Log in

View Full Version : New Processing Key found!! (MKB v3 is now open)


Pages : 1 [2] 3

FoxDisc
31st May 2007, 17:03
I read an analysis by one of the AACS system designers about how to build systems that comply with the AACS license requirements. It was intended for software/hardware guys and he seemed to be saying that the license required more than just trying to prevent cracks, which is what older DVD/CSS licenses required. He seemed to be saying that the AACS license was worded more strictly and required success.

I wonder if the open platform players could end up getting cut off because they could not succeed.

honai
31st May 2007, 17:13
He seemed to be saying that the AACS license was worded more strictly and required success.

Well, in the classified sector government agencies also required success, and still the suppliers' schemes were broken.

As for the Vista DRM capabilities, it has been demonstrated a few months ago that PVP and assorted kernel-mode technologies can be subverted by the user simply because the Windows devs implemented the backdoors themselves (ironically, often in order to grant Windows Media Player and other MS tools direct access to the OS).

Galileo2000
31st May 2007, 17:19
As for the Vista DRM capabilities, it has been demonstrated a few months ago that PVP and assorted kernel-mode technologies can be subverted by the user simply because the Windows devs implemented the backdoors themselves (ironically, often in order to grant Windows Media Player and other MS tools direct access to the OS).

That's what I wanted to hear :D

Can you provide a link?

FoxDisc
31st May 2007, 17:49
Well, in the classified sector government agencies also required success, and still the suppliers' schemes were broken.

The point I was trying to make was that this might be one of the few ways they could actually close off the entire "open platform" i.e. software player market despite contracts that have probably been signed between the software companies and the LA. The LA says "You are in breach since you didn't succeed so you get no more Device Keys."

meditate2
31st May 2007, 17:56
Dongles had proved it's total ineffectiveness long time ago. ....."Software protection with the dongles is fine, except dongles are expensive and do not really work in terms of protecting the software".

I doubt it, the ONLY "normal" protection i know which is not broken for over a year now, is a dongle protection. And it is used for THE programs in the audio area(new Cubase for example , #1 audio sequencer), so many groups tried but bitten their teeth out of this. Syncrosofts previous protection was cracked by "H2O", formerly THE cracking group in the audio area, but they said that it was such a huge work that it took easily over 1000 hours and that they dont want to do something like this again....

http://www.syncrosoft.com/Jan._25_2007_Products_uncracked_for_more_than_12_months-78-86.html

Fortunatly this protection wouldnt work that easily with movies....

Anyway keep up the good work, guys...:thanks:

diogen
31st May 2007, 18:40
That's what I wanted to hear :D
Can you provide a link?I think this is the one.
Security researcher Alex Ionescu claims to have successfully bypassed the much discussed DRM protection in Windows Vista, called 'Protected Media Path' (PMP)...http://it.slashdot.org/article.pl?sid=07/01/29/1811201
Microsoft would love to see Vista as the sole platform for HD playback, but the software companies will fight that...The are just two: Cyberlink and Intervideo. And according to Chris, nobody will get new licenses for XP players, nor will XP be updated to prevent key sniffing.
they will never enable HD DVD playback in any other method then what's there now (eg. PowerDVD/WinDVD) in Windows XP...
Windows XP is done in terms of new features. That's it, nothing new will become.http://www.avsforum.com/avs-vb/showthread.php?p=10649617&&#post10649617

Diogen.

FoxDisc
31st May 2007, 19:22
Microsoft would love to see Vista as the sole platform for HD playback, but the software companies will fight that...
The are just two: Cyberlink and Intervideo. And according to Chris, nobody will get new licenses for XP players, nor will XP be updated to prevent key sniffing.

Those were interesting links - thanks. I'm not quite sure of the point you are making though. It seems likely that Cyberlink and Intervideo are the only two because they're the only ones with enough cash to pay license fees and other costs and still expect to make a profit. To recover those costs, they need to keep selling to the XP market. Microsoft will certainly not improve XP, so if the key leakage continues, as seems likely, the question becomes what the LA will do.

