsible for approximately one-quarter of all album sales in the United States. Among the CDs that it has been selling in 2005, however, are millions that include copy-protection software. If the owner of one of these CDs wants to play or copy these CDs on her Windows computer, she must first install software intended to restrict the number and kind of copies that her computer can make.

After quietly distributing these CDs for months, Sony BMG was caught flat-footed when computer security professionals in early November 2005 discovered that its copy-protection software creates serious security risks. At least one variant1 of the protection software installs itself even if users decline the pop-up end-user license2 agreement and eject the CD. Moreover, when the CDs are played, the software phones home to servers controlled by Sony BMG, reporting details regarding the user's listening habits. Finally, once installed, the copy-protection software is difficult, if not impossible, to uninstall.

The response from customers, musicians and consumer journalists has been swift and merciless. A reporter for Stereophile magazine put it this way: In other words, Sony installs files on its consumers' computers without their permission, does not allow the files to be removed, and spies on its customers. His verdict: Weasels, we calls 'em. On the opinion pages of The New York Times, a working musician urged the music industry to recognize that copy-protection software is bad for everyone, consumers, musicians and labels alike. At online retailer4 Amazon.com, the reviews of Sony BMG's copy-protected CDs are filled with customer complaints.

But the public relations meltdown was only the beginning of Sony BMG's troubles. Within weeks, more than 10 class action lawsuits5 in both state and federal courts had been filed against Sony BMG (including two in which this author serves as counsel). Texas Attorney General Greg Abbott has also filed an action against Sony BMG, and the attorneys general of New York, Illinois and Massachusetts have expressed concern about the CDs in question.

Sony BMG's experience is quickly shaping up into an object lesson in the legal risks that companies can face when they distribute faulty software and mislead the public.

THE PROBLEM AND SONY BMG'S RESPONSE

All of Sony BMG's copy-protected CDs include one of two protection technologies, either First4Internet's Extended Copy Protection (XCP) or SunnComm's MediaMax software.

The initial security revelations, published on the SysInternals Web log in early November 2005, related to the XCP software. The Web log reported that the XCP software automatically installed a rootkit on Windows computers. A rootkit is essentially6 the computer equivalent of Harry7 Potter's invisibility cloak, permitting software to render itself invisible to a computer's operating system, anti-virus and anti-spyware software, thereby8 hiding itself from the computer user. Rootkits are generally associated with viruses, spyware and other malware that wants to burrow9 deep into a computer in order to avoid discovery and removal. The XCP rootkit posed a serious security risk because, once installed on a user's computer, it could be used by other third parties to hide their own malicious10 software.

Sony BMG initially11 responded to the XCP revelations by attempting to downplay the risks, with one senior Sony BMG executive opining that most people, I think, do not even know what a rootkit is, so why should they care about it? While typical computer users may not have appreciated the vulnerabilities created by XCP's rootkit feature, virus writers responded within days by developing and releasing viruses designed to exploit it. Soon thereafter, the leading makers12 of anti-spyware and anti-virus tools, including Microsoft, Symantec and Computer Associates, branded XCP a security threat. Their concerns were soon echoed by the U.S. Computer Emergency Readiness Team (US-CERT), an arm of the Department of Homeland Security charged with the task of protecting the nation's Internet infrastructure13.

Security woes14 were only part of the problem. Having paid full retail3 price for the CDs, music fans got them home only to discover that using them on a computer was subject to a bewildering and outrageous15 array of contractual conditions imposed by a mandatory16 end-user license agreement (EULA). For example, the EULA includes provisions purporting17 to require the immediate18 deletion of all copies if a user files for personal bankruptcy19 or parts with possession of the CD (including, presumably, if the CD were stolen from your car). The EULA also attempts to limit Sony BMG's liability to no more than $5, well short of a refund20 of the purchase price, and to force consumers to litigate in New York if they have any disputes with Sony BMG. In short, when it came to using these CDs on their computers, music fans are getting far less for their money than they had with traditional CDs.

