AACS Device Key Found 351
henrypijames writes "The intense effort by the fair-use community to circumvent AACS (the content protection protocol of HD DVD and Blu-Ray) has produced yet another stunning result: The AACS Device Key of the WinDVD 8 has been found, allowing any movie playable by it to be decrypted. This new discovery by ATARI Vampire of the Doom9 forum is based on the previous research of two other forum members, muslix64 (who found a way to locate the Title Keys of single movies) and arnezami (who extracted the Processing Key of an unspecified software player). AACS certainly seems to be falling apart bit for bit every day now."
Will they actually do it? (Score:5, Interesting)
Will they actually revoke these software players from all new disks?
Its time for them to put their money where their mouth is and actually block access to these broken players.
If they allow it to continue, all their movies will be piratable (insert oh noes! here).
I wonder how pissed off people will be if they can't play their new movies?
Re:Will they actually do it? (Score:5, Interesting)
Re: (Score:3, Insightful)
Fortunately, it's still in infancy :) (Score:5, Insightful)
So, of course; don't buy them. Tell your friends not to buy the, and spread the word. If technology was selected based on worth and merit, we'd all have been using beta-max and mini-discs. But consumers don't always go for quality, innovation or convenience. Most often they like whet their friends have, they like what they already have, and sometimes? They just follow the pr0n industry (uh oh, did i just predict the HD-DVD?) THe point being, this one is easy to 'nip in the bud.'
Now, if you were to start a large-scale boycott of xxAA products? That would rock the boat. But I'm not holding my breath for you.
Re: (Score:2, Funny)
So, of course; don't buy them. Tell your friends not to buy the, and spread the word.
But then the Merch will turn into the Flesh Reaper and start collecting torsos!
If technology was selected based on worth and merit, we'd all have been using beta-max and mini-discs. But consumers don't always go for quality, innovation or convenience.
What the hell? Minidisc absolutely sucks. It's not a good example of a quality product.
Now, if you were to start a large-scale boycott of xxAA products? That would rock the boat. But I'm not holding my breath for you.
Sigh. Didn't I already mention the torsos?
Re:Fortunately, it's still in infancy :) (Score:5, Interesting)
Sooner or later it's going to be your torso, unless you keep buying product. I didn't want to have to do this, but as nobody seems tyo be getting the joke [penny-arcade.com]
I guess they aren't the worst format ever invented, but they don't really fit anywhere. They're not quite good enough for professional use, but they were too expensive and user-unfriendly for recreational use. Most people can't stand the interface of minidisc players. Some players made it really hard to work out how to even start a recording.
The other problem was that to get the audio off the device onto your computer, you had to play back the content in real-time. I don't know of anyone who had a minidisc drive in their computer which could read the disc as data. Same for transferring audio from the computer to disc. May as well use a proper DAT tape if you have to do that.
The blank discs were also expensive, and when they did introduce the "Net MD" that could connect to a computer, the Sony software sucked, and it was full of proprietary formats.
Compare to the CD - cheap, ubiquitous, and you can rip or burn an entire CD in minutes - which was standards-compliant and could be used almost anywhere. Plus it has better audio quality.
Which is why i don't understand why Sony made the MD format. It wasa obvious that hard drives and flash memory was the future - and they introduced a new optical audio disc right at the end of the optical audio disc's popularity and usefulness. Kind of like someone releasing a new line of 5.25" floppy disk drives with improved storage, at the same time as almost everybody had moved to 3.5" floppies.
Why didn't Sony just release their own "iPod" instead? They could have made a "pro" line of HD-based players that had professional quality audio inputs for recording, and a "consumer" line focused on playback, portability and fashion.
Re:Fortunately, it's still in infancy :) (Score:4, Insightful)
I think that where MD really fell down was that Sony hadn't quite realized that people were ready to start treating their music as a digital resource that could be manipulated by computer. MiniDisc is a format that is based around MD player/recorders functioning as single-use appliances. Most people changed how they thought about music somewhere between 1996-2002, depending on how wired they were. They realized that music formats were digital and that music could be downloaded, stored, and manipulated on computer. MD was a format that didn't allow these functions, and so it was useless. Not a bad format for what it did, but it missed a shift in how people thought about what music did.
As a side note, I think that the same shift is happening with television. It's taken longer to catch on, but now everyone's starting to understand that the episode of Lost they missed doesn't mean they have to beg to borrow a tape off some friend because it's on the internet and can be downloaded if they want to...
