View Full Version : MKB V4 and BD+
evdberg
4th October 2007, 11:47
The first HD disks with new protections are here and I see no activity or excitement on this forum. Are we just waiting for SlySoft to come with a solution, or do we not want to help Fengtoa ? :) Just wondering ... personally I am quite interested to figure out how BD+ works.
Doom9
4th October 2007, 12:13
What makes you so sure the discs use BD+? So far I've only seen a lot of speculation, and seeing that no current software is able to deal with the latest AACS update, we lack confirmation that a properly ripped Fox disc really is still unplayable.
SuperGoof
4th October 2007, 14:12
What makes you so sure the discs use BD+? So far I've only seen a lot of speculation, and seeing that no current software is able to deal with the latest AACS update, we lack confirmation that a properly ripped Fox disc really is still unplayable.
No. BD+ is definitely here.
Please read this post:
http://forum.slysoft.com/showthread.php?p=53719#post53719
It has a link to a .rar file for "Day After Tomorrow". Please download it and have a look at dir.txt file there. You will see that this disc has a folder called "BDSVM". You can also see what files it contains. I think "SVM" means "Secure Virtual Machine". It's indeed BD+.
FoxDisc
4th October 2007, 15:05
The AACSLA claims they have expired PDVD keys as of September 7. (They also say they have turned on "proactive renewal" automatic key expiration.)
Are there any released HD DVD disks with an MKB v4? BD+ can be implemented independently of the MKB update/revocation processing of AACS. Do we know for certain if the new BD+ disks are the new MKB v4?
gioowe
4th October 2007, 15:46
It seems they revoked some more hosts.
V3 = ===============================================
RECORD >>> Host Revocation (3.2.5.3)
===============================================
000000C 21 Record Type OK
------- -----------------------------------------------
000000D 00 00 64 Record Size OK
------- -----------------------------------------------
0000010 00 00 00 06 Total Number of Entries = 6 OK
------- -----------------------------------------------
0000014 00 00 00 06 Number of Entries in Block #1 = 6 OK
------- -----------------------------------------------
0000018 00 09 FF FF 00 00 00 0B Revocation #1 = FFFF0000000B..0014 --
------- -----------------------------------------------
0000020 00 02 FF FF 00 00 00 21 Revocation #2 = FFFF00000021..0023 --
------- -----------------------------------------------
0000028 00 03 FF FF 00 00 00 26 Revocation #3 = FFFF00000026..0029 --
------- -----------------------------------------------
0000030 00 03 FF FF 00 00 00 35 Revocation #4 = FFFF00000035..0038 --
------- -----------------------------------------------
0000038 00 02 FF FF 00 00 00 4E Revocation #5 = FFFF0000004E..0050 --
------- -----------------------------------------------
0000040 00 03 FF FF 00 00 00 54 Revocation #6 = FFFF00000054..0057 --
------- -----------------------------------------------
0000048 33 6E D8 52 52 54 10 75
0000050 4F 0D 12 21 EC 3B C4 25 C6 21 E3 B5 80 EF 60 67
0000060 3F AC EC FB AD 3B D7 0D EC 70 6B 70 C4 E8 AF 87 Signature of Block VERIFIED
------- -----------------------------------------------
V4 = ===============================================
RECORD >>> Host Revocation (3.2.5.3)
===============================================
000000C 21 Record Type OK
------- -----------------------------------------------
000000D 00 00 64 Record Size OK
------- -----------------------------------------------
0000010 00 00 00 06 Total Number of Entries = 6 OK
------- -----------------------------------------------
0000014 00 00 00 06 Number of Entries in Block #1 = 6 OK
------- -----------------------------------------------
0000018 00 09 FF FF 00 00 00 0B Revocation #1 = FFFF0000000B..0014 --
------- -----------------------------------------------
0000020 00 08 FF FF 00 00 00 21 Revocation #2 = FFFF00000021..0029 --
------- -----------------------------------------------
0000028 00 03 FF FF 00 00 00 35 Revocation #3 = FFFF00000035..0038 --
------- -----------------------------------------------
0000030 00 04 FF FF 00 00 00 4E Revocation #4 = FFFF0000004E..0052 --
------- -----------------------------------------------
0000038 00 03 FF FF 00 00 00 54 Revocation #5 = FFFF00000054..0057 --
------- -----------------------------------------------
0000040 00 03 FF FF 00 00 00 5E Revocation #6 = FFFF0000005E..0061 --
------- -----------------------------------------------
0000048 0E 96 07 86 79 CE 33 98
0000050 EC 6E 5A 0A 5E F7 E3 E1 D4 BE 50 96 3C 72 CE 1C
0000060 39 84 09 45 01 89 9F 4D 30 C0 B2 F2 70 AB 07 B7 Signature of Block VERIFIED
------- -----------------------------------------------
bcrabl
4th October 2007, 17:54
Hope somebody would find a HD DVD standalone device key. Then we could buy a little more time before they found the key (implement sequence keys I think)
mrazzido
4th October 2007, 18:28
i wonder why sonys spiderman 1 2 3 bluray has no new protection :) works fine , i try to get any BD+ disc and test then :)
greath
4th October 2007, 20:45
Strange that the new MKB has been released so quickly. When they announced that it was changed I thought that the first release with it would be Transformers. So it's a surprise to see that Fox's discs are the first to use it.
