Slashdot Log In
Vista DRM Cracked by Security Researcher
Posted by
ScuttleMonkey
on Mon Jan 29, 2007 02:16 PM
from the only-a-matter-of-time dept.
from the only-a-matter-of-time dept.
An anonymous reader writes "Security researcher Alex Ionescu claims to have successfully bypassed the much discussed DRM protection in Windows Vista, called 'Protected Media Path' (PMP), which is designed to seriously degrade the playback quality of any video and audio running on systems with hardware components not explicitly approved by Microsoft. The bypass of the DRM protection was in turn performed by breaking the Driver Signing / PatchGuard protection in the new operating system. Alex is now quite nervous about what an army of lawyers backed by draconian copyright laws could do to him if he released the details, but he claims to be currently looking into the details of safely releasing his details about this at the moment though."
Related Stories
[+]
Vista Protected Processes Bypassed 221 comments
Anonymous Hero writes "Security Researcher Alex Ionescu strikes again, this time with a proof of concept program that will arbitrarily enable and foremost disable the protection of so-called 'protected processes' in Windows Vista. Not only threatening Vista DRM and friends, it's also another step towards hardened and even more annoying malware. Normally, only specially signed processes made by special companies (decided by Microsoft) can be protected, but now the bad guys can protect any evil process they want, including the latest version of their own keylogger, spambot, or worm, as well as unprotect any 'good' one."
This discussion has been archived.
No new comments can be posted.
Vista DRM Cracked by Security Researcher
|
Log In/Create an Account
| Top
| 379 comments
| Search Discussion
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
very fitting (Score:5, Funny)
Re:very fitting (Score:5, Funny)
(http://www.atomjax.com/)
Re:very fitting (Score:5, Funny)
Or 'It's hard out here for a PMP'
Re:very fitting (Score:5, Funny)
(http://www.hyperlogos.org/ | Last Journal: Wednesday July 18, @08:19PM)
I don't know what you heard about me
But you can't get your video out of me
High quality video you can't see
Because I've got uncracked PMP [azlyrics.com].
Re:very fitting (Score:5, Funny)
Re:very fitting (Score:5, Funny)
As a user of the Windows Home Operating Rights Environment, I must state for the record that all of my transactions with said system are completely clean, and take place using the most effective protection available. If you truly feel that some of your Media exchanges are tainted, I'd suggest it's probably because you didn't pay the requisite PMP fees.
1st thing is to get a good lawyer (Score:3, Funny)
Re:1st thing is to get a good lawyer (Score:5, Informative)
Re:1st thing is to get a good lawyer (Score:5, Informative)
He [Alex] is currently studying at Concordia University in Montreal, Canada"
So does the DMCA apply?
Re:1st thing is to get a good lawyer (Score:4, Insightful)
that depends, does he travel to or through the US?
Re:1st thing is to get a good lawyer (Score:5, Interesting)
(http://www.victors.ca/)
"Government for the corporations, by the corporations, for the benefit of all corporations..." or something to that effect.
Thank god for the primary process!!! (Score:4, Funny)
(http://youtube.com/watch?v=FCDJ0jhWKno | Last Journal: Tuesday November 14 2006, @01:31PM)
*stabs self in eyes with thumbs*
JAZZ HANDS!
Re:1st thing is to get a good lawyer (Score:5, Funny)
Re:1st thing is to get a good lawyer (Score:5, Informative)
(http://www.misalpina.net/ghost3k/)
"He is also a Microsoft Student Ambassador and is representing the company on campus as a Technical Rep."
1st is to realize credit is overrated. (Score:5, Insightful)
(http://kadin.sdf-us.org/ | Last Journal: Tuesday October 16, @01:46PM)
Here's the problem: there's virtually no way to get in trouble, if you just release an exploit anonymously. (By definition, if it's truly anonymous, they can't catch you; there are lots of ways to basically ensure your anonymity today.) Where you start to get in trouble is when you want to release an exploit that's going to ruin somebody's day and take credit for it.
This comes up with regards to other, less-politically-sensitive bugs. When you step forward and take credit for something that you've released, you're basically holding up a big "come and get me!" sign. It's a lot easier to sling mud at a person, than it is at some anonymous entity on the Internet.
It's really taking credit that burns people, not releasing the bug/hack/exploit. It would have been trivial for this guy to release his code, anonymously or even pseudonymously, and keep it firewalled from his real-world identity. If he had done that, there might have been some attempts to uncover who he really was, but I doubt anyone would try that hard -- it's harder to go after someone that's anonymous, than an actual person. With a person, you have something to put in your mind under 'enemy,' that you just don't have with some vaporous person or persons on the Internet. Being anonymous diffuses a lot of the hatred, because it's harder to hate someone that might not exist. By standing up and taking credit, you're accepting everything.
Personally, if I were to discover something like this, there's no way I'd publicly admit it. I live a happy enough life without becoming some sort of hacker/security icon; the downsides of becoming the next Dimitry Sklyarov seem far greater than the possible benefits. Release the code somewhere in public, maybe signed with a private key that you have stashed away (so, decades down the line, you'd be able to claim it, if you wanted to and if the statute of limitations had run out), and only communicate via Usenet dead-drops and anonymous remailers. The tools to remain completely hidden are all there -- heck, you could probably do interviews in Wired under a psuedonym, the only absolute would be keeping the Clark-Kent-esque secret of your true identity hidden, and I'm not sure if some people would be able to swallow their pride enough to do that.
Pro Bono Security Attorneys (Score:4, Interesting)
(http://www.adambha.com/)
Re:Pro Bono Security Attorneys (Score:5, Informative)
Re:Pro Bono Security Attorneys (Score:4, Funny)
(http://www.keirstead.org/)
I mean sure, The Joshua Tree was great, but they've been going downhill for awhile....