Re:Fortunately, it's still in infancy :) (Score:5, Insightful)
A lot of the time it seems like Sony exists solely to push their proprietary formats
I'm not quite sure what the logic is behind creating their own format for everything (Memory Stick instead of CF or SD, ATRAC instead of MP3 or Vorbis, Blu-Ray instead of HD-DVD)... seems to me that the R&D money could have been spent elsewhere, perhaps on more useful things.
Re: (Score:3, Informative)
Re:Will they actually do it? (Score:5, Insightful)
Re:Will they actually do it? (Score:4, Insightful)
Now we go one baby-step down the path where debugging tools like the ones used by these "hackers","pirates", and "anti-establishmentarians" require a license to own and use, because tools like this can apparently cause more damage to our society than an unlicensed firearm can do in a school...
From The Right To Read [gnu.org]:
--jeffk++
Re: (Score:3, Insightful)
Re: (Score:3, Interesting)
It's those pesky users that are the problem. (Score:4, Interesting)
First they'll just make precompiled debuggers illegal. And then when that doesn't work, they'll make compilers illegal. And when people go after the hardware, they'll pot the whole motherboard in epoxy, doped with iron filing and wired with self-destruct mechanisms. And only signed code will run as root or system, so even if you do get a compiler, you'll have to somehow forge Microsoft Central Control's signature to run it on the bare metal. Oh, and the whole thing will probably brick itself if it doesn't dial in for re-verification and updates on a weekly basis. Hell -- don't even let the user install any software: if they want something, they can call Microsoft with their MasterCard in hand, pay for it, and it'll get downloaded to their machine overnight.
There's precedent for most of this already; the US government has already mandated that all VCRs look for and cripple themselves if they detect Macrovision signals, so it's really not much of a hop from there to a "full length" mandatory HDCP. Since the only way you can make DRM stick is by not letting the user actually do anything, that's the obvious solution. Just lock them out.
Re:Miserable? (Score:4, Interesting)
When I explained to them why their disc wouldn't play, they were mad. When I gave them a working copy of the disc, they were happy.
Re:Miserable? (Score:4, Informative)
Re: (Score:2)
Those who just want to watch/listen/experience can do that.
Those cursed with natural human curiosity can watch the small unit self-destruct when tampered.
But does it sell?
Re:Miserable? (Score:5, Insightful)
Re:Miserable? (Score:5, Informative)
So, am I not "supposed" to watch my DVDs on my old TV? The macrovision protection makes the picture nearly unwatchable. The TV is very nice, and does the job well. Why should I have to throw away a perfectly good TV and buy a new one just to watch a DVD? It doesn't make any sense - if I have to buy a new TV, that's less money for me to spend on DVDs, so the copy protection would actually reduce their sales.
Likewise, have you never bought a DVD from another country? If you're not supposed to do that, then why can I buy DVDs from another country? Sure, you can get region-free DVD players, but not everybody has one - and with "RCE" protection, some titles won't even work on some region-free players. And region-free players are technically illegal in some places.
I also like to watch movies but some titles won't let me go straight to the movie, and instead force me to sit through unskippable ads and FBI warnings. I even had one disc that I bought, which made me sit through a quite long lecture about the evils of piracy, telling me how people who copy DVDs are funding terrorism and destroying the industry. Ironically, it was quite simple to make a copy of that DVD, with the anti-piracy ad removed. If they didn't have that unskippable propaganda at the beginning. If I ever get another disc with that ad, I'm going to return it as defective. I paid to watch the movie, not to be lectured by propaganda.
Re: (Score:3, Informative)
At least in the US, they are never illegal to possess. The only illegality involved with region-free players is that the manufacturer of the player signed an agreement to obey region encoding in order to license the technology (MPEG2 decryption probably, plus to use the DVD consortium's trademarks). Thus, manufacturing a regionless player may or may not be illegal. Possessing one is definitely legal in the United States.
Re: (Score:3, Informative)
Re:Miserable? (Score:5, Interesting)
But then, I'm not trying to do something with it that I shouldn't, like copying it when the purchase agreement clearly says I'm not suppose to...
What purchase agreement? I agreed to nothing when I bought it. And I'll do whatever the hell I want with the property that I own. Much like I don't use CDs anymore when playing audio content, I don't want to use DVDs when playing movies. So I rip and watch on a HTPC. The process is much more complex than ripping an audio CD, mostly because of the DRM.
