Sony's rootkit uninstaller is *really* dangerous

We've written here that the "uninstaller" that Sony provides for getting rid of the malicious trojan horse that is installed on your computer when you play one of their music CDs introduces some pretty big security holes into your PC.

But it looks like it might be worse than we suspected. DRM-fighting Princeton prof Ed Felten sends us this:

Alex Halderman and I have confirmed that Sony's Web-based XCP uninstallation utility exposes users to serious security risk. Under at least some circumstances, running Sony's Web-based uninstaller opens a huge security hole on your computer. We have a working demonstration exploit.

We are working furiously to nail down the details and will report our results here as soon as we can.

In the meantime, we recommend strongly against downloading or running Sony's Web-based XCP uninstaller.

Link,

Link to November 14 time-line of Sony's misdeeds

(Thanks, Ed!)