Log in

View Full Version : Already HD titles that don't play?


Pages : [1] 2

evdberg
4th May 2007, 21:50
I was just wondering ... with all the commotion on the PK and the announcement of revoking the 'old' keys, are there already new HD-DVDs or BluRays that do not play on the 'old' versions of PowerDVD or WinDVD?

Or in other words, are there already new discs that we can not get the VUK anymore? Either by the 1st method (reading memory of software player) or the 2nd method (combining PK and VID)?

woah!
5th May 2007, 01:00
i dont think any have come up yet, maybe the may releases will turn some up..

Qjimbo
11th May 2007, 14:21
Yeah this is one thing I don't understand, how can they change the key without it suddenly not working on all players? If they still work on hardware players without flashing the firmware, there must still be some underlying code somewhere.

FoxDisc
11th May 2007, 14:47
Yeah this is one thing I don't understand, how can they change the key without it suddenly not working on all players? If they still work on hardware players without flashing the firmware, there must still be some underlying code somewhere.

So far, no "new" discs have surfaced. The current discs actually have 512 encrypted copies of a media key needed to decrypt/play the disc. The famous 09 f9 PK can only decrypt one of those 512 copies (the first one). Hardware players probably use another one (if anyone has found out for sure, it's not public info).

New discs will stop using the 09 f9 key to encrypt the media key. This will "revoke" the software players that used that old key, but not the hardware players that almost certainly never used it in the first place.

zeroprobe
11th May 2007, 15:09
The only way to defeat this is going for the standalones. Will take some clever gifted people to do this.

Qjimbo
11th May 2007, 18:05
This just seems really silly. I mean if they revoke the key, are they just going to stop supporting software players or give them a new key? And surely a key could be obtained from hardware players, so they're fighting a losing battle. If it can be played back by ANYTHING, it can be ripped. Period.

FoxDisc
11th May 2007, 19:30
The only way to defeat this is going for the standalones. Will take some clever gifted people to do this.

Standalones can be revoked, just like software players. It's not like finding a standalone player key will bring down the whole system. Standalones can even be revoked individually (Bob's player is revoked while Sally's player is not even though Bob and Sally both have the same model player).

The big difference between a standalone and a software player is that it is harder to identify the standalone, and you have to individually ID it to revoke it. (Players use different device keys, but calculate the same processing key, and it's the PK that gets revoked. You need to know the device keys/device number to figure out which new PK keys to use so that device can't figure out the new PK being used.)

OTOH, you don't really need to individually ID the software player - they get revoked as a pretty large group anyway.

If you look at how slow the revocation process is (at least so far), the AACS LA may not even be able to keep up with the software player hacking, so hardware player hacking may never come into play.

xt5
11th May 2007, 19:47
Im very interesting in know when the current Processing Key will be revoked, please use this thread to tell when it happens.

the revokation process seems very slow in the AACS LA side.

Johhn
11th May 2007, 20:21
Whilst waiting for new disks to appear that are encypted under a different PK, has anyone "upgraded" WinDVD or PowerDVD and had a preliminary look at what is going on when playing existing disks?

FoxDisc
11th May 2007, 20:28
Whilst waiting for new disks to appear that are encypted under a different PK, has anyone "upgraded" WinDVD or PowerDVD and had a preliminary look at what is going on when playing existing disks?

This is an interesting question, too. (The other interesting question is where are the new discs?) It would not surprise me if the new upgraded player software uses the old PK for old discs and new DKs to calculate a new PK for new discs. This would make it harder to find the new PK and track what changes were made.

Johhn
11th May 2007, 21:09
The other point that comes to mind is the x-boxhack. If, as I believe it can, it will yield VID's for the "new" disks, then there is already something to look for in the operation of the upgraded players when handling later disks.

As regards the delays in getting new disks out, we live in the days of "lean manufacturing" and "just in time". The lead time has got to be weeks between making a master and the disks reaching the stores. Fox virtually suspended new releases within a couple of days of the PK compromise being published. That suggests to me that they might have had to scrap a load of manufactured disks in the pipeline, and that the manufacturing and supply chain could be, shall we say, disrupted.

enantiomer
12th May 2007, 00:12
Judging by the number of mega-hits coming out on May 22, I'm guessing that's when we'll see "new" discs.