The physical media that we buy can become scratched and broken, even when we take care of it. And thanks to the convenient duplicity of ideology that is held by the content companies, we are said to be buying only a license to the content, which happens to have a copy along with it on the media. Good luck getting replacement media so you can exercise that license if a disc happens to get scratched. They want to have their cake and eat it too, so we get, "You should take better care of your discs." and DRM protecting the content.
This is BULLSHIT. There's really no way to get the message across to them, so no more. I won't buy another movie on DRM-protected media. Until they change, or offer a (paid for) download of the video without DRM, I won't be buying another movie. I'll rent from an online source and rip to a media server. Yeah, I'll still watch them and get the content, but I won't purchase the discs anymore.
Illegal? Probably. Unethical? I don't think so, and really, I don't care.
Re: (Score:2)
Well, they do say that ignorance is bliss.
I'm not trying to do something with it that I shouldn't, like copying it when the purchase agreement clearly says I'm not suppose to
There is no purchase agreement, actually. When a DVD has a notice on it to the effect of 'copying this DVD is illegal' that isn't even arguably an attempt at forming a contract, it's just a simplistic and one-sided restatement of the law. Believe me, if they wanted to push a contract on you, you'd know it; l
Solution is easy, pity it's illegal. (Score:3, Interesting)
You can also get rid of the obnoxious "No UOP" functions, and other garbage. If you're like me, you can just do a title rip, and strip out all the crap besides the movie itself, and pretend you're in a theater. (Well, without the 15 minutes of ads and previews. So basically, not like a theater at all, anymore.)
I used to do this to most of my DVDs, but then I built a MythTV box, and started using its built-in DVD player, w
Re:Will they actually do it? (Score:5, Insightful)
Re:Will they actually do it? (Score:5, Insightful)
Assuming they keep their word, and revoke the keys as they're found, software players will become nearly unusable, with patches every few weeks to update the key, attempt to obfuscate it more, and make it usable with new disks again. If they go that route, it's only a matter of time until software HD-DVD/BR players are permanently blacklisted and cease to exist. Consumers won't like that much. We'll see special cables running from new drives to new video cards, because consumers will not put up with a lack of being able to play HD discs on their computers. And the ones that bought software players will be ROYALLY pissed.
If they let it slide, or just sue the people who found the key in the memory dumps, but do not revoke software player keys there's STILL no way to put the cat back in the bag - HDDVD/BR content protection is finished.
Which way will it go?
key in memory - on some PCs yes (Score:5, Insightful)
It will work something like this:
There will be two channels of data, one from the media source to the dongle, and one from the dongle to the playback device.
The dongle will decrypt data from the media source, or possibly ordinary RAM. In some cases, will be done with the aid of software tokens purchased from rights owners. In others, it will merely verify region, time-expiration, and other restrictions embedded in the media are complied with. In some cases, part of the key will be downloaded from the Internet in real time, or a time-bombed key will be renewed at regular intervals.
The dongle will re-encrypt the data so the playback hardware can play it, but memory-snoopers can't access it.
The dongle will be a "black box," protected by hardware features and possibly legal protection: "Tamper with this for the purposes of understanding it and go to jail."
The dongles will be handed out like candy for little or not profit, but they will be revoked individually if any one is compromised. People concerned about privacy and tracking implications will trade dongles or simply buy them by the bucketful.
I don't know if these dongles will be USB dongles or if they will be on a faster bus or maybe even connected directly to the video playback circuitry.
Mark this post, it may prove useful in challenging future dongle patents.
Re:key in memory - on some PCs yes (Score:4, Interesting)
patent and publishing (Score:2)
However, it was sufficient to show that any such device is "obvious." I literally came up with it on the spur of the moment. Patenting such an obvious patent then donating it to a patent-freedom agency would itself be an abuse of the patent system.
"Finishing" the patent would - or should - require at least one real or paper implementation. Anyone with particular
Re: (Score:2)
At some point in the digital playback device, the data becomes cleartext. Given enough effort, that data could be extracted. Especially if it's a CRT, as AFAIK, the method used by a CRT monitor to drive the CRTs is quite simple. A LCD is probably more complicated, but it'd give you a 100% precise result.
Besides, I am fairly sure that with the right equipment you could do a decent analog recording anyway. Use a big, good quality LCD monitor with a DVI connection, and a camera pointe
Re: (Score:3, Interesting)
As a refinement to the idea, the dongle could send the decrypted video straight to the video card to play on an overlay. That would probably work better since it wouldn't be so easily circumventable.
