dacium
16th May 2007, 14:59
Can someone please correct me where i'm wrong:
Programs like dumbvid show how it is possible to intercept comms to the drive at the correct time to take the vid. No matter how the software players update, it will be possible to fake being their thread, and getting in at the right time will never be an issue because we can always set our threads to a higher priority. So I cannot see how it is possible for them to do anything to avoid us getting the vid from a system that has registered software player. Even if they force bus encryption, we can intercept and modify the packets so that the software always says it can't encrypt bus or visa versa.
Now this is where I am not 100% sure, but it seems the mkbrom.aacs can be read without authentification. So once the vid is published, anyone can get the vuk, is this correct?
As for creating a free-open source player. This would seem practically impossible. We can assume that AES won't be cracked, and equally that the one way encryption steps in the mkb likewise won't be able to move backward, then it is impossible to decode the disc without obtaining either the vid/vuk or a players own key and certification - both of which require the latest update of a official certified software player.
The player key is going to become extremely hard to get through the software by them hiding it better, and is hard to for people to get hold of in other ways (firmware mods etc), and once we do have it they will just revoke it and we start all over again.
The vuk's of course can't be revoked. The vuk's however mean we need a database of vuk keys. This has already been setup and pulled down etc.
Now comes my final question. If a database is setup online for the vuk's, there is nothing stopping their being an open source platform independent player/dumper is there? Because with the vuk we don't need to authenticate to read the movie data Is this correct? So it seems possible that there can be an independant player, but it would relay on the public to send in vuk's for each disc, which can only be obtained by at least the submitters have an updated legit player.
Ideally we would want to remove the need for an online database, and/or the need for someone to have a certified software with key to ready the new discs vuk's. How to do this seems next to impossible. However, if we can somehow get an official players key and certificate (I don't know how legal this would be to include in the software), then the game would sort of be opposite - they would have to go through our code to try and find these values, so there would be incentive not to make it open source? Of course then the pirates would release copies and the digital signature would be in the video and allow them to revoke the key.
Also a question about authetification certificate, it is my understanding that this can't be revoked/changed in anyway. Once we the one pbl thats it.
Programs like dumbvid show how it is possible to intercept comms to the drive at the correct time to take the vid. No matter how the software players update, it will be possible to fake being their thread, and getting in at the right time will never be an issue because we can always set our threads to a higher priority. So I cannot see how it is possible for them to do anything to avoid us getting the vid from a system that has registered software player. Even if they force bus encryption, we can intercept and modify the packets so that the software always says it can't encrypt bus or visa versa.
Now this is where I am not 100% sure, but it seems the mkbrom.aacs can be read without authentification. So once the vid is published, anyone can get the vuk, is this correct?
As for creating a free-open source player. This would seem practically impossible. We can assume that AES won't be cracked, and equally that the one way encryption steps in the mkb likewise won't be able to move backward, then it is impossible to decode the disc without obtaining either the vid/vuk or a players own key and certification - both of which require the latest update of a official certified software player.
The player key is going to become extremely hard to get through the software by them hiding it better, and is hard to for people to get hold of in other ways (firmware mods etc), and once we do have it they will just revoke it and we start all over again.
The vuk's of course can't be revoked. The vuk's however mean we need a database of vuk keys. This has already been setup and pulled down etc.
Now comes my final question. If a database is setup online for the vuk's, there is nothing stopping their being an open source platform independent player/dumper is there? Because with the vuk we don't need to authenticate to read the movie data Is this correct? So it seems possible that there can be an independant player, but it would relay on the public to send in vuk's for each disc, which can only be obtained by at least the submitters have an updated legit player.
Ideally we would want to remove the need for an online database, and/or the need for someone to have a certified software with key to ready the new discs vuk's. How to do this seems next to impossible. However, if we can somehow get an official players key and certificate (I don't know how legal this would be to include in the software), then the game would sort of be opposite - they would have to go through our code to try and find these values, so there would be incentive not to make it open source? Of course then the pirates would release copies and the digital signature would be in the video and allow them to revoke the key.
Also a question about authetification certificate, it is my understanding that this can't be revoked/changed in anyway. Once we the one pbl thats it.