Log in

View Full Version : BackupHDDVD, a tool to decrypt AACS protected movies


Pages : 1 [2] 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23

Susana
28th December 2006, 15:37
With keys or without keys, :thanks:

Gradius
28th December 2006, 15:38
1st of all, congratulations to muslix64 for this (yeah, kinda same way as xing player was w/ DVDs).

But I totally aggree with 1st XStylus's post, this stuff was too soon to be released to public/masses, the best way was to wait more 2 years to release this, but yeah, what is done, is done.

Keep in mind to clean up all your cache around, even change your ISP, etc, etc, and good luck with your identity. :thanks:

Hollywood and other EVIL guys think, in a digital world, something will be 100% unbreakable, in reality they're as stupid as they can be. They keep themselves busy to find new ways to protect your sh** while forget to provide us GOOD stuff to market (at fair price of course), so good that I'll BUY them, and not just to try to make a mere copy.

But fell sorry for them, after all, they're VERY poor doing just $1 trillion/year. :rolleyes:

Btw, Blu-ray is the next target! ;) :p

PS: About the upgrade stuff, just keep the good old ones working. ;)

BUZZARD1
28th December 2006, 15:49
Good job man. Forget them people telling you that it was a bad idea to release it when you did ect. ect. Some people cant be pleased no matter what. I do hope you protect your identity cuase I would like you to stick around. Keep up the good work bro!

cwm9
28th December 2006, 15:50
I don't think this is going to affect the studios one whit.

Consider who DRM is really aimed at:

In the end, no matter how good the encryption, you can always crack open a TV and wire up an analog to digital converter directly to whatever outputs are driving the pixels on the display. Do it with high enough quality ADCs, and the capture will be nearly perfect. Once you've done that, it's a simple matter of streaming the data to a very fast hard drive array and then re-compressing it. Too much work for the average joe, maybe, but not too much work for a dedicated counterfeiter that intends to make 100,000 units and make a $300K profit. Yes, but what happens when the counterfeiter's player keys are revoked, you say? If you're making $100K+ from each title you counterfeit you throw away the player with the revoked key and buy a new one.

Thus, this exploit really means very little to a determined counterfeiter.

So if the DRM wasn't meant to stop a determined counterfeiter, then who was it meant to stop? Probably the average joe. And if that's the case, this hack probably won't mean much. Why? Think about what the studios really want... They want piracy to go away, obviously. But if you can't have your wish, what's the next best thing? To reduce it, of course.

The goal of this DRM is to make it more difficult for the average joe to copy his friends movies. With DVDs, you can download DVDShrink which "just works" pretty much all the time. That was a disaster for the studios because once someone was shown how to copy a DVD one time, they had no problem doing it over and over.

But there will (probably) never be such a solution with HDDVD because of the way keys are distributed. Sure, you'll be able to download the most current Title Encryption Key database that contains every key known to date, and there will probably be newsgroups dedicated to keeping up with the latest 0-day exploit, but a very large percentage of people who now copy DVDs will not be able to keep up with these tit-for-tat exchanges between the crackers and the publishers. They'll get shown how to copy an HD DVD by someone, and they'll be able to copy any HD DVD that was released prior to that date, but they won't know where to go to update their software with the latest keys or exploits needed to copy title released AFTER that date.

If instead of having one icon that you click on you have to go searching for the latest exploit on Google, that's a win for the studios because ANY added complexity to the process of piracy necessarily excludes those people without the skills to overcome that added complexity gap.

How much of a dent in piracy would it take for the studios to be happy? 5%? 10%? I doubt very much the studio executives ever expected this to make piracy go away forever. I do think they are hoping to see a small decrease in piracy because of it.

Blu-Ray is just as vulnerable to the FET-Driver to ADC hack as HD DVD is, so it wins no points there. Will it make a difference that the "advanced joe" can't copy Blu-Ray? Maybe. Hard to say.