However even then 1) you could circumvent it using custom hardware snooping the video card's data bus and 2)
Re:key in memory - on some PCs yes (Score:5, Insightful)
First off, this isn't even remotely new. Dongles for copy protection are as old as the concept of copy protection. AutoCAD used a dongle. I'm sure there are dozens of other examples. But they haven't been widely implemented for the same reason this won't be. Cost.
It's too expensive to ship a sophisticated $20 part with a pressed disc that costs $1 to make and you're selling for $20. Dongles have only really been used in very expensive software packages for this reason.
Also, the whole content industry is moving to a "download over the Internet" model. Bill Gates was right when he said this is likely to be the last physical format war. Any solution that is not software only is a non-starter in this context.
The dongle will decrypt data from the media source, or possibly ordinary RAM. In some cases, will be done with the aid of software tokens purchased from rights owners. In others, it will merely verify region, time-expiration, and other restrictions embedded in the media are complied with. In some cases, part of the key will be downloaded from the Internet in real time, or a time-bombed key will be renewed at regular intervals.
If you're going to require an internet connection, what's the point of the dongle? Just make the user verify the key in real time against the server for every play. This would already have been implemented if they thought users would stand for it. They won't.
The dongle will re-encrypt the data so the playback hardware can play it, but memory-snoopers can't access it.
This makes no sense. The playback hardware presumably doesn't have encryption capability. If it does, and it has the encryption hardware built in, what is the point of the dongle? You're also expecting a DONGLE to decrypt, encrypt, and transfer HD video in full resolution all in real-time. That's a pretty beefy dongle. See above for the cost issues.
I think it's worth expanding on this point. Do you really understand how sophisticated the dongle you're talking about would have to be? It would have to include a CPU, memory, and storage to do the encryption. And how they're totally useless unless you ship a SEPERATE one attached to EACH video you want to play? The keys have to be individual for each "disc" (or instance of video) and ROM-burned, not flashable. The idea of some sort of "dongle vault" or multikey that allows you to used multiple stored keys is fatally flawed for a vast number of reasons. The most basic being that it would make hacking the dongles extremely attractive.
Now if you're thinking of "embedding" this dongle into the computer itself, it's been done. This is the whole concept of the TPM chip and concerns about it being used for DRM. This solution is also not feasible for any number of reasons.
I don't know if these dongles will be USB dongles
No, it will have to be a proprietary interface. USB is too easy to sniff.
maybe even connected directly to the video playback circuitry.
So users are going to have to crack their case open every time they want to play a video? I think not.
Mark this post, it may prove useful in challenging future dongle patents.
None of this is either novel or practical.
Re: (Score:2)
The key will have to be in memory, but there is no reason for it to be unobfuscated. Any kind of simple obfuscation will stop the kind of attack used here. Sure, somebody can start reverse engineering the code to work out the obfuscation, but that takes a lot more skill and time th
Re: (Score:2)
Except, of course, for Windows Media Player which already has (i) patches every few weeks or months anyway (and so its mean time between patches << the probable mean interval between key revocation and 99.99% of customers purchase of a new disc); and (ii) a mechanism for patch delivery that most users are already using and comfortable with.
I'm sure Microsoft would be very upset if 99.99% of the population's perceptions were that every other software movie disc player had issues playing some, mostly n
Re: (Score:2, Insightful)
Re: (Score:2)
Nope. Hardware players can be individually revoked.
Re:Will they actually do it? (Score:5, Interesting)
Re: (Score:2)
Re: (Score:3, Insightful)
Making a key per player copy is infeasible. How would you do that? Basically, every disk would need to have the data encrypted with each player's key. That number would be in the millions.
Re:Will they actually do it? (Score:5, Informative)
It's not only feasible, it's exactly what AACS does. Each player has about 500 keys from which it can derive billions more, all structured so that a disk only needs a small number of media keys encrypted with "processing" keys, which the players can derive from the device keys they have. The number of copies of the media key that must be present on each disk is guaranteed to be no more than 2r, where r is the number of individual players that have been revoked. On average, only 1.25r media keys are required.
Though the application is evil, the "subset-difference tree" concept used to make all this work is a very cool bit of math.
Re: (Score:3, Interesting)
How large can r get before there's some serious performance issues (either filling up the disc or requiring a long boot-up time)?
