Electronic Frontier Foundation
EFF is the leading civil liberties group defending
your rights in the digital world. » About Us
  • Home
  • About
  • Our Work
  • Deeplinks Blog
  • Press Room
  • Take Action
  • Shop
Home » Deeplinks Blog » December, 2005
  • Deeplinks Archives
    • October, 2011
    • September, 2011
    • August, 2011
    • July, 2011
    • June, 2011
    • May, 2011
    • April, 2011
    • March, 2011
    • More Archives
  • Blog Categories
    • Accessibility for the Reading Disabled
    • Analog Hole
    • Announcement
    • Anonymity
    • Anti-Counterfeiting Trade Agreement
    • Bloggers' Rights
    • Broadcast Flag
    • Broadcasting Treaty
    • CALEA
    • Call To Action
    • CDA 230
    • Cell Tracking
    • Coders' Rights Project
    • Commentary
    • Copyright Trolls
    • Council of Europe
    • Criminalizing Content
    • Development Agenda
    • Digital Books
    • Digital Radio
    • Digital Rights Management
    • Digital Video
    • DMCA
    • DMCA Rulemaking
    • Do Not Track
    • E-Voting Rights
    • EFF Europe
    • EFF15
    • File Sharing
    • FOIA Litigation for Accountable Government
    • Free Speech
    • Free Trade Agreement of the Americas
    • Hollywood v. DVD
    • Innovation
    • Intellectual Property
    • International
    • International Privacy Standards
    • Legal Analysis
    • Legislative Analysis
    • Locational Privacy
    • Mandatory Data Retention
    • miniLinks
    • National Security Letters
    • Net Neutrality
    • News Roundup
    • News Update
    • No Downtime for Free Speech Campaign
    • NSA Spying
    • Online Behavioral Tracking
    • Patents
    • PATRIOT Act
    • Pen Trap
    • Printers
    • Privacy
    • Real ID
    • RFID
    • Search Engines
    • Search Incident to Arrest
    • Security
    • Social Networks
    • Technical Analysis
    • Terms Of (Ab)Use
    • Test Your ISP
    • The COICA Internet Censorship and Copyright Bill
    • The Global Network Initiative
    • Transparency
    • Travel Screening
    • Trusted Computing
    • Video Games
    • Wikileaks
    • WIPO
December 9th, 2005
Email This Digg This Post this to Reddit Share this blog post with delicious Share this on Facebook Tweet this blog post Dent this blog post

Open Letter to SunnComm/MediaMax

Deeplink by Kurt Opsahl

Mr. Kevin M. Clement
President and Chief Executive Officer
MediaMax Technologies, Inc.

Mr. Clement:

As you know, we have already discovered one security concern arising from the MediaMax software, resulting in the patch issued on Tuesday and the revised patch issued yesterday.

The Electronic Frontier Foundation (EFF) remains concerned that additional security flaws will be discovered in MediaMax software, in both version 5 and version 3. EFF isn't alone in this concern. Indeed, as Professor Ed Felten has noted, "Experience teaches that where there is one bug, there are probably others. That's doubly true where the basic design of the product is risky. I'd be surprised if there aren't more security bugs lurking in MediaMax." See http://www.freedom-to-tinker.com/?p=944.

While Sony BMG has taken some steps to address the security vulnerabilities in the MediaMax software, we are very concerned about consumers who purchase "MediaMax'd" CDs from labels other than Sony BMG, such as Cuban Link's "Chain Reaction" by Men of Business Records, Peter Cetera's "You Just Gotta Love Christmas" by Viastar Records or MediaMax'd releases on KOCH Records. Many of these consumers have not been notified of this security issue, and indeed may be unaware that they even have a security vulnerability.

To ensure that all affected consumer received notice of the problem and to reduce the possibility that such problems will re-occur, we urge SunnComm International, Inc. and MediaMax Technology Corp. to promptly:

  1. Publish a list of every CD, regardless of label, that employs the MediaMax technology, including the version.

  2. Provide every other label using MediaMax with information about the vulnerability, and confirm this to EFF.
  3. Work with those labels to quickly and effectively resolve the security vulnerability.
  4. Publicly commit to ensuring that MediaMax software does not install when the user clicks "No."
  5. Publicly commit to including true uninstallers in all versions of MediaMax software.
  6. Publicly commit to providing all future MediaMax software to an independent security testing firm, and to the public release of the results of such test.

We look forward to a prompt response affirming your intent to take the above steps and setting forth a timeline for their completion.

Sincerely,

Kurt Opsahl
Staff Attorney, Electronic Frontier Foundation

Related Issues: Digital Rights Management

[Permalink]

Donate to EFF
Make a One-Time Contribution
Join EFF
Become a Member

Subscribe to EFFector

EFF's Newsletter and Action Alerts

Headlines

  • Victory for Reader Privacy
  • The Humble Frozen Synapse Bundle
  • Don't Let Privacy Law Get Stuck in 1986
  • Open Source Security
  • 2011 Pioneer Awards!

Projects

  • Bloggers' Rights
  • Coders' Rights
  • FOIA Project
  • Follow EFF
  • Patent Busting
  • Surveillance Self-Defense
  • Teaching Copyright
  • Takedown Hall of Shame
  • TOSBack
  • Ways To Help
Want to learn how you can defend free speech, stand up for privacy, fight for government transparency, support consumer rights, and protect your right to innovation in the digital world? Visit http://eff.org/fight to find ways to help.
Creative Commons Licensed
  • Thanks
  • RSS Feeds
  • Copyright Policy
  • Privacy Policy
  • Contact EFF