I don't think studios will be jumping ship over this because I imagine they fully expect Blu-Ray to fall to the exact same kind of exploits. Blu-Ray also has a standard encryption scheme, and it's keys will likely be exposed by a bad Blu-Ray implementation as well. What's the point in spending all that money to convert?

Blu-Ray has has the ROM Mark -- but it's a pseudo advantage. If a title is released on Blu-Ray and counterfeiters capture the output via any exploit, they might not be able to release their re-compressed version on Blu-Ray, but nothing prevents them from pressing the exact same re-compression on HD DVD.

So if the watermark can't prevent the distribution of movies, what can it do? It's really only effective for one application... games for the PS3, which only uses with Blu-Ray. Given the PS3s lackluster acceptance, one has to wonder if that means anything anyway, and even if it does, we all know there are hackers out there hard at work trying to find a hardware mod exploit to circumvent that DRM too.

Blu-Ray's one real advantage is BD+ which lets them change the encryption method from AACS to something else.... but what are they going to replace AACS with? As far as I know, there is nothing better than AACS that could be used to replace AACS. It will probably be at least a year before they do have a decent replacement that COULD be deployed via BD+, and I'm not sure what they can come up with that doesn't involve some sort of key that can be revealed by faulty software just like AACS and DVD has.

In summary, no matter what you do as a studio -- release on HD DVD or Blu-Ray -- some professional counterfeiter can hack open a TV, digitize the output, re-compress the movie, and release the title on HD DVD (or dvd, or super-dvd, or whatever.) Because the profit margin is so high, they could afford to trash their revoked player and buy a replacement for every movie if they had to. Every (smart) studio exec knows this; there's no reason for them to bail out just because of this. The "average joe" is probably screwed by either DRM even if this exploit turns out to work. The "advanced joe" will probably still find a way to copy movies. Overall, the best the execs can hope for is a small reduction in "average-joe" piracy which might or might not translate into a small boost in sales, which, over the next decade, might eventually amount to something more than a hill a beans after paying for the development of the DRM.

You know what I really think? I think some of the less knowledgeable suits at the studios wanted a pipe dream, and I think some engineers were more than willing to be paid to work on that pipe dream. If someone waves money in your face and asks you to do the impossible, what's a man to do but take the money and do his best?

BUZZARD1
28th December 2006, 15:55
Good job man. Forget them people telling you that it was a bad idea to release it when you did ect. ect. Some people cant be pleased no matter what. I do hope you protect your identity cuase I would like you to stick around. Keep up the good work bro!

Logik
28th December 2006, 16:24
very :cool:

0xdeadbeef
28th December 2006, 17:06
Well, worst case scenario would be:

- Compromised software player ist blacklisted immediately, so it won't be possible to extract title/disc keys with it any more as soon as the revocation list entry is activated.

- HD-DVD/BlueRay-Support for XP is generally cancelled. Player software will only run on Vista with fully AACP compatible hw/sw chain.

- Vista's new content protection functionality could make it really hard to read out more title/disc/player keys.

- Since no fast attack on AES is known (as it is for CSS), it will be impossible to decrypt HD-DVDs without valid keys.

One could imagine a way though to circumvent AACP without breaking AES: if the firmware/hardware of the HD drive could be altered to NOT update/use the revocation list, even a blacklisted player could be used as "zombie"-application to read out disc/title keys. Indeed only a few altered drives would have to exist to create a database of keys. Hosting this database would be a legal problem though. Then again, if there are countries which assume hosting of torrent hashs legal, there should be some which consider hosting decryption keys to be ok.

Just my 2 cents though.

TehMark
28th December 2006, 17:14
TYVM!! I love this community!

drbuzz0
28th December 2006, 17:16
Some observations:

1. A lot of people have been saying AACS is the end of backing up your media. They claim this because of all the measures against it and how the devices are updatability and keys are individual per movie. I've heard this all before (many times). Any protection system is only as strong as it's weakest link, if a system uses a crazy-secure rolling-key 512bit encryption algorithm, that does not mean the system is necessarily secure if there is a backdoor method of telling it that you are authorized. Example would be Nagravision, a satellite encryption that was hacked to pieces by figuring out how to fake being authorized. The more complicated a protection system is, the greater the chances that there's a weakness in it somewhere.

