Log in

View Full Version : How to stop HD DVD and BD ripping tools and hackers.


Jeremy Duncan
4th May 2007, 00:03
How to stop the Keys to HD DVD from being cracked.
By Jeremy Duncan.

1) Create A pay per view model. But only in the way that the provider needs to be contacted.
2) When the person wants to watch a HDdvd, they get a short key from the cyberlink web site,
to be added to the short key on the HDdvd.
3) At Cyberlink, A key is generated each time the customer connects with the web site, and matches the key made
in step 2. This acts like a Simple Hash.
4) If the Key is going to be hacked, they will need to guess the hash each time for every dvd they play.

5) The Volume ID needs to be authenticated with a similar hash pattern.
By reading Geremia's post. The Volume ID can be patched.
So, if the Volume ID can be patched so as to render the Hacks from working...
the volume id patch can have a hash made from a bit of hash existing on the pc/disk, and a bit of hash being randomly generated at Cyberlink.
and verified by the cyberlink website.
6.) The cyberlink beification of the hash can check the integrity of the various bits of hardware.
If a certain bit is more vulnerable, then if tampered with the verification can render the dvd useless instantly.
Hack the hackers by reading their tampering methods then disabling the device when registering the device tamper.
Instant killswitch.

I'm just throwing these ideas out there to see what you all think of them.

:readguid:

________________
Edit below Updated May 4, 2007

1) Create A pay per view model. But only in the way that the provider needs to be contacted.





2)
- The person puts in the hddvd.
- The person id/reg # (already in the PC/standalone player), and HDdvd key then uploads to the cyberlink website.
- The program is then installed with the unique updates (Think "marking it"), and the Volume ID must be uniquely updated.
- Two things happed here.
The person uploaded the info to the website, and the person id'd himself.
These are mixed into a unique key string within the software being downloaded from the website.
Mixing these two factors properly is the key formula they would have to hack to overcome the defense.
By frauding either of the two factors.
The defenses to prevent them from breaking these two factors are not discussed here.





Your problem.





By reading Geremia's post. The Volume ID can be patched.
So, if the Volume ID can be patched so as to render the Hacks from working...
the volume id patch can have a unique update made disabling this entry.





3) Since the software can be replicated and the keys taken that way.
The program itself is a type of Key, that can be overcome by force.

Understand ?

So, the program itself must be treated like a unique key generated by the website.
Else it be a lost cause.
The answer is unique, randomly generated, verified updates.





I'm just pointing to the answer and the small details are not my concern.
I'm doing this because I'm a security hack who is doing this for fun.

Without a unique id via update, they will overpower the HDdvd defenses like aacs.
There's the perimeter of the problem. Own it.

BLACKBIRDxx
4th May 2007, 00:17
i think , #1 your posting in the wrong forum.
#2 your information could be put to better use with cyberlink or better yet aacs la. maybe you could apply for a job with them.

Johnny381
4th May 2007, 00:17
In my honest opinion just keep throwing them ideas-------away far away. JMO

hoozdapimp
4th May 2007, 00:22
I'm sure consumers would love to have to connect to the internet everytime they want to watch a DVD.

Consumers are already on the sh*t end of the stick when it comes to fair use.

setarip_old
4th May 2007, 00:38
Create A pay per view model. But only in the way that the provider needs to be contacted.If you are proposing that the ONLY means of viewing a purchased HD DVD or BluRay DVD would be on a "pay per view" basis, while paying the full present pricing, I'd suggest to you that there would be no benefit to the end user to EVER "purchase" such HD DVDs or BluRay DVDs.

I'd suggest that such a proposal would lead to a "Rental only" market which, in turn, would result in tremendously diminished income for the studios.

I gather that marketing is not your forte, eh? ;>}

HyperHacker
4th May 2007, 00:51
How does your method stop someone from, e.g., using screen capture software to rip the movie frame-by-frame as it's played?

Galileo2000
4th May 2007, 01:32
I think the better title for this thread would be "How to stop HD DVD and BD DVD". It could end there or "from the customers who bought HD DVD and BD DVD" could be added to the title.

as of my emotions reading the what OP decided to post here, no comments. Absolutely. Not even one word with no four letters. Ever. Promise.

MLS
4th May 2007, 01:56
Behold the epitome of a troll.