Sony BMG's initial efforts to address the problem were half-hearted, at best. An early uninstaller, offered to customers only after completing a complex request procedure, created new security vulnerabilities. Nearly two weeks elapsed before Sony BMG finally announced that it would halt further production of the XCP CDs. Ultimately, Sony BMG announced that it would offer to exchange XCP-protected CDs for unprotected replacements21. More than a month after the initial public revelations, a revised XCP uninstaller was finally released.

The other copy-protection technology, SunnComm's MediaMax, presented its own problems. Researchers discovered that the MediaMax software installed itself on Windows computers even when users declined the pop-up license agreement. When Sony BMG released an uninstaller for MediaMax, it created additional security risks. The Electronic Frontier Foundation (EFF) subsequently commissioned an examination of the MediaMax software, revealing a potentially dangerous security vulnerability. When Sony BMG released a patch to address this flaw, another vulnerability was discovered, necessitating22 the withdrawal23 of the patch.

Both XCP and MediaMax are also troubling from a privacy perspective, as they routinely transmit information over the Internet to servers controlled by Sony BMG, sending information about a user's listening habits. This phone home feature is not disclosed to CD buyers, who are instead told by Sony BMG that no information is ever collected about you or your computer without your consenting.

THE LEGAL CLAIMS

The numerous lawsuits filed against Sony BMG in the wake of the protected-CD debacle provide an illuminating24 overview25 of the kinds of claims that companies may face when distributing faulty software.

One set of claims is rooted in statutes27 forbidding computer intrusion. For example, a number of the class action complaints rely on the federal Computer Fraud and Abuse Act (CFAA), 18 U.S.C. § 1030, which forbids accessing a computer without, or in excess of, the authority of the owner of the computer. Private civil litigants28 are entitled to bring suit where the prohibited computer intrusion causes losses exceeding $5,000, threatens public health or safety, or damages a computer system used by government entities29 for judicial30, national security or defense31 functions. Similar state laws have also been invoked33, including California's Penal34 Code §502, which prohibits the unauthorized introduction of a contaminant into a computer that transmits information about a computer to third parties without authorization35.

Recently enacted36 state laws aimed at spyware and adware are a second basis for legal claims against Sony BMG. Class actions filed in California, for example, allege37 violations38 of recently enacted California Business & Professions Code §22947.3, which prohibits deceptively taking control of a user's computer, modifying computer settings or preventing users from uninstalling software. Similarly, the Texas attorney general relied on the Consumer Protection Against Computer Spyware Act, Texas Business & Commercial Code §48.053, which prohibits manipulating software in order to prevent a computer user from detecting, locating and removing the software. The Texas statute26 also prohibits intentionally40 misrepresenting that the installation of software is necessary for security or privacy reasons. §48.055(1). In addition to California and Texas, 10 other states have enacted laws aimed at spyware, many of which may reach Sony BMG's conduct.

Several complaints brought in California also articulate claims based on the Consumer Legal Remedies Act (CLRA), California Civil Code §1770, a state consumer protection statute applicable to consumer transactions involving goods. This statute forbids, among other things, the imposition of unconscionable contractual terms on consumers, misrepresentations about a product and misleading advertising41.

Some class action complaints have also included common law trespass42 to chattels43 claims, alleging44 that Sony BMG's copy-protection software constitutes unauthorized intermeddling with the possessory interests of computer owners, resulting in damage to their computers. While this theory of liability has proven controversial when applied45 in Internet contexts, several courts have indicated a willingness to entertain such claims. See Register.com v. Verio, 356 F.3d 393, 404 (2d Cir46. 2004); eBay v. Bidder's Edge, 100 F.Supp.2d 1058 (N.D. Cal. 2000).

Finally, many of the complaints include allegations that Sony BMG's conduct amounts to an unfair or deceptive39 trade practice, fraud, or false advertising under applicable state statutes. The class actions filed in California, for example, invoke32 California's Business & Professions Code §§17200 and 17500, while those filed in New York invoke General Business Law §§349 and §§350.