Do they have the right to terminate Cyberlink and Intervideo? Would they want to? The studios want to sell discs and at least for now, large file sizes, slow transfer speeds and high blank media costs limit the actual financial impact of any hidef copying. Customers will scream pretty loudly if their software suddenly turns off as the LA cuts off Cyberlink and Intervideo.

It looks to me like the LA will keep on struggling by playing the cat and mouse game. There seems to be few other options for them.

Galileo2000
31st May 2007, 19:40
I think this is the one.
http://it.slashdot.org/article.pl?sid=07/01/29/1811201
Diogen.

Thanks Diogen.

I think the entire PMP thing is an insult to the consumers, plain and simple.

Quote from the comments to the article:
"As a user of the Windows Home Operating Rights Environment, I must state for the record that all of my transactions with said system are completely clean, and take place using the most effective protection available. If you truly feel that some of your Media exchanges are tainted, I'd suggest it's probably because you didn't pay the requisite PMP fees."

honai
31st May 2007, 20:25
Do they have the right to terminate Cyberlink and Intervideo? Would they want to? The studios want to sell discs and at least for now, large file sizes, slow transfer speeds and high blank media costs limit the actual financial impact of any hidef copying. Customers will scream pretty loudly if their software suddenly turns off as the LA cuts off Cyberlink and Intervideo.

I tend to believe that the opposite is true, i.e. if it weren't for proliferation of HD media to the PC desktop market both formats would be dead by now. The AACS LA actually needs the Windows XP player sales for now.

Same thing happened to the DVD. Sales went up, not down, after CSS was beaten. Though that might be a correlation rather than causality.

diogen
31st May 2007, 21:43
...Do they have the right to terminate Cyberlink and Intervideo? Would they want to?That's the million dollar question... :)
I think MS and the rest of the gang have different views on this issue.
...The studios want to sell discs and at least for now, large file sizes, slow transfer speeds and high blank media costs limit the actual financial impact of any hidef copying.Let's hope their priorities are in this order.
The very fact that DVDDecryptor and RipIt4Me were "killed" today when only a lazy can't copy a regular DVD, means that they take it "personally".
Hence, I have a hard time to imagine they would let this game continue for long.
...Customers will scream pretty loudly if their software suddenly turns off as the LA cuts off Cyberlink and Intervideo.They certainly will. But will studious listen?

Diogen.

mlansell
31st May 2007, 21:52
Same thing happened to the DVD. Sales went up, not down, after CSS was beaten. Though that might be a correlation rather than causality.

The vast majority of people do not copy DVDs, either for backup, media serving or for piracy. They simply do not have the technical know-how to do it, even with all the tools that are available.

They may buy knock-off movies from some stall in a market, but that's irrelevant to my point - which is that 99% of sales are driven by the availability of cheap, dedicated, under-the-telly boxes to play the disks.

Frankly I'm amazed (after the CSS debacle) that PC drives and software players are even available - if it were not possible to play HD DVDs or BluRay disks on a PC, I doubt that movie sales would have been harmed much at all, and cracking the copy protection would be so much harder.

Johhn
31st May 2007, 23:08
....................

Frankly I'm amazed (after the CSS debacle) that PC drives and software players are even available - if it were not possible to play HD DVDs or BluRay disks on a PC, I doubt that movie sales would have been harmed much at all, and cracking the copy protection would be so much harder.

I believe that market research showed that unless HD movie disks were playable on pc's and games machines, with the same disk format being available as a recordable media, and the drives having normal usage in pc's, that the whole enterprise would not have been viable.

bourke
1st June 2007, 01:50
I think they will give CyberLink and InterVideo a couple of attempts at obfuscating their code - probably a three strikes and you're out policy. So I think they are down to having one or two strikes remaining each and then 'sorry you breached your AACS license agreement'.

Sure I think they'll now treat every breach as entirely separate since now they can pinpoint the culprits easier - i.e they'll revoke licences for XP players long before Vista players.

