View Full Version : So what will actually happen if AACS revokes keys from Cyberlink and Intervideo?
Galileo2000
22nd January 2007, 19:36
I keep hearing people scared to death of the prospective that AACS will revoke keys from Cyberlink and Intervideo.
I would like someone more knowledgeable in the situation than I am to give an overview of such scenario and it's effect to BackupHDDVD development.
My take it is non-issue, but maybe I am missing something here.
diogen
22nd January 2007, 20:01
I'm not knowledgeable to give a definite answer, but based on AVS posts the player manufacturer issues a patch, gets a new AACS key, and after that every newly released disk has the the old AACS key blacklisted (patch has to be applied).
That is the theory.
Real life might change this scenario: if AACS LA decides that keys can't be protected under XP, players might get a new key valid only in Vista; playback under XP is banned alltogether.
Amir sounded upset in one of his rare comments on this issue, it looks like not everything is honky-dory in AACS land. A decision what to do might take a while. Some studios might opt to halt new releases until this decision is made.
Diogen.
honai
22nd January 2007, 20:15
The point is that PowerDVD and WinDVD themselves have to implement key revocation, i.e. key revocation isn't like a program on a disc that gets automagically executed but rather PowerDVD/WinDVD have to have some code in there that finds out they're being revoked, and then disable themselves.
I find this scenario highly unlikely. Would Cyberlink/Intervideo risk consumer charges when their software suddenly stops working? I don't think so. Both companies make their money from consumers, not from the AACS-LA. And the prospective fines by the latter for Cyberlink/Intervideo not implementing/executing key revocation are still much smaller than the money they'd lose from customers who sue them, or just choose not to buy new versions but rely on cracked ones because they still want to exercise their fair use rights.
diogen
22nd January 2007, 20:18
The point is that PowerDVD and WinDVD themselves have to implement key revocation... PowerDVD/WinDVD have to have some code in there that finds out they're being revoked, and then disable themselves.True, and if they want to stay in business, they will do just that. It's in the licensing agreement.
Diogen.
muslix64
22nd January 2007, 20:32
They will eventualy revoke software players.
Will they allow more secure soft player on Windows? May be, may be not... Will the restrict software player to Vista? May be, may be not...
We have to extract a maximum of keys while we can. That way, when more secure version of player will be there, we will know what values to look for in memory, speeding up the process of reversal. Once you know the key protection method in memory, it will be easy to extract keys, like we are doing now.
Another scenario, is to fully implement AACS process (with MKB and all the stuff) and steal some player keys. We don't disclose the devices keys, be we disclose volume keys like we are doing now... bypassing the revocation system
I'm not scared at all... it will be harder but still possible, no big deal.
People forget that you can also extract key from standalone (in your living room) player.
Just dump the memory through the JTAG port...
What do you think?
honai
22nd January 2007, 20:40
@diogen
I'm quite sure that both players have a "bug" that prevents key revocation from "functioning properly" ...
@muslix64
Toshiba's players might be another good attack vector. They run custom versions of Red Hat Linux, but I don't think that Toshiba had the budget to implement protection layers like in the XBOX360 or PS3, so injecting custom software into the machine should work.
Galileo2000
22nd January 2007, 20:48
They will eventualy revoke software players.
Will they allow more secure soft player on Windows? May be, may be not... Will the restrict software player to Vista? May be, may be not...
We have to extract a maximum of keys while we can. That way, when more secure version of player will be there, we will know what values to look for in memory, speeding up the process of reversal. Once you know the key protection method in memory, it will be easy to extract keys, like we are doing now.
Another scenario, is to fully implement AACS process (with MKB and all the stuff) and steal some player keys. We don't disclose the devices keys, be we disclose volume keys like we are doing now... bypassing the revocation system
I'm not scared at all... it will be harder but still possible, no big deal.
People forget that you can also extract key from standalone (in your living room) player.
Just dump the memory through the JTAG port...
What do you think?
Muslix,
Extract the keys from the standalone players is an excellent idea. I am pretty sure it will be even easie than what's you and others have already done on this project.
After that any key revocation will be a kiss of death for AACS.
CE manufacturers and consumers will be very very upset if they need to put a new firmware on millions of the devices.
dvdguru
22nd January 2007, 20:55
Toshiba's players might be another good attack vector. They run custom versions of Red Hat Linux, but I don't think that Toshiba had the budget to implement protection layers like in the XBOX360 or PS3, so injecting custom software into the machine should work.
In the new generation of toshiba player the firmware is inside a totaly protected eprom:
http://img263.imageshack.us/img263/7590/dsc007638lj.jpg
anche the network adapter is totally protected.
http://img297.imageshack.us/img297/8206/dsc007566uv.jpg
You can damage the components if you try to remove the glue.
2bigkings
22nd January 2007, 20:57
wow great pictures dvdguru. thanks
diogen
22nd January 2007, 20:58
CE manufacturers and consumers will be very very upset if they need to put a new firmware on millions of the devices.This isn't neccessary.
Given enough time and determination, only the "guilty" ones can be forced to do it.
And if it is a BD player, BD+ (at least in theory) can just "kill" it for good.
Diogen.
mikeathome
22nd January 2007, 21:02
Hi,
how do you get a Volume Key from PowerDVD. As far as I know only the Jap WinDVD 8 HD player has been compromised. So, it's easy to blacklist, PowerDVD does not store keys in mem, game over...
mike
P.S. I would like somebody prove me wrong :script:
Edit: I know quite a few SAP (Standalone Players) that use encrypted FW procedures, means the FW itself is protected in Flash and will be decrypted only in Ram for execution AND there's no such JTAG access to RAM at all. I fear the whole hole was just 'initiated' to boost HD sells and very soon, game over... Well, if by this time the Software Player will work correctly and respect the investment some of us made in HDCP compatible HW I can live with that, sorry... not meant to be provoking!
Galileo2000
22nd January 2007, 21:04
This isn't neccessary.
Given enough time and determination, only the "guilty" ones can be forced to do it.
And if it is a BD player, BD+ (at least in theory) can just "kill" it for good.
Diogen.
They all will be "guilty", they all run some stripped-down Linux with exactly the same structure, at least those on the market right now.
If my BD player will be murdered, I will revenge it's death, and so will others.
calinb
22nd January 2007, 21:04
You can damage the components if you try to remove the glue.Yeah--but for someone who's skilled at reworking fine pitch components on tightly spaced traces, that glue shouldn't pose much of a challenge.
Galileo2000
22nd January 2007, 21:05
Hi,
how do you get a Volume Key from PowerDVD. As far as I know only the Jap WinDVD 8 HD player has been compromised. So, it's easy to blacklist, PowerDVD does not store keys in mem, game over...
mike
P.S. I would like somebody prove me wrong :script:
Yes it (PowerDVD) does.
Search is your friend.
diogen
22nd January 2007, 21:10
They all will be "guilty", they all run some stripped-down Linux...Yes, the revocation process will be some sort of never ending cat-n-mouse game.
You should read Felten's 6-part series (http://www.freedom-to-tinker.com/) about AACS.
Diogen.
dvdguru
22nd January 2007, 21:14
Yeah--but for someone who's skilled at reworking fine pitch components on tightly spaced traces, that glue shouldn't pose much of a challenge.
It's not a soft glue. It's similar to glass... :D
mikeathome
22nd January 2007, 21:14
Yes it (PowerDVD) does.
Search is your friend.
Hi,
easy to proof me wrong and post your link. I did search as I do not have this jap. version but a few HDs with no keys available yet...
mike
zeroprobe
22nd January 2007, 21:16
there is more or us than them so we will prevail. :)
Galileo2000
22nd January 2007, 21:24
Hi,
easy to proof me wrong and post your link. I did search as I do not have this jap. version but a few HDs with no keys available yet...
mike
Mike, you need to work on your search skills...
http://forum.doom9.org/showthread.php?p=934036&highlight=powerdvd#post934036
mikeathome
22nd January 2007, 21:31
Mike, you need to work on your search skills...
http://forum.doom9.org/showthread.php?p=934036&highlight=powerdvd#post934036
Hi,
THANKS!