From a legal perspective, the many suits against Sony BMG will raise a welter of questions of first impression for the courts on whose dockets they appear. Whether those courts have an opportunity to rule on all of them may depend on whether Sony BMG opts47 to seek an early and comprehensive settlement aimed at repairing the damage that already has been done by its ill-considered copy-protection strategy. But irrespective of the outcome in these cases, counsel advising companies that distribute software with their products have been afforded a sneak preview of the kinds of legal actions that can be brought against clients that release defective software into the national marketplace



点击收听单词发音收听单词发音  

1 variant GfuzRt     
adj.不同的,变异的;n.变体,异体
参考例句:
  • We give professional suggestions according to variant tanning stages for each customer.我们针对每位顾客不同的日晒阶段,提供强度适合的晒黑建议。
  • In a variant of this approach,the tests are data- driven.这个方法的一个变种,是数据驱动的测试。
2 license B9TzU     
n.执照,许可证,特许;v.许可,特许
参考例句:
  • The foreign guest has a license on the person.这个外国客人随身携带执照。
  • The driver was arrested for having false license plates on his car.司机由于使用假车牌而被捕。
3 retail VWoxC     
v./n.零售;adv.以零售价格
参考例句:
  • In this shop they retail tobacco and sweets.这家铺子零售香烟和糖果。
  • These shoes retail at 10 yuan a pair.这些鞋子零卖10元一双。
4 retailer QjjzzO     
n.零售商(人)
参考例句:
  • What are the retailer requirements?零售商会有哪些要求呢?
  • The retailer has assembled a team in Shanghai to examine the question.这家零售商在上海组建了一支团队研究这个问题。
5 lawsuits 1878e62a5ca1482cc4ae9e93dcf74d69     
n.诉讼( lawsuit的名词复数 )
参考例句:
  • Lawsuits involving property rights and farming and grazing rights increased markedly. 涉及财产权,耕作与放牧权的诉讼案件显著地增加。 来自辞典例句
  • I've lost and won more lawsuits than any man in England. 全英国的人算我官司打得最多,赢的也多,输的也多。 来自辞典例句
6 essentially nntxw     
adv.本质上,实质上,基本上
参考例句:
  • Really great men are essentially modest.真正的伟人大都很谦虚。
  • She is an essentially selfish person.她本质上是个自私自利的人。
7 harry heBxS     
vt.掠夺,蹂躏,使苦恼
参考例句:
  • Today,people feel more hurried and harried.今天,人们感到更加忙碌和苦恼。
  • Obama harried business by Healthcare Reform plan.奥巴马用医改掠夺了商界。
8 thereby Sokwv     
adv.因此,从而
参考例句:
  • I have never been to that city,,ereby I don't know much about it.我从未去过那座城市,因此对它不怎么熟悉。
  • He became a British citizen,thereby gaining the right to vote.他成了英国公民,因而得到了投票权。
9 burrow EsazA     
vt.挖掘(洞穴);钻进;vi.挖洞;翻寻;n.地洞
参考例句:
  • Earthworms burrow deep into the subsoil.蚯蚓深深地钻进底土。
  • The dog had chased a rabbit into its burrow.狗把兔子追进了洞穴。
10 malicious e8UzX     
adj.有恶意的,心怀恶意的
参考例句:
  • You ought to kick back at such malicious slander. 你应当反击这种恶毒的污蔑。
  • Their talk was slightly malicious.他们的谈话有点儿心怀不轨。
11 initially 273xZ     
adv.最初,开始
参考例句:
  • The ban was initially opposed by the US.这一禁令首先遭到美国的反对。
  • Feathers initially developed from insect scales.羽毛最初由昆虫的翅瓣演化而来。