2. Having keys which need to be obtained or distributed is not that big a problem. Remember that it only has to be figured out once, whether by sniffing, leaking or even brute force... only needs to be done ONCE and then it's out. The studios can keep changing the key, but there are limits. Again using the satellite comparison, a while back distributing "seed codes" was how the Videocipher was hacked. They never really managed to close that hole until they completely redid the hardware.

3. AACS can be updated, but there are limits. It can only be updated to a certain degree, legacy support has to be maintained and there is a need to keep ontop of things. It's much like software protection. It's damn near impossible to keep a piece of software truely secure. As soon as it gets out the cracks and keygens start popping up left and right. The more popular the software, the faster it happens.

4. The DMCA is something I do not worry about. It's not a law, because it's an *ILLEGAL LAW* That is, it is superseded by the US Constitution and International principals of expression.
Gahndi said something like (to paraphrase) "To break an unjust law is a crime against the government. To follow an unjust law is a crime against justice and the human spirit."

This law is not valid. It is unjust and illegal. It may not have been struckdown (yet). But recall Dred Scott.



My sincere hope is that AACS weaknesses are not confined to underground discussion and groups. I hope that it will eventually end up like CSS and other DVD protection methods. I think at this point there's no point in trying to protect DVD's and crack down on DeCSS/DVD43/DVDDecrypter. The protection has been hacked to pieces. The cats out of the bag. It's something they have to live with and they have decided that they won't make the same mistake with AACS. Looks like maybe they have though :-P

nonphixion
28th December 2006, 17:27
First, great job on this.

Second, i am receving an error when running the app.

C:\hd\backuphddvd
Error occurred during initialization of VM
Unable to load native library: The specified procedure could not be found

java.exe gives the err "The procedure entry point _JVM_GetClassConstantPool@8 could not be located in the dynamic link library jvm.dll

i copied jvm.dll to the dir specified in the earlier post, and i get the first error. Any ideas?

0xdeadbeef
28th December 2006, 17:47
My sincere hope is that AACS weaknesses are not confined to underground discussion and groups. I hope that it will eventually end up like CSS and other DVD protection methods. I think at this point there's no point in trying to protect DVD's and crack down on DeCSS/DVD43/DVDDecrypter. The protection has been hacked to pieces. The cats out of the bag. It's something they have to live with and they have decided that they won't make the same mistake with AACS. Looks like maybe they have though :-P
There are two fundamental differences between CSS and AACS.

Firstly, CSS used a positive list of player keys, which has proven to be an error, as nearly all of the 408 supported player keys were published shortly after the first player key was compromised. AACS uses a negative list - this mechanism could only become useless if hundreds of player keys were compromised, which could only happen in a few years as there only a few players on the market right now. While for hardware players, this is still problematic, this is a nearly perfect solution for software players as they can just blacklist any compromised player and force the users to update their software.

Secondly, the encryption algorithm of CSS was flawed in a number of ways. In contrast to this, AES (used by AACS) is a pretty secure algorithm. In the last few years, several apporaches were discussed how to break a key faster than using a brute force attack. Then again until know, it's unclear if any of the suggested attacks could even be theoretically faster than a brute force attack. Don't get me wrong: as with most (if not any) other encryption scheme, some mathematician could come up with an algorithm tomorrow to break AES in a few iterations. However, this could also take until 2030 or may even never occur.

Deihmos
28th December 2006, 17:51
Did anyone confirm this working? It does not look that way so is this a hoax or is it real?

Sirber
28th December 2006, 17:59
look at page 1, it's for real.