/MLS

Galileo2000
4th May 2007, 02:10
Received brand new HD DVD today.
Opened it and put it into HD DVD drive.
Launched PDVD.
"Incompatible graphics driver".
Launched AnyDVD HD.
Video works.
But no sound.

Sound works just fine everywhere on the computer.

Ripped.

Started PDVD.

Everything works perfectly.

Just a small tale of today.

dwbrowneye
4th May 2007, 02:13
Hash! makes your eyes red just thinkin' about it don't it?

bourke
4th May 2007, 02:33
I think a far easier method of securing the movies is to have one key per firmware of player and so if a player becomes compromised then they can simply not include that key with new releases.

To do this you simply have a 'boot disc' CD released with every title that contains the VUK encrypted with a few million keys. The players then find their individual encrypted copy of the VUK and decrypt it. Now that they have the VUK, they then prompt you to insert the video disc!

I mean surely if the studios are willing to invest millions of dollars on security they can afford to include a CD full of keys with each title?!

The obvious problems are:
1. Users will hate having to use a boot disc - maybe players can have two trays so users can put both disc in at once (i.e. one drive but two trays).
2. Users will hate the fact that if they misplace the boot disc they cannot play the video disc!

Cheers,
Bourkie

Galileo2000
4th May 2007, 02:42
I think a far easier method of securing the movies is to have one key per firmware of player and so if a player becomes compromised then they can simply not include that key with new releases.

To do this you simply have a 'boot disc' CD released with every title that contains the VUK encrypted with a few million keys. The players then find their individual encrypted copy of the VUK and decrypt it. Now that they have the VUK, they then prompt you to insert the video disc!

I mean surely if the studios are willing to invest millions of dollars on security they can afford to include a CD full of keys with each title?!

The obvious problems are:
1. Users will hate having to use a boot disc - maybe players can have two trays so users can put both disc in at once (i.e. one drive but two trays).
2. Users will hate the fact that if they misplace the boot disc they cannot play the video disc!

Cheers,
Bourkie

bourke, it is NOT an unbreakable scheme, it can be broken easily too, for the reasons too many to mention.

But.



So far I've spent close to $1000 so far for the HD DVD playback.

I will not spend one single penny on this stuff anymore until I know for sure I can WATCH MY PURCHASED HD DVDs AT FULL 1920x1080p RESOLUTION on my HDTV.

I hope someone is listening.

If not, all bets are off.

I'll finish this adventure, ebay whatever and throw the rest into the garbage basket.

Good ffdshow settings and fast PC can bring your PQ quite close to the HD DVD from the regular DVD.

I might just go that route.

setarip_old
4th May 2007, 03:02
@Galileo2000

May I suggest that you not take the one or two "suggestions" in this thread to heart?

1) They are highly impractical (See my post) - perhaps bordering on the absurd

2) They have likely been posted primarily to incite - and the simple way to avoid that is by not being goaded into posting an emotional response

Galileo2000
4th May 2007, 03:13
@Galileo2000

May I suggest that you not take the one or two "suggestions" in this thread to heart?

1) They are highly impractical (See my post) - perhaps bordering on the absurd

2) They have likely been posted primarily to incite - and the simple way to avoid that is by not being goaded into posting an emotional response

I know, I know..

But I've seen this self-censorship stuff before and it wasn't pretty.

And it was under much more serious circumstances.

To me it is the beginning of the end before the society will became a group of lemmings.

Did I post emotional response? I didn't think so. I could be wrong.

What was a game before is becoming a real issue now in terms of attitude and that's what bothers me most.

setarip_old
4th May 2007, 03:19
Sorry if I misinterpreted the tenor of your posting but:You guys are just too clever for my stomack to tolerate it.andI am getting increasingly tired of all this cr..seemed to me to be emotional statements...

Galileo2000
4th May 2007, 03:20
Take a look here:

http://www.avsforum.com/avs-vb/showthread.php?t=843032

I wonder whether jeremy duncan and 8:13 are the same person.

Galileo2000
4th May 2007, 03:21
Sorry if I misinterpreted the tenor of your posting but:andseemed to me to be emotional statements...

OK, do you want me to delete those statements?

Done.