If this is in part of their agreement - then you will probably see CyberLink and InterVideo trying to crack each other's programs in order to have them removed from the market and so create a monopoly on HD player software for themselves!

So roughly by what magnitude is it more difficult to kernel debug a Vista application compared to the equivalent XP app?

insomniak1981
1st June 2007, 02:27
I think the bypassing of vista DRM belongs to both Alex and Joanna , both formerly of COSENIC. They ran training courses at the recent black hat conference describing kernel attacks which could also be used to bypass vista DRM.
As the training will be focused on Windows platform and Vista x64 specifically, we will also present some new kernel attacks against latest Vista x64 builds. These attacks, of course, work on the fly and do not require system reboot and are not afraid of the TPM/Bitlocker protection. (Although they could also be used to bypass Vista DRM protection, this subject will not be discussed during the training).

From http://theinvisiblethings.blogspot.com/
Seems the Alex mentioned previously and the Alex I was thinking of are not the same. Sorry.

xyz987
1st June 2007, 09:34
Frankly I'm amazed (after the CSS debacle) that PC drives and software players are even available - if it were not possible to play HD DVDs or BluRay disks on a PC, I doubt that movie sales would have been harmed much at all, and cracking the copy protection would be so much harder.

Soft players are available because Hollywood needs them to convert PCs in a DRMed by hardware platform (Trusted Computing and alikes).

DRM is all about market control, not about piracy. Piracy is just a false motivation, a lie. DMCA was passed on 1998 (furthermore DMCA is based on 2 WIPO treaties passed on 1996), DVD Video spec (with DRM) was approved on 1995, Napster was first released on 1999 (only for music). DRM was first, piracy was later. You can check the dates at Wikipedia.

So they need soft players because they want to control PC market.

Of course market control is useful to destroy fair use (and other purposes).

arnezami
1st June 2007, 09:57
Just to clear up usage of aacskeys: if you put only the new Processing Key in the ...Simple.txt file then it will only be capable of finding keys for new discs (MKB v3 discs). So its better to put both the old Processing Key (09F9) and the new one (455F) in the ...Simple.txt file.

In other words: the new Processing Key cannot open up old discs only new ones. So you need both to find keys for all released discs so far.

richardlee
1st June 2007, 10:55
Quick question, but as far as I know there are two processing keys floating around, but the MKB is on version 3.

Did we miss out a processing key somewhere, or did the AACS LA just skip version 2?

FTX
1st June 2007, 11:02
Do they have the right to terminate Cyberlink and Intervideo? Would they want to? The studios want to sell discs and at least for now, large file sizes, slow transfer speeds and high blank media costs limit the actual financial impact of any hidef copying. Customers will scream pretty loudly if their software suddenly turns off as the LA cuts off Cyberlink and Intervideo.

It seems that Intervideo has gone "vista only" with WinDVD 8 Platinum HD/BD (http://www.intervideo.com/nVidia/WinDVD8_3in1_landing.jsp):
System Requirements
Operating System: Microsoft® Windows Vista™ only
VGA card: NVIDIA GeForce 8500GT, GeForce 8600GT, GeForce 8600GTS only

F

aKzenT
1st June 2007, 11:19
Quick question, but as far as I know there are two processing keys floating around, but the MKB is on version 3.

Did we miss out a processing key somewhere, or did the AACS LA just skip version 2?

AFAIK there are no known HDDVDs with an MKBv2. My guess is that after they designed the MKBv2 (but before it was used) there was some critical new attack (e.g. leaking of processing key, device key, ...) which they wanted to prevent in new HDDVD releases. So they quickly designed the new one.