Malow
28th December 2006, 17:59
Did anyone confirm this working? It does not look that way so is this a hoax or is it real?

just wait a few hours, someone in 2,710 user acessing this forum now, should have an xbox hd-dvd drive and some disks... ;)

edo1080
28th December 2006, 18:04
Hi, I posted a topic moths ago about D-Theater backup, and now all is almost done. I'm programming an FPGA and hope to be able to backup on HDD drive all my D-Theater tapes in one or 2 weeks.

I've tested this program and seems working, I obviously have to find a way to find the keys in memory. Maybe a way like to UN-DRM the old WMV-HD discs? In that case also the key was recovered from memory and dumped on an file on HDisk dirve

DVDCake
28th December 2006, 18:20
Howdy all,

The xbox hddvd drive works great on the 360, bought one for my Pop. AMAZING news that the ball is rolling on backing up HDDVDs! I'll pick on up this week to connect to my PC to see what this thing is all about.

To continue the tech discussion, what's known about the file format for HDDVD? Those files we saw on the youtube video, any way to analyze them to find the main feature A/V components?

Maybe I’m jumping the gun here, I feel like a kid with my face pressed up against the window of toy store =]

I’ll post anything I find once I get the xbox drive.

~DC

Deihmos
28th December 2006, 18:25
look at page 1, it's for real.

The person from the first page isn't the author? I meant if anyone else confirmed it working. I read many forums and no one got it to work.

Nic
28th December 2006, 18:35
It's very hard for anyone to actually test the software decrypts a HD-DVD as no decryption keys are available with the software. Someone would need to reverse engineer a key (perhaps from software such as Power DVD 6.5).

However, his story and code appear very plausible and at present there is no reason to believe this is a hoax. If it is a hoax, it is a very good one.

-Nic

monkeycz
28th December 2006, 18:50
wonderful!

Malow
28th December 2006, 19:12
It's very hard for anyone to actually test the software decrypts a HD-DVD as no decryption keys are available with the software.
-Nic

and the keys in the file tkdb.cfg?

EDIT: oops, my mistake. there are no keys, just example of code to identify the hd-dvd i guess..

0xdeadbeef
28th December 2006, 19:19
In the version linked to in this thread, there are only hash values and blank keys. It's however said that there's a version out there with valid keys. Can't confirm though.

ChronoCross
28th December 2006, 19:57
The source code basically shows that you need to manaully enter the keys into a list. You can get them because the DVD software leaves the key resident in memory. So it's not actually breaking the protection it's simply using a legal key to decode the video. AACS will simply change the decryption key and this software won't work once the patch is introduced to the HDDVD player that has this leak.


Efficient program for ripping too bad it's a little over exagerrated in what it actually does.

Krawhitham
28th December 2006, 20:14
The source code basically shows that you need to manaully enter the keys into a list. You can get them because the DVD software leaves the key resident in memory. So it's not actually breaking the protection it's simply using a legal key to decode the video. AACS will simply change the decryption key and this software won't work once the patch is introduced to the HDDVD player that has this leak.

Then the cat & mouse game begins, they release new players that store the key differently and hackers figure out how to get the key from memory each time

SeeMoreDigital
28th December 2006, 20:31
Then the cat & mouse game begins, they release new players that store the key differently and hackers figure out how to get the key from memory each timeWell if the consortium behind the HD-DVD format were dumb enough to allow the manufacture of HD-DVD drives and the creation of software players for use in PC's... what did they expect was going to happen ;)

I bet they wish they had confined the release of HD-DVD to "stand-alone" players only!

Looks like it might be worth getting an external HD-DVD drive (for the Xbox 360) after-all.....

bagel
28th December 2006, 20:40
Dia de los Santos Inocentes ?

I hope not...

Solo
28th December 2006, 21:32
mmm looks promising ....

At least I won't have to replace my expensive 24" LCD screen + non-HDCP GFX to watch future HD-DVD movies.

I have a feeling there is going to be an increase in HD-DVD drive sales soon ;)

Adub
28th December 2006, 21:36
I wonder how DVD Jon will react to this? Do you think he will take it and run? As in, make it better?

