You Knew It Was Inevitable [7:58 pm]
I also like how “Sony BMG” is being used to name a computer system defect - the PR folks must be having a cow: Hackers use Sony BMG to hide on PCs [pdf]
A computer security firm said on Thursday it had discovered the first virus that uses music publisher Sony BMG’s controversial CD copy-protection software to hide on PCs and wreak havoc.
Under a subject line containing the words “Photo approval,” a hacker has mass-mailed the so-called Stinx-E trojan virus to British email addresses, said British anti-virus firm Sophos.
When recipients click on an attachment, they install malware, which may tear down a computer’s firewall and give hackers access to a PC. The malware hides by using Sony BMG software that is also hidden — the software would have been installed on a computer when consumers played Sony’s copy-protected music CDs.
“This leaves Sony in a real tangle. It was already getting bad press about its copy-protection software, and this new hack exploit will make it even worse,” said Sophos’s Graham Cluley.
Ya think?
Related: Give Me Back My Digital Rights!
See also CNet’s ‘Bots’ for Sony CD software spotted online
Later: Sony BMG pulls CD software [pdf]; WaPo: Sony to Suspend Making Antipiracy CDs; also a broader commentary in the NYTimes’ The Ghost in the CD; Sony rootkit prompts office clampdown on CD use