12 makers 22a4efff03ac42c1785d09a48313d352     
n.制造者,制造商(maker的复数形式)
参考例句:
  • The makers of the product assured us that there had been no sacrifice of quality. 这一产品的制造商向我们保证说他们没有牺牲质量。
  • The makers are about to launch out a new product. 制造商们马上要生产一种新产品。 来自《简明英汉词典》
13 infrastructure UbBz5     
n.下部构造,下部组织,基础结构,基础设施
参考例句:
  • We should step up the development of infrastructure for research.加强科学基础设施建设。
  • We should strengthen cultural infrastructure and boost various types of popular culture.加强文化基础设施建设,发展各类群众文化。
14 woes 887656d87afcd3df018215107a0daaab     
困境( woe的名词复数 ); 悲伤; 我好苦哇; 某人就要倒霉
参考例句:
  • Thanks for listening to my woes. 谢谢您听我诉说不幸的遭遇。
  • She has cried the blues about its financial woes. 对于经济的困难她叫苦不迭。
15 outrageous MvFyH     
adj.无理的,令人不能容忍的
参考例句:
  • Her outrageous behaviour at the party offended everyone.她在聚会上的无礼行为触怒了每一个人。
  • Charges for local telephone calls are particularly outrageous.本地电话资费贵得出奇。
16 mandatory BjTyz     
adj.命令的;强制的;义务的;n.受托者
参考例句:
  • It's mandatory to pay taxes.缴税是义务性的。
  • There is no mandatory paid annual leave in the U.S.美国没有强制带薪年假。
17 purporting 662e1eb2718c2773c723dc9acb669891     
v.声称是…,(装得)像是…的样子( purport的现在分词 )
参考例句:
  • Cindy Adams (Columnist) : He's purporting to be Mother Teresa. 辛迪?亚当斯(专栏作家):他无意成为德兰修女。 来自互联网
  • To prohibit certain practices purporting to be sales by auction. 本条例旨在对看来是以拍卖方式作出的售卖中某些行为予以禁止。 来自互联网
18 immediate aapxh     
adj.立即的;直接的,最接近的;紧靠的
参考例句:
  • His immediate neighbours felt it their duty to call.他的近邻认为他们有责任去拜访。
  • We declared ourselves for the immediate convocation of the meeting.我们主张立即召开这个会议。
19 bankruptcy fPoyJ     
n.破产;无偿付能力
参考例句:
  • You will have to pull in if you want to escape bankruptcy.如果你想避免破产,就必须节省开支。
  • His firm is just on thin ice of bankruptcy.他的商号正面临破产的危险。
20 refund WkvzPB     
v.退还,偿还;n.归还,偿还额,退款
参考例句:
  • They demand a refund on unsatisfactory goods.他们对不满意的货品要求退款。
  • We'll refund your money if you aren't satisfied.你若不满意,我们愿意退款给你。
21 replacements 1f6e0d51ec9f57961e86b4aa2e91ef29     
n.代替( replacement的名词复数 );替换的人[物];替代品;归还
参考例句:
  • They infiltrated behind the lines so as to annoy the emery replacements. 他们渗透敌后以便骚扰敌军的调度。 来自辞典例句
  • For oil replacements, cheap suddenly looks less of a problem. 对于石油的替代品来说,价格变得无足轻重了。 来自互联网
22 necessitating 53a4b31e750840357e61880f4cd47201     
使…成为必要,需要( necessitate的现在分词 )
参考例句:
  • Multiple network transmissions overlapping in the physical channel, resulting in garbled data and necessitating retransmission. 多个网络传输重迭发生在同一物理信道上,它导致数据被破坏,因而必须重传。
  • The health status of 435 consecutive patients with sleep disturbances necessitating polysomnography was investigated. 435个患有睡眠紊乱的病人进行多导睡眠描记法对其健康状况进行调查。
23 withdrawal Cfhwq     
n.取回,提款;撤退,撤军;收回,撤销
参考例句:
  • The police were forced to make a tactical withdrawal.警方被迫进行战术撤退。
  • They insisted upon a withdrawal of the statement and a public apology.他们坚持要收回那些话并公开道歉。