3r1c
12th May 2007, 01:33
The current discs actually have 512 encrypted copies of a media key needed to decrypt/play the disc.

does that mean if we find all 512 keys then its completely cracked and non-revokable ??

bourke
12th May 2007, 01:34
Online shops have already shipped many titles early that were due for release on May 22nd.

E.g. My set of the 'Ultimate Matrix Collection' is currently airborne somewhere at 40,000 feet over the Pacific ocean heading towards me at Mach 0.8 :-)

QuePaso
12th May 2007, 01:54
Ive read that Matrix hd-dvd is V2. That will probably be the first to be attacked. Im sure the pirates flicks on BD are the new keys as well.

Mug Funky
12th May 2007, 06:47
@ Johhn:

i hope you're wrong about that :|

even a company such as Fox wouldn't waste that much money (to say nothing of the discs that had to be shredded and put to landfill).

HD-DVD recalls are hugely expensive and embarrassing for a company - far more so than speculative losses due to piracy (i mean, come on! who can bittorrent 20 gigs at a time?).

... but then again, delayed releases are also a huge source of loss and embarrassment, and that didn't seem to stop Studio Canal.

FTX
12th May 2007, 10:10
Matrix trilogy was on the slysoft forum confirm by someone that it has the new keys. It also failed with AnyDVD-HD.
Matrix Trilogy HD-DVD fails (http://forum.slysoft.com/showthread.php?t=4214)
Filip

zeroprobe
12th May 2007, 10:23
i mean, come on! who can bittorrent 20 gigs at a time?

It is already happening.

Fahzuu
12th May 2007, 10:26
It is already happening.

Sad :(

FoxDisc
12th May 2007, 13:51
does that mean if we find all 512 keys then its completely cracked and non-revokable ??

No. The current PK (09 f9...) is a calculated number (from device keys) used by all software players to decrypt the first one of the 512 encrypted copies of the media key on current discs. Players can calculate millions of possible PKs, and the LA chooses which key they have to calculate. Right now they are using a PK that all software players can calculate, but the next discs will use one (actually, probably more than one) that old software players can't calculate.

frogman
13th May 2007, 19:00
Update Slyfox has released a new beta for new HD Disc and it seem to be working. hehehe! Gotta love it.

evdberg
13th May 2007, 19:19
This means that they have already ripped the keys out of the updated PowerDVD or WinDVD?

Hmmm ... according to James' comment in the previously mentioned thread, they only added beta support for the 1st Matrix movie. This could mean they only figured out the VUK for that disk, but have not yet the device key(s) and host certificate of either software player.

SvT
13th May 2007, 19:32
If I read the SLysoft post.

It's an update for 1 specific disc. Not an update for all new disks.

I quote James from SLysoft "I have made a beta version for you, so you can at least watch Matrix 1. For Matrix 2 & 3 you have to wait a couple of days (I hope the discs arrive soon)."

Reading this I dont think they broke it already.

So evdberg I think you're right.

zeroprobe
14th May 2007, 07:11
On the right tracks again though it seems. Would be great if it took less than week to do and then the balls back in AACS LAs court to take another 3months to fix again lol.

Fahzuu
14th May 2007, 10:27
This could mean they only figured out the VUK for that disk, but have not yet the device key(s) and host certificate of either software player.

How would they have done that? He wrote, that they didn't yet receive the discs. Strange...

evdberg
14th May 2007, 11:10
Maybe they got the Volume ID and MKBROM.AACS files from one of their customers. And maybe the current processing key still works (could be well possible, why would the AACS-LA otherwise send the C&D letters to remove the PK?). Remember that they used the host certificate of PowerDVD to authenticate the drive so they can read the Volume ID. This certificate is revoked and replaced by a new one, so theirs won't work anymore. However, with a Xbox drive you can also read the Volume ID differently. Since they claim they do not use any code from the doom9 forum, they should not use this trick in their software ...

Anyway, if anyone has (one of) the Matrix disks and a Xbox drive, they can use the tools available on this forum to see if they can obtain the VUK.

Fahzuu
14th May 2007, 11:36
Maybe they got the Volume ID and MKBROM.AACS files from one of their customers. And maybe the current processing key still works (could be well possible, why would the AACS-LA otherwise send the C&D letters to remove the PK?).

Hmm, sounds plausible...