FoxDisc
4th October 2007, 21:47
Hope somebody would find a HD DVD standalone device key. Then we could buy a little more time before they found the key (implement sequence keys I think)
Without commenting on whether someone has already found each and every one of the keys in a hardware player (or not), it's not clear having those keys would be useful or that releasing them now would do any good:
1) No one has found an HD-DVD disc that uses a V4 MKB and keys from an HD DVD hardware player won't help with the BD+ issue. (I'm assuming the V4 MKB quoted above is from the referenced BD+ disc not an HD)
2) Even if someone released the keys from a stand alone HD DVD, there is still the KCD problem. KCD was intended to prevent standalone keys from being used with software players. The KCD can be read with the XBOX drive hacks, but as far as I know there's no decrypting software out yet that will let you enter the KCD.
3) PowerDVD may get cracked for the HD-DVD (or may already be cracked for all I know) before anyone gets any HD-DVD discs that need the the keys.
Thunderbolt8
4th October 2007, 21:48
fantastic four: silver surfer is also said to be BD+
Ryokurin
4th October 2007, 21:57
http://www.highdefdigest.com/news/show/1035 Fantastic Four 2 and The Day After Tomorrow seem to be the first. Samsung's BDP-1200 and LG's BH100 can't play the disks at all, errors and stutter on Samsung's BDP-1000, playable on PS3 and others but some machines are having up to two minutes of load time.
edit: checking avsforum, it seems that the only one is the day after tomorrow, where some BD+ folders can be found when looking at the disk structure. Both disks do have the two minute load time on a bunch of players however.
greath
5th October 2007, 07:11
[url]Both disks do have the two minute load time on a bunch of players however.
That's kind of Fox. It gives you time to have a toilet break before the movie starts.............
SuperGoof
5th October 2007, 09:46
checking avsforum, it seems that the only one is the day after tomorrow
No, "Fantastic Four 2" also has BD+. The same person who posted info on "Day After Tomorrow" now posted it on Fantastic Four 2. And this movie also has BDSVM folder on disc.
See http://forum.slysoft.com/showthread.php?p=54988#post54988
evdberg
5th October 2007, 09:47
1) No one has found an HD-DVD disc that uses a V4 MKB
Evan Almighty seems to have MKB V4.
SuperGoof
5th October 2007, 09:53
i wonder why sonys spiderman 1 2 3 bluray has no new protection :) works fine , i try to get any BD+ disc and test then :)
Spider-Man discs are the most weird of all. They don't have BD+, don't even have new MKB (decrypted fine with existing tools), and yet PowerDVD Ultra 3104a does not play them from disc. Only does when ripped to hard drive... I got new version from Cyberlink today, will test tonight whether they fixed this or not.
SuperGoof
5th October 2007, 09:54
Evan Almighty seems to have MKB V4.
Also "Troy", as far as I know.
greath
5th October 2007, 11:33
The KCD can be read with the XBOX drive hacks, but as far as I know there's no decrypting software out yet that will let you enter the KCD.