24 illuminating IqWzgS     
a.富于启发性的,有助阐明的
参考例句:
  • We didn't find the examples he used particularly illuminating. 我们觉得他采用的那些例证启发性不是特别大。
  • I found his talk most illuminating. 我觉得他的话很有启发性。
25 overview 8mrz1L     
n.概观,概述
参考例句:
  • The opening chapter gives a brief historical overview of transport.第一章是运输史的简要回顾。
  • The seminar aims to provide an overview on new media publishing.研讨会旨在综览新兴的媒体出版。
26 statute TGUzb     
n.成文法,法令,法规;章程,规则,条例
参考例句:
  • Protection for the consumer is laid down by statute.保障消费者利益已在法令里作了规定。
  • The next section will consider this environmental statute in detail.下一部分将详细论述环境法令的问题。
27 statutes 2e67695e587bd14afa1655b870b4c16e     
成文法( statute的名词复数 ); 法令; 法规; 章程
参考例句:
  • The numerous existing statutes are complicated and poorly coordinated. 目前繁多的法令既十分复杂又缺乏快调。 来自英汉非文学 - 环境法 - 环境法
  • Each agency is also restricted by the particular statutes governing its activities. 各个机构的行为也受具体法令限制。 来自英汉非文学 - 环境法 - 环境法
28 litigants c9ff68410d06ca6c01713855fdb780e5     
n.诉讼当事人( litigant的名词复数 )
参考例句:
  • Litigants of the two parties may reconcile of their own accord. 双方当事人可以自行和解。 来自口语例句
  • The litigants may appeal against a judgment or a ruling derived from the retrial. 当事人可就重审案件的判决或裁定进行上诉。 来自口语例句
29 entities 07214c6750d983a32e0a33da225c4efd     
实体对像; 实体,独立存在体,实际存在物( entity的名词复数 )
参考例句:
  • Our newspaper and our printing business form separate corporate entities. 我们的报纸和印刷业形成相对独立的企业实体。
  • The North American continent is made up of three great structural entities. 北美大陆是由三个构造单元组成的。
30 judicial c3fxD     
adj.司法的,法庭的,审判的,明断的,公正的
参考例句:
  • He is a man with a judicial mind.他是个公正的人。
  • Tom takes judicial proceedings against his father.汤姆对他的父亲正式提出诉讼。
31 defense AxbxB     
n.防御,保卫;[pl.]防务工事;辩护,答辩
参考例句:
  • The accused has the right to defense.被告人有权获得辩护。
  • The war has impacted the area with military and defense workers.战争使那个地区挤满了军队和防御工程人员。
32 invoke G4sxB     
v.求助于(神、法律);恳求,乞求
参考例句:
  • Let us invoke the blessings of peace.让我们祈求和平之福。
  • I hope I'll never have to invoke this clause and lodge a claim with you.我希望我永远不会使用这个条款向你们索赔。
33 invoked fabb19b279de1e206fa6d493923723ba     
v.援引( invoke的过去式和过去分词 );行使(权利等);祈求救助;恳求
参考例句:
  • It is unlikely that libel laws will be invoked. 不大可能诉诸诽谤法。
  • She had invoked the law in her own defence. 她援引法律为自己辩护。 来自《简明英汉词典》
34 penal OSBzn     
adj.刑罚的;刑法上的
参考例句:
  • I hope you're familiar with penal code.我希望你们熟悉本州法律规则。
  • He underwent nineteen years of penal servitude for theft.他因犯了大窃案受过十九年的苦刑。
35 authorization wOxyV     
n.授权,委任状
参考例句:
  • Anglers are required to obtain prior authorization from the park keeper.垂钓者必须事先得到公园管理者的许可。
  • You cannot take a day off without authorization.未经批准你不得休假。
36 enacted b0a10ad8fca50ba4217bccb35bc0f2a1     
制定(法律),通过(法案)( enact的过去式和过去分词 )
参考例句:
  • legislation enacted by parliament 由议会通过的法律