Since they claim they do not use any code from the doom9 forum, they should not use this trick in their software ...

First, the code for the Xbox360 trick does not originate from the doom9 forum. It merely was mentioned here - or rather brought here.
Also: when they claimed, not to use code from the doom9 forum, they only wanted to clarify, that they did their own work in breaking AACS, because they had been "accused" of commercializing the work being done here (even though I don't see how they could be "accused" of doing that, because there is no license here that would not allow anyone to do just that).
And also: this statement having been made at that time did not include the words "we will never use code from...", right?

I wouldn't blame them for using the Xbox drive hack (I'd rather do so for them not using it).
It's not (or cannot be) copyrighted, it's a - now - freely available set of commands...

Adbear
14th May 2007, 12:22
How would they have done that? He wrote, that they didn't yet receive the discs. Strange...

Well I just used DVDfabHD that I already had installed and it did the first Matrix disc no probs, but then I put the second disc in and it must have done something to the 360 drive because now DVDfabHD won't recognise the drive at all

evdberg
14th May 2007, 13:21
The 2nd disk most likely had a newer version of the MKB, so your drive copied that to its persistant memory ... and that MKB revocates the previous PowerDVD host certificate (amongst things).
This also means that the 1st Matrix movie had still the old keys, so this also explains why they could get the VUK for it.
You should still be able to get the VUK for the 1st Matrix disk using the Volume ID retriever and MKB tool. You should also be able to get the Volume IDs for the disk 2 and 3, but MKB tool should not work anymore. Can you please verify this?

First, the code for the Xbox360 trick does not originate from the doom9 forum. It merely was mentioned here - or rather brought here.
That's true. Let me refrase it then ... the Xbox360 Volume ID retriever by xt5 and Geremia.

FoxDisc
14th May 2007, 15:53
You should still be able to get the VUK for the 1st Matrix disk using the Volume ID retriever and MKB tool. You should also be able to get the Volume IDs for the disk 2 and 3, but MKB tool should not work anymore. Can you please verify this?
It would also be interesting to know if the "AACS" directory on disks 2 and 3 have an "SKB.AACS" file, which would signal the use of Sequence Keys by the LA.

awhitehead
14th May 2007, 18:53
Hmm, sounds plausible...



First, the code for the Xbox360 trick does not originate from the doom9 forum. It merely was mentioned here - or rather brought here.


I apologize for being difficult, but I don't think you are correct about the above. Geremia indeed started the dumping of the flash of SD-S802A (http://www.xboxhacker.net/index.php?topic=6866.0) in xboxhacker.net forums, and posted work on reverse-engineering Toshiba WinVUP firmware updater there.

However majority of the work on the actual "Xbox360 trick", as in figuring out the firmware modifications at first to not require authentication, and later the undocumented was originally posted at doom9 forum. In fact, arnezami collaborated with Geremia, and wrote a utility that modified the firmware's signature, so that editing actual firmware would still result in a valid firmware file.

xt5 also registered on doom9, and my understanding is that the main reason his original utility was first posted on xboxhacker was due to the 5 day registration delay.

So in fact "Xbox 360 trick" was not "brought here", it actually was first posted here.

Hope this helps.

And yes, since we are talking about SlySoft, James Wong admitted that they use the "Xbox 360 trick" in their lab (http://forum.slysoft.com/showpost.php?p=28237&postcount=14), so yes, they are using the fruits of labour of doom9 members.

Slysoft's peer and James are very bright. But there are many bright people all over the world. The main reason Slysoft got to where they are now is simple: most folks working on AACS in this forum do that in their copious spare time, in addition to work, school, family, other commitments, etc. James and peer are paid for doing it full time, and paid to get the latest discs and latest hardware.

It's business vs hobbyists. Such is life.

Fahzuu
14th May 2007, 19:37
I apologize for being difficult, but I don't think you are correct about the above. Geremia indeed started the dumping of the flash of SD-S802A (http://www.xboxhacker.net/index.php?topic=6866.0) in xboxhacker.net forums, and posted work on reverse-engineering Toshiba WinVUP firmware updater there.

Ok, then I was wrong, sorry.

And yes, since we are talking about SlySoft, James Wong admitted that they use the "Xbox 360 trick" in their lab (http://forum.slysoft.com/showpost.php?p=28237&postcount=14), so yes, they are using the fruits of labour of doom9 members.