Can it? I thought that the way to read the KCD was "secret" and was one of the only hidden parts of the AACS specification.
FoxDisc
5th October 2007, 13:58
Can it? I thought that the way to read the KCD was "secret" and was one of the only hidden parts of the AACS specification.
The KCD is intended for use only by hardware standalone players. It's stored on each disc in a way that can't be read by a standard HD-DVD drive when the AACS authentication session is established with a software player. That means that (in theory) a player like PDVD can't use stolen hardware keys since the PDVD player can't ask the drive to give it the KCD data on the disc it would need to use the stolen hardware key.
However, the XBOX drive is unusual in that it has a hardware player built into it. It's not a standard HD-DVD drive intended only for installation in a computer. That design lets Microsoft hand off the whole player task to the drive manufacturer when the drive is in the XBOX. It also means that an XBOX does not have to go through a standard AACS software player<->disc drive authentication session (which would prohibit reading the KCD and would require that the XBOX have software player keys built into it and Microsoft comply with the same terms that other software player manufacturers do - like constant key revocation, proactive renewal, etc.).
Instead, the XBOX drive *is* a hardware player (stored in its firmware), and unlike a standard HD-DVD add-on drive it *can* read the KCD. The XBOX hack that broke the volume ID also broke the KCD. So, bottom line, yes, it can read the KCD.
edit: To be clear - the XBOX drive also functions like a standard HD-DVD drive when a software player talks to it. PDVD can't ask the drive to give it the KCD since PDVD enters into a standard AACS authenticated session with the drive.
The KCD can be used to generate the necessary keys if you have hardware player keys - it's not a hard problem - so hardware keys are useful if you have the KCD. If Slysoft obtains hardware keys, and wants to use them, their customer will need an XBOX drive, or they will need to put the KCD into their software database. Again, those aren't hard problems.
oeschmar
5th October 2007, 14:34
I think "SVM" means "Secure Virtual Machine".
Yes, secure virtual machine.
Sony has some patents on it:
http://appft1.uspto.gov/netacgi/nph-Parser?Sect1=PTO2&Sect2=HITOFF&p=1&u=%2Fnetahtml%2FPTO%2Fsearch-bool.html&r=0&f=S&l=50&TERM1=bdsvm&FIELD1=&co1=AND&TERM2=&FIELD2=&d=PG01
FoxDisc
5th October 2007, 14:54
Evan Almighty seems to have MKB V4.
Has a version of PowerDVD been released that will play it? Has Slysoft released a version of AnyDVD that will decrypt it?
evdberg
5th October 2007, 15:28
Has a version of PowerDVD been released that will play it?
I have read that PowerDVD customers can contact Cyberlink, and then they provide a download link by email.
Has Slysoft released a version of AnyDVD that will decrypt it?
Not yet, as far as I know.
SamuriHL
5th October 2007, 18:43
Has a version of PowerDVD been released that will play it? Has Slysoft released a version of AnyDVD that will decrypt it?
As evdberg said, there is a new version of PowerDVD Ultra that you can email support and ask for. Supposedly it'll be officially out next week sometime from what I've heard. AnyDVD hasn't been updated yet to handle MKB4. I haven't seen any ETA on the Slysoft forum as to when that'll be released, but, they are apparently working on it. BD+ is going to take them longer, but, they're looking into that, as well.
lightshadow
6th October 2007, 02:55
Yes, secure virtual machine.
By Virtual Machine I don't suppose it means what we relate to a VM from e.g. Java, right?
gioowe
6th October 2007, 03:22
Sure it does. A running java application within the drive's "OS" in a virtual machine.
lightshadow
6th October 2007, 03:59
Sure it does. A running java application within the drive's "OS" in a virtual machine.
I am impressed by that! I would never have thought that a drive could have that much memory and CPU power to run a VM!
If it is a Java application, would it then be possible to rip out the Java/black box, and then run it on Linux/Windows where there are great debugging tools?
SamuriHL
6th October 2007, 04:03
I am impressed by that! I would never have thought that a drive could have that much memory and CPU power to run a VM!
If it is a Java application, would it then be possible to rip out the Java/black box, and then run it on Linux/Windows where there are great debugging tools?
