Well, that's not what I said, but doesn't a company have a responsibility to virus-check any software they ship *before* they ship it? It's not like this is something so new that a normal check wouldn't have found it.
Todd is right.
It is important to differentiate between maliciousness and a really embarrassing error. Sony *wrote* a rootkit for the purpose of cracking into their customers' systems to force their customers to act in a way more profitable to Sony, and to spy on their customers. It was not a mistake.
Paul Schmehl (pauls@xxxxxxxxxxxx) Adjunct Information Security Officer University of Texas at Dallas AVIEN Founding Member http://www.utdallas.edu/ir/security/ _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/