Actually now I am curious why everybody's developing keyextractors is using WinDVD jap. HD Version and is not focussing on the more spread PowerDVD? Btw. which PowerDVD are we speaking about 6.5 or 7.1 Ultra? I'll give it a try anyway, need to see with my own eyes, one can write and tell a lot...
mike
K40
22nd January 2007, 21:38
Would the info for revoked Softwareplayers be stored in the
drive the first time a newer HDDVD with updated list is
inserted?IF so,must a HDDVD player be installed on this PC to
pass this update to the drive or is it possible it gets there on
a system with only BackupHDDVD installed?
guile
22nd January 2007, 21:44
Mike, you need to work on your search skills...
http://forum.doom9.org/showthread.php?p=934036&highlight=powerdvd#post934036
Although it seems Janvitos may have "found" a key (or keys) through Power DVD (it was never mentioned what version he may have been using), he never elaborated (nor has anybody else for that matter) further. It seems more people are using PowerDVD as a player (imo). As I do have the Jap version of Windvd, I don't have an HDCP compliant card or monitor so it is impossible for me to search out keys. I am eager to do this through Powerdvd though.
Galileo2000
22nd January 2007, 21:45
"It’s believed that wrongly implemented AACS-compliant PowerDVD 6.5 HD DVD player retrieves the encrypted title key from the HD-DVD disc and stores the key in a database-formatted configuration file that PowerDVD at some points loads into unencrypted portion of memory in clear text format. By using this title key, the revocation system which intends to protect the DRM from crack can be bypassed or failed as useless too."
http://www.mydigitallife.info/2007/01/01/crack-decrypt-and-copy-hd-dvd-aacs-drm-protected-movies-with-backuphddvd/
Why don't you guys contact Janvitos, in his threads or through PM and ask him what he did?
tonyp12
22nd January 2007, 21:57
http://forum.doom9.org/showthread.php?p=934036&highlight=powerdvd#post934036
It's a quote a few post below there they talk about powerdvd.
It does not mean that the quote is how to find keys in powerdvd.
I have done 10 memory dump with powerdvd and search for
known keys, it never finds it.
Windvd does not run on my computer so I can not contribute
to new keys until someone figure out how to do it in powerdvd.
mikeathome
22nd January 2007, 21:59
Although it seems Janvitos may have "found" a key (or keys) through Power DVD (it was never mentioned what version he may have been using), he never elaborated (nor has anybody else for that matter) further. It seems more people are using PowerDVD as a player (imo). As I do have the Jap version of Windvd, I don't have an HDCP compliant card or monitor so it is impossible for me to search out keys. I am eager to do this through Powerdvd though.
Hi,
I actually found something, so there's hope ...
... more info about the PowerDVD trick not very specific though.
http://forum.doom9.org/showthread.php?p=935102#post935102
mike
Galileo2000
22nd January 2007, 22:12
Hi,
I actually found something, so there's hope ...
... more info about the PowerDVD trick not very specific though.
http://forum.doom9.org/showthread.php?p=935102#post935102
mike
So now you can ask both Janvitos and Bystander what they did.
It will be really interesting when Intervideo finally releases their HD pack for English WinDVD 8.
dito
22nd January 2007, 22:42
back to topic...
I thought the keys was revoked every 18 months... Is this not the case?
Best regards!
He-Man
22nd January 2007, 23:21
It's not a soft glue. It's similar to glass... :D
It might be easier to use a Dremel to remove the outside of plastic on the IC itself. The chip die is only in the middle and the SMD soldering pins goes a bit inside the chips where they are connected to very small wires that connects to the die itself. With careful use of a Dremel you can expose the pins at the outside of the IC under the plastic and attach a logic analyzer. It might be easier to drill in this plastic than the glue.
Galileo2000
23rd January 2007, 04:44
Hi,
how do you get a Volume Key from PowerDVD. As far as I know only the Jap WinDVD 8 HD player has been compromised. So, it's easy to blacklist, PowerDVD does not store keys in mem, game over...
mike
P.S. I would like somebody prove me wrong :script:
Edit: I know quite a few SAP (Standalone Players) that use encrypted FW procedures, means the FW itself is protected in Flash and will be decrypted only in Ram for execution AND there's no such JTAG access to RAM at all. I fear the whole hole was just 'initiated' to boost HD sells and very soon, game over... Well, if by this time the Software Player will work correctly and respect the investment some of us made in HDCP compatible HW I can live with that, sorry... not meant to be provoking!
Yeah, now muslix is an agent of the HD consortium.
Mike, you are not contributing, on the contrary IMHO.
HyperHacker
23rd January 2007, 05:39
Seems if you looked up datasheets for those chips, you might find one that tells you the exact pin spacing (many do). From there, if the "glue" is soft/strong enough, you could drill right through it to the pins themselves and simply stick wires in the holes. You wouldn't even need to solder or worry about touching other pins if you used a small enough bit.
Or of course you can try to trace the printed circuits and simply splice into some exposed traces. Maybe melt the glue off. Attack the RAM chips. Put huge amounts of data in fields on discs (file names, etc) and try to overflow buffers. Really, putting a blob of goo over the firmware and network chips is hardly protection.
Spc01
23rd January 2007, 08:58
In the new generation of toshiba player the firmware is inside a totaly protected eprom:
http://img263.imageshack.us/img263/7590/dsc007638lj.jpg
anche the network adapter is totally protected.
http://img297.imageshack.us/img297/8206/dsc007566uv.jpg
You can damage the components if you try to remove the glue.
OMG.
They actually protected the chips.
:eek:
bomlat
23rd January 2007, 10:13
This black glue is a good news for us.
First, it mean that they didn't implemented any sophysticated crypto+efuse style protection like in the xb2.
Second, this thing is removable, as you can see on this page: http://forums.xbox-scene.com/index.php?showtopic=560275
This glue is similar to this: http://www.maxconsole.net/content_img/bl336.jpg
.This is the protection for the xb2 dvd rom firmware that is used by the M$.
So,there are guys out there that are able to remove this glue with a pyro pen.
Sorry,but as I see the youtube has deleted this video.
He-Man
23rd January 2007, 13:06
Sorry,but as I see the youtube has deleted this video.
The video is mirrored here: http://www.360mods.net/files/Untitled-1.html
Direct link if you want to download the flash movie before watching it (16.1 MB): http://www.360mods.net/files/epoxy.flv
blutach
23rd January 2007, 14:07
Hi,
easy to proof me wrong and post your link. I did search as I do not have this jap. version but a few HDs with no keys available yet...
mike
@mikeathome - please do not hijack this thread.
Observe rule 1a - this has been discussed before. And to retort as you have borders on a rule 4 violation.
Regards
ernysmuntz
23rd January 2007, 18:53
Its not hard to remove the glue, its just very time consuming. I removed that black epoxy stuff on my Xbox 360 drive in about 5 hours by heating\cooling\heating cooling it, it becomes brittle over time and is then much easier to scrape out, I used a bent safety pin. Time consuming but by no means difficult.
bomlat
23rd January 2007, 19:18
Yeah,and as I said:they don't want to protect it if it haven't got any sensible informations.:D
The volume/player key is under the black glue.
mikeathome
23rd January 2007, 19:38
@mikeathome - please do not hijack this thread. Observe rule 1a - this has been discussed before. And to retort as you have borders on a rule 4 violation.
Regards
Thread Title: So what will actually happen if AACS revokes keys from Cyberlink and Intervideo?
Correct?
There's no way to extract keys from PowerDVD. I tried for hours (both 6.5 and 7.1), search the board others did as well. I find sections look like TKs but no VK.
@ALL: Try it and let us know if you find typical byte sequences.
Cyberlink stated there's no leak. When WinDVD HD 8 will be blacklisted, game over ... until somebody helps us finding the keys in other players.
I wanted to initiate this AND HELP, if nobody's interested, you'll be soon, wait for Babel HD. AND if it is not Babel then Lotr or SW ... Actually the thread moves toward chip extraction.
Kick me, I am not contributing anyway, since 2001...
mike
mikeathome
23rd January 2007, 19:47
Its not hard to remove the glue, its just very time consuming. I removed that black epoxy stuff on my Xbox 360 drive in about 5 hours by heating\cooling\heating cooling it, it becomes brittle over time and is then much easier to scrape out, I used a bent safety pin. Time consuming but by no means difficult.