So far there is no word on his site, the last post was on december 1st. I can't wait to hear what he says.

Edit: did anyone else notice the black bar in the youtube video when the camera scans over the tkdb.cfg file? It seems the author was being safe, as he doesn't release the keys themselves, so technically he is not doing anything wrong. It is the next step that may be considered illegal.

zeroprobe
28th December 2006, 21:37
Has anyone actually tried doing anything with powerdvd yet?? If I had the drive I would be playing already.

Cant be that hard find if the key is decrypted somewhere.

edo1080
28th December 2006, 21:40
The program which the author is referring to as exposing the key in memory is probably PowerDVD 6.5. I'm trying to locate where in the memory the key is located, anyway if someone could post at least one key, I could be able to tell where PowerDVD will place the keys

zeroprobe
28th December 2006, 21:42
The program which the author is referring to as exposing the key in memory is probably PowerDVD 6.5. I'm trying to locate where in the memory the key is located, anyway if someone could post at least one key, I could be able to tell where PowerDVD will place the keys

Good stuff I thought everyone was just waiting for everyone else.

Jebus just looked at my join date and 4 posts, thats one a year lol. Amazing what gets me from under a rock.

OverlordQ
28th December 2006, 21:53
The program which the author is referring to as exposing the key in memory is probably PowerDVD 6.5. I'm trying to locate where in the memory the key is located, anyway if someone could post at least one key, I could be able to tell where PowerDVD will place the keys


Well yea, I"m sure with one key alot of people could find where in memory its stored, that's not the hard part. Either wait till he releases the newer version, or do some actual work in trying to find the keys, load up your favorite debugger and have a whack.

Sy
28th December 2006, 21:54
So the question is where are the keys.... hmmm... I don't have cyberlink or a hd-dvd drive to search for them but here are a couple of thoughts.

when playing a hd-dvd does cyberlink write a file to its install directory with the sha1 code so that it can identify the disk easily? is that where the original TKDB.cfg came from? How about in the registry? Else it looks like you are gonna need a way to dump the memory and scour through that.

~Sy

swiego
28th December 2006, 22:16
Interesting! I will have to try this to see if the same vulnerability affects WinDVD HD (which comes with my Toshiba HD-DVD laptop).

On the one hand, it would be nice to reduce wear and tear on what I feel is a pretty flimsy notebook drive. On the other hand, I'd hate to see this affect the popularity of a format that I very much enjoy.

Gradius
28th December 2006, 23:15
Yeah, WinDVD is vulnerable too.

Gradius

blutach
28th December 2006, 23:23
@cwm9 - :goodpost:

Hollywood and other EVIL guys think, in a digital world, something will be 100% unbreakable, in reality they're as stupid as they can be. They keep themselves busy to find new ways to protect your sh** while forget to provide us GOOD stuff to market (at fair price of course), so good that I'll BUY them, and not just to try to make a mere copy.You are implying that you don't buy but rather illegally copy digital video. This is against rule 6.


The DMCA is something I do not worry about. It's not a law, because it's an *ILLEGAL LAW* That is, it is superseded by the US Constitution and International principals of expression.
Gahndi said something like (to paraphrase) "To break an unjust law is a crime against the government. To follow an unjust law is a crime against justice and the human spirit."

This law is not valid. It is unjust and illegal. It may not have been struckdown (yet). But recall Dred Scott.Whatever your feelings, the law is passed in the US and is valid. What you are saying amounts to incitement to forum members and guests to break this law. Rule 6 is very pertinent in this regard.


The program which the author is referring to as exposing the key in memory is probably PowerDVD 6.5. I'm trying to locate where in the memory the key is located, anyway if someone could post at least one key, I could be able to tell where PowerDVD will place the keysAnyone posting a key on this forum is in direct violation of rule 6. Please read that rule carefully as well as the announcement at the top of this forum.

I really think this discussion needs to have very careful regard to forum rules and the laws of the various lands. Future posts which do not have such regard will incur strikes.

