November 16, 2005 | By Kurt Opsahl

US-CERT: Never Install Audio-CD DRM Software

The United States Computer Emergency Readiness Team (US-CERT) is a part of the Department of Homeland Security that is charged with the task of "protecting the nation's Internet infrastructure" by coordinating the "defense against and responses to cyber attacks across the nation." In response to the Sony XCP DRM debacle:

US-CERT recommends the following ways to help prevent the installation of this type of rootkit:

  • Do not run your system with administrative privileges. Without administrative privileges, the XCP DRM software will not install.
  • Use caution when installing software. Do not install software from sources that you do not expect to contain software, such as an audio CD. [emphasis added]
  • Read the EULA (End User License Agreement) if you do decide to install software. This document can contain information about what the software may do.

Yep, you read it right. US-CERT recommends that you never install DRM software that comes with an audio-CD. Frankly, that's good advice. As for the EULA advice, it's a good idea, but Sony's problematic EULA does not tell you much about what the XCP may do.


Deeplinks Topics

Stay in Touch

NSA Spying

EFF is leading the fight against the NSA's illegal mass surveillance program. Learn more about what the program is, how it works, and what you can do.

Follow EFF

The British are coming! One, if by land, two, if by a mandated backdoor in end-to-end crypto. https://eff.org/r.xwry

May 28 @ 2:40pm

EFF strongly objects to the US proposed Wassenaar implementation. We're drafting comments and you should too! https://eff.org/r.sg5g

May 28 @ 12:21pm

There's just 3 days, 9 hours, and 45 minutes until Section 215 of the Patriot Act sunsets. Time to call Congress: https://eff.org/r.88yz 

May 28 @ 11:14am
JavaScript license information