Hi,
the way I used to do this is using a gas solder with brought (SMD) nozzle, then quickly supercool with cooler spray, be careful and heat only the glue. Actually that way the glas/ceramic stuff is easier to remove than rubber like stuff (an acetonic solution might help).
mike
Galileo2000
23rd January 2007, 19:56
Thread Title: So what will actually happen if AACS revokes keys from Cyberlink and Intervideo?
Correct?
There's no way to extract keys from PowerDVD. I tried for hours (both 6.5 and 7.1), search the board others did as well. I find sections look like TKs but no VK.
@ALL: Try it and let us know if you find typical byte sequences.
Cyberlink stated there's no leak. When WinDVD HD 8 will be blacklisted, game over ... until somebody helps us finding the keys in other players.
I wanted to initiate this AND HELP, if nobody's interested, you'll be soon, wait for Babel HD. AND if it is not Babel then Lotr or SW ... Actually the thread moves toward chip extraction.
Kick me, I am not contributing anyway, since 2001...
mike
Did you contact Janvitos and Bystander?
I see no reason not to believe those guys, they have posted a lot of useful stuff on this forum.
If you cannot do it, it does not mean it cannot be done. No one thought things will be completely taken apart just a month ago until muslix got in.
Now, I am pretty sure if keys are revoked, they are revoked from all the software players in existence. Or did you think they will trust Cyberlink word that there are no vulnerabilities in thier players?
Original intention of the thread was "what if.." we no longer can use any player in existense to extract the keys.
Now, you sure had contributed to the forum since 2001 and I am just a newbee so feel free to ignore me.
Rufus210
23rd January 2007, 21:52
Just a note, AACS has both Content Revocation along with Device Revocation. Knowing exactly what to look for (title and volume keys from WinDVD) makes hacking anything else a lot easier. No need to try decoding using something you found, just check it against the known-good list.
AACS thought of this. Look at page 5 of the AACS Prerecorded book:
A Content Revocation List (CRL) is also embedded onto media and then stored in non-volatile memory by players and contains a list of content that contains a valid signature but has since been revoked.
There's little question that the Device Keys for WinDVD will be revoked, since it's trivial to just say "upgrade to the new version to play the new movies". Revoking content is a far trickier thing, since it would force everyone with a movie that's been revoked to trade it in or something for a new copy. Also as long as you never play any "post-revocation" content you'll never get an updated CRL so the old movies with known keys will still play.
Just another aspect to think of in what will inevitably become an arms race between "us" and "them".
zeroprobe
23rd January 2007, 22:14
I cant see them revoking 150 titles which will mean these will playback in new software players with the exploited keys.
Voila easy to find the keys again.
mikeathome
23rd January 2007, 22:21
Just a note, AACS has both Content Revocation along with Device Revocation. Knowing exactly what to look for (title and volume keys from WinDVD) makes hacking anything else a lot easier. No need to try decoding using something you found, just check it against the known-good list.
AACS thought of this. Look at page 5 of the AACS Prerecorded book:
There's little question that the Device Keys for WinDVD will be revoked, since it's trivial to just say "upgrade to the new version to play the new movies". Revoking content is a far trickier thing, since it would force everyone with a movie that's been revoked to trade it in or something for a new copy. Also as long as you never play any "post-revocation" content you'll never get an updated CRL so the old movies with known keys will still play.
Just another aspect to think of in what will inevitably become an arms race between "us" and "them".
Hi,
eventually the allready decrypted content won't be recognised as 'decrypted' and not compromised after all :-) This might lead to an increase in illegal P2P downloads ...
For those of you owning a XBox 360 addon connected to a PC thru USB, since the Mem Unit in the drive is not accessible -lack of Windows driver- the content revocation won't work for this drive at all, I guess...
mike
Galileo2000
24th January 2007, 01:24
For those of you owning a XBox 360 addon connected to a PC thru USB, since the Mem Unit in the drive is not accessible -lack of Windows driver- the content revocation won't work for this drive at all, I guess...
mike
Unless it is forced thru Automac updates on XP/Vista or included into Vista Service pack(s).
Mug Funky
24th January 2007, 02:45
revoking commercial titles is suicide. i think AACS allows it more because it can than it should.
a single DVD recall can cost huge amounts of money to the distributor (i wont say how much of course - a lot though). a revoked key would mean a product recall, meaning a tremendous loss (to say nothing about all the wasted plastic and hazardous chemicals - really a horrible thought that all those discs would be shredded and discarded. environmentally criminal in my opinion).
in fact, content revokation in the wrong hands could mean big distributors committing commercial sabotage on smaller ones - what would happen to an independent distributor of HD-DVDs having ALL their titles revoked at once? they'd be completely sunk in a matter of weeks and fall into massive, crippling debt (the customers and thus stores will all want refunds that the distributor will not be able to give).
of course, that's speculation, but food for thought nonetheless. think what would happen if certain governments had less liberal views on dissent in the media?
Metro
24th January 2007, 03:31
Hi,
For those of you owning a XBox 360 addon connected to a PC thru USB, since the Mem Unit in the drive is not accessible -lack of Windows driver- the content revocation won't work for this drive at all, I guess...
mike
Actually, if you allow the hardware wizard to connect to Windows Update, those 'unknown devices' will be installed as "XBOX 360 HD-DVD Interface 0" and "1" respectively, allegedly working correctly and 'no driver needed' according to XP's device manager. I haven't yet isolated the file that gets downloaded and allows them to be identified, and I suspect it's not going to be much help anyway.
The actual external drive shows up as a Generic USB Hub with four ports. The first port is a USB Composite Device (the "Memory Unit") with the two mysterious Interfaces "0" and "1" hanging off that. The second and third ports are the rather-underpowered USB outlets on the back of the case - you can't plug anything needing more than a few milliamps into these. The last port is a USB Mass Storage Controller with the Toshiba X807616 HD-DVD drive hanging off that.
The point of this is that once you've updated your hardware the Memory Unit is recognized by Windows even if it doesn't know what to do with it yet. It's not beyond the bounds of possibility that MS will send a package that makes use of the Memory Unit for something if it suits them...
Edit: Of course, if you pull the Tosh drive out of the case and hook it up with an adapter rather than use the MS circuit board, you've taken the "Memory Unit" right out of the equation.
mb2696
24th January 2007, 03:42
Edit: Of course, if you pull the Tosh drive out of the case and hook it up with an adapter rather than use the MS circuit board, you've taken the "Memory Unit" right out of the equation.
Is anyone aware of this being done successfully? I'd like to do this but I don't have the guts to be the first. Any links would be appreciated.
Galileo2000
24th January 2007, 04:50
Is anyone aware of this being done successfully? I'd like to do this but I don't have the guts to be the first. Any links would be appreciated.
Please, let's stay on the topic.
Either start your own thread or Please, Use Search.
It's been discussed before and people reported success.
Search is your friend.
Metro
24th January 2007, 04:59
Is anyone aware of this being done successfully? I'd like to do this but I don't have the guts to be the first. Any links would be appreciated.
There's a collection of pictures here: http://uneasysilence.com/archive/2006/11/8303/ - though they weren't too bright at identifying the plug - it's a mini-IDE, and you can get an adapter to connect it to IDE on eBay for less than $10.
I don't think it's too far off-topic, since removing the Memory Unit components from the drive would certainly reduce the likelihood of the drive hardware being used to lock out decryption. But I agree, we should stop this line of discussion here.
Foreigner999
24th January 2007, 14:20
I think the AACS creators have long ago had these hard back-room discussions on what they would do if the encyption and protection methods were compromised by some exploit in the wild. I believe they must have been well aware of the consequences of revoking software and devices and hosts and are absolutely going to implement revocation.
I don't think in the future it will be intelligent to play a cat and mouse game, because in the end after every attempt that is made to bypass the protection, we will indirectly be helping them to find better implementations and further secure against exploits both on hardware and software. Therefore, this IMHO, is a losing battle for the consumer/fair use side of the battle.