BigDid
4th May 2007, 03:30
Take a look here:

http://www.avsforum.com/avs-vb/showthread.php?t=843032

I wonder whether jeremy duncan and 8:13 are the same person.
Hi,

Yes as stated in this thread: http://www.avsforum.com/avs-vb/showthread.php?p=8353902&&#post8353902

Did

Galileo2000
4th May 2007, 03:33
Hi,

Yes as stated in this thread: http://www.avsforum.com/avs-vb/showthread.php?p=8353902&&#post8353902

Did

Cool, thanks BigDid, I thought the guy had an agenda.

@Jeremy Duncan aka 8:13:

Keep in mind that AVS forum is MUCH MUCH less civil than doom9.

I will crash you if you keep promoting this garbage there.

It is not a threat, I am serious.


"The Man Who was Thursday". Highly recommended.

http://en.wikipedia.org/wiki/The_Man_Who_Was_Thursday

bourke
4th May 2007, 04:45
I will crash you if you keep promoting this garbage there.

It is not a threat, I am serious.

Crash?! DDoS?

diogen
4th May 2007, 04:50
1) Create A pay per view model. But only in the way that the provider needs to be contacted.The new optical formats were created to avoid the PPV model... For now.
2) When the person wants to watch a HDdvd, they get a short key from the cyberlink web site, to be added to the short key on the HDdvd.You want to make it work like https. Do more reading on the differences.
3) At Cyberlink, A key is generated each time the customer connects with the web site, and matches the key made
in step 2. This acts like a Simple Hash.Is Cyberlink the player? No more players allowed? Do you by any chance have a Soviet Union connection?
4) If the Key is going to be hacked, they will need to guess the hash each time for every dvd they play.Is this sort of DVD-A? You know were that ended up, don't you?

Is this enough to show that - at least on the logistical level - it is nothing but a nightmare?

___________________________

"How to avoid being drawn into a discussion about 2 and 2 not always being 4"
By Diogen.

Don't read Jeremy Duncan's posts.

Diogen.

Galileo2000
4th May 2007, 05:21
Crash?! DDoS?

bourke, do you think you can stay away when you have nothing to add to the thread?

Galileo2000
4th May 2007, 05:26
The new optical formats were created to avoid the PPV model... For now.
You want to make it work like https. Do more reading on the differences.
Is Cyberlink the player? No more players allowed? Do you by any chance have a Soviet Union connection?
Is this sort of DVD-A? You know were that ended up, don't you?

Is this enough to show that - at least on the logistical level - it is nothing but a nightmare?

___________________________

"How to avoid being drawn into a discussion about 2 and 2 not always being 4"
By Diogen.

Don't read Jeremy Duncan's posts.

Diogen.


@diogen:

he is as much Jeremy Duncan as you and me.

He is 8:13 from the AVS forum.

His agenda:

To make the format competing with his endeavors to disappear and take a stand of protecting rightful DRM.

At the same time DecSS protection DRM no longer interests anybody since it has been broken long time ago.

CD protection is no longer of interest of anybody since it was broken long time ago and now you can rip your CDs with the "legitimate" Windows Media Player.

Guess what will happen to AACS LA.

woah!
4th May 2007, 06:08
i bet he/she/it doesnt even own a hddvd or blueray player...

burfadel
4th May 2007, 06:28
I think the whole high def DVD, whether its blu-ray or HD-DVD, is flawed.

- There should be a set standard like there are with video codecs, with companies working together to make a workable disk. Downside is companies will have to listen to one another.

- Should be one standard codec for video and audio, that being the best available at the time. The standards should have some room for upgrade, and the players, even if 5 years old, should have support to be upgradeable to the later standard if one should arise.

- Should do away with this bs copy protection stuff, at least in the guise of how it is at the moment or some of the proposed stuff. The protection only stops the freedom of the innocent! Like it or not people will always find a way to crack the copy protection, and if it gets too difficult for people they will just download off bittorrent or something.

- Online checking is absurd. some people will not be able to view their disks at all due to the situation they're in.

- I personally would have preferred the DVD cassette system that was proposed at one stage. The disk is always protected, can be of higher capacity, and can be stored as is. One of the concerns I have with current high def formats is damaging the disks, or even getting it slightly dirty or something. The cassettes can be 'locked' into the drive!, and normal DVD's can be played in DVD portable cassette's. If you're only ever going to play DVD's in the HD player you can store the DVD in the cassette as well. Cassette's give you the freedom to have proper labelling as well. You won't need a DVD case...