Also if there are in fact HDDVDs with a MKBv2, then there is a high propability that the new processing key can also be used for this MKB IMO, since they are propably very similar and share many subset differences.

arnezami
1st June 2007, 11:23
It seems that Intervideo has gone "vista only" with WinDVD 8 Platinum HD/BD (http://www.intervideo.com/nVidia/WinDVD8_3in1_landing.jsp):
System Requirements
Operating System: Microsoft® Windows Vista™ only
VGA card: NVIDIA GeForce 8500GT, GeForce 8600GT, GeForce 8600GTS only

F

Interesting. Btw: it still says XP is ok here:

http://www.intervideo.com/jsp/bdhdTool_Download.jsp

KenD00
1st June 2007, 11:45
Quite interesting that it only works on the GF8 series and even there only on the mainstream series, not the high end ones. If i remember correctly the mainstream series supports HDCP over dual-link DVI and has some extra video features, maybe also more DRM? I wonder how many they will sell...
How did you get that link? Seems not to be reachable over the main site, this even states that the HD pack will be available soon (says that for 4 months now...).

:rolleyes:

arnezami
1st June 2007, 11:54
How did you get that link? Seems not to be reachable over the main site, this even states that the HD pack will be available soon (says that for 4 months now...).

:rolleyes:

Looking at the url its possible this is for WinDVD 8 trial versions bundled with certain nVidia cards? And they get redirected here maybe? It also says "Limited time offer" at the right top of the page.

FTX
1st June 2007, 12:24
Interesting. Btw: it still says XP is ok here:

http://www.intervideo.com/jsp/bdhdTool_Download.jsp

Yes, but that is only the "advisor"

FTX
1st June 2007, 12:25
Quite interesting that it only works on the GF8 series and even there only on the mainstream series, not the high end ones. If i remember correctly the mainstream series supports HDCP over dual-link DVI and has some extra video features, maybe also more DRM? I wonder how many they will sell...
How did you get that link? Seems not to be reachable over the main site, this even states that the HD pack will be available soon (says that for 4 months now...).

:rolleyes:

Probably only on the 8600/8500 cards because only they come with the VP2 while the 8800 only has VP1

arnezami
1st June 2007, 12:31
Yes, but that is only the "advisor"

Not just the advisor. Requirements for the advisor are shown at the top of the page under "Notes".

But a little lower there are the "High-Definition Suggested System Requirements" and there it says XP too. These are the requirements for HD playback. (btw this is the page you get when clicking in the advisor itself on something that isn't ok).

FTX
1st June 2007, 12:35
Someone on AVS has bought it and apparently, it doesn't support the Xbox add-on... so much for HD-DVD playback with it.

F

SuperGoof
1st June 2007, 12:38
How did you get that link?


My guess is:

The front page has this link :

Corel Announces InterVideo® WinDVD® BD/HD-DVD Playback/Navigation Support for NVIDIA® GeForce® 8 Series GPUs (http://www.intervideo.com/jsp/Press.jsp?mode=05-31-2007)

which in turn says:

Availability, Licensing
WinDVD 8 BD/HD-DVD is available through Corel’s worldwide resellers and online at www.intervideo.com/nvidia (http://www.intervideo.com/nvidia).

And the last link redirects to

http://www.intervideo.com/nVidia/WinDVD8_3in1_landing.jsp

Galileo2000
1st June 2007, 13:20
Not just the advisor. Requirements for the advisor are shown at the top of the page under "Notes".

But a little lower there are the "High-Definition Suggested System Requirements" and there it says XP too. These are the requirements for HD playback. (btw this is the page you get when clicking in the advisor itself on something that isn't ok).

According to AVS there are problems with S/PDIF out on playback. Doesn't work with AnyDVD HD and doesn't like 360 xbox HD DVD add-on."Connected HD DVD device is not supported".
The last one is pretty bad.

Just 3 video cards supported?

They probably were so scared by AACS they only tested for the leaked keys and not much more.

Peer van Heuen
1st June 2007, 14:25
According to AVS there are problems with S/PDIF out on playback. Doesn't work with AnyDVD HD and doesn't like 360 xbox HD DVD add-on."Connected HD DVD device is not supported".
The last one is pretty bad.

Just 3 video cards supported?

They probably were so scared by AACS they only tested for the leaked keys and not much more.

I haven't looked at this too closely yet, but it appears to me, that this is just another WinDVD OEM version, that comes bundled with select NVidia cards. The fact that the link also includes an offer to buy it, is a puzzle to me though.