Each copy of the media key consumes 32 bytes. 16 bytes for a descriptor and 16 bytes for the encrypted key. So, on average, the publishers have to use another 40 bytes of disk space per player key published. Given that single-layer HD-DVDs hold 15,000,000,000 bytes, they have plenty of space to handle any conceivable number of revoked players.
I went through some numbers in this comment [slashdot.org]
As for startup time, the process of comparing each descriptor in the MKB to the device's own "key path" is quite ef
Re: (Score:2)
Re: (Score:3, Informative)
This is not the case. The media key block on the HD discs contains the media key, encrypted with several hundred device keys. There's not nearly enough room in the key block to have an individual key for each player produced, it's just enough for each model, or perhaps each hardware revision / production run of each model.
There are a finite number of keys on each disc. The way keys are "revoked" is by simply not using that key on any new disc pressings. A disc ma
Re: (Score:3, Informative)
It is actually more sophisticated than that, relying on each individual unit having a certain set of 512 keys out of a billion or so, and then providing only enabling a subset of possible keys on each disc in the MKB. The trick is once they know the specific unit
Re: (Score:3, Funny)
Re: (Score:2)
Re: (Score:2)
Given the cheap price, I imagine most people would not bother and would just buy another. Of a different make, since it would damage that manufacturer's reputation. They probably wouldn't even know that it would need updating since while their new DVD won't play their old ones would still work.
Re: (Score:2)
While breaking one or more hardware players ma
Re:Will they actually do it? (Score:5, Informative)
Breaking a single hardware device won't be a big deal, either, since the key revocation scheme allows that single player to be revoked (not the brand, not the model, not even the factory batch -- that single, specific physical player). What would be big would be finding a way to easily extract the keys from a model, or, even better, a whole class of players. Then, the hackers could just do a player every few weeks, and the worst case for those of us who like to back up the movies we buy is that we'd have to wait a few weeks after the release before we could back it up.
The way AACS key revocation works is that there is a massive binary tree of binary trees of possible encryption keys. The "main" tree is 31 levels deep (allowing for 2^31 possible player devices) and each node has a number of "shadow" trees associated with it (specifically, nodes in layer n of the main tree have n-1 shadow trees). Each player is given a carefully selected and unique set of ~500 keys, from which it can derive an enormous number of keys -- almost every key in that big tree of trees, in fact.
The "almost" in the last sentence is important.
Assuming no players are revoked, each disk needs only have few copies of the media key[1], each encrypted with a "processing" high up in the tree. All players have keys needed to derive[2] these processing keys. When a player is revoked, the publishers carefully select a set of processing keys to use so that every player *except* the revoked player can derive the processing keys. There's a fairly simple algorithm to select such a set of keys, and the structure of the trees ensures that for any set R of revoked players, no more than 2|R| processing keys need to be used (|R| means "size of R", in case that's not obvious).
Each encrypted copy of the media key consumes 32 bytes of disk space, so, assuming a million players have been broken and revoked, each new disk will "waste" 32 MB on encrypted media keys. Given the capacity of HD-DVD and Blu-Ray disks, 32MB is a pittance, so it really is practical for publishers to revoke every key that is extracted and published -- the hard part will be finding them all.
Yep, that's a seriously hard problem to solve -- especially when you consider that time and manpower are 100% on the side of the attackers. The attackers have a disadvantage in that they have to work with binary-only code, but if this goes on for long enough, I'll bet the major software players will be so thoroughly reverse engineered that this will cease to be a very meaningful disadvantage.
Large-scale DRM simply cannot work. If you give the devices to enough interested and technically skilled people, they will be broken again, and again, and again.
And, of course, if publishers *did* somehow manage to get ahead of this game, it would just mean that the hackers would keep the keys to themselves, publishing them only to small groups of trusted friends -- all of whom would be ripping movies like mad and making torrents available so that everyone else can get them.
[1] The Media Key is used to encrypt the title keys, which are used to encrypt the titles. There are generally multiple titles per disk -- usually one for the main feature, and others for each of the extras, some for bits of the animated menus, etc. I've been puzzling over exactly how many copies of the media key are required in the no-devices-revoked case, and I haven't been able to figure it out yet. An answer and explanation from someone who understands this stuff well would be appreciated.
