Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity
    • IT Management
    • Mobile
    • Storage

    Sony USB Fingerprint Readers Caught in Rootkitlike Action

    Written by

    Lisa Vaas
    Published August 29, 2007
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Sony appears to be reliving its rootkit nightmare of 2005, when it had to yank its XCP digital rights management technology after security experts said the technology used malicious rootkit techniques to evade detection on Windows systems.

      This time, three Sony USB fingerprint devices are planting hidden files for two separate rootkitlike programs, according to security vendor F-Secure, based in Helsinki, Finland. F-Secure reported on Aug. 29 that its DeepGuard HIPS (host-based intrusion prevention system) was warning about a USB stick software driver.

      According to a spokesperson for Sony, headquartered in Tokyo, the issue relates to three models in Sonys Micro Vault line, which offer fingerprint authentication technology. The models have recently been discontinued, the spokesperson said, and “no customers have reported problems to date,” although Sony is still investigating the problem and is “taking the issue very seriously.”

      According to F-Secures blog posting, the USB devices in question contain a built-in fingerprint reader that installs a driver that hides a directory under c:windows. The directory and any files within are hidden when viewing files and subdirectories in the Windows directory.

      In effect, the fingerprint softwares driver opens up a path for malware to sneak onto a system, according to F-Secure.

      “If you know the name of the directory, it is e.g. possible to enter the hidden directory using Command Prompt and it is possible to create new hidden files,” wrote F-Secure Chief Research Officer Mikko Hypponen in the post. “There are also ways to run files from this directory. Files in this directory are also hidden from some anti-virus scanners (as with the Sony BMG DRM case)—depending on the techniques employed by the anti-virus software. It is therefore technically possible for malware to use the hidden directory as a hiding place.”

      Click here to read more about security vulnerabilities involving USB drivers.

      This rootkitlike behavior is “closely related to the Sony BMG case,” Hypponen said. “First of all, it is another case where rootkitlike cloaking is ill-advisedly used in commercial software. Also, the [devices] we ordered are products of the same company—Sony Corporation.”

      Beyond testing the software packaged with these devices, F-Secure also tested what Hypponen said is the latest software available from Sony at its Micro Vault site. This version contains the same directory-hiding characteristic, he said. The Sony spokesperson said the company is now investigating whether this version is current and whether it displays the hiding behavior.

      As for why the fingerprint technology would need to hide a folder in the first place, F-Secure conjectured that it might be to shield fingerprint authentication from tampering and bypass.

      “It is obvious that user fingerprints cannot be in a world-writable file on the disk when we are talking about secure authentication,” Hypponen said. “However, we feel that rootkitlike cloaking techniques are not the right way to go here.”

      F-Secure noted that although the devices in question are old, the security firm had managed to track them down and purchase them.

      Check out eWEEK.coms Security Center for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEKs Security Watch blog.

      Lisa Vaas
      Lisa Vaas
      Lisa Vaas is News Editor/Operations for eWEEK.com and also serves as editor of the Database topic center. She has focused on customer relationship management technology, IT salaries and careers, effects of the H1-B visa on the technology workforce, wireless technology, security, and, most recently, databases and the technologies that touch upon them. Her articles have appeared in eWEEK's print edition, on eWEEK.com, and in the startup IT magazine PC Connection.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×