Slysoft's peer and James are very bright. But there are many bright people all over the world. The main reason Slysoft got to where they are now is simple: most folks working on AACS in this forum do that in their copious spare time, in addition to work, school, family, other commitments, etc. James and peer are paid for doing it full time, and paid to get the latest discs and latest hardware.

It's business vs hobbyists. Such is life.

I just feel, I need to defend that company every now and then, because they keep getting bashed for no reason, just because some people dislike the fact, that they charge money for what they do.
I'm happy that they do it, because, yes, there are freeware products out there, that do nearly the same as their stuff, but I happily pay them for simply doing it better and to some extent more reliably and that the products are easier to use.

So I actually buy their products, so they can employ Peer and James who work full-time to keep my software up to date :)

Ok, enough said - they should actually pay me for this ;)

Johhn
14th May 2007, 23:26
They actually say that they might use those hacks "internally, in the lab". I would have thought that this means that they use whatever tools they find - not that they copy and sell other people's work.

For example, the X-box hack either is, or can be developed to be, a very quick and efficient method of extracting Vid's which is probably future-proof. That in itself is not a sellable feature. You cannot somehow incorporate the X-box hack into software that runs on a pc. But being able to quickly extract Vid's is another matter.

Who knows? Maybe the X-box hack will turn out to facilitate a side-channel gateway into ascertaining what is going on the updated players?

awhitehead
15th May 2007, 03:23
They actually say that they might use those hacks "internally, in the lab". I would have thought that this means that they use whatever tools they find - not that they copy and sell other people's work.

True, but my point was that they do benefit from research that happens in this forum, even if they do not sell it directly to the end users. When people see that, they start wondering: "Should I post this piece of code I just wrote, or cool trick I just reverse-engineered, or should I keep it to myself and my buddies?". And as a result everyone suffers.

On the other hand, I do respect the fact that SlySoft attempts to honor the copyrights and GPL, and specifically works to comply with the licenses, as opposed to replacing copyrights on GPLed software and selling it as their own. They should be aplauded for that.

James is wondering why there are people out there that do not like SlySoft. I can't speak for everyone, but I can disclose my feeling on the matter:

I am a little bit frustrated that SlySoft is not sharing some of the technical information about their findings, but I realize that they are in the business of making money. As my mom would say: c'est la vie, mon chéri.

My only concern for a while was that they dominate the niche rather thoroughly, and for a while it seemed like they monopolize the niche in it's entirety. Unfortunately homogenuity of any kind is bad, since, in the worst case, with SlySoft gone, for example, everyone gets left hanging. In addition, lack of competition leads to lack of innovation, which is why I was really happy that FengTao released a competing product (and yes, I know of GPL violations in it).

Other then that.... SlySoft is not competition unless you are in the business of selling DVD decrypting software. In some ways they are the good guys, since they facilitate adoption of the next generation HD formats and give fair use rights back to the consumer, even if at a cost.

All right, I'll get off the soapbox.

zeroprobe
15th May 2007, 07:34
True, but my point was that they do benefit from research that happens in this forum, even if they do not sell it directly to the end users. When people see that, they start wondering: "Should I post this piece of code I just wrote, or cool trick I just reverse-engineered, or should I keep it to myself and my buddies?". And as a result everyone suffers.

On the other hand, I do respect the fact that SlySoft attempts to honor the copyrights and GPL, and specifically works to comply with the licenses, as opposed to replacing copyrights on GPLed software and selling it as their own. They should be aplauded for that.

James is wondering why there are people out there that do not like SlySoft. I can't speak for everyone, but I can disclose my feeling on the matter:

I am a little bit frustrated that SlySoft is not sharing some of the technical information about their findings, but I realize that they are in the business of making money. As my mom would say: c'est la vie, mon chéri.

My only concern for a while was that they dominate the niche rather thoroughly, and for a while it seemed like they monopolize the niche in it's entirety. Unfortunately homogenuity of any kind is bad, since, in the worst case, with SlySoft gone, for example, everyone gets left hanging. In addition, lack of competition leads to lack of innovation, which is why I was really happy that FengTao released a competing product (and yes, I know of GPL violations in it).