- A feature where connectivity is available would be to see other movies from the same studio, same writes, same actors, same genre etc. along with many other features. However, the disk will still work fine without connectivity.

- Have a set decoding software, so each player plays with the same compatibility. Therefore no compatibility problems should arise, and if they do the disks will have to be replaced at no charge to the consumer.

- Have a set firmware revision number for each brand and model. That is, regardless of the brand or model have the first part of the firmware revision relate to its compliance to the HD standard. That includes updates to the decoder etc and features. The second part relates to the companies firmware revision for company and model specific features. Such as v1.12a-Panasonic-f7351-1.1a (sounds long I know, but when you read the disk labels it says requires firmware v1.13 or later you know you will have to update your player).

- If the update fails for some reason have in the specification a failsafe mode, say hold the play button when you turn it on and it will always skip to the original firmware revision (only for that power on), so you can try updating again.

Just a few ideas. The cassette reasoning is that even though both formats claim they've worked out data integrity, they're still more susceptible to problems. The cassette idea the disk is always protected.

avih
4th May 2007, 08:22
Guys, Take it easy pls. thx.

Mtz
4th May 2007, 09:05
How to stop the Keys to HD DVD from being cracked.
I think is more "simple":
A:
1. Go to the DVD shop and ask for your favorite movie.
2. Somebody will ask you all your personal data.
3. Come after 6 months at the same shop and buy the DVD.
4. The DVD will include all your data on the movie in a big permanent subtitle which cannot be removed and is looking like this:
http://img201.imageshack.us/img201/6507/hdvdvdbdvw9.jpg (http://imageshack.us)

B: somebody launch all the atomic bombs in the world. No buyers, no crackers. :stupid:

C: cannot be presented because of "B".

enjoy,
Mtz

xyz987
4th May 2007, 09:21
So an attacker develops his own program, this program connects with Cyberlink and gets the key(s), this program decrypts the movie. End of story.

If each copy of Cyberlink soft has its own authentication key, any appropriate crack will reveal it.

bourke
4th May 2007, 12:36
bourke, it is NOT an unbreakable scheme, it can be broken easily too, for the reasons too many to mention.

OK, so there may indeedbe too many to mention all of them.

So just explain to us the top three.

bourke
4th May 2007, 12:37
bourke, do you think you can stay away when you have nothing to add to the thread?

Is it rag week for you or something, mate?

blutach
4th May 2007, 15:58
Galileo2000 - I have warned you several times before about respecting other members and observing rule 4. This time a strike must be issued.

Everyone else - this thread is turning into a farce (maybe from post 1). Let us get on with what Doom9's forums are all about and stop this trash talk please.

Regards

Galileo2000
4th May 2007, 17:04
Galileo2000 - I have warned you several times before about respecting other members and observing rule 4. This time a strike must be issued.

Everyone else - this thread is turning into a farce (maybe from post 1). Let us get on with what Doom9's forums are all about and stop this trash talk please.

Regards

So posts from this member about castration were ignored by the moderators.

And my attempt to follow Doom9 advice of keeping signal to noise ratio high had caused a strike issued.

blutach
4th May 2007, 17:09
@Galileo2000

Again, you refuse either to read or understand rule 4.

If you have a problem with another member turn to the respective moderator and if the moderator can't help you send a private message to Doom9.

Just how hard is this to understand?

By replying in this way, you have also forfeited the right to contest your strike.

I now ask you for the last time to drop it (and put aside whatever personal differences you may have with Jeremy Duncan). Not doing so will risk a 3rd strike for rule 16.

Regards

mikeathome
4th May 2007, 17:43
How to stop the Keys to HD DVD from being cracked.
By Jeremy Duncan.

1) Create A pay per view model. But only in the way that the provider needs to be contacted.
2) When the person wants to watch a HDdvd, they get a short key from the cyberlink web site,
to be added to the short key on the HDdvd.
3) At Cyberlink, A key is generated each time the customer connects with the web site, and matches the key made
in step 2. This acts like a Simple Hash.
4) If the Key is going to be hacked, they will need to guess the hash each time for every dvd they play.

