View Full Version : BD+ titles out?
oddball
20th June 2007, 21:14
Just read a rumour somewhere that BD+ titles were now out. Wondering if someone will find a way to bypass it. Just curious that is all :)
arnezami
20th June 2007, 21:30
Just read a rumour somewhere that BD+ titles were now out. Wondering if someone will find a way to bypass it. Just curious that is all :)
It'll probably take some time before BD+ protected titles will come out.
Anyway. Don't expect BD+ to be broken very fast. Not only is it a "different animal" than AACS it also has to be completely reverse engineered. This alone (eg. like building a open source decoder for a new audio format) takes a lot of time (as in: months). However this is a one time only delay. This has nothing to do with the strength of the DRM protection (if there is such a thing). In the end BD+ uses keys and software using those keys. If you can play BD+ discs you will have both (in memory)...
What we need is specs. If you get your hands on (parts of them) you know who to contact ;).
And always keep in mind: as long as BD+ has not been opened, don't buy the discs. Really. And more importantly tell others why not to buy them: their fair-use rights will be taken from them.
Regards,
arnezami
The General
20th June 2007, 21:58
I found a PDF with some info on BD+ ... It's probably not enough information to do anything with, but it's a start.
http://www.blu-raydisc.com/assets/downloadablefile/5th_japan_05-13343.pdf
Johhn
20th June 2007, 22:10
The actual "announcement" appears on the following page:
http://www.bdplusllc.com/
If that is the current state of play, then it will be some time before the disks reach store shelves.
But an amusing thought arises as to whether the players/drives are already BD+ enabled, or whether they will need upgrading. Either way, it might be possible for someone to make at least some progress with a player/drive, before they get the disks.
I imagine that the day following that on which the disks do reach stores, there will be a flood of hits on Freedom to Tinker, where people are looking for cryptic messages.
col_oddball
21st June 2007, 00:17
It amazing how much trouble they are going to, to stop you from watching the HD stuff. They should just display a HifDef Black screen and make done with it....
casket
22nd June 2007, 13:22
My understanding of BD+ is that there is some kind of Virtual Machine that runs a "Fix Function"... ie a second layer of encryption ontop of the AACS. ("The General"'s link above is good).
Theoretically, if you decode the movie on HD-DVD... then you already know what the bits of th final message/movie should look like. Comparing 1 Gig of differences(HD vs. Blue-Ray) I would think that a pattern may emerge.
*********
This is speculation though... what we really need is the specs.
Peer van Heuen
22nd June 2007, 13:29
Theoretically, if you decode the movie on HD-DVD... then you already know what the bits of th final message/movie should look like. Comparing 1 Gig of differences(HD vs. Blue-Ray) I would think that a pattern may emerge.
This would simply be a "known plaintext attack" - I'd expect the second layer of encryption to be AES as well, so you will not see a pattern of any kind there...
But, hey, you all stay calm, we're gonna get there... :)
bcrabl
22nd June 2007, 13:52
Is the BD+ a layer before OR after aacs? Meaning has anybody figured out what is the sequence of events that lead to decryption?
casket
22nd June 2007, 16:14
On page 18 of the general's link... the picture seems to show that it is "before". (ie. 1. Encrypt Video with BD+ 2. Encrypt Video with AACS)
On the reverse side:
AACS Decrypt is performed... and then BD+ Decrypt is performed.
zeroprobe
22nd June 2007, 17:36
Not liking the sound of BD+ . As Blu-ray becomes more mainstream it's going to be the Number 1 thing to hack.
Electrox3d
22nd June 2007, 17:44
The *sound* of BD+ may not be enticing to the end user, but thats only because the end user is trying to copy or rip the movie - lol.
Think of how proud they are that they've developed a second level of encryption and lets just see how fast it gets taken down. I mean, AACS is pretty much automatically removed with some software out there. It seems easier to copy BD with AACS than some newer DVD's.