Other then that.... SlySoft is not competition unless you are in the business of selling DVD decrypting software. In some ways they are the good guys, since they facilitate adoption of the next generation HD formats and give fair use rights back to the consumer, even if at a cost.

All right, I'll get off the soapbox.


It's good to keep some things private especially keys that Slysoft use or any other methods. The more secret it is the harder for AACS LA to find out how there doing it.

Doom9
15th May 2007, 08:17
It's good to keep some things private especially keys that Slysoft use or any other methods. The more secret it is the harder for AACS LA to find out how there doing it.The demise of DVD Decrypter and RI4M prove differently.. if information is widely disseminated, it gets a lot harder to squash.
I do use AnyDVD HD as well and there's nothing wrong with making money off a useful service, but the possibility to back up HD discs is even better protected if there are alternatives just in case.

Fahzuu
15th May 2007, 08:40
awhitehead, you got some really good points here.

But do they really benefit from anything being done here?
The first version of AnyDVD HD I layed my hands on was Feb. 7th. That was before the processing key showed up here and way before the Xbox hack was discovered. They already had a fully grown authentication built-in and were able to decrypt all HD-DVDs. So they were using a/the processing key or even device keys.
I just don't see, what real use they can pull out of the xbox hack or anything else from this forum other than curiosity.

But you see me hanging out here, not so much on their forum. That's simply because the talk here is more interesting.
...because they refuse to disclose their knowledge, yes, I understand that this can be frustrating.


True, but my point was that they do benefit from research that happens in this forum, even if they do not sell it directly to the end users. When people see that, they start wondering: "Should I post this piece of code I just wrote, or cool trick I just reverse-engineered, or should I keep it to myself and my buddies?". And as a result everyone suffers.

But wouldn't that be a very stupid attitude? Holding back code just because someone doesn't want anyone to make financial profit with it?
This is nearly the same reason, why they are holding back their knowledge - with a slight difference: if anyone else makes profit with their findings, they make less. So they have a substantial reason, people here don't.

My only concern for a while was that they dominate the niche rather thoroughly, and for a while it seemed like they monopolize the niche in it's entirety. Unfortunately homogenuity of any kind is bad, since, in the worst case, with SlySoft gone, for example, everyone gets left hanging. In addition, lack of competition leads to lack of innovation, which is why I was really happy that FengTao released a competing product (and yes, I know of GPL violations in it).

Yes, 100% agree. It's good, that this forum has added to the diversity.
About FengTao - judging from a few facts:

- product showed up a while after doom9 forum disclosed all required information
- released a freeware product (certainly not because FengTao wants to give us all a nice present)

tells me, that they actually did simply wrap up doom9 info.
The '"freeware"-point, I think, is a hint, telling me that they rely on doom9 forum to find a way to break the "next-gen" keysets, which this thread is about.
And they don't trust in that enough, to charge money for their product - just yet.

So in this way, FengTao probably does not add to the list, it may be just a "Doom9-clone".

But when HD/BD becomes more popular, I'm sure, some more "participants" will join :-)

evdberg
15th May 2007, 09:43
Can we please get back on topic again? Are there already owners of the matrix disks that did the tests I described in post 29? My Matrix box is still on order and not even shipped ...

FoxDisc
15th May 2007, 18:25
Are there already owners of the matrix disks that did the tests I described in post 29?
I'd like to know about the test I suggested in post 30 too. It is extremely easy, just look in the "AACS" directory for the SKB.AACS file. Adbear, where are you?

K40
16th May 2007, 00:20
The 2nd disk most likely had a newer version of the MKB, so your drive copied that to its persistant memory ... and that MKB revocates the previous PowerDVD host certificate (amongst things).
This also means that the 1st Matrix movie had still the old keys, so this also explains why they could get the VUK for it.
You should still be able to get the VUK for the 1st Matrix disk using the Volume ID retriever and MKB tool. You should also be able to get the Volume IDs for the disk 2 and 3, but MKB tool should not work anymore. Can you please verify this?