Knowing that they _WILL_ revoke software that is currently working in these sets of exploits, I persinally believe it would be more intelligent in the long run to add a serious penalty to every attempt to use the revocation lists. Such as:
Implement hardware exploits:
Everytime they issue revocations for hardware they will at least affect a thousand or more people. This is good for encouraging lawsuits. The first few times they can get away with replacement of hardware or telling joe nobody that it is a firmware issue. But the more they do this the worse the companies selling products look and incur stereotypes, and that will hurt their bottom line.
Software exploits while the "easiest" and least expensive of these exploits will hardly be noticed by joe nobody when they are asked to update thier software and in 9 or 12 months we will be finding the situation out that far to be a rather difficult one. The AACS creators will easily require that the software giants implement internet checks for updates before playback; Or worse, like crippled cd's that they phone home every playback attempt to easily fish out who is doing rather odd playback behavior. I believe I read on doom9 that this was actually in the specs but on the hardware side.
Get them to revoke hardware and tv panels of all kinds because they might reveal the keys and in probably 7 months down the road after two or three revocation updates they will have a major consumer backlash over HDCP and AACS copy protection/revocation. Make Consumers Care ;)
Off Topic is it possible to model in software the different interactions of MKB VKU's and whatever other key type acronym I might have missed? In other words a software emulator to mimic the processes of key veryfication and software revocation to better understand how the system might have flaws or weaknesses.
blutach
24th January 2007, 14:55
Well, we each have a view and can only wait to see what, if anything, will happen. No-one's crystal ball is better than anyone else's. FWIW: I agree with Mug Funky, whom I know has been around the industry for a while.
And Foreigner, every time something is stepped up, someone else finds a smarter way round it. Take ARccOS/Ripguard for example - the biggest fizzer around.
Regards
bdraw
24th January 2007, 20:00
Isn't possible for the current exploitable versions to stop working at all without an update? Maybe it is planned to have an update every 6 months and it will stop working without the update.
I interviewed Kevin Collins from MS on the latest Engadget HD podcast.
Here is the transcript from that question.
Me: Isn't the player itself that is already out in the wild that allows people to capture the keys off the titles, so as long as they don't update they will always be able to obtain keys?
Kevin: With software players there is a renewable factor so every certain amount of time a software player has to renew it's keys on there and if there is a preach then AACS has the option to revoke the key on that version, until there is a remedy and it would be disabled, that is all something that AACS is working on.
http://www.engadgethd.com/2007/01/24/engadget-hd-podcast-039-1-24-2007/
mikeathome
24th January 2007, 21:49
Isn't possible for the current exploitable versions to stop working at all without an update? Maybe it is planned to have an update every 6 months and it will stop working without the update.
I interviewed Kevin Collins from MS on the latest Engadget HD podcast.
Here is the transcript from that question.
http://www.engadgethd.com/2007/01/24/engadget-hd-podcast-039-1-24-2007/
Hi,
as long as a player is NOT required to run ONLY while having/had access to IN, timing is a very relative thing...
Is WinDVD HD making home calls? Does it require an initial home call to work? Sorry, for asking but I do not own this piece of soft.
mike
Gusar
25th January 2007, 00:53
For the time being has anyone knowledge of a good USB protocal capture/analyzer?
Do you know about usbsnoop (http://benoit.papillault.free.fr/usbsnoop/)? I don't know much about it, except that it's used for creating linux drivers for usb tv tuners. Maybe it will help you with whatever you're trying to do.
Zagor
25th January 2007, 22:37
Looks like the AACS finally admitted the keys are available.
RESPONSE TO REPORTS OF ATTACKS ON AACS TECHNOLOGY
AACS LA has confirmed that AACS Title Keys have appeared on public web sites without authorization. Such unauthorized
disclosures indicate an attack on one or more players sold by AACS licensees. This development is limited to the compromise
of specific implementations, and does not represent an attack on the AACS system itself, nor is it exclusive to any particular
format. Instead it illustrates the need for all AACS licensees to follow the Compliance and Robustness Rules set forth in the
AACS license agreements to help ensure that product implementations are not compromised. AACS LA employs both technical
and legal measures to deal with attacks such as this one, and AACS LA is using all appropriate remedies at its disposal to
address the attack. AACS was designed to address a number of potential attacks with minimal impact using a variety of means
including the ability to renew or upgrade players.
http://www.aacsla.com/press
HyperHacker
25th January 2007, 22:51
Knowing that they _WILL_ revoke software that is currently working in these sets of exploits, I persinally believe it would be more intelligent in the long run to add a serious penalty to every attempt to use the revocation lists. Such as:
Implement hardware exploits:
Everytime they issue revocations for hardware they will at least affect a thousand or more people. This is good for encouraging lawsuits. The first few times they can get away with replacement of hardware or telling joe nobody that it is a firmware issue. But the more they do this the worse the companies selling products look and incur stereotypes, and that will hurt their bottom line.
[...]
Get them to revoke hardware and tv panels of all kinds because they might reveal the keys and in probably 7 months down the road after two or three revocation updates they will have a major consumer backlash over HDCP and AACS copy protection/revocation. Make Consumers Care ;)
This seems like the right way to go. If we crack a software player, they can simply revoke it and have it pop up a message saying "an update is required, go get it on our website" or even update automatically. If we crack a hardware player, there's a good chance the update process will be much more difficult. Best-case scenario (for them), it can simply download an update from the Interweb, or have the user insert a disc (burned or sent in the mail) that will perform the update. Other players might not be so easy to update, which will be a pain for the users. I could see manufacturers not using user-updateable firmware for fear of firmware hacks, which would mean having to send the player in for "repair" for each update.
Also, hardware players are likely to be less secure, as they're dedicated to their task and less powerful. With software players we have a potentially several gigahertz CPU and gigabytes of RAM and storage space that can be used to make things more difficult, plus we may even have to work against the OS (especially with Vista and/or automatic updates). With a hardware player the CPU power, memory and storage space is going to be much less, and Windows won't be able to get in the way, so their protection is likely to be much less significant. Also, since they're single-tasking embedded systems, we can for example attack the memory chips to read keys out of memory, or go after the firmware chips to make some modifications. On a PC we can't easily do that, because the program's memory space is going to be in a different physical memory location every time it's run, and may be split across multiple memory chips, the hard drive (virtual memory), etc, especially for dynamically-allocated memory.
xyz987
25th January 2007, 23:46
Tons of keys will follow in next days.
Thanks mrazzido....
Good news :-)
xyz987
25th January 2007, 23:48
"does not represent an attack on the AACS system itself"
Well, it is a point of view.
Metro
26th January 2007, 01:06
The mentioned MS Auto update never did work for me. I tried as I usual hate yellow exemption marks ;-). It has been reported though, that MCE is doing a propper job AND yes no one was able to extract the updated driver, as far as my investigations went. So, this indeed, is suspicious and indicates that there might be 'hidden features'. But this is just speculations.
Hi Mike -
This is the gist of the .inf file that MS sends as part of the XP driver update. I did some registry trawling to find it, then modified it slightly to avoid copyright issues, but it's basically what gets delivered to your PC and it will work as it is. If you paste it into a file called xboxhd.inf and point 'Update Driver' to it, your yellow exclamation marks will vanish. However as you can see, MS has written a dummy file - it's just NULL 'driver services' for the memory unit interfaces.
; XBOXHD.INF
;
; Sets user friendly names for unsupported interfaces in the XBOX HD/DVD Drive.