That it doesn't work with AnyDVD - well WinDVD didn't play unencrypted Blu-Ray discs before either, so that's no wonder (unencrypted BDMV is not in the specs anyway, we're all lucky, that PowerDVD is such a friendly software - I hope, you're all buying their stuff :) they actually deserve it).

Whether it would play HD-DVD with AnyDVD remains to be confirmed, though, if it really doesn't work with the X-Box drive, there is no way to tell at the moment...

Peer van Heuen
1st June 2007, 14:30
AFAIK there are no known HDDVDs with an MKBv2. My guess is that after they designed the MKBv2 (but before it was used) there was some critical new attack (e.g. leaking of processing key, device key, ...) which they wanted to prevent in new HDDVD releases. So they quickly designed the new one.

Also if there are in fact HDDVDs with a MKBv2, then there is a high propability that the new processing key can also be used for this MKB IMO, since they are propably very similar and share many subset differences.

The MKB version number is mainly used for synchronizing revocation lists. This applies to HRLs/DRLs.
From my understanding, the version number wouldn't have to change at all if the only news is some revoked device keys (effectively revoking a processing key if you like).

So they may just have forgotten some Host IDs on v2 (after all, the list of revoked host certificates in v3 is fairly long).

aKzenT
1st June 2007, 15:30
The MKB version number is mainly used for synchronizing revocation lists. This applies to HRLs/DRLs.
From my understanding, the version number wouldn't have to change at all if the only news is some revoked device keys (effectively revoking a processing key if you like).

So they may just have forgotten some Host IDs on v2 (after all, the list of revoked host certificates in v3 is fairly long).

Good point. However even if it was because of some new revoked device keys, it would make sense for the AACS LA to give it a new version number to distinguish the two versions internally.

Elias
1st June 2007, 19:51
What the hell is the point with cracking and releasing AACS keys if it can be updated with new keys?

KenD00
1st June 2007, 20:10
Was it my comment that they'd "be used for only a moment on small areas of the data" that you thought was wrong?
Yes.
I think the reason they might start using SKs is to break the current software and database schema here and to make it harder to find the multiple VVUKs needed for decryption. If their purpose is to hide those keys, I'd expect them to make short brief usage.
I think that too. But if these sections are only small, lets say 1 second, people might get the idea "hey, why not just skip that part, the movie is still watchable". I just wanted to show that this might not work.

However i'm not sure if they will use SKs very soon, its quite some work to encode multiple angles, especially for BluRay the authoring effort seems quite high. Even today DVDs use multi angles very rarely.

:rolleyes:

FoxDisc
1st June 2007, 21:34
if these sections are only small, lets say 1 second, people might get the idea "hey, why not just skip that part, the movie is still watchable". I just wanted to show that this might not work.

However i'm not sure if they will use SKs very soon, its quite some work to encode multiple angles, especially for BluRay the authoring effort seems quite high. Even today DVDs use multi angles very rarely.

I basically agree with your comments. The SKB system was designed as a type of watermark, not for encryption. There are up to 32 segments per title, so it could be pretty annoying to "just skip that part," particularly if they tried to do that at the critical emotional highlights of a movie, but I can see your point. All of that takes more authoring effort. I think we just have to wait and see.

mlansell
1st June 2007, 22:47
What the hell is the point with cracking and releasing AACS keys if it can be updated with new keys?

Er, so that they have to release new keys? Since they have to give 90 days notice, that means no more tha 4 updates per year.

If your real question is "why release the keys" then I guess that depends on how the system works. If it is possible to find and use a key without the AACS being able to find out which key it is, then it would be better for the "Masters of Keyfinding" to keeep their discoveries to themselves (or at least only circulated among the people writing the decrypting apps).

If simply using a key means the AACS-LA can find out which one it must be, then not releasing it serves no purpose.