Regards

Gradius
28th December 2006, 23:34
@cwm9 - :goodpost:

You are implying that you don't buy but rather illegally copy digital video. This is against rule 6.

Not here, THANKS GOD I'm not in US. :devil:

Btw, I'm not implying anything, I let that to other ppl around. :cool:

Gradius

Bathrone
29th December 2006, 00:08
Edited - my words came out the wrong way my apologies.

blutach
29th December 2006, 00:16
Let's stay on topic please bathrone. And might I remind you of rule 4.

Regards

swiego
29th December 2006, 00:22
Well, the players aren't adhering to AACS spec if the decrypted title key can be snooped from RAM, although that does call into question the ability to have a PC-based player. The spec basically says that the decrypted title key should be discarded if the disc is ejected, power is lost, an AACS boot sequence initiates or the player stops. I would think a memory dump or a freeze of a process to inspect its memory contents would constitute stopping the player!

Anyway, getting the volume id is easy enough but I'm still searching for the right title key from a ram dump of windvd hd. For all I know, WinDVD has gotten it right and the decrypted key just ain't there.

hirez80
29th December 2006, 00:28
Gotta agree with Bathrone,
plus I read the rules, i do not think he was "NOT nice" and I do think you can respect someone even though you think he is hypocritical or ??

But I know on the other hand, that this site and many others have to have this dubbel standard sort of speak, as it would otherwise directly violate isps, hosting services etc.
So there is a fine line between endorsing someone to do something, and just showing and talking about it.

Even though you guys have tutorials etc. which basically show stuff which is not allowed, as long as you say that i guess its possible?
Anyway, their our "doing their job" so THAT we should respect, but yes, this is a hypocritical world.. too bad..

Nuf said, I like many others am very happy about the progress with the HD DVD backups. My questions is, are they able to block a piece of software from FUTURE dvds just because a few ppl hacked it?? thats like asking everyone to reinstall windows, or word etc. (ok you get the point). even standalone players, say that a Pioneer chip gets compromised, thats it? i cant watch more recent movies after they update the key?? sounds like they are diging their own grave.. ppl will be VERY pissed if this happens...

Bathrone
29th December 2006, 00:55
What I am particularly interested in is how this exploit might be patched. How can volitile memory be completly protected from dumping? Encrypt the decrypt key? But then that has to have another decryption key so the cycle starts again.

ChronoCross
29th December 2006, 00:57
Not here, THANKS GOD I'm not in US. :devil:

Btw, I'm not implying anything, I let that to other ppl around. :cool:

Gradius

remember anyone who has a trade agreement with the US (basically anyone who gets legal hollywood movies/TV) has to respect US copyright law. This includes DMCA.

ChronoCross
29th December 2006, 01:00
What I am particularly interested in is how this exploit might be patched. How can volitile memory be completly protected from dumping? Encrypt the decrypt key? But then that has to have another decryption key so the cycle starts again.

TCP. Basically the key would never pass through memory but rather it would be stored in the TCP Chip and all DRM'ed data would have to pass through this. The TCP Platform is supposed to be separate from a OS and would prevent anything the is designed to use TCP from leaking out.

TCP is the ultimate in evil DRM and with all these companies pushing it, any new hardware in the future might have it so there may be no way around it........which is why I joined the EFF and steadfastly oppose the TCP.

TCP is trusted computing platform.

dukey
29th December 2006, 01:05
Someone correct me if I am wrong. But normally you can't read the memory of a program unless it is an area of specifically shared memory. However unless you 'zero' the memory before you exit the program that data will still be left in RAM. In the same way as when you delete files off your hard disk, they are not 'really' deleted, the sectors on the drive are just marked as aviaiable to write over.

If the program zeros the memory it uses for the keys before it exits (like it should really ..) u could probably get around this by just killing the app and forcing it to close before it can do this.

0xdeadbeef
29th December 2006, 01:46
Someone correct me if I am wrong. But normally you can't read the memory of a program unless it is an area of specifically shared memory.