; Installs a NULL driver service for the two memory unit interfaces
;
[Version]
Signature="$WINDOWS NT$"
Class=USB
ClassGUID={36FC9E60-C465-11CF-8056-444553540000}
Provider=%MSFT%
CatalogFile=XBoxHDDVD.cat
DriverVer=11/09/2006,1.0.0.0
; Add source disk to allow chkinf to work properly
[SourceDisksNames]
1=%XBoxHDDVD.DiskName%
[SourceDisksFiles]
[DestinationDirs]
[ControlFlags]
ExcludeFromSelect = *
[Manufacturer]
%MSFT%=MSFT,NTx86,NTia64,NTamd64
[MSFT] ; Added to keep chkinf from complaining
%Interface0.DeviceDesc%=Nullx,USB\VID_045e&PID_029E&MI_00
%Interface1.DeviceDesc%=Nullx,USB\VID_045e&PID_029E&MI_01
[MSFT.NTx86]
%Interface0.DeviceDesc%=Nullx,USB\VID_045e&PID_029E&MI_00
%Interface1.DeviceDesc%=Nullx,USB\VID_045e&PID_029E&MI_01
[MSFT.NTia64]
%Interface0.DeviceDesc%=Nullx,USB\VID_045e&PID_029E&MI_00
%Interface1.DeviceDesc%=Nullx,USB\VID_045e&PID_029E&MI_01
[MSFT.NTamd64]
%Interface0.DeviceDesc%=Nullx,USB\VID_045e&PID_029E&MI_00
%Interface1.DeviceDesc%=Nullx,USB\VID_045e&PID_029E&MI_01
[NullX]
CopyFiles = NullX.CopyFiles
AddReg = NullX.AddReg
[NullX.CopyFiles]
[NullX.AddReg]
[NullX.Services]
AddService= ,0x00000002 ; null service install
[Strings]
MSFT = "Microsoft"
XBoxHDDVD.DiskName = "XBOX HD-DVD installation media"
Interface0.DeviceDesc = "Xbox 360 HD DVD Interface 0"
Interface1.DeviceDesc = "Xbox 360 HD DVD Interface 1"
Sorry if it's drifting off topic a bit, but it does highlight the possibility that MS could send a real driver and do things with the interface if they so chose - and those 'things' may not be friendly. Not sure that it would interfere with the drive operation though, since the USB hub appears to be just that.
-s-
noclip
26th January 2007, 01:49
The title key for the currently playing title will always have to be in memory, and any obfuscation will always have to be undone for playback. We will always be able to obtain the title keys in any software player.
Wookie Groomer
26th January 2007, 01:56
We're not laughing at you AACs, we're laughing with you. :D
cwl7454
27th January 2007, 00:39
Of interest to all;
AACS confirms hacks on high-definition DVD players
but the attacks on the new format echo the early days of illegal trafficking in music files, AACS spokesman Michael Ayers said on Thursday.
We want to make sure we address this now. It has a potentially limited impact now but some sobering possibilities," Ayers said.
The hackers did not attack the AACS system itself, but stole the keys as they were exchanged between the DVD and the player to strip the encryption from the film
The hackers obtained the keys from "one or more" player applications but AACS would not identify them or say whether their AACS licensing would be revoked.
"We certainly have not ruled out any particular response and we will take whatever action is appropriate," Ayers said
The confirmation of the attack comes about a month after a hacker called Muslix64 described in an online posting how he defeated the encryption system by using DVD player software
Metro
27th January 2007, 02:09
Well, they didn't get it quite right, although the 'player applications' bit is on target. It almost sounds as if they think the key was somehow intercepted from the cable between drive and player, but I suppose they don't want to give too much away to anyone who hasn't found this forum.
What will be interesting is to see how long it is before they do anything. It sounds as if they're keen to respond aggressively this first time round, so we should get a good clue as to how quickly they can actually get a 'fix' rolled out.
Galileo2000
27th January 2007, 02:17
Well, they didn't get it quite right, although the 'player applications' bit is on target. It almost sounds as if they think the key was somehow intercepted from the cable between drive and player, but I suppose they don't want to give too much away to anyone who hasn't found this forum.
What will be interesting is to see how long it is before they do anything. It sounds as if they're keen to respond aggressively this first time round, so we should get a good clue as to how quickly they can actually get a 'fix' rolled out.
Metro, what do you mean by "fix"? IMHO, there is no fix available other than recalling all the titles in existence, going back to the drawing board and rewriting the entire specification. Which is not going to happen.
There are quite enough smart people here who know how to read registers and memory dumps. I used to be pretty good at this myself when I programmed in IBM 3090 BAL. Too bad it was long ago :(
Now, on the different note, there are cheap BROKEN Toshiba A1s on ebay going for $50-$80. Do you think it might be a good idea to get one and dissassemble it for the "scientific purposes"? :D
P.S. Newspeak. George Orwell would be proud of me.
diogen
27th January 2007, 02:45
...IMHO, there is no fix available other than recalling all the titles in existence, going back to the drawing board and rewriting the entire specification....I don't think any titles will be recalled.
If you believe Amir, doing the very thing that revealed the keys in software players on XP (i.e. reading the memory while playing), is much harder to do under Vista.
But for this to be the case, the players have to be re-written and utilize this "secure path" technology built into Vista. Forcing the players to use it and banning playback under XP could be the first step.
Diogen.
Galileo2000
27th January 2007, 02:50
I don't think any titles will be recalled.
If you believe Amir, doing the very thing that revealed the keys in software players on XP (i.e. reading the memory while playing), is much harder to do under Vista.
But for this to be the case, the players have to be re-written and utilize this "secure path" technology built into Vista. Forcing the players to use it and banning playback under XP could be the first step.
Diogen.
I believe it is M$ hype coming in. There will be quite a simple trick to read memory / registers, and someone will figure it out pretty soon.
Memory is memory is memory.
In the meantime consumers will suffer because rewriting half baked players as they are today in order to implement "secure path" or whatever they call it will cause more bugs and more frustration. It seems to me like one of the best ways to kill HD /BD adoption on the PC for the foreseeable future by the average user.
diogen
27th January 2007, 02:59
Time will tell.
It might come to a stand-off:
either all software players are banned or studios stop releasing movies.
Microsoft won't be happy.
It would be interesting to hear any studio reaction on all this...
Diogen.
Galileo2000
27th January 2007, 03:07
Time will tell.
It might come to a stand-off:
either all software players are banned or studios stop releasing movies.
Diogen.
IMHO, neither.
Think about it: there is at most a few hundred people in the world who have knowledge, tools and computer equipment to deal with the stuff.
It will never became the mass phenomenon until we will be speaking in terabytes in storage and gigabytes in seconds. Which is not going to happen anytime soon.
If I were a movie executive or AACS member I wouldn't be worried at all.
Metro
27th January 2007, 03:23
@Galileo - by 'fix' I meant anything which meets the AACS-LA declared intention of '"...we will take whatever action is appropriate," Ayers said.'
The nature of their action will be as interesting as the time it takes them to deliver it.
diogen
27th January 2007, 05:12
Think about it: there is at most a few hundred people in the world who have knowledge, tools and computer equipment to deal with the stuff.Didn't the same argument apply to regular DVDs?
In a couple years it was brought down to a level that only a lazy couldn't do it.
It will never became the mass phenomenon until we will be speaking in terabytes in storage and gigabytes in seconds. Which is not going to happen anytime soon.1TB drive is just about here, i.e. 50 movies (20GB each). About the same number we could fit on a hard drive when DVDs became rippable.
If I were a movie executive or AACS member I wouldn't be worried at all.The studios went with the new formats mainly because they got another shot at keeping control over the disribution. And it is ripped out shortly after they got out of the gate.
I wish you were right. I doubt it very much.
Diogen.
Turtleggjp
27th January 2007, 06:41
Didn't the same argument apply to regular DVDs?
In a couple years it was brought down to a level that only a lazy couldn't do it.
I agree, if they weren't worried about a few hundred people being able to rip these discs, they wouldn't have put all this effort into such a complex authentication process. With the Internet today, it only takes one person to crack a movie and release it unprotected. Granted the ongoing distribution of such content would be difficult for just one person, but several hundred could do it more easily. For this reason, they were trying to lock down the system completely (which I think we all believe is a fundamentally impossible task).
Perhaps DVD-Audio helped to boost their confidence in the success of advanced copy protection systems. That format never received this much attention or attempts to defeat it, but then again it never was a very popular format. Now that they have applied this type of system to something that looks to be a more popular format, we can see that although difficult, it can be defeated if enough people go after it. Now we will see just what happens when these revocation capabilities are actually put into action. I hope they eventually realize that it causes more trouble that it is worth.
Matt
Soulhunter
27th January 2007, 15:24
Real life might change this scenario: if AACS LA decides that keys can't be protected under XP, players might get a new key valid only in Vista; playback under XP is banned alltogether.