Mal

greath
1st June 2007, 23:32
One thing I was wondering was, the AACS LA will need to either reverse engineer AnyDVD to find out the key it is using, or to construct a MKB with some particiular values so that they can find out which C-value the programme uses. However, if I were writing AnyDVD, I would CRC each MKB and if it's not matching an officially released MKB then do nothing. This way there would be no way for the AACS to "probe" my software. True, there would be a need to update the decrypting programme when a new MKB is released, but then there would be a need anyway as the processing key will likely have been revoked.

arnezami
1st June 2007, 23:48
One thing I was wondering was, the AACS LA will need to either reverse engineer AnyDVD to find out the key it is using, or to construct a MKB with some particiular values so that they can find out which C-value the programme uses. However, if I were writing AnyDVD, I would CRC each MKB and if it's not matching an officially released MKB then do nothing. This way there would be no way for the AACS to "probe" my software. True, there would be a need to update the decrypting programme when a new MKB is released, but then there would be a need anyway as the processing key will likely have been revoked.

This is subtle and hard to explain. But a different MKB version means that the subset difference record is different. But two MKB files with the same version (but of two different movies) are not the same: the C-values (encrypted Media Keys) are never the same (something I also mistakenly assumed back in feb, evdberg corrected me).

The point: they can create special discs on which they use the same/latest MKB version but just alter the C-values. The only thing they would have to do is to look at the decypted content (which is different according to the keys used by AnyDVD). There is no hiding here.

Regards,

arnezami

shevegen
2nd June 2007, 00:46
I think they hate us all ;)

psme
2nd June 2007, 02:51
If AnyDVD uses a VID database ONLY, then there would be nothing to trace, right? When it encounter a new disc, it can upload the encrypt table and later update the database.

regards,

Li On

bourke
2nd June 2007, 05:20
Sounds like a plan :-)

Next processing key someone finds just sit back and make an automatic VUK uploading online database :-)

If someone wants a disc that aint in there, simply have them snail mail you the disc :-)

awhitehead
2nd June 2007, 06:44
Sounds like a plan :-)

Next processing key someone finds just sit back and make an automatic VUK uploading online database :-)

If someone wants a disc that aint in there, simply have them snail mail you the disc :-)

SKBs are designed to specifically figure out which keys were comporomised in event of a black box attack. An example of such a black box would be a website, that allows a user to select and upload the MKBROM.AACS file from an HD-DVD disc, and produce a VUK.

lightshadow
2nd June 2007, 10:07
In regards to when AACS LA will revoke the second Processing Key...

Perhaps AACS LA have a deal like Apple, that they are forced to fix any attack within a fixed number of weeks?

I think Apple's period is 3 weeks. If Apple haven't fixed the attack, then Apple have to pay huge amount of cash to the record companys.

If such deal exist, then it is not enough for AACS LA to just issue now Processing Keys. They will then be forced fix the attack.

That being said, it could be, that AACS LA have been working on SK since the first attack, and this second Processing Key was just to buy some time...

aKzenT
2nd June 2007, 10:28
SKBs are designed to specifically figure out which keys were comporomised in event of a black box attack. An example of such a black box would be a website, that allows a user to select and upload the MKBROM.AACS file from an HD-DVD disc, and produce a VUK.

I don't think that is true. While SKBs are designed to prevent black box attacks, a webservice that gives you a VUK if you upload a MKBROM.AACS will never use SKBs (they are not in this file). However if they start using SKs, your webservice simply can't give you all information needed to decrypt the WHOLE movie by just looking at the MKB.

Also, if this service would accept any MKB, they could simply trace the player by trying different subset difference records.
And even if you create a hash of the Subset Difference record and only allow specific versions, they could still create a fake MKB where they use a different media key for each subset difference and see which one is used to get the VUK.

Correction: The last sentence is incorrect. While the AACS LA could do that, your webservice could easily detect that by verifying the media key with the verify media key record in the mkb. They could do the same however with multiple attacks, where some C values have the correct encrypted media key and some have not.

greath
2nd June 2007, 10:31
This is subtle and hard to explain. But a different MKB version means that the subset difference record is different. But two MKB files with the same version (but of two different movies) are not the same: the C-values (encrypted Media Keys) are never the same (something I also mistakenly assumed back in feb, evdberg corrected me).i

Yes, that would make sense. I'm new to all this clandestine activity:-) If each MKB version produced the same media key because the C-values and the processing key were identical then only a media key would be needed to unlock all discs with that MKB version and the AACS would have no clue of the processing key used and hence the device key.