Sure it took a while, but it was fun for some to figure out, and fun for some to test it, but this is just another level of fun.
xyz987
23rd June 2007, 00:45
I found a PDF with some info on BD+ ... It's probably not enough information to do anything with, but it's a start.
http://www.blu-raydisc.com/assets/downloadablefile/5th_japan_05-13343.pdf
Thanks for the link
Several thoughts:
1- 100 lines of code and 60 instructions. Not hard to emulate.
2- BD+ VM runs in parallel while AACS soft is decrypting, so a buffer overflow of the VM can be used to get the AACS DK/PK (or SKs) from the standalone.
3- "BD+ includes the ability to load native code (code that runs directly on the player’s host process)". This is ideal for standalone hacking 8-)
BD+ is a Bad Idea for them. Will they really use it?
Zotty
23rd June 2007, 13:53
Thanks for the link
Several thoughts:
1- 100 lines of code and 60 instructions. Not hard to emulate.
2- BD+ VM runs in parallel while AACS soft is decrypting, so a buffer overflow of the VM can be used to get the AACS DK/PK (or SKs) from the standalone.
3- "BD+ includes the ability to load native code (code that runs directly on the player’s host process)". This is ideal for standalone hacking 8-)
BD+ is a Bad Idea for them. Will they really use it?
There's only one way to find out what the possibilities are :devil:
As far as I know Fox had been waiting for this. So for the moment I'm assuming BD+ will actually hit the streets soon. Keeping my fingers crossed this will explode right in their faces!
Btw, read it was developed by the peepz at Cryptography Research (http://www.cryptography.com/technology/spdc/bluray.html). Also read their lead developer apparently stated they we're forced to push the release date forward. And pushed technology could possibly leave more holes to exploit... which is good for us.
Peer van Heuen
24th June 2007, 20:37
Thanks for the link
Several thoughts:
1- 100 lines of code and 60 instructions. Not hard to emulate.
2- BD+ VM runs in parallel while AACS soft is decrypting, so a buffer overflow of the VM can be used to get the AACS DK/PK (or SKs) from the standalone.
3- "BD+ includes the ability to load native code (code that runs directly on the player’s host process)". This is ideal for standalone hacking 8-)
BD+ is a Bad Idea for them. Will they really use it?
I doubt, that BD+ VM-code / native code will be allowed to run from non-encrypted discs. That code will surely be signed - so it should be quite impossible to make "unauthorized discs" holding that kind of trojan code.
It is a lot easier for us to remove AACS encryption entirely from a disc than to add it ;)
xyz987
25th June 2007, 09:57
I doubt, that BD+ VM-code / native code will be allowed to run from non-encrypted discs. That code will surely be signed - so it should be quite impossible to make "unauthorized discs" holding that kind of trojan code.
Yeah, will surely be signed, but it is possible to run Linux on Xbox (sans modchip) if you have an original MechAssault disk. This game has a bug and its savegames can be used to run arbitrary code on unmodified Xbox.
It is not improbable a moviemaker releases a BD+ disk with a similar bug.
Edit: to clarify:
On a PC you can cause a buffer overflow if a *legitime* app has a bug, and you feed this app with corrupted data. Also you can cause a buffer overflow if a *legitime* OS has a bug, and you feed a function of this OS with corrupted data.
VM (on player) is like OS
BD+ disk specific DRM routine is an app
Encrypted movie is the data and it is possible to corrupt it because the encrypted movie is not signed AFAIK.
bob0r
25th June 2007, 11:29
New Content Protection System Ready for Blu-ray Disc
http://www.dailytech.com/article.aspx?newsid=7777
Peer van Heuen
25th June 2007, 14:59
Encrypted movie is the data and it is possible to corrupt it because the encrypted movie is not signed AFAIK.
The Content Hash Table ensures that the video data remains untouched, so the encrypted movie is in fact indirectly signed.
But the specs do leave a little room there: the tail of up to 95 sectors will not be hashed.
Also, a player is not required to check the whole movie against the hash values, but only 1% (if I recall correctly) is expected to be verified.
xyz987
26th June 2007, 13:09
Also, a player is not required to check the whole movie against the hash values, but only 1% (if I recall correctly) is expected to be verified.