I think thats exactly what will happen! They will simply revoke Power/Win-DVD licenses and dont gives new ones for non WinVista based playback software as it doesnt/cant meet the license agreements [its not save]. However, via WinVista it should be possible to make HD playback "save" as its comes with PMP and all the other shit... And as more and more joe-average users will get WinVista anyway, its not even a big thing for em to exclude WinXP! Well, I hope Im wrong with this prognosis... :\
Bye
pacman2006
27th January 2007, 17:15
But what are WinDVD and PowerDVD supposed to tell their customers? "Dear customer, sorry but the software you have paid lotta $$$$ for, will not play any of the new HD releases. There will be no patches or updates to fix this. Our software will be worthless to you from now on. Please buy windows Vista and our new HD player for this OS. Thank you" :D
Seriously, I think they will revoke the player keys and the software players will be updated with a more secure key storage. This will be available for win XP too, simply because they don't want to cut of millions of potential HD-DVD customers.
The new players will be hacked again and keys will be revoked once again. It will be a never ending fight, but as long as keys are revoked once in a while it will make it difficult for the average user to backup their HD-DVD's because there is not a easy, simple way to do it.
If movie studios were a little smarter they would'nt have adopted HDCP. Without this Muslix64 would not have needed to backup his movies. All he wanted to do was to play the movie that he legitly bought. Just give the customers what they ask for. They are paying your salary. But I guess hollywood will never learn.
bomlat
27th January 2007, 17:27
With revoking all of the keys from the xp they not able to solve the issue.
First, they will miss a big possbile market,because in the case of the DVD the pc owners was the early adopters, and that can be the case in the hddvd too.So they will slow down the addoptation of the new formats.
Secon,we have the keys!And that is the issue,not the "trustable,closed"chain.
PeSan
27th January 2007, 17:32
I'm very new to HD related ripping, so don't flame me if i get something wrong.
If we can extract the device key from another, non-revoked, software or hardware player, and put it back into the revoked Windvd version, that is used to find the volume keys in the memory, the revokation list mecanism should mistake it for a new player? Am I wrong ? Is it possible or is there a mecanism to make sure this doesn't happen?
Has the device key (or the adress where it is stored) from WinDVD that is used to decrypt the volume key from the disc been found?
And about no longer supporting WinXP for software players, I think it is suicide, just like it was for dvd-audio and sacd not to allow pc software players.
PeSan
Metro
27th January 2007, 17:47
... If we can extract the device key from another, non-revoked, software or hardware player ...
If we could extract the device key, I believe we wouldn't need to put it in a player at all, we could wrap code around it to pull all the other keys off the disc. To date we haven't worried too much about the device key as far as I know. We're allowing the player to use its device key under the covers and thus obtain the volume keys for us. I would envisage a solution - probably in the distant future - which uses plug-in device keys, emulates a player, and rips directly to HDD. But I could be totally off the mark here, too.
Galileo2000
27th January 2007, 18:05
One word of caution guys: I think they are watching this forum and we shouldn't do too much brainstorming for them.
Metro
27th January 2007, 19:17
One word of caution guys: I think they are watching this forum and we shouldn't do too much brainstorming for them.
That's a very valid point, and I'm tempted to draw a parallel with the early days of the osx86project (running Mac OSX on vanilla PC hardware, for those who don't know). I was involved in that project from the outset and I still moderate the InsanelyMac forum, hence the link in my sig.
We were sure that Apple lawyers were watching our every move, and indeed this was confirmed when we received a DMCA takedown notice. In the event we stayed up because we had an inviolable policy of discussion and coding but no copyright material and no links to torrents or anyone else's intellectual property. We (the staff) worked hard to keep our members and the Apple lawyers happy, and it paid off. The site is still going strong and has transformed into a great forum for all things Mac and some things Windows too (shameless plug).
Almost two years on from the first Intel Mac development kit rolling out we've been able to look critically at Apple strategy. We were worried that we were feeding them the very tools that they would use to prevent us from defeating the Apple-only hardware restrictions. In fact it turned out that we weren't telling them anything they didn't know already, and talking to an Apple developer I discovered that they were almost amused, and their techies at least were quite excited, by the speed of the progress we made. They knew they couldn't stifle our work totally without attracting more attention to it and also attracting negative publicity. They did close some 'hackintosh' sites down and they did get some public flak for it. I know they were pretty shocked at the outset that their TPM protection and encrypted OS files were broken relatively quickly, but each new iteration of the protection met the same fate.
In the final analysis Apple seems content to let us be, probably because the number of people with the technical skills to build a 'hackintosh' is relatively small and the impact to the company is very low in the greater scheme of things. On the flipside for Apple, we probably converted more people to using (real) Macs than all their advertising in the preceding year...
Now, looking at the HD-DVD scenario, I think that at this stage things are very similar. You can't rip an HD-DVD without a degree of skill and perseverance, and you need hardware and software which is not within Joe User's grasp. While the impact looks significant to us, as long as hardware and media costs are high and huge files take an eternity to download the movie studios probably aren't going to lose their shirts over our efforts here. Indeed, like most people here I'm absolutely not interested in ripping the movies to avoid buying them, I just feel infuriated that I can't play movies - which I've purchased in good faith - in full resolution on my existing hardware.
Personally I believe the studios have every right to protect their investment and intellectual capital, but I don't like the way they are going about it in this instance. Just like Apple's probable sales gains as a result of attention to our efforts and our introducing people to OSX in InsanelyMac, there will be a lot of people here who will buy HD-DVD as a result of what's going on in this forum.
So in conclusion I don't think that we're telling them much new here. I think, however, that when the complete one-click ripper appears and HD burners and media fall to consumer prices the studios will be a lot more aggressive about enforcing their rights. For the moment I have every faith in Blutach and the rest of the Doom9 staff keeping a close eye on this forum and maintaing the balance. If I, or anyone else, says something out of place, I would fully expect it to be deleted. Meanwhile - great work, guys!
Soulhunter
27th January 2007, 20:46
But what are WinDVD and PowerDVD supposed to tell their customers? "Dear customer, sorry but the software you have paid lotta $$$$ for, will not play any of the new HD releases. There will be no patches or updates to fix this. Our software will be worthless to you from now on. Please buy windows Vista and our new HD player for this OS. Thank you" :D
How n what to tell the customers is the prob of the software producers that coded software which infringes the license agreement, not the prob of the ones who decide if the licenses get revoked, huh?
Bye
bomlat
27th January 2007, 21:48
How n what to tell the customers is the prob of the software producers that coded software which infringes the license agreement, not the prob of the ones who decide if the licenses get revoked, huh?
Bye
The software providers did everything properly,the license agrement did't tell them anything about the volume keys.:D
So, this is not the fault of the intervideo,but the fault of the AACS.
Soulhunter
27th January 2007, 21:57
The software providers did everything properly,the license agrement did't tell them anything about the volume keys.:D
So, this is not the fault of the intervideo,but the fault of the AACS.
So they cant revoke the licenses?
Gooooooooood... ^^
Thx n' Bye
bomlat
27th January 2007, 21:58
Basicly,the issue of the AACS and every other DRM is simply:you can not win a war against your costumer .
Right now the content providers are thinking about how can they punish that customer who give them the money for the milk and butter!Can you feel this?The disney want to sell us crypto systems, that will restrict us! But we want to pay for the Pirates of caribean, not for the AACS!
calinb
27th January 2007, 22:32
In the final analysis Apple seems content to let us be, probably because the number of people with the technical skills to build a 'hackintosh' is relatively small and the impact to the company is very low in the greater scheme of things.
If movie studios were a little smarter they would'nt have adopted HDCP. Without this Muslix64 would not have needed to backup his movies. All he wanted to do was to play the movie that he legitly bought. Just give the customers what they ask for. They are paying your salary. But I guess hollywood will never learn.