[2] The keys given to the players are called "device keys". The players look through the descriptors in the Media Key Block (MKB), looking for one that mentions a key they either have or can derive from a key they have. Derivation is done by AES-encrypting a seed value (7B103C5DCB08C4E51A27B01799053BD9) three times, incrementing it by one each time, using the device key. The result of the first encryption is the "left" device key of the associated "shadow" tree and result of the third encryption is the "right" device key of the shadow tree and the other result is a "processing key". Generally, the processing keys used to generate the MKB block entries will be from a shadow tree, so the player might have to repeat this process multiple times, each time taking either the left or right device key as the encryption key for the next step down the tree. It continues this process until it gets to the processing key specified in the descriptor. When it has that, it uses it to decrypt the media key, then uses that to decrypt the title keys, then uses those to decrypt the title data.
Re:Will they actually do it? (Score:5, Informative)
Correction -- If a million players are revoked, up to *two* million copies of the media key will be required, consuming 64MB of space on each disk. However, that's only if the million broken devices are selected so that revocation is maximally inefficient. If they're selected at random, on average only ~1.25M MKB entries are required, so only 40MB of the disk must be used for MKB entries. That's 0.2% of a single-layer HD-DVD and 0.08% of a dual-layer Blu-Ray. Or, it's about 20 seconds of HD video, assuming that a single-layer HD-DVD will hold two hours. If a dual layer Blu-Ray disk contained video encoded at such a high bit rate that it would only hold two hours, the MKB block would eat up space equivalent to six seconds of video -- and that's with a *million* revoked keys).
In practice, of course, the time unavailable for video will bever be a problem. If the movie and the MKB can't both fit, you just tweak the encoding to drop the average bitrate by a 10-20 kbps. When you're encoding normally at 8,000-20,000 kbps no one will be able to see the reduced quality. Also, even regular DVDs are rarely within 100MB of being full. There's plenty of room available for "large" MKBs.
Go to plan B (Score:5, Insightful)
Sure it will be somewhat inconvienient and more expensive for customers, but that's the price they are choosing to pay when they turn a blind eye to piracy.
Re:Go to plan B (Score:5, Funny)
Re: (Score:2)
Eventually they will come to their senses and ship the content DRM-free. Didn't one of the Harry Potter movies ship DRM-free (no CSS) and still se
Re: (Score:2)
That only applies if there are many keys, which there aren't. Hackers only reverse-engineer software players, and there are only two software players. Worst-case, AACS LA could just revoke both.
Also, cracking DRM is all about revealing secrets; how could you expect the hackers to agree to some kind of "code of silence" when it comes to their work?
Re: (Score:2)
The academics won't, but the tradespeople will.
Introduction of hardware DRM (Score:5, Insightful)
Of course such restrictions would make debugging your own programs harder if it was always on.
Re:Introduction of hardware DRM (Score:5, Insightful)
This is crackable anyways. The original Xbox was cracked by someone building their own data sniffer hardware installed on the system bus. No kidding. People will go to pretty much any length, including hardware modification, to break out of constricting usage limitations (aka DRM)...
what about memory encryption? (Score:2)
Re: (Score:3, Insightful)
Re: (Score:2)
Wrong verb tense! (Score:3, Informative)
What do you mean, "will result?" It already has resulted in hardware DRM -- if you have Vista and a machine with a TPM, it's already there!
Re:Wrong verb tense! (Score:5, Informative)
What do you mean, "will result?" It already has resulted in hardware DRM -- if you have Vista and a machine with a TPM, it's already there!
No, actually, it isn't. While the TPM could be used to "seal" the HD-DVD/Blu-Ray player device keys to a given boot state, the decryption of the disk contents would still have to be done using the main processor (TPMs don't do bulk decryption, don't know anything about AACS, and aren't programmable to teach them how to do the AACS key derivation/decryption scheme).
Also, I don't know that Vista is really TPM-aware.
In the near future, it may become the case that if you have (a) Vista + some service pack, (b) a TPM and (c) a processor with hardware virtualization support (Intel VT/AMD-V), then your HD-DVD/Blu-Ray player may run on a separate virtual machine which your main OS has no access to and which you therefore cannot debug, and the TPM may be used to seal the device keys to the particular software in that VM, so that no other piece of software has any reasonable hope of retrieving them.
Collectively, BTW, (a), (b) and (c) above are known as Palladium, aka NGSCB.