BTW, I guess this means that the replicators must either get a MKB "template" from AACS and they must work out the C-values. Or, the AACS issues for each disc a MKB and gives the replicator a media key. They must have to do something for their $1,500 a disc licence fee...........

Johhn
2nd June 2007, 23:07
In regards to when AACS LA will revoke the second Processing Key...

Perhaps AACS LA have a deal like Apple, that they are forced to fix any attack within a fixed number of weeks?

I think Apple's period is 3 weeks. If Apple haven't fixed the attack, then Apple have to pay huge amount of cash to the record companys.

If such deal exist, then it is not enough for AACS LA to just issue now Processing Keys. They will then be forced fix the attack.

That being said, it could be, that AACS LA have been working on SK since the first attack, and this second Processing Key was just to buy some time...

It isn't like Apple. Apple offer a drm cloaked download service and they can deliver updates through that service at no notice. With aacs, revocation and blacklisting is by means of data carried on new disks. They therefore need players and drives to be updated before new disks are released, and so there is a notice provision in the licensing arrangement which currently entitles drive and player makers 90 days notice before new disks should appear.

That involves serving notice on the player and drive manufacturers who then have 90 days before the new disks will appear. They will need to develop the upgrades/updates etc. and have them out before the disks are released. Also, replicators should also have the information before the 90 days to allow for manufacturing and distribution lead times. In theory, disks released within the 90 day limit should not have the latest data on them, and those released afterwards should. So a situation like Matrix where a set of disks has different versions should not really have arisen. Maybe there was a blunder at the replicators, or the timetabling of the procedures does not easily handle a situation where several different disks are made over a period of time, but they are released as a set.

Also, the aacsla is not an independent enterprise selling services to the studios. It is a consortium of the studios, and I doubt if the same sort of commercial pressure exists that would apply to Apple.

In addition to changing the keys, those players were supposedly changed to make it more difficult to glean keys, and thus "fix the attack" - but it is difficult to draw inferences.

As regards the SK regime, that is primarily for tracing the source of gleaned keys and is not a layer of extra security to make key extraction significantly more difficult. It remains to be seen whether it also has that effect.

One problem the LA have is that although they can determine where the keys came from, they will not necessarily know how they were extracted. That can make decision making tricky as there is little value in blacklisting a key leaked via a software player compromise, if you don't also try and plug the compromise by which it came.

wilmac
2nd June 2007, 23:21
It isn't like Apple. Apple offer a drm cloaked download service and they can deliver updates through that service at no notice. With aacs, revocation and blacklisting is by means of data carried on new disks. They therefore need players and drives to be updated before new disks are released, and so there is a notice provision in the licensing arrangement which currently entitles drive and player makers 90 days notice before new disks should appear.

That involves serving notice on the player and drive manufacturers who then have 90 days before the new disks will appear. They will need to develop the upgrades/updates etc. and have them out before the disks are released. Also, replicators should also have the information before the 90 days to allow for manufacturing and distribution lead times. In theory, disks released within the 90 day limit should not have the latest data on them, and those released afterwards should. So a situation like Matrix where a set of disks has different versions should not really have arisen. Maybe there was a blunder at the replicators, or the timetabling of the procedures does not easily handle a situation where several different disks are made over a period of time, but they are released as a set.

Also, the aacsla is not an independent enterprise selling services to the studios. It is a consortium of the studios, and I doubt if the same sort of commercial pressure exists that would apply to Apple.

In addition to changing the keys, those players were supposedly changed to make it more difficult to glean keys, and thus "fix the attack" - but it is difficult to draw inferences.