If the movie studios were a little smarter, they'd be Apple! ;)
Seriously, most of us feel-ripped off with the DRM (Digital Restrictions Management) requirements for new TVs with HDCP or a new computer, or a new OS, or a new video card; when our current (and recently purchased) hardware is fully capable of playing HD-DVD discs with the simple addition of a new optical drive and software player, if it were not for the DRM. I hope the MPAA and the CE manufacturers hear that message loud and clear when they visit this site. I am convinced that most of us simply want to watch our legally obtained discs on any capable hardware platform of choice with a minimum of hassle. Those who are ripping off the studios probably weren't going to purchase the products anyway.
Metro
28th January 2007, 01:53
Well, the one-click ripper may be closer than we think. I just saw on CDFreaks that SlySoft is actively working on AnyDVD-HD which, quote "will be really, really awsome!!!! :D "
If it's what it appears to be, it will be very interesting.
Link to the info post by a SlySoft team member here. (http://club.cdfreaks.com/showpost.php?p=1680063&postcount=19)
( first part of James' post refers to Saw3, which apparently is now fixed in the latest AnyDVD )
Galileo2000
28th January 2007, 02:13
Well, the one-click ripper may be closer than we think. I just saw on CDFreaks that SlySoft is actively working on AnyDVD-HD which, quote "will be really, really awsome!!!! :D "
If it's what it appears to be, it will be very interesting.
Link to the info post by a SlySoft team member here. (http://club.cdfreaks.com/showpost.php?p=1680063&postcount=19)
( first part of James' post refers to Saw3, which apparently is now fixed in the latest AnyDVD )
So commercial software house is working on the solution?
I am sure AACS will be very happy to learn about this.
Spc01
28th January 2007, 07:03
If movie studios were a little smarter they would'nt have adopted HDCP. Without this Muslix64 would not have needed to backup his movies. All he wanted to do was to play the movie that he legitly bought. Just give the customers what they ask for. They are paying your salary. But I guess hollywood will never learn.
That's very true.
If i buy a movie i want to watch it on my existing hardware that is more than capable of playing HD (Core 2 Duo XE6800 2.93GHz, 2GB ram) content i can't .. because i don't have DHCP monitor so then i have to buy a new monitor because my current monitor for $1000 doesn't support HDCP.
That's just sick.
diogen
28th January 2007, 07:29
From AACS-LA press release (http://www.aacsla.com/press) about the compromise:
"...it illustrates the need for all AACS licensees to follow the Compliance and Robustness Rules set forth in the AACS license agreements"
It most likely means that there are Rules that WinDVD/PowerDVD didn't follow.
"AACS LA employs both technical and legal measures to deal with attacks such as this one..."
Legal actions are coming...
Diogen.
arnezami
28th January 2007, 10:21
They will eventualy revoke software players.
I would like to go into this for a moment. In other words: What will actually happen if AACS revokes keys from Cyberlink and Intervideo?
After reading the specs I believe they will revoke two things: on the upcoming new disc releases they will revoke the (set of) device keys belonging to the (compromised) software players. This is a form of implicit revocation: the information to retrieve the key to decrypt the disc simply isn't on the disc. But they might do this anyway, just to be sure (even if no software players are publicly compromised). The effect of this would make it impossible to play new movies with old versions of software players.
But they can (and will most likely) also add hosts to the host revocation list. A host is essentially 1 part of a device (the drive is the other part of a device). Standalone devices don't know this difference (and don't use host/drive revocation) but PC drives and software players use this distinction. This is a form of explicit revocation: a drive is told not to communicate with a host (= software player). The result though of this revocation is that when you put a new disc in your PC drive (containing a new host revocation list) your drive won't allow old and new movies to be decrypted with old versions of revoked software players.
We have to extract a maximum of keys while we can. That way, when more secure version of player will be there, we will know what values to look for in memory, speeding up the process of reversal. Once you know the key protection method in memory, it will be easy to extract keys, like we are doing now.
It will be interesting to see what will be easier when they "plug" this hole: finding title/volume keys or finding device keys/host private keys.
Another scenario, is to fully implement AACS process (with MKB and all the stuff) and steal some player keys. We don't disclose the devices keys, be we disclose volume keys like we are doing now... bypassing the revocation system
I agree it would be a good idea to do the whole process at least once. So we would have a program that either needs volume/title keys or it would use device keys/host private keys. The question is: if we find more than one device/host private key should we release one of them. I mean: they are going to be revoked anyway (on future discs) so why not release them now so everybody can benefit from the easiness?
Anyway. I've got an idea to make some progress in getting the device keys. The following figure shows the general picture of the decryption process:
http://img223.imageshack.us/img223/829/progress4fn2.png
The blue parts shows our current progress. We can get title keys (Kt) fairly easy now. We can also find volume (variant) unique keys (Kvvu) which are used to decrypt the title keys. The red part is what doesn't interest us at all: its the part that would limit our playback possibilities so we can simply leave that out. The yellow parts could be our next step: getting the volume ID from the disc and using it to find the media (variant) key (Kmv). If we could get the volume ID of a certain movie we could start searching for the media keys: eg using the same known plaintext attack.
First thing to do would be to get the volume ID. Its on a protected area on the disc so we need a valid/non-revoked host private key to ask our drive to give it to us**. Or we could let WinDVD do it for us ;). Here is the figure that shows how the Volume ID is retrieved:
http://img230.imageshack.us/img230/4934/aacsdriveauth2jd.th.png (http://img230.imageshack.us/my.php?image=aacsdriveauth2jd.png) http://img157.imageshack.us/img157/821/volumeidbh9.th.png (http://img157.imageshack.us/my.php?image=volumeidbh9.png)
So it seems the Volume ID is transferred unencrypted towards the host (its concatenated with Dm but thats just for verification, we don't need that).
Here is a confirmation of this (chapter 4.1):
A Bus Encryption Capable (BEC) bit, where 1 shall be used to indicate that the drive is capable of
performing the Bus Encryption that is to be later specified. If the drive is not capable of performing the
Bus Encryption, the BEC bit shall be set to 0. When both the drive and PC host are capable of
performing the Bus Encryption, the Bus Encryption shall be performed. The details of Bus Encryption
will be specified at a future date. Until such time, the BEC bit will be set to 0.
I guess this means if we can somehow "listen" to the atapi commands send to the drive we could see when the volumeid is requested and when it is send back. We could use the volume id to find the media (variant) keys in the memory dump of WinDVD/PowerDVD using the known plaintext attack. If we have the media key (and its location) we are one step closer to finding the device keys. :)
Are there tools out there that could look at atapi commands etc? We might be able to log traffic to the drive and/or filter it for certain type of (atapi) commands. There is Bus Doctor (http://protocoltools.com/protocols/ata/) but it seems to require special hardware. Alternatively we could try to find/intercept calls to atapi drivers/dlls. I guess that may be harder hacking wise. Any ideas?
Regards,
arnezami
** Technically we could retrieve the volumeid using a drive with a hacked firmware. It wouldn't care whether or not we were a valid (that is: unrevoked) host. The xbox hd dvd drive (and the ps3 blu ray drive) would be good candidates since that would also open up playback of backed up media on those consoles (once you hacked them you could also fool the console os that the non-burnable protected areas on a burned disc are identical to that of an original disc thus enabling playback of backups on those consoles). But thats off topic I guess ;).
blutach
28th January 2007, 11:09
Well, the one-click ripper may be closer than we think. I just saw on CDFreaks that SlySoft is actively working on AnyDVD-HD which, quote "will be really, really awsome!!!! :D "
If it's what it appears to be, it will be very interesting.
Link to the info post by a SlySoft team member here. (http://club.cdfreaks.com/showpost.php?p=1680063&postcount=19)
( first part of James' post refers to Saw3, which apparently is now fixed in the latest AnyDVD )Wonder how much they will take of the great work done here, package it up with a foxy icon and sell it to people?
Regards
2bigkings
28th January 2007, 11:40
new anydvd version from jan. 26
- New: Added UDF 2.5 support to the UDF parser.
- New: AnyDVD status window shows larger volume names
- New: Recognizes HD-DVD video discs and correctly displays
HD-DVD volume names
i think they nearer on a anydvd-hd version as we think..