Moving to Redmond? (Score:3, Interesting)
Re:Moving to Redmond? (Score:4, Funny)
"He is currently studying at Concordia University in Montreal, Canada, and is in his first year of obtaining a bachelor's degree in Software Engineering. He is also a Microsoft Student Ambassador and is representing the company on campus as a Technical Rep."
Uh oh.
Re:Moving to Redmond? (Score:4, Interesting)
(http://www.sigsegv.cx/)
You make enough stink on a non-moderated list like FD with the sole purpose to get hired and you get hired. There are pimps that follow FD, BUGTRAQ and the like for "fresh talent".
It's all in the details. (Score:4, Funny)
Re:It's all in the details. (Score:4, Funny)
Re:It's all in the details. (Score:5, Funny)
(http://fxaffinity.com/)
Buffalo buffalo Buffalo buffalo buffalo buffalo Buffalo buffalo. [wikipedia.org]
/me watches the skies over Montreal... (Score:1)
I have a brilliant crack of the Vista DRM too... (Score:5, Funny)
In future news... (Score:4, Funny)
Too bad this didn't come out 3-6 months from now (Score:1)
(Last Journal: Saturday May 12 2007, @04:18AM)
Post the details on MySpace (Score:5, Funny)
What a revelation! (Score:2)
Yeah, right. They'll just keep up with their usual approach, one akin to installing a governor on your car to deter theft.
just release it (Score:3, Funny)
(http://www.devinmoore.com/ | Last Journal: Thursday May 24, @06:16AM)
He won't need to ... (Score:5, Insightful)
(http://slashdot.org/ | Last Journal: Saturday February 05 2005, @03:50AM)
Re:He won't need to ... (Score:5, Interesting)
(http://www.hyperlogos.org/ | Last Journal: Wednesday July 18, @08:19PM)
One wonders if the harassment of people who are not breaking US law in their own jurisdiction when they come to the US will have a chilling effect on technology in the USA. Certainly, some very smart people would be very stupid to visit here...
Seems that the cat is already out of the bag... (Score:5, Informative)
And what he did, if I understand correctly, is have some of his own code run as kernel without it being in a "test signed" driver. That seems to be the essense of his approach. Once you figure out how to do that, you can basically do anything, and Microsoft can't stop you.
Alex is also re-implementing the win32 kernel (Score:5, Interesting)
Although ReactOS can share a lot of work with the WINE project for the win32 userland, it could still use any developers that are familiar with win32 development and would like to see a truly free operating system capable of using windows drivers/software.
Why bother even having DRM? (Score:4, Insightful)
Re:Why bother even having DRM? (Score:5, Insightful)
Re:Why bother even having DRM? (Score:4, Insightful)
(http://www.wavenger.com/)
The goal is not to make a secure system. The idea of securing a system from its owner (who has physical access) while maintaining usability is absurd and approaches impossiblity. They just want to make a system which 99.9% of users cannot crack, make it so that the crack cannot be generalized across different systems, and prosecute the remaining 0.1%.
Really, the only way to defeat DRM is to prove to companies that they will make more money without DRM than with, or, failing that, make the preceding true via strikes and public awareness.
What with (Score:3, Funny)
What with HD-DVD and Blu-Ray being cracked already, and now this, combined with all the hate and general unity by consumers against the big movie and music industry, how much more signal do they need that DRM is pointless and unwanted and to finally stop trying to force it on us?
Its a shame (Score:3, Interesting)
Re: It's a shame (Score:5, Insightful)
It's a shame that things have come to a point where developers/security researchers have to worry about releasing findings like this, perhaps *even* when they are not under US law.
Is it illegal for me to have someone check safety? (Score:4, Interesting)
So if I use windows
I'll do it... (Score:2)
(http://205.205.253.95/Crackster | Last Journal: Wednesday September 22 2004, @09:57PM)
Re:I'll do it... (Score:5, Funny)
And... (Score:1)
Crushing of Freedom of Speech (Score:4, Insightful)
(http://bumpylight.com/ | Last Journal: Friday January 09 2004, @12:36AM)
Yes, I know it's been said very many times before, but I'm moved to say it again. It's simply obscene that runaway copyright law provisions should be used to casually stomp on this kind of freedom of speech, especially in the U.S.A., where allegedly there is a First Amendment guaranteeing freedom of speech. I would very much like to see a full-out legal confrontation between these terroristic laws as they stand, and the Constitution. The alleged and artificial "right" of the smirking lawyers at commercial companies to keep their nasty little secrets does not in any sense abrogate the innate, natural right of the people to talk to each other about any damn thing they want, particularly complex subjects, and in any way they wish, including via carrier pigeons and Morse code, let alone in plain English (or whatever language) on the Web.
It's really a shame that other countries such as Sweden actually surpass the U.S.A. in this area.
Frankly, this pisses me off enough that I'm very strongly tempted once my finances improve enough for the expensive legalities, to spit in the eyes of these jerkoffs with a direct, blunt and extremely widespread explanation (possibly on a Russian server to further annoy and frustrate them) of whatever it is that they absolutely are frantic to not have explained, along with the text of the Constitution with the First Amendment highlighted in red. I think a well-crafted attack on this crap would gather quite a lot of support, moral and otherwise.
Honest question (Score:4, Interesting)
(http://www.ping972.com/)
"*Any* video and audio"? (Score:3, Interesting)
Norwegians, I'm ashamed of you (Score:5, Funny)
Someone in America cracked this first.
Re:Norwegians, I'm ashamed of you (Score:5, Funny)
-Eric