This is virtually 0% ;-)
Any attacker can pick randomly a little portion of the movie to corrupt it, and the probability this portion is not checked is 99%.
Peer van Heuen
26th June 2007, 15:33
This is virtually 0% ;-)
Any attacker can pick randomly a little portion of the movie to corrupt it, and the probability this portion is not checked is 99%.
Note, that 1% is merely a minimum requirement.
A Player is allowed to check all of it. And of course it is a lot easier to implement a check routine, that scans each and every sector instead of going into the trouble of implementing an algorithm that picks 1% randomly...
So it's not really unlikely that all of it is checked. Depends on whether the programmers don't mind wasting CPU power ;)
dmz01
26th June 2007, 16:09
I don't quite understand. If the entire movie is hashed, how can a player check only part of it? Are there multiple hashes depending on the portion of the movie that the player is willing to check? Also checking the hash of an entire movie is very time consuming. I doubt very much that the entire ~20GB movie is read off of a disk to check a hash, since that would take 30 minutes or so (at 4x read speed) and who's willing to wait that long before watching it...
KenD00
26th June 2007, 18:52
The movie is not hashed in one piece but every single EVOBU (don't know how long one is, at most a couple of seconds) is, so the hashes are checked on the fly while the movie is played back.
:rolleyes:
Peer van Heuen
26th June 2007, 22:45
I don't quite understand. If the entire movie is hashed, how can a player check only part of it? Are there multiple hashes depending on the portion of the movie that the player is willing to check? Also checking the hash of an entire movie is very time consuming. I doubt very much that the entire ~20GB movie is read off of a disk to check a hash, since that would take 30 minutes or so (at 4x read speed) and who's willing to wait that long before watching it...
The movie is hashed in 96-sector-blocks (-> many hash values) and the checking is done while playback. Compared to decoding video and sound it's not much extra load.
xyz987
26th June 2007, 23:12
So it's not really unlikely that all of it is checked. Depends on whether the programmers don't mind wasting CPU power ;)
I agree, but the tail is unhashed, isn't it?
This is a bit strange. All the movie is hashed, but the tail is not.
Peer van Heuen
27th June 2007, 08:12
I agree, but the tail is unhashed, isn't it?
This is a bit strange. All the movie is hashed, but the tail is not.
Yes, well, the specs say, the movie is divided into blocks of 96 sectors and a hash is calculated over each of those.
I guess they were just too lazy to specify how to handle the remainder, which usually is less than 96 sectors.
Or they saw trouble coming, that if they did a player would have to tell between interrupted playback and streams that end before a 96 sector block has finished. That does make some sense, I think.
Whatever, I wouldn't give a buffer overrun attack much of a chance, because that requires so much knowledge about the code that is running on the host, that you should already have retrieved the keys by examining it anyway ;)
stars
9th July 2007, 14:21
Hi.. I think we have an intresting siuation here..
The movie industri see a chance to win the movie market back, by enforcing new and more advanced encryption on there comsumer products...
The question do we really need HD TV ??? or do the movie industry need it....
Since the DVD format is totally hacked the movie industry looks to the HD format and sadely the consumer suffer, by paying more for unfinished hightec stuff...
I have been into sat tv decryption for many years and the
way BD+ is encrypted looks very similar...
The only difference is that you dont need a smartcard for the decryption.
Is the decoding software built into the BlueRay player or is it
loaded into some type of memory in the BlueRay player...??
It should be a big weakness if the decryption or hash tables
are stored into a memory or transfered from the disc.
In the sat world are the software stored in the smartcard and
a smartcard can be hacked if you have the enought money and right equipment... The only reason why there are a few hacked smartcards is that the market for hacked smartcards are limited to geografical areas...
A hacked firmaware for BD+ decryption or a simulated software would have the world as a market..the hacker would get his invested money back...
So i think its only a matter of time before we will see something happen....
But mean while we are having fun trying to understand the the encryption system....
stars....
vBulletin® v3.8.11, Copyright ©2000-2026, vBulletin Solutions Inc.