Don't forget that PowerDVD has to run the virtual machine code inside memory on a Windows machine, so, yes, it can probably be debugged, but, it will not be without challenge. The memory will be protected. Also, BD+ has the ability to modify both the video and audio stream on the fly. What this means is that they can add extra layers of encryption within the VM and decrypt all or individual parts of the streams. Very nasty.
lightshadow
6th October 2007, 05:17
Don't forget that PowerDVD has to run the virtual machine code inside memory on a Windows machine, so, yes, it can probably be debugged, but, it will not be without challenge. The memory will be protected. Also, BD+ has the ability to modify both the video and audio stream on the fly. What this means is that they can add extra layers of encryption within the VM and decrypt all or individual parts of the streams. Very nasty.
What about for hardware players? What kind of low cost hardware (memory and CPU vise) can handle such a complex VM?
evdberg
6th October 2007, 10:14
The VM for BD+ is small and simple, supports only 60 commands and can execute programs of 100 lines of code (see here (http://arstechnica.com/news.ars/post/20070620-blu-ray-content-protection-agency-certifies-bd.html)).
So the 20MB SVM files listed in the directories of Day After Tomorrow seem a bit too big ...
Also as far as I know the BD+ VM runs in the player, not in the drive.
SuperGoof
6th October 2007, 13:09
By Virtual Machine I don't suppose it means what we relate to a VM from e.g. Java, right?
No. According to Peer from Slysoft, BD+ is not Java at all:
http://forum.slysoft.com/showthread.php?p=44419#post44419
gioowe
6th October 2007, 13:10
Well, the MKB has a size of 1.000.000 bytes but currently only uses 12.628 bytes - the rest is filled with 00h. File size is no information.
I'm not sure where the VM is running in a Host/Drive-Environment. If it runs within the host then it'll be much easier to analyse.
lightshadow
6th October 2007, 15:42
The VM for BD+ is small and simple, supports only 60 commands and can execute programs of 100 lines of code (see here (http://arstechnica.com/news.ars/post/20070620-blu-ray-content-protection-agency-certifies-bd.html)).
So the 20MB SVM files listed in the directories of Day After Tomorrow seem a bit too big ...
People report of 2 minutes waiting time on BD+. Could that be the time it takes to do a checksum of 20MB?
Have anyone tried to zip it, just to see what kind of (random) data it contains to hide the actual code?
One positive thing about BD+ though is, that when it have been broken to pieces, people will clearly write some cool applications for the VM =) Perhaps even a debugger for hacking DRM? =)
gioowe
6th October 2007, 16:01
Perhaps someone could zip the whole disk (exclusive \BDMV\STREAM) for a first analysis.
The 2 minute startup time might only be related to BD-J and all that interactive stuff, not BD+. Or BD+ checks the firmware and 99% of 00000.svm contain checksums for each player firmware. We'll see..
evdberg
6th October 2007, 22:27
I am quite sure the BD+ code is protected by AACS, and since the MKB V4 is not broken yet we can not do much at this moment ... besides hunting for the new Processing Key.
gioowe
6th October 2007, 22:48
BD+ is surely not protected by AACS. It is protected by something but it has nothing to do with MKB V4. There's nothing new or different in V4.
woah!
7th October 2007, 00:48
I am quite sure the BD+ code is protected by AACS, and since the MKB V4 is not broken yet we can not do much at this moment ... besides hunting for the new Processing Key.
which at least means we (hd-dvd) can carry on regardless of the BD+ crap :)
Johhn
7th October 2007, 09:08
Unlikely as the contingency is, I assume that someone continues to monitor the "You Can Own an Integer Too — Get Yours Here" thread on Freedom to Tinker, and to check any numbers that turn up there.
I recall that the last processing key discovered was posted there and it was many days before anyone realised.
honai
7th October 2007, 09:53
People report of 2 minutes waiting time on BD+. Could that be the time it takes to do a checksum of 20MB?
No, it's the time needed to kick off the VM and compile the code that "protects" the disc.
Perhaps someone could zip the whole disk (exclusive \BDMV\STREAM) for a first analysis.
The code is digitally signed, and unless the folks at Slysoft find a design flaw in the actual implementation I don't think we're going to see a circumvention of BD+ anytime soon.