As regards the SK regime, that is primarily for tracing the source of gleaned keys and is not a layer of extra security to make key extraction significantly more difficult. It remains to be seen whether it also has that effect.

One problem the LA have is that although they can determine where the keys came from, they will not necessarily know how they were extracted. That can make decision making tricky as there is little value in blacklisting a key leaked via a software player compromise, if you don't also try and plug the compromise by which it came.

Nice, good food for thought...

xyz987
3rd June 2007, 00:31
As regards the SK regime, that is primarily for tracing the source of gleaned keys and is not a layer of extra security to make key extraction significantly more difficult. It remains to be seen whether it also has that effect.


Yes, that's right, it is *not* an extra layer. So it is possible LA never uses SKs. There is no need for traitor tracing because all the leaked keys are published.


One problem the LA have is that although they can determine where the keys came from, they will not necessarily know how they were extracted. That can make decision making tricky as there is little value in blacklisting a key leaked via a software player compromise, if you don't also try and plug the compromise by which it came.

Far interesting. They have a traitor tracing system, but they don't have a hole tracing system.

The 90 days notice and the above, altogether, make things far difficult to LA.

awhitehead
3rd June 2007, 00:40
@aKzenT
You are correct that in order to decrypt SKBs I also need SKB.AACS and SKF.AACS. My point is that if my hypothetical Black Box server v2.0 accepts MKBROM.AACS, SKB.AACS and SKF.AACS (Last two if available/applicable), and generates a VUK, and there are more then a handful of AACS licensees, then yes, in order to fingerpoint, AACS LA will probably have to start using SKBs.

Currently the menthod of trying a bunch of MKBs works because there are only a handfull of keys out there. I can think of only Cyberlink, Nero and Intervideo as having the device keys that can use the MKB to generate a valid VUK, and Toshiba (on HD-DVD side) and 3 or 4 Blu-Ray vendors on the Blu-Ray side, that have the KCD style device keys.

If AACS takes off, and there are 30 or 50 licensees, just brute-forcing will no-longer works, esp if my hypothetical Black Box Server does something to rate-limit the number of VUKs it will generate per "customer" per day. If you need to do 30 tries to figure out which device key I use, and I tell you that you can run the test once every 3 days.... By the time you know, I will probably be on a new key.

@greath AACS MKB costs 1.5K USD, and another two hundred dollars for electronic delivery. Additionally,there is a one time cost between 3K and 10K USD upon setting up the contract. source (http://www.avsforum.com/avs-vb/showthread.php?p=10058863&&#post10058863).
You'd think that the studios are paying because they feel that they will lose more then at least 1700 USD per movie due to casual copying, etc. Guarantee to the studios about fixing something in X # of days is silly - if the disc encryption is broken, it is broken, and short of re-releasing the disc, you can't change that fact. If you are a studio that made 20K discs of "Inside Weyland-Yutani", and sold 2K copies world wide, you think that being told that "Yeah, we will give you your next MKB for the re-issuing of this title for free" would help?

("Inside Weyland-Yutani" is a made up name, I have no idea if a movie by that name exists)

Johhn
3rd June 2007, 02:53
I imagine that the sales of some movies are so low that they would have been better to master them without aacs and give them away. Well maybe it isn't that bad, but it isn't very good either.

Take a look at the following article about sales:

http://www.tvpredictions.com/whip060207.htm

Galileo2000
3rd June 2007, 04:00
I imagine that the sales of some movies are so low that they would have been better to master them without aacs and give them away. Well maybe it isn't that bad, but it isn't very good either.

Take a look at the following article about sales:

http://www.tvpredictions.com/whip060207.htm


Interestingly enough, Circuit City had Matrix Trilogy HD DVDs for $19.99.

For 3 days.

All the orders in quantity of 1 were completed.

Don't believe it was a price mistake.

Looks like more like the guerilla attack from the HD DVD camp.

People who didn't have the HD DVD players were buying and THEN getting HD DVD players.

Things are going to be interesting, but my bet BD will lose.

Anyway, we have about a hundred releases to enjoy soon.

Thanks to all.