Foreigner999
28th January 2007, 12:53
If we could extract the device key, I believe we wouldn't need to put it in a player at all, we could wrap code around it to pull all the other keys off the disc. To date we haven't worried too much about the device key as far as I know. We're allowing the player to use its device key under the covers and thus obtain the volume keys for us. I would envisage a solution - probably in the distant future - which uses plug-in device keys, emulates a player, and rips directly to HDD. But I could be totally off the mark here, too.
Thats exactly what i was talking about back a few days ago in this thread.
I don't think it would honestly bother them that much to just block winXP from accessing HD content. They would just ask microsoft to start development on an emergency patch for a semi-secure path software addon. Roll it out on a website and this way they can call it "added functionality" and cover up the release website with trailers or some wallpaper junk to whatever title that person bought.
If microsoft says no then they will just accept giving refunds for the people buying the revoked discs/hardware/software and give them some crappy discount to vista or a new hardware player. Better to put that plan in action now than later when it goes mainstream.
K40
28th January 2007, 13:07
The result though of this revocation is that when you put a new disc in your PC drive (containing a new host revocation list) your drive won't allow old and new movies to be decrypted with old versions of revoked software players.
In this case ,would the updated PC Drive still working with
BackupHDDVD to decrypt old movies or even new movies
when the VUK are known from another source??
arnezami
28th January 2007, 13:27
In this case ,would the updated PC Drive still working with
BackupHDDVD to decrypt old movies or even new movies
when the VUK are known from another source??
Yes. BackupHDDVD will still be able to decrypt old and new movies. If a volume/title key is found you can always decrypt the content.
Its just not possible anymore to use the old software player to get any "secret" info from the old or new discs. This is because volumeid is not available (to for example WinDVD) so it won't be able to get any title or volume keys of these discs anymore. For somebody who is trying to easely retrieve volume keys (using a working key retrieval program) from old (and still publicly undecrypted) discs this is a problem. This is also a problem for someone who is trying to hack the software player (its full aacs implementation) by using old discs. But this revocation only occurs when the new disc (with a new host revocation list) is inserted into/played from the drive: only then will the drive start rejecting the old software player.
This is why (among other reasons) its a good idea to get as many volume/title keys we can for all released discs so far. :)
cwl7454
28th January 2007, 14:43
new anydvd version from jan. 26
- New: Added UDF 2.5 support to the UDF parser.
- New: AnyDVD status window shows larger volume names
- New: Recognizes HD-DVD video discs and correctly displays
HD-DVD volume names
i think they nearer on a anydvd-hd version as we think..
Yes, while they may be working on it, reveiw their version update history and you will see that pretty much every week they have issued updates for corrections and bugs on their current versions. Looks like presale and using the funds to develop the program, paid betas, instead of tried and true versions.
One question to Muslix64; given the statements from ACCS, and having to do it over again, would you release as you did or would you hold back untill you had a viable program, ie: more discreetly? Maybe untill it was economically unviable for them to change things as with regular DVD progression decryption.
Metro
28th January 2007, 15:26
Yes, while they may be working on it, reveiw their version update history and you will see that pretty much every week they have issued updates for corrections and bugs on their current versions. Looks like presale and using the funds to develop the program, paid betas, instead of tried and true versions.
I have more faith in AnyDVD. Yes, there have been bugs but mostly their updates address new ARccoS implementations which the studios roll out with each new title. As for presale, this didn't come from any commercial announcement, I happened to spot an unguarded comment one of their developers made in a non-company forum. Since they would want to produce a generic solution they may well be working on pulling VolumeIDs, but that's my speculation.
hd1080p
28th January 2007, 16:38
I would like to go into this for a moment. In other words: What will actually happen if AACS revokes keys from Cyberlink and Intervideo?
After reading the specs I believe they will revoke two things: on the upcoming new disc releases they will revoke the (set of) device keys belonging to the (compromised) software players. This is a form of implicit revocation: the information to retrieve the key to decrypt the disc simply isn't on the disc. But they might do this anyway, just to be sure (even if no software players are publicly compromised). The effect of this would make it impossible to play new movies with old versions of software players.
But they can (and will most likely) also add hosts to the host revocation list. A host is essentially 1 part of a device (the drive is the other part of a device). Standalone devices don't know this difference (and don't use host/drive revocation) but PC drives and software players use this distinction. This is a form of explicit revocation: a drive is told not to communicate with a host (= software player). The result though of this revocation is that when you put a new disc in your PC drive (containing a new host revocation list) your drive won't allow old and new movies to be decrypted with old versions of revoked software players.
It will be interesting to see what will be easier when they "plug" this hole: finding title/volume keys or finding device keys/host private keys.
I agree it would be a good idea to do the whole process at least once. So we would have a program that either needs volume/title keys or it would use device keys/host private keys. The question is: if we find more than one device/host private key should we release one of them. I mean: they are going to be revoked anyway (on future discs) so why not release them now so everybody can benefit from the easiness?
Anyway. I've got an idea to make some progress in getting the device keys. The following figure shows the general picture of the decryption process:
http://img223.imageshack.us/img223/829/progress4fn2.png
The blue parts shows our current progress. We can get title keys (Kt) fairly easy now. We can also find volume (variant) unique keys (Kvvu) which are used to decrypt the title keys. The red part is what doesn't interest us at all: its the part that would limit our playback possibilities so we can simply leave that out. The yellow parts could be our next step: getting the volume ID from the disc and using it to find the media (variant) key (Kmv). If we could get the volume ID of a certain movie we could start searching for the media keys: eg using the same known plaintext attack.
First thing to do would be to get the volume ID. Its on a protected area on the disc so we need a valid/non-revoked host private key to ask our drive to give it to us**. Or we could let WinDVD do it for us ;). Here is the figure that shows how the Volume ID is retrieved:
http://img230.imageshack.us/img230/4934/aacsdriveauth2jd.th.png (http://img230.imageshack.us/my.php?image=aacsdriveauth2jd.png) http://img157.imageshack.us/img157/821/volumeidbh9.th.png (http://img157.imageshack.us/my.php?image=volumeidbh9.png)
So it seems the Volume ID is transferred unencrypted towards the host (its concatenated with Dm but thats just for verification, we don't need that).
Here is a confirmation of this (chapter 4.1):
I guess this means if we can somehow "listen" to the atapi commands send to the drive we could see when the volumeid is requested and when it is send back. We could use the volume id to find the media (variant) keys in the memory dump of WinDVD/PowerDVD using the known plaintext attack. If we have the media key (and its location) we are one step closer to finding the device keys. :)
Are there tools out there that could look at atapi commands etc? We might be able to log traffic to the drive and/or filter it for certain type of (atapi) commands. There is Bus Doctor (http://protocoltools.com/protocols/ata/) but it seems to require special hardware. Alternatively we could try to find/intercept calls to atapi drivers/dlls. I guess that may be harder hacking wise. Any ideas?
Regards,
arnezami
** Technically we could retrieve the volumeid using a drive with a hacked firmware. It wouldn't care whether or not we were a valid (that is: unrevoked) host. The xbox hd dvd drive (and the ps3 blu ray drive) would be good candidates since that would also open up playback of backed up media on those consoles (once you hacked them you could also fool the console os that the non-burnable protected areas on a burned disc are identical to that of an original disc thus enabling playback of backups on those consoles). But thats off topic I guess ;).
Just a thought. Assuming AACS is successful in revoking keys. This will foster growth of piracy for the decrypted copies already out there in the cyberspace. The real solution is to make movies of all kind cheap to buy and easy to download. Unlike music, most people don't watch the same movie twice. Make per view cheap like 99cents, then we won't trouble ourselves with all the dencrypting hassles.
Galileo2000
28th January 2007, 16:57
Just a thought. Assuming AACS is successful in revoking keys. This will foster growth of piracy for the decrypted copies already out there in the cyberspace. The real solution is to make movies of all kind cheap to buy and easy to download. Unlike music, most people don't watch the same movie twice. Make per view cheap like 99cents, then we won't trouble ourselves with all the dencrypting hassles.
It would be no fan then :D
Remember, this project is not about saving money and pirating stuff.
It is about our "Fair Use" right and avoidance of the HDCP crap which renders our existing equipment obsolete for no apparent reason.
vBulletin® v3.8.11, Copyright ©2000-2026, vBulletin Solutions Inc.