Sharktooth
8th October 2007, 00:39
Simple solution: dont buy movies on BD.
woah!
8th October 2007, 01:10
so now the BR standalones are not going to be quicker at loading anymore, another thing they will have to strike off the plus list... HD-DVD players were slow loading from the start as they are using a completed spec with HDi etc... BR pretty much just had to load a TS file and away it went... not so anymore it seems...
Wilbert
8th October 2007, 19:48
Unlikely as the contingency is, I assume that someone continues to monitor the "You Can Own an Integer Too — Get Yours Here" thread on Freedom to Tinker, and to check any numbers that turn up there.
Someone posted a number in that thread (on 07/10). Is that the right one?
gioowe
8th October 2007, 22:17
I get no match on a BD V4.
Ajax_Undone
9th October 2007, 05:08
I beleave the person involved with trying to crack BD+ will have realy nothing to do but try... (FAIL):eek:
All you need to do is create a Ram resident VM that keeps the BD+ VM busy by Emulating the hardware... Mean while the video is unlocked... find the key and rip at will:devil:
ps i dont know if this will...
zeroprobe
11th October 2007, 19:31
Slysoft are feeling confident.
from James
"we can unstick this thread in a 1-2 weeks or so anyway, as then there will be MKB v4 support in AnyDVD HD."
"With a little luck we will be ready for the Transformers HD DVD release on October 16.""
Wombler
12th October 2007, 08:13
Slysoft are feeling confident.
from James
"we can unstick this thread in a 1-2 weeks or so anyway, as then there will be MKB v4 support in AnyDVD HD."
"With a little luck we will be ready for the Transformers HD DVD release on October 16.""
The expertise that these guys have constantly amazes me.
Just as well they're on our side! :)
Wombler
Humpa
12th October 2007, 20:01
Slysoft are feeling confident.
from James
"we can unstick this thread in a 1-2 weeks or so anyway, as then there will be MKB v4 support in AnyDVD HD."
"With a little luck we will be ready for the Transformers HD DVD release on October 16.""Just some FYI.
James clarified that remark.
He says that they should have MKB4 support by Oct 16th, but BD+ will be more like 6 weeks.
SamuriHL
12th October 2007, 20:13
Just some FYI.
James clarified that remark.
He says that they should have MKB4 support by Oct 16th, but BD+ will be more like 6 weeks.
I hope people take these time frames for what they are. They're simply estimates. They're not hard set in stone. If it takes them longer, hopefully we won't see the usual "OMG, they said 6 weeks and it took them x!" kinds of posts. :) BD+ is probably going to be a tough nut to crack. Let's hope they can do it in 6 weeks, but, that's just a guess on their part.
bob0r
12th October 2007, 20:38
If you can crack it in 6 weeks, you can track it in 6 minutes.
He just says that to keep customers close.
You cannot give any ETA on cracking, it could be minutes or it could be years, you just never know.
All the true crackers from the passed all have retired, joined the "government" or went commercial.
Just be glad some people are still trying to "give us an open world" and support them in any way you can.
Wombler
12th October 2007, 20:45
I hope people take these time frames for what they are. They're simply estimates. They're not hard set in stone. If it takes them longer, hopefully we won't see the usual "OMG, they said 6 weeks and it took them x!" kinds of posts. :) BD+ is probably going to be a tough nut to crack. Let's hope they can do it in 6 weeks, but, that's just a guess on their part.
To be honest if they can crack it at all that will impress me.
Nobody else even seems to be remotely close to this yet.
Wombler
SamuriHL
12th October 2007, 20:50
Yea, I agree. My point was simply that when they say "6 weeks" I hope people aren't just sitting by their Blu-ray player counting down the days. bob0r is right in that cracking something like that isn't an exact science where they have a project plan and project schedule in place that says "oh, yea, 6 weeks and we'll have it done." :D it's just a guess to give them some breathing room. I think they'll eventually be able to do it. How long it'll take is a very good question.
Pulp Catalyst
13th October 2007, 01:48
it is quite strange, where are all the original crackers of AACS, i don't see any of them posting here no more, have they all retired or something?
vBulletin® v3.8.11, Copyright ©2000-2026, vBulletin Solutions Inc.