Personally, I think it's more likely that your video card may gain an AACS subsystem, so your PC would feed the data stream from the disk to your video card, which will decrypt the data and display it. The video card would then have to have a way to securely transfer the audio stream to your sound card. Or maybe your sound and video card will negotiate secure data connections to your HD-DVD-ROM drive and the drive would do the AACS stuff and feed it securely to your output devices, so that your main processor never gets to see an unencrypted copy.
There are ways to make software players more secure, but a TPM alone is insufficient, unless the OS is airtight, unhackable/modifiable even by the administrator. Given Microsoft's track record with making an OS unhackable by random people around the world with no privileges on the box at all, I don't think that's going to happen.
Re: (Score:2)
crack some device keys and that will toss monkey fecies in the face of every MPAA executive pretty hard. They dont DARE revoke any keys from the expensive hardware. Pissing off your early adopters, specifically the rich ones will guarentee doom.
selling a secret to consumers... (Score:2, Interesting)
You can't sell a product with a "secret" key inside it to tech-savvy consumers and expect it to remain secret for any extended period of time.
It just won't work. It's time for this incovenience to end (not that it will).
Okay that does it (Score:2, Interesting)
How many keys are there? Why aren't there just one? What's the difference? IS there any difference?
Is this better than the last key uncovered? Are there more keys to uncover?
What is the final ACCS "key"? How many levels are there?
I'm not being ignorant, I'm just confused, and I'm sure I'm not alone.
Thank you.
Re:Okay that does it (Score:5, Informative)
Re: (Score:2, Informative)
Each player (software or hardware) has a key, or actually a tree of keys. Some ingenious trickery is being used so that each player can have its own key, but that isn't done on software players (because it would be a pain to enforce it so each downloader gets a different key).
The disc contains title keys for various player keys. When the player wants to play a disc, it takes its player key, decrypts the disc's title key with it, and decrypts the content with the title key.
Now, two
Re:Okay that does it (Score:5, Informative)
AACS uses a bunch of different keys in a hierarchical structure. Gradually, the cracks have been revealing keys higher and higher up the food chain. As I understand it, this is a bottom-up description of AACS's key structure:
At the lowest level, every piece of content is encrypted with a Title Key, which is unique to at least an individual title, possibly a particular printing of the title. The original cracks revealed the Title Keys for individual titles one at a time. These can be used to decrypt the content, but don't break the scheme, just the encryption on an individual piece of content.
The Title Key is stored on the actual media, encrypted by the Volume Unique Key, which is unique to a given title.
The Volume Unique Key is the result of a keyed hash of the Volume ID (stored on the media) and a Media Key, which is unique per title.
The Media Key used is generated by combining the Media Key Block (stored on the media) with a key unique to the decrypting device. Each device has a different key, but generates the same Media Key.
I'm not entirely sure why so many keys are used, but that's basically how the scheme works. Previous cracks were based on revealing keys that were title-specific. This one has revealed a device-specific key, which means that until the key is revoked, which would cause all future discs to no longer play on that particular player, any piece of content can be completely decrypted.
Re: (Score:2)
Re:Okay that does it (Score:5, Informative)
It's more news in that it could make HD content decryption as universally accessible as DVD decryption currently is. A lot of people might want to extract their HD content but not have the know-how or motivation to do anything beyond "download this program, hit start", though it's less news since I've heard there are already programs that will do that using a list of title keys that's periodically updated over the Internet.
Re: (Score:2)
As I've mentioned in another post, each device has a whole bunch of keys, which can be used to derive any one of a few billion processing keys. Those processing keys are what are actually used to encrypt the media keys. Device revocation is done by choosing a set of processing keys which are not derivable by any of the revoked devices.
Re:Okay that does it (Score:5, Funny)
It seems to go on and on forever. But then you get to the end and a gorilla starts throwing barrels at you.
I don't know what is the idea behind this (Score:2, Insightful)
Re: (Score:2)
Re:The "Man" is me. (Score:4, Insightful)
And I believe player pianos were supposed to break musical profits. and TV was supposed to break movies' business model. and cassettes were supposed to destroy record companies. And Valenti compared VCRs to the Boston Strangler. And music and movie downloads are supposed to break the RIAA and MPAA members. Both outfits are making more money today than they did last year, and the year before.
You are wrong. And you've bought laws to invade our lives and put grandmothers in prison. The least we can do is break your balls, over and over and over.
and please, do, go out of business.
