Log in

View Full Version : New Processing Key found!! (MKB v3 is now open)


Pages : 1 2 [3]

Galileo2000
3rd June 2007, 04:07
BtCB made it clear where it came from. He used Ed Felten's automatic key assignment proggie on that web page. Wow! It's amazing that he happened to be assigned a valid PK! I wonder what the chances are that it will happen again..... say shortly after the next revocation.:)

@FoxDisc:
I love this post. I love Ed Felten's automatic key assignment on the web page.

Now it is clear how the key was obtained.

Chances are high the key will be obtained again pretty soon using the same assignment.

Hyp-X
3rd June 2007, 10:09
If AACS takes off, and there are 30 or 50 licensees, just brute-forcing will no-longer works, esp if my hypothetical Black Box Server does something to rate-limit the number of VUKs it will generate per "customer" per day. If you need to do 30 tries to figure out which device key I use, and I tell you that you can run the test once every 3 days.... By the time you know, I will probably be on a new key.

Not really. Finding the key used out of 30 possible takes 5 tries using divide and conquer.
Also finding the key of Black Box Server is not harder for them than finding which key is used in AnyDVD.
(And rate limiting doesn't necessarily work if one uses a different machine with a different IP for each query.)

arnezami
10th June 2007, 12:18
@Boing99 and @FoxDisc: please log on and read your pms. :)

blutach
11th June 2007, 04:07
If he wanted to do that Gilileo2000, he woulda posted it instead of using PMs. The "P" in PM stands for private.

Regards

Galileo2000
11th June 2007, 04:17
If he wanted to do that Gilileo2000, he woulda posted it instead of using PMs. The "P" in PM stands for private.

Regards

OK.


Deleted.

"Gilileo2000" is not my user name.

Regards.

blutach
11th June 2007, 14:43
My apologies for the typo.

Regards

arnezami
17th June 2007, 21:18
Does anybody else find that the AACS LA is a little silent lately?

No response to any of the new events since May 7th. ;)

Galileo2000
18th June 2007, 02:36
Does anybody else find that the AACS LA is a little silent lately?

No response to any of the new events since May 7th. ;)
They are silent, mostly thanks to you and Ed Felten's method of discovering the keys:D

They are facing a big dilemma along with their customers I think.

They can try full-strength and tremendously increase the manufacturing costs for the formats that are not mature yet and haven't been established into the mainstream.

This way they will cut on profits and might just kill both formats.

And yet they have no guarantee it will be bullet-proof 100%.

Or they can do nothing. And see what happens to the sales figures.

I know I won't be buying their "newly protected" stuff. (unless we need it for testing :D).

Just think about the following picture for a second:

- I don't use AnyDVD and don't decrypt the disc.

- I just put my purchased Matrix HD DVD into my purchased Xbox HD DVD to play on my carefully assembled HTPC ( and the video card is HDCP-compliant btw ). PowerDVD flashes nice bitmap which says something about 5 years in federal prison and then puts a dialog saying it cannot play because my driver (the latest ATI driver) is not good enough.

I have no HD DVD or Blu Ray STB boxes.

If I have no tools at my disposal to play HD DVDs I bought, I will return them for the full refund and will never buy them again.

They should thank people for opening the gate.

They got their money.

We got our HD DVD playback and spent money they got.

Johhn
18th June 2007, 10:44
Does anybody else find that the AACS LA is a little silent lately?

No response to any of the new events since May 7th. ;)

Maybe they are waiting until software players have to be "updated" again, and then the press releases on their site dated January 24th 2007, February 15th 2007, and April 16th 2007, will, in true Hollywood fashion, be re-released.

bourke
19th June 2007, 01:21
Sounds plausible - it will probably give them an extra week's worth of security by not telling us when the new keys are due to come out!

That way we wont be able to have a day-0 (or day -1) attack ready ;-)

jojo4u
26th July 2007, 11:15
Probably only on the 8600/8500 cards because only they come with the VP2 while the 8800 only has VP1

Source: german printed magazine C't 15/07 page 136.
Yes, nvidia is supposed to encrypt the data over the PCIe bus (AES 128 bit engine). This probably only works for VP2. The author speculated wether ATI does not encrypt since the CPU load with encryption is lower. Also nvidia only considers Vista and PCIe for security reasons.

noclip
30th July 2007, 04:23
I seem to recall some research that looked into the feasibility of obtaining the LA root certificate using some heavyweight cryptanalysis (and 10^7 revoked keys). Is this being looked into? I'm doubtful it's possible, but I imagine it would be be checkmate for the LA if we got our hands on it.

abcx
30th July 2007, 06:14
I seem to recall some research that looked into the feasibility of obtaining the LA root certificate using some heavyweight cryptanalysis (and 10^7 revoked keys). Is this being looked into? I'm doubtful it's possible, but I imagine it would be be checkmate for the LA if we got our hands on it.10^7 revoked keys?! Where would we get that?