Random Stuff Forums
 

Go Back   Random Stuff Forums > RSF Exclusive Content > User Knowledgebase and Help > Computing

Computing Discuss anything related to computing here, such as hardware and technical problems.

Reply
 
LinkBack Thread Tools Display Modes
  #1  
Old 09-05-2007, 08:01 PM
Chickenultra (Offline)
Yar... PIRATE!
 
Join Date: Feb 2007
Posts: 2,100
Chickenultra is an unknown quantity at this point
Default DVD Hack

The New HD-DVD/Blu-Ray Hack: What It Might Mean For Us

Picture_7_8 09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0

That's the so-called "Processing Key" that unlocks the heart of every HD-DVD disk to date. Happy Valentine's day, AACS.

AACS, a DRM scheme used to encrypt data on HD-DVD and Blu-Ray disks, would appear to be cracked wide open by that short string of hexadecimal codes, as previously, only disk-specific Volume Keys were compromised. The new hack is the work of Arnezami, a hacker posting at the doom9 forums, fast becoming the front line in the war on DRM.

"The AACS is investigating the claims right regarding of the hack," said AACS spokesporson Jacqueline Price. "It is going to take a appropriate action if it can be verified."

Price said she could not disclose what their investigation might entail, or what "appropriate action" might be.

“We’ve just learned of this claim today and are checking into it,” said Andy Parsons, chair of the Blu-ray Disc Association and senior V.P. of product development at Pioneer Electronics, in an email.

The new crack follows that from earlier this year, when a hacker by the name of muslix64 broke the AACS system as it applied to each movie. While the earlier hack led to 100 HD-DVD titles and a small number of Blu-Ray movies being decrypted one-by-one, the so-called "processing keys" covers everything so far made.:

"Most of the time I spend studying the AACS papers," Arnezami said in his forum post revealing the successful assault on the next-gen DRM system. "... what I wanted to do is "record" all changes in this part of memory during startup of the movie. Hopefully I would catch something insteresting. ... I now had the feeling I had something. And I did. ... Nothing was hacked, cracked or even reverse engineered btw: I only had to watch the "show" in my own memory. No debugger was used, no binaries changed."

It's not yet clear what it means for the consumer's ability to copy movies, or, for that matter, that of mass-market piracy operations. The short form is that the user still needs a disk's volume ID to deploy the processing key and break the AACS encryption — but getting the ID is surprisingly easy.

Arnezami found that they are not even random, but often obvious to the point of foolishness: one movie's Volume ID turns out to be it's own name and the date it was released. There isn't yet an automatic system, however, that will copy any disk, in the manner of DeCSS-based DVD copying systems.

Even so, the new method completely compromises HD-DVD in principle, as it relies on AACS alone to encrypt data, even if there are other parts of the puzzle that are yet to fit together. Blu-Ray has two more levels of protection: ROM-MARK (a per factory watermark, which might revoke mass production rights from a factory but not, it seems individuals) and BD+, another encyption system, which hasn't actually been used yet on sold disks (but which soon will be), meaning that its own status seems less obviously compromised.

How might the companies respond? The processing key can now be changed for future disks. However, the flaws inherent in the system make it appear easy to discover the replacement: the method of attack itself will be hard to offset without causing knock-on effects. For example, revoking player keys (in advance of obfuscating the keys in memory in future revisions of the system) would render current players unable to view future movies. Revoking the volume and processing keys that have been hacked would mean that all movies to date would not run on new players.

Publishers could randomly generate Volume IDs in future releases (as they are still needed for the current hack to work), which would make them harder to brute-force. That said, it's claimed that the "specific structure" of the Volume ID in memory makes it feasible to brute-force randomized ones anyway.

Following are links to the current discussion at the doom9 forums, in which Arnezami and other provide regular updates on their progress. We don't offer any warantee that the software implementations so far produced won't blow up your computer or get you thrown in jail and whipped with wet towels by MPAA lawyers:

Proof of concept code for the process key hack is here: http://forum.doom9.org/showthread.ph...484#post953484

Implementation for Windows: http://forum.doom9.org/showthread.ph...496#post953496

Implementation for OSX: http://forum.doom9.org/showthread.ph...516#post953516
Whoa, that's weird
Reply With Quote
  #2  
Old 15-05-2007, 05:25 AM
TDD's Avatar
TDD (Offline)
This Duck Dies?
 
Join Date: Feb 2007
Posts: 381
TDD is an unknown quantity at this point
Default

where did this information come from?
__________________

To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.
Reply With Quote
  #3  
Old 15-05-2007, 10:36 AM
Andrew's Avatar
Andrew (Offline)
Active Member
 
Join Date: Feb 2007
Location: Georgia
Posts: 879
Andrew is an unknown quantity at this point
Default

I love the doom9 forums.
__________________


Live Chat:
To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.

The Official Rules:
To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.

The Official Middleman List:
To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.

PM me for help:
To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.

My Blog:
To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.



To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.

To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.

To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.




:cool:


Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 10:23 PM.

Powered by vBulletin® Version 3.8.3
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.0
Copyright © 2006 - 2012, Rsforums.org