  • Outside in the little lobby another scene was begin enacted. 外面的小休息室里又是另一番景象。 来自英汉文学 - 嘉莉妹妹
37 allege PfEyT     
vt.宣称,申述,主张,断言
参考例句:
  • The newspaper reporters allege that the man was murdered but they have given no proof.新闻记者们宣称这个男人是被谋杀的,但他们没提出证据。
  • Students occasionally allege illness as the reason for absence.学生时不时会称病缺课。
38 violations 403b65677d39097086593415b650ca21     
违反( violation的名词复数 ); 冒犯; 违反(行为、事例); 强奸
参考例句:
  • This is one of the commonest traffic violations. 这是常见的违反交通规则之例。
  • These violations of the code must cease forthwith. 这些违犯法规的行为必须立即停止。
39 deceptive CnMzO     
adj.骗人的,造成假象的,靠不住的
参考例句:
  • His appearance was deceptive.他的外表带有欺骗性。
  • The storyline is deceptively simple.故事情节看似简单,其实不然。
40 intentionally 7qOzFn     
ad.故意地,有意地
参考例句:
  • I didn't say it intentionally. 我是无心说的。
  • The local authority ruled that he had made himself intentionally homeless and was therefore not entitled to be rehoused. 当地政府裁定他是有意居无定所,因此没有资格再获得提供住房。
41 advertising 1zjzi3     
n.广告业;广告活动 a.广告的;广告业务的
参考例句:
  • Can you give me any advice on getting into advertising? 你能指点我如何涉足广告业吗?
  • The advertising campaign is aimed primarily at young people. 这个广告宣传运动主要是针对年轻人的。
42 trespass xpOyw     
n./v.侵犯,闯入私人领地
参考例句:
  • The fishing boat was seized for its trespass into restricted waters.渔船因非法侵入受限制水域而被扣押。
  • The court sentenced him to a fine for trespass.法庭以侵害罪对他判以罚款。
43 chattels 285ef971dc7faf3da51802efd2b18ca7     
n.动产,奴隶( chattel的名词复数 )
参考例句:
  • An assignment is a total alienation of chattels personal. 动产转让是指属人动产的完全转让。 来自辞典例句
  • Alan and I, getting our chattels together, struck into another road to reassume our flight. 艾伦和我收拾好我们的财物,急匆匆地走上了另一条路,继续过我们的亡命生活。 来自辞典例句
44 alleging 16407100de5c54b7b204953b7a851bc3     
断言,宣称,辩解( allege的现在分词 )
参考例句:
  • His reputation was blemished by a newspaper article alleging he'd evaded his taxes. 由于报上一篇文章声称他曾逃税,他的名誉受到损害。
  • This our Peeress declined as unnecessary, alleging that her cousin Thornhill's recommendation would be sufficient. 那位贵人不肯,还说不必,只要有她老表唐希尔保荐就够了。
45 applied Tz2zXA     
adj.应用的;v.应用,适用
参考例句:
  • She plans to take a course in applied linguistics.她打算学习应用语言学课程。
  • This cream is best applied to the face at night.这种乳霜最好晚上擦脸用。
46 cir 200a0788aebd9afa51a778331cb0d3c8     
abbr.circular 通知;circulation (货币,货物等的)流通;circle 圆;circa (Latin=about) (拉丁语)大约
参考例句:
  • The regime-switching model about interest rate extends Vasicek and CIR models. 利率的结构转换模型是对Vasicek模型和CIR模型的推广。 来自互联网
  • The CIR blending DFS algorithm is introduced. 介绍了CIR混合动态频率选择 (DFS)算法 。 来自互联网
47 opts eb4112b6a6b76c8a84808a40baa94769     
v.选择,挑选( opt的第三人称单数 )
参考例句:
  • One player hoping to get another chance to shine if Mourinho opts to rest Cole backBridge. 假如穆里尼奥安排阿。科尔轮休,那么同一位置上的将会得到一个上场的机会来证实自己。 来自互联网
  • If he opts out this summer, he d sign a five year deal. 如果今夏跳出,他估计会签五年。 来自互联网
TAG标签:
发表评论
请自觉遵守互联网相关的政策法规,严禁发布色情、暴力、反动的言论。
评价:
表情:
验证码:点击我更换图片