This is great news (Score:5, Interesting)
One thing's for sure... (Score:4, Funny)
Holy Neverwinternight... (Score:2, Funny)
Ugh (Score:5, Insightful)
- WinDVD is not handling its device key in a secure manner
- WinDVD cannot be trusted
- WinDVD won't be getting another player key
Or even worse:
- WinDVD did its best to protect its device key
- It's impossible to protect a device key in a program that people can reverse-engineer [true]
- We'd better not allow any software to read AACS-protected content
Although this may all be moot anyway, as they can extract future process keys with relatively little effort (though it'll be a lot more effort if hackers have to break hardware systems instead of software).
Re: (Score:2)
Re: (Score:3, Insightful)
here is a little secret for you. Hardware players do not exist. every HD-DVD player and Blu Ray Player is a software player. and hacking those is not any harder, just requires different tools they have to be built or bought instead of warezed off of a bittorrent site.
DRM is provably insecure (Score:5, Insightful)
Care to show a proof? (Score:2)
Re: (Score:2)
Encryption is used so that A can send a message to B in such a way that C cannot intercept and read what the message is. DRM sets B
Re: (Score:3, Insightful)
At some point between the information and your eyes and ears, the information must be in "plaintext." (Otherwise you can't see it or hear it.) At that very point, the information stream can be intercepted and stored. This is true even if we have jacks in the backs of our heads to accept personal AV signals.
Here's another way to loo
Re: (Score:2)
Re: (Score:3, Insightful)
Re:DRM is provably insecure (Score:4, Insightful)
fair-use community? (Score:2)
Re: (Score:3, Insightful)
All your problems solved (Score:2)
Glad it is broken (Score:2)
Of course (Score:3, Insightful)
Now that picture and audio quality is already better than humans can perceive, I wonder what new marketing bullshit feature they'll come up with this time to persuade the public they really need spend thousands more on yet newer hardware just because it has even more restrictive DRM and no bacwkard-compatability.
Look out for super ultra mega HD resolution media and players with 12.1 audio and smellyvision coming to your local store soon!
Re:All your video are belong to us (Score:5, Funny)
MPAA: What happen ?
RIAA: Somebody set up us the bomb.
RIAA: We get signal.
MPAA: What !
RIAA: Main screen turn on.
MPAA: It's you !!
J.Q. Public: How are you gentlemen !!
J.Q. Public: All your video are belong to us.
J.Q. Public: Your revenue stream are on the way to destruction.
MPAA: What you say !!
J.Q. Public: Your business model have no chance to survive make your time.
J.Q. Public: Ha Ha Ha Ha
RIAA: MPAA !! *
MPAA: Take off every 'Lawyer' !!
MPAA: You know what you doing.
MPAA: Move 'Lawyer'.
MPAA: For great injustice.
Re:The hackers are moving too early... (Score:4, Insightful)
Ultimately, the only real way to protect content is going to have remote-controlled content-monitoring LCD shutters surgically implanted in everyone's eyes as soon as they are old enough to enjoy TV (and these creeps would do just that if they could get away with it.) Anything else will be circumvented sooner or later, which they know perfectly well. It's also why the content companies are pushing so damned hard to export US/EU-style IP law around the world and have copyright infringement treated as a heinous crime akin to murder. Once the cops (everywhere) are accustomed to treating copyright infringers as serious criminals, the MPAA and their ilk are hoping and praying that people won't do it anymore.
I think they will be disappointed. I hope they will. There aren't enough jails to hold everyone that ever violated a copyright, or exercised fair-use rights in countries that support them.
Re: (Score:2)
2) So they key gets revoked -- now that they've got the software key for one player they can start getting the disk keys for a lot of disks, based on that they can then use these known keys to get back to the software keys of a *lot* of players.
3a) Apparently it does - that's 3 seperate people now working on cracking this one, and
Re: (Score:2)
Both use IDEA-encrypted data segments and extensive checking that munges data structures.
No-go protections are easy. Just JMP past them. Data corruption techniques are the nastiest to crack, if you can understand the format..
Re: (Score:2)
Not if you're trying to prove a point ... (Score:5, Insightful)
If you're trying to demonstrate that DRM is futile waste of energy, it's in your best interests to release as early as possible.
Releasing an exploit a couple of years after the technology is first released gives people the impression that the DRM was "good" for those two years. On the other hand, releasing the exploit a week later drives home the point that the copy-protection racket is selling nothing but snake oil.
Re:Fair-use community? (Score:5, Funny)