EMI: We don't use rootkits
The EMI Group, one of the world's largest recording companies, has distanced itself from the controversy surrounding digital rights management (DRM) software used by Sony BMG by stating that it does not use rootkits on its own products.
Context & Ripple Effects
Sony BMG’s copy-protection software had already been tied to a potential security problem, with security experts warning about the technology and Sony BMG preparing a patch with antivirus companies and its technology partner. EMI’s statement is a reputational separation from that implementation controversy, not evidence that it has abandoned DRM.
The episode puts the distinction between copy protection and software that alters a customer’s computer at the center of label DRM policy. Sony BMG’s XCP2 deployment made that boundary a commercial and security issue rather than only an anti-piracy choice.
First-order effects
- EMI can differentiate its own products from Sony BMG’s rootkit controversy, while Sony BMG remains occupied with a patch and coordination with antivirus companies.
- Consumers and security vendors have a clearer reason to scrutinize music-CD protection software for concealed system-level behavior.
Second-order effects
- Sony BMG’s remediation effort raises the reputational cost for labels that rely on intrusive DRM, making implementation details part of how copy-protection products are judged.
- DRM technology partners face greater pressure to demonstrate that their software does not weaken customer systems or evade security tools.
Third-order effects
- If labels keep separating DRM from rootkit-like behavior, the market’s durable dividing line becomes consent and system safety, not merely whether a release is copy-protected.
- The controversy points toward DRM governance in which music companies bear responsibility for the behavior of third-party protection software distributed with their releases.
The trend: Digital-rights management is becoming a trust and endpoint-security issue, forcing labels to defend not only anti-piracy goals but the software methods used to pursue them.