I played around with the trilogy and can confirm that
the 1st Matrix has old keys.It's working with Windvd and Winhex
to get the VUK and the same result with fetchvid and mkb.exe
Tried BackupHDDVD and DumpHD and both are decrypting fine.
Matrix Reloaded and Revolutions are not working with WinDVD
and Nero Showtime.They are playing only in updated
Power DVD Ultra.I can use fetchvid to get the VID.
When using Mkb.exe :
Skipped Section 10
Skipped Section 21
Skipped Section 20
Found Verification Data
Skipped Section 7f
Skipped Section 07
Found Explicit Subset Difference 528 records
Found Media Key Data 527 records

After playing Reloaded and Revolutions my XBox Drive
still is working with WinDVD when using Matrix.
So in my case there seems to be no revocation.

arnezami
16th May 2007, 05:30
I played around with the trilogy and can confirm that
the 1st Matrix has old keys.It's working with Windvd and Winhex
to get the VUK and the same result with fetchvid and mkb.exe
Tried BackupHDDVD and DumpHD and both are decrypting fine.
Matrix Reloaded and Revolutions are not working with WinDVD
and Nero Showtime.They are playing only in updated
Power DVD Ultra.I can use fetchvid to get the VID.
When using Mkb.exe :
Skipped Section 10
Skipped Section 21
Skipped Section 20
Found Verification Data
Skipped Section 7f
Skipped Section 07
Found Explicit Subset Difference 528 records
Found Media Key Data 527 records

After playing Reloaded and Revolutions my XBox Drive
still is working with WinDVD when using Matrix.
So in my case there seems to be no revocation.

Very interesting. 527 C-values (Media Key Data). Thats not a lot more than the 512 last time. So far this feels like a rather simple revocation. Possibly no fancy stuff.

Can you run the latest version of aacskeys (http://www.sendspace.com/file/q44d83) and post the verbose output (won't give much but it will give the "First u mask nr" and "First uv"). That could already give us a hint.

What are the Volume IDs of Matrix 2 and 3 btw?

Could you post the first records in the MKB files (most notably the record beginning with 04000A somewhere around position 700h in winhex). What I am really curious about is whether the records starting with 04000A (so from approx postion 700h-1100h in winhex) are exactly the same on both Matrix 2 and 3. If this record is the same on all new discs this would mean only one Processing Key would be needed. :D

What about the SKB.AACS file? Is it on the disc?

Could you give a directory list of the AACS dir on the disc (including filesizes and dates). That would be great. :)

Regards,

arnezami

PS. @K40 and @Adbear: please check your pm.

evdberg
16th May 2007, 09:34
After playing Reloaded and Revolutions my XBox Drive
still is working with WinDVD when using Matrix.
So in my case there seems to be no revocation.
This means that only the PowerDVD host certificate is revoked, which is logical since AnyDVD used it ... it also means the well known Processing Key does not work anymore, just as we expected.

Fahzuu
16th May 2007, 10:04
This means that only the PowerDVD host certificate is revoked, which is logical since AnyDVD used it ...

I don't think this is so logical, I find it very strange actually.
WinDVD was the program causing the biggest trouble for AACS.
If I were them, I'd revoke that old version for good, so it can cause no more damage. After all, it's nothing more than a 6 Byte Host ID to be added to the revocation list.
I'm very surprised, that they left it in the game.

evdberg
16th May 2007, 10:30
I was only talking about the host certificate, most likely the device key of WinDVD has been revoked (since it was published on this forum), at least it won't work on the newer titles anymore.

SuperGoof
16th May 2007, 10:34
This means that only the PowerDVD host certificate is revoked.

It does not mean that, actually. Maybe no certificates were revoked at all, only device/processing keys. He did not say that after inserting Matrix Reloaded or Revolutions the first Matrix stoped playing in the OLD PowerDVD. In fact he probably does not have it installed already and did not test this.

Fahzuu
16th May 2007, 10:44
I was only talking about the host certificate, most likely the device key of WinDVD has been revoked (since it was published on this forum).

Yes me too. Revoking the host certificate is no trouble for them and it results in old WinDVD versions not working with any (old) discs anymore, as soon as the drive updates its blacklist.

The "device key" you are referring to: is that the "aa ...." thing that was mentioned here some time ago?
That would be the direct parent of the processing key - so every player, not only WinDVD will necessarily be using this intermediate subdevice key (what I'm saying is: this key does not belong to WinDVD).
And that key is effectively the same thing as the processing key itself (meaning: not worth more than), because it cannot reveal anything else but the processing key, since it doesn't even have descendant subdevice keys.
So, yes, I'm quite certain, that the whole set of WinDVD's device keys have been revoked, but I really can't believe that they didn't revoke the host key, while they're at it...

