I guess Sony wasn't happy getting scads of bad publicity from their Rootkit CD adventure - they've expanded the rootkit game to one of their USB stick products. From f-secure:
We received a report that our F-Secure DeepGuard HIPS system was warning about a USB stick software driver. The USB stick in question has a built-in fingerprint reader. The case seemed unusual so we ordered a couple of USB sticks with fingerprint authentication. We installed the software on a test machine and were quite surprised to see that after installation our F-Secure BlackLight rootkit detector was reporting hidden files on the system.
...
This USB stick with rootkit-like behavior is closely related to the Sony BMG case. First of all, it is another case where rootkit-like cloaking is ill advisedly used in commercial software. Also, the USB sticks we ordered are products of the same company -- Sony Corporation.
This isn't ordinary stupidity at work here - after the previous incident, this is deep, deep stupidity.
Technorati Tags:
PR, malware