Let me tell you about the time Sony put malware on 22 million music CDs.
Sony the corporation, on purpose.
2005. you buy a CD at a music store. you get home. you put it in your computer. Windows autorun kicks in.
Sony's software silently installs a rootkit on your system. It hides itself using the same techniques professional malware uses to evade detection. it runs constantly in the background. it phones home to Sony with information about what you're listening to.
and it cannot be uninstalled.
The removal tool Sony eventually released to fix it required your email address and installed additional software that introduced further vulnerabilities. the fix was worse than the rootkit.
A security researcher named Mark Russinovich found it on Halloween 2005. published his findings. the internet erupted.
Sony's President of Global Digital Business responded: "most people don't even know what a rootkit is, so why should they care about it?"
things then got worse:
other malware authors discovered that anything hidden using Sony's rootkit technique became invisible to antivirus software too. they started hiding their own malware inside the same hidden directory. Sony had accidentally created the perfect malware concealment system and shipped it to 22 million people.
50 artists had CDs with the rootkit. Celine Dion. Neil Diamond. Santana. none of them knew.
Van Zant's album that started the whole investigation ranked 887 on Amazon. after reviews warned about the rootkit it dropped to 25,802 in three weeks.
Sony recalled the CDs. settled with the FTC. paid millions. Mark Russinovich became CTO of Microsoft Azure.
the rootkit is the reason we now consider autorun a security risk.
Sony shipped malware to protect music.
the malware protected nothing.
the music got pirated anyway.