Firstly, a ring0 process can read and write any memory. This includes kernel debuggers of course.
Secondly, every normal process can read and write in another process' memory if it is able to load a dll into that process' memory. Which is usually pretty easy to do.


However unless you 'zero' the memory before you exit the program that data will still be left in RAM. In the same way as when you delete files off your hard disk, they are not 'really' deleted, the sectors on the drive are just marked as aviaiable to write over.

Using a memory dump is a somewhat dumb attempt to find the key. Usually you would use a debugger and set a breakpoint on certain API calls. At some point some call will return the key on the stack or in some registers.


If the program zeros the memory it uses for the keys before it exits (like it should really ..) u could probably get around this by just killing the app and forcing it to close before it can do this.
Anyway, dumping the memory doesn't make much sense. Indeed since the application allocates memory dynamically, the key might land in different locations depending on order of things done before. E.g. if a HD-DVD has more chapters or whatever, more memory is allocated on the heap for internal structures and the key lands at a higher address.

Best guess would be to examine which routines are called after you inserted a disk. The key exchange has to be one of the first operations, so disc insertion should be a good place to start.

zilexa
29th December 2006, 01:59
F A N T A S T I C ! ! !

hey muslix64,
now that you made the playback of HD-DVD almost as easy as a normal DVD movie, this could very well be THE reason for people to upgrade to a HD-DVD player!
(And since Bluray uses AACS as well this could mean the same thing for Bluray).

Since there has not been a bump for HD-DVD and Bluray like there was when DVD was released, it didn't seem very realistic these new HD players would break through.
But now with your work, this could lead to a breakthrough in the near future!
Congratulations man, and thanks!

hechacker1
29th December 2006, 02:53
so who is going to take this program to the next step?

Right now there is nothing illegal about the program because it doesn't provide any keys. It's just a nice proof of concept.

But for decryption to be useful I would think we need some automated way of extracting the key from the dvd. At that point we have a viable method of copying dvd's.

If we are forced to share keys through warez sites or download lists from offshore locations it makes the decryption unreliable and poorly supported (because we all know legitimate places like doom9 won't support the sharing of keys). +, there are so many variations of dvd's, probably each with it's own key.

I guess somebody is going to have to reverse engineer the playback and decryption of the key similar to the way commercial software players do it. Otherwise there will always be a cat and mouse game of updates to circumvent the protection.

Anyways, thank you so much for your program!

Gradius
29th December 2006, 03:00
remember anyone who has a trade agreement with the US (basically anyone who gets legal hollywood movies/TV) has to respect US copyright law. This includes DMCA.

Not here in Mars. :p

The world can live w/o US, never the inverse. :cool:

harycover
29th December 2006, 03:23
Hi muslix64

I know nothing about decrypting but I congratulate you and fully support you : you bought it, you should be able to watch it !

That said, HDmovies are now quite common on newsgroups, allready ripped and ready to watch with a pc, I think that's mainly HD streams ripped

Movies industry should resign and adopt other strategy such as price drop to sell more, if they Imagine That I would pay 25 euros or such per movie giving that I've already paid to watch it at the movie theater then they will wait a (very) long time for my money to come their way.

Cheers all

OverlordQ
29th December 2006, 03:47
Well, the players aren't adhering to AACS spec if the decrypted title key can be snooped from RAM, although that does call into question the ability to have a PC-based player. The spec basically says that the decrypted title key should be discarded if the disc is ejected, power is lost, an AACS boot sequence initiates or the player stops. I would think a memory dump or a freeze of a process to inspect its memory contents would constitute stopping the player!

Anyway, getting the volume id is easy enough but I'm still searching for the right title key from a ram dump of windvd hd. For all I know, WinDVD has gotten it right and the decrypted key just ain't there.


Reading memory would not stop playback unless you freeze the program to get an exact snapshot of it's current ram contents, I'd think pausing the movie within the player to guarantee the important values will not change would be enough so that a sequential scan would reveal what you need to know.