Log in

View Full Version : Does anyone know when AACS will be cracked?


nightcity
25th February 2008, 18:23
I need to backup DB movies to harddisk, but anydvd hd is so expensive, can anyone tell me or just guess when the hacker can crack the AACS and BD+?

I thought some hackers are much more powerful than the engineers working in companies like slysoft, why this time they can do nothing? To find the keys from powerdvd is so difficult?

Dark Shikari
25th February 2008, 18:38
AACS is already cracked...

bcrabl
25th February 2008, 18:46
AACS is far from being hacked. Controrary a BD+ hack can theoretically be a total hack by using a fully reverse engineered VM.

Dark Shikari
25th February 2008, 18:49
AACS is far from being hacked. Controrary a BD+ hack can theoretically be a total hack by using a fully reverse engineered VM.I'm pretty sure that BD+ isn't part of AACS, given that HD DVD didn't support it, despite its support of AACS.

And I'm pretty sure that AACS is cracked, in some form or another, given the huge number of decrypted HD movies on my local torrent site ;)

setarip_old
25th February 2008, 18:53
@nightcity

Hi!but anydvd hd is so expensiveBut you apparently have already purchased AnyDVD HD, so why don't you use it?

http://forum.doom9.org/showpost.php?p=1077605&postcount=4

Guest
25th February 2008, 18:55
His trial period ran out. :)

Zotty
25th February 2008, 20:30
AACS isn't cracked publicly. Slysoft has cracked AACS in a commercial and windows only product, but that's it. Wouldn't call that cracked from a doom9 and other OS point of view.

KenD00
26th February 2008, 00:17
AACS is renewable, unless someone finds the holy grail which allows us to generate our own keys to decrypt the mkb / skb there will be always the hunt for the recent keys. And thats what SlySoft did, they found the current key while others haven't. Well, maybe they have but they won't give it away for free ;).

:rolleyes:

nightcity
26th February 2008, 04:26
AACS is renewable, unless someone finds the holy grail which allows us to generate our own keys to decrypt the mkb / skb there will be always the hunt for the recent keys. And thats what SlySoft did, they found the current key while others haven't. Well, maybe they have but they won't give it away for free ;).

:rolleyes:

KenD00, I understand what you mean, but I want to know when you hacker can finish the work like anydvd? Is it possible? or can you estimate how long it will take?

Doom9
26th February 2008, 06:45
Here's an idea: instead of clamoring for others to do the work for you.. get busy yourself. If you are too cheap to buy AnyDVD HD then at least you could volunteer your time.

FoxDisc
26th February 2008, 20:20
KenD00, I understand what you mean, but I want to know when you hacker can finish the work like anydvd? Is it possible? or can you estimate how long it will take?

AACS is not cracked - it's easily renewable.

BD+ is not part of AACS.

AACS and BD+ are part of the BluRay spec. AACS is part of the HD-DVD spec.

AnyDVD has obtained the latest AACS decryption keys. Those keys are not public at this point and both AnyDVD and the player software PowerDVD have gone to a lot of effort to hide them. As far as I can tell, there is not a lot of non-commercial hacker effort going on towards getting the newest keys, but you never know who's doing what on their own. It's certainly possible for hackers to get the latest keys - AnyDVD has them.

Shinigami-Sama
26th February 2008, 21:18
until someone gets the keys above processing we're pretty much screwed
anydvd from what we can tell has this version's processing key

BD+ can be half beaten, we can get it off the disc, and in theory we might be able to get it to play on standalones
but thats about all we can do with it

kcynice
27th February 2008, 09:41
I know AnyDVD,and i want to know how it resolve the decryption,too. There are two drivers anydvd installed.It seems that it hides some information or operation by this way.btw,such method have some effect to anti-debug.
As FoxDisc said,slysoft perhaps have the lastest keys. In another way,slysoft could create its own compatible protocol for blu-ray device driver,if so,anydvd could cheat the blu-ray drives consider it as legitimate drives.
But I also not sure.

linx05
27th February 2008, 14:12
...

In another way,slysoft could create its own compatible protocol for blu-ray device driver,if so,anydvd could cheat the blu-ray drives consider it as legitimate drives.
But I also not sure.
That is how I've always thought one would get rid of protection.

bcrabl
27th February 2008, 15:22
Just a reminder. AnyDVD has gone Oracle meaning no processing ore device key is in the software. They are on their servers.

What can be found are the volume unique keys that are storred in the AnyDVDs database.

So no more talks.

Here's an idea: instead of clamoring for others to do the work for you.. get busy yourself. If you are too cheap to buy AnyDVD HD then at least you could volunteer your time.

kcynice
27th February 2008, 15:41
I think,that only could be a guess. if so,i have no idea how slysoft does this work in AnyDVD.But AnyDVD resolve it perfectly.I also have tried by the tools shared by arnezami but faild.For example aacskeys said my media key was revoked.
The tools had been post more than one year before,but there is no effective method which can work well for any blu-ray drive,perhaps anydvd can. anydvd can decrypted all the blu-ray discs of mine.it seems that it can decrypt all the blu-ray discs in market.
I hope someone,would be glad to explore how slysoft resolve such work,but also for AACS.

