Log in

View Full Version : HDDVD decrypt situtation...


dacium
16th May 2007, 14:59
Can someone please correct me where i'm wrong:

Programs like dumbvid show how it is possible to intercept comms to the drive at the correct time to take the vid. No matter how the software players update, it will be possible to fake being their thread, and getting in at the right time will never be an issue because we can always set our threads to a higher priority. So I cannot see how it is possible for them to do anything to avoid us getting the vid from a system that has registered software player. Even if they force bus encryption, we can intercept and modify the packets so that the software always says it can't encrypt bus or visa versa.

Now this is where I am not 100% sure, but it seems the mkbrom.aacs can be read without authentification. So once the vid is published, anyone can get the vuk, is this correct?

As for creating a free-open source player. This would seem practically impossible. We can assume that AES won't be cracked, and equally that the one way encryption steps in the mkb likewise won't be able to move backward, then it is impossible to decode the disc without obtaining either the vid/vuk or a players own key and certification - both of which require the latest update of a official certified software player.

The player key is going to become extremely hard to get through the software by them hiding it better, and is hard to for people to get hold of in other ways (firmware mods etc), and once we do have it they will just revoke it and we start all over again.

The vuk's of course can't be revoked. The vuk's however mean we need a database of vuk keys. This has already been setup and pulled down etc.

Now comes my final question. If a database is setup online for the vuk's, there is nothing stopping their being an open source platform independent player/dumper is there? Because with the vuk we don't need to authenticate to read the movie data Is this correct? So it seems possible that there can be an independant player, but it would relay on the public to send in vuk's for each disc, which can only be obtained by at least the submitters have an updated legit player.

Ideally we would want to remove the need for an online database, and/or the need for someone to have a certified software with key to ready the new discs vuk's. How to do this seems next to impossible. However, if we can somehow get an official players key and certificate (I don't know how legal this would be to include in the software), then the game would sort of be opposite - they would have to go through our code to try and find these values, so there would be incentive not to make it open source? Of course then the pirates would release copies and the digital signature would be in the video and allow them to revoke the key.

Also a question about authetification certificate, it is my understanding that this can't be revoked/changed in anyway. Once we the one pbl thats it.

FoxDisc
16th May 2007, 16:39
I cannot see how it is possible for them to do anything to avoid us getting the vid
The VID should be obtainable with at least the x-box hack if not by bus sniffing.

Now this is where I am not 100% sure, but it seems the mkbrom.aacs can be read without authentification. So once the vid is published, anyone can get the vuk, is this correct?
Not correct - you need to decrypt the C-value in the MKB to get the media key. That requires a processing key, which is usually derived from a device key. The VID and media key give you the VUK which gives you the video data, provided that SKB processing is not required.

The player key is going to become extremely hard to get through the software by them hiding it better, and is hard to for people to get hold of in other ways (firmware mods etc), and once we do have it they will just revoke it and we start all over again.
The vuk's of course can't be revoked. The vuk's however mean we need a database of vuk keys. This has already been setup and pulled down etc.
The game will be played, but we have yet to see whether they can revoke faster than others can find required keys. My bet is that database techniques will be implemented and there may be some newer discs that won't play, but only until they are cracked.

Now comes my final question. If a database is setup online for the vuk's, there is nothing stopping their being an open source platform independent player/dumper is there? Because with the vuk we don't need to authenticate to read the movie data Is this correct?
Correct - but getting the VUK is not trivial, and you may need more if SKBs are used.
So it seems possible that there can be an independant player, but it would relay on the public to send in vuk's for each disc, which can only be obtained by at least the submitters have an updated legit player.
The VUK tells the world nothing about where it came from. If it came from a hardware player, revoking software players does no good. The LA needs to find out where the VUK came from, and that's not easy unless they read it here :)
They'll eventually need to implement SKBs. The whole purpose of SKBs is traitor tracing.

Ideally we would want to remove the need for an online database,and/or the need for someone to have a certified software with key to ready the new discs vuk's. How to do this seems next to impossible. However, if we can somehow get an official players key and certificate (I don't know how legal this would be to include in the software), then the game would sort of be opposite - they would have to go through our code to try and find these values, so there would be incentive not to make it open source? Of course then the pirates would release copies and the digital signature would be in the video and allow them to revoke the key.

The "revocation" terminology can be confusing. I'll use:

"MKB Revocation" for implicit device key/processing key/device ID number revocation

"HRL Revocation" for explicit Host Private Key/ Host Certificate/ Host ID number revocation and

DRL Revocation or CRL Revocation for Drive and Content explicit revocation.

If a database is not used, then MKB revocation is easy for the LA. Ultimately, I think a combination of a DB and one or more current/updateable keys will be used in non-authorized players.

Also a question about authetification certificate, it is my understanding that this can't be revoked/changed in anyway. Once we the one pbl thats it.

I don't quite understand this, but HRL and DRL revocation are options for the LA. There are three ways to totally and irrevocably break the AACS system:

1) Find or steal the master keys. (Yes there are some, but they have never been released) This is not going to happen.

2) Cryptographically break AES and the AACS sytem. This is not going to happen either.

3) Get enough of the device/sequence keys that the system crumbles. If all sequence keys are identified, it becomes impossible to trace and revoke players. This is possible, but seems unlikely anytime soon.

Realistically, the cat/mouse game is here to stay, and it's likely to involve a database.

Anyway, that's my take on it.

arnezami
16th May 2007, 20:29
@FoxDisc: it seems you have mastered AACS :).

Even if they force bus encryption, we can intercept and modify the packets so that the software always says it can't encrypt bus or visa versa.

Thought I could comment on this. This is not the case: if Bus encryption is involved you cannot intercept or modify anything. Bus encryption is really nasty.

Of course right now no drives do Bus encryption (in fact: how the bus encryption should work isn't even in the specs!). And after thinking about this for some time: to "upgrade" a drive (like the xbox HD DVD drive) to be capable of Bus encryption would not just involve a general firmware patch. Why? Because the ability of BEC is signed by the AACS for each individual drive. And (as an example) the xbox HD DVD drive does not seem to have a command to flash these parts of the flash memory: the AACS related stuff that is. So I don't see this happening. :D

I guess the current xbox HD DVD drives (not capable of bus encryption) will be worth a lot in the future ;). I would buy one if I were you...

arnezami

dacium
17th May 2007, 01:55
It would seem that the bus encryption is turned on only after the certificates have been passed. We can fake a hardware drive in software and pass the packets onto the real hardware and just change the bus encryp enable bit.

arnezami
17th May 2007, 03:52
It would seem that the bus encryption is turned on only after the certificates have been passed. We can fake a hardware drive in software and pass the packets onto the real hardware and just change the bus encryp enable bit.

Nope. The bus encrypt enable bit is in the certificate: its signed by the AACS LA themselves. No way to turn it off (if it is on). The software player will immediatly see the certificate is not valid if you change it.

Of course the opposite is also true: if your bus encryption bit is turned off there is no easy way (for them) to turn it on: they would have (1) figure out a way to flash the AACS part of the flash mem (which doesn't seem to be possible) (2) force a firmware patch (3) the Software Player (assuming thats the program that would do the forced patch) would have to include contain all certificates of all xbox hd dvd drives sold so so far). So I really don't think they can do anything about these "old" drives being sniffed. ;).