K40
16th May 2007, 15:33
I didn't tried if the OLD Pwdvd version still plays old
HDDVD with the Xbox Drive.Will try this too.
The directory list of the AACS from M.Reloaded:
CONTENT_CERT.AACS 1KB
CONTENT_HASH_TABLE 1.AACS 235KB
CONTENT_HASH_TABLE 2.AACS 53KB
CONTENT_REVOCATION_LIST:AACS 977KB
DKF.AACS 1KB
MKBRECORDABLE.AACS 977KB
MKBROM.AACS 977KB
MNGCPY_MANIFEST.XML 1KB
VTKF000.AACS 3KB
VTUF000.AACS 1KB

The M.Revolutions has exactly the same Filelist
and the size of the files is the same except
The CONTENT_HASH_TABLE 1A is 196 KB
The Date is 05.04.2007 for both HDDVD's.

K40
16th May 2007, 16:47
With aacskey and M.Reloaded i get this:
Could not open file : c:\\Processing Device Keys
Simple.txt First C-value:
5948FCD2570039644A2CB5E2C7C815EC

First u mask nv: 05
First uv: 0000001C

Also the message that aacskey encountered a problem and must
be closed appears.

arnezami
16th May 2007, 17:38
I didn't tried if the OLD Pwdvd version still plays old
HDDVD with the Xbox Drive.Will try this too.
The directory list of the AACS from M.Reloaded:
CONTENT_CERT.AACS 1KB
CONTENT_HASH_TABLE 1.AACS 235KB
CONTENT_HASH_TABLE 2.AACS 53KB
CONTENT_REVOCATION_LIST:AACS 977KB
DKF.AACS 1KB
MKBRECORDABLE.AACS 977KB
MKBROM.AACS 977KB
MNGCPY_MANIFEST.XML 1KB
VTKF000.AACS 3KB
VTUF000.AACS 1KB

The M.Revolutions has exactly the same Filelist
and the size of the files is the same except
The CONTENT_HASH_TABLE 1A is 196 KB
The Date is 05.04.2007 for both HDDVD's.

Great! No Sequence Keys! :D :D

Which makes our life a LOT easier.

At first glance it seems the Explicit Subset Difference Record is slightly changed: the first tree seems to be divided a few times (which was expected). If we can compare several of the ESDRs then we can see if one or more Processing Keys are needed to decrypt all new discs.

Much more to analyze.

Update: the ESDR on Matrix 2 is exactly the same as on Matrix 3. :D :D These AACS guys have been very lazy. One Processing Key will probably (again) open up AACS. Duh. I think we will now get a race to find a/the new Processing Key. :)

Regards,

arnezami

PS. Some people should now check their pm boxes ;). And if you think you can (maybe) get Device/Processing Keys out of a Software Player (or think you already have) then contact me.

FoxDisc
16th May 2007, 18:49
At first glance it seems the Explicit Subset Difference Record is slightly changed: the first tree seems to be divided a few times (which was expected).

Some may not understand the significance of the subdivided "first tree." Up until the new discs, all software players were members of the first tree. A "tree" corresponds to a "subset difference set" or more simply, a group of authorized players. It isn't public yet whether anyone knows if hardware players are members of that first tree, but it is widely believed that they are not. Each group of players or set of players has a different processing key. 09 f9..was the PK for only the first tree.

By dividing up the first tree, they have made smaller groups of players. Each of those groups has to calculate a different processing key. I vaguely recall posting recently that the processing key tells the LA nothing about where it came from. That's not quite true. I should have written that the processing key tells the LA nothing about which member of the group produced that key, but it definitely reveals the group (or "tree") that calculated it. Only the VUK, VID, media key and title key are truly anonymous.

I'm guessing here, but by dividing up the first tree, they probably figured they could assign different software players to different groups within that original first tree. The PK for WinDVD will probably be different from the PK for PowerDVD. This is a kind of "poor man's" simple traitor tracing method using the MKB. If another processing key surfaces, they'll know who to point the finger at. They didn't implement SKBs, which is the fancy complex method of traitor tracing. Again, guessing, I bet they had problems with some of the players handling SKBs.

One interesting question is whether any of the other trees were divided. I suspect they weren't, meaning they are focusing on the software tree.