I deeply believe that the most people update the world history!

Regards.

bcrabl
27th February 2008, 15:53
I think,that only could be a guess. if so,i have no idea how slysoft does this work in AnyDVD.But AnyDVD resolve it perfectly.I also have tried by the tools shared by arnezami but faild.For example aacskeys said my media key was revoked.
The tools had been post more than one year before,but there is no effective method which can work well for any blu-ray drive,perhaps anydvd can. anydvd can decrypted all the blu-ray discs of mine.it seems that it can decrypt all the blu-ray discs in market.
I hope someone,would be glad to explore how slysoft resolve such work,but also for AACS.

I deeply believe that the most people update the world history!

Regards.

What I've said is not speculation. Peer and James (developers of AnyDVD have confirmed them countless times).

Guest
27th February 2008, 15:59
AnyDVD has gone Oracle Please explain what that means for those of us that don't know the jargon. Thank you.

bcrabl
27th February 2008, 16:05
That means that the MKB files are uploaded to a slysoft server. There in combination with the Volume ID, the volume unique keys are derived. These are the nessesary keys for the decryption of the AES-128 encrypted .evo or .mts files on the disks.

KenD00
27th February 2008, 16:14
In another way,slysoft could create its own compatible protocol for blu-ray device driver,if so,anydvd could cheat the blu-ray drives consider it as legitimate drives.
But I also not sure.

For that reason the Drive Revokation List exists. To be a "legitimate" (aacs enabled) drive you need a Drive Certificate which can be revoked like everything else that is needed to decrypt a disc. Maybe its time for an AACS for dummies sticky, always the same ideas, always the same reasons why they don't work...

:rolleyes:

Shinigami-Sama
27th February 2008, 21:50
Please explain what that means for those of us that don't know the jargon. Thank you.

you(anydvd) ask them, and they(slysoft servers) send down the key
AFAIK they gather up lots of titles and save their VUKs and package them up as updates to the end users

kcynice
28th February 2008, 00:40
if it's true(the MKB would be uploaded to slysoft's server[s]),but how about one pc has no internet?
It seems that anydvd needn't to get any key from slysoft's server(s),if so,anydvd can't complete the work so fast.
In another hand,when slysoft find a new disc with different MKB,it would have to update it's key-data.

talon95
28th February 2008, 00:55
if it's true(the MKB would be uploaded to slysoft's server[s]),but how about one pc has no internet?
It seems that anydvd needn't to get any key from slysoft's server(s),if so,anydvd can't complete the work so fast.
In another hand,when slysoft find a new disc with different MKB,it would have to update it's key-data.

I think Anydvd contains the keys for disks that have already been encountered. It just has to go out to the server when a new disk is encountered (that it doesn't have a key for). So, if you have no internet connection, you just have to wait for the next Anydvd update.

kcynice
28th February 2008, 02:04
perhaps. I tried for a new disc using anydvd. The content really can't be play correctly.AnyDVD tole me I had to update it to a new version.Then,I updated it,and the player playback the disc well soon.

kcynice
28th February 2008, 02:08
I think Anydvd contains the keys for disks that have already been encountered. It just has to go out to the server when a new disk is encountered (that it doesn't have a key for). So, if you have no internet connection, you just have to wait for the next Anydvd update.

I will compare all the files(including drivers installed by anydvd) to see the difference.Perhaps it would give me some information.

Wombler
28th February 2008, 09:52
I think Anydvd contains the keys for disks that have already been encountered. It just has to go out to the server when a new disk is encountered (that it doesn't have a key for). So, if you have no internet connection, you just have to wait for the next Anydvd update.

Yes I believe that's exactly how it operates.


Wombler

kcynice
28th February 2008, 13:12
Yes I believe that's exactly how it operates.

perhaps. but i am puzzled about what its driver(AnyDVD.sys) does.

nightcity
29th February 2008, 05:40
It seems that anydvd has VUKs of all the blu ray movies. But where does the VUKs come from?

They have got devices or new version processing key?

Or they just process all the blu ray movies and get every VUK from them?

I think to find VUK is easies than getting devices or processing key, right? I'm a freshman in this topic, so if i make mistakes, don't laugh at me.

nightcity
29th February 2008, 06:04
Another question, if hackers find device keys or processing key, and they just release VUKs, how does aacs know which devices should be revoked? They just guess the key is from some software player and do some revoke work, right? But if hacker can get devices keys from any hardware, the device keys will not be revoked, since aacs don't know which hardware is the leak source, what can they do?

KenD00
29th February 2008, 06:49
They have got devices or new version processing key?
They have, you can't calculate a VUK without these.


I think to find VUK