5) The Volume ID needs to be authenticated with a similar hash pattern.
By reading Geremia's post. The Volume ID can be patched.
So, if the Volume ID can be patched so as to render the Hacks from working...
the volume id patch can have a hash made from a bit of hash existing on the pc/disk, and a bit of hash being randomly generated at Cyberlink.
and verified by the cyberlink website.
6.) The cyberlink beification of the hash can check the integrity of the various bits of hardware.
If a certain bit is more vulnerable, then if tampered with the verification can render the dvd useless instantly.
Hack the hackers by reading their tampering methods then disabling the device when registering the device tamper.
Instant killswitch.

I'm just throwing these ideas out there to see what you all think of them.

:readguid:

Hi,
this does though assume that anyone installs the Cyberhome/Intervideo/Ahead/Sony Trojan Horses...

mike

mikeathome
4th May 2007, 17:53
In one (or two) months this could read...

Received brand new HD DVD today.
Opened it and put it into HD DVD drive.
Launched PDVD.
"Incompatible graphics driver".
Launched AnyDVD HD.
Video works.
But no sound.

Sound works just fine everywhere on the computer.

Ripped.

Uninstalled PDVD...

Started MPC.

Everything works perfectly.

Just a small tale of today.

P.S.
Galileo, forgive me for hijacking you Quote, please...

mikeathome
4th May 2007, 17:57
I think a far easier method of securing the movies is to have one key per firmware of player and so if a player becomes compromised then they can simply not include that key with new releases.

To do this you simply have a 'boot disc' CD released with every title that contains the VUK encrypted with a few million keys. The players then find their individual encrypted copy of the VUK and decrypt it. Now that they have the VUK, they then prompt you to insert the video disc!

I mean surely if the studios are willing to invest millions of dollars on security they can afford to include a CD full of keys with each title?!

The obvious problems are:
1. Users will hate having to use a boot disc - maybe players can have two trays so users can put both disc in at once (i.e. one drive but two trays).
2. Users will hate the fact that if they misplace the boot disc they cannot play the video disc!

Cheers,
Bourkie

... I could think of a USB dongle, like some Softwares come along with

mike

mikeathome
4th May 2007, 18:15
Galileo2000 - I have warned you several times before about respecting other members and observing rule 4. This time a strike must be issued.

Everyone else - this thread is turning into a farce (maybe from post 1). Let us get on with what Doom9's forums are all about and stop this trash talk please.

Regards

Hi,
the whole thingy was setup with the intend to start a flame war here AND foresure JD is sitting home right now laughing about us...

mike

P.S.
You find trolls allover the INs forums.

Jeremy Duncan
4th May 2007, 18:35
So an attacker develops his own program, this program connects with Cyberlink and gets the key(s), this program decrypts the movie. End of story.

If each copy of Cyberlink soft has its own authentication key, any appropriate crack will reveal it.

Good find.
I updated the first post the counter this hack.

mikeathome
4th May 2007, 18:41
Good find.
I updated the first post the counter this hack.

Hi,
will you donate 1% of Cyberlinks profit to doom9. I think that's fair use of the forum, what do you think ?

mike

KenD00
4th May 2007, 19:39
The safest and only for sure working way to stop all these ripping tools is to abandon all this aacs-css-drm-user restricting-and-pressing-every-cent-out-of-them crap. This way all these 3v1l h4xx0rs can use use their spare time for more useful things like... hmm... buying more movies or so.
We live in the information age, don't let it progress to the sueing age where every single piece of information/content is locked in a vault, guarded by an army of lawyers, which can only be opened for a glimpse by spending an arbitrary amount of money every time.

:rolleyes:

setarip_old
4th May 2007, 21:28
Despite the fact that I posted once previously to this thread, at this point I'd like to mention that this is a DEcrypting forum, not an ENcrypting forum...

Pelican9
4th May 2007, 22:48
The real question is How to stop Jeremy Duncan's offense against this forum?

honai
4th May 2007, 22:58
I second that. While under normal circumstances it might be wrong to talk about meta-aspects of a forum - in this case the agenda of a poster - it should be noted that Jeremy Duncan and his various avatars here and at avsforum.com do indeed have a tendency to flamebait and incite. Also, this fellow repeatedly posts highly misleading "information" while at the same time pretending that he were acting in good faith and in close talks to other respected members of both forums, which more often than not is completely false and fabricated. Actually, the sole reason why he often changes his nickname is because of his previous posts being utterly discredited by their sheer ill-informed content.

I respectfully suggest to close this thread.

blutach
5th May 2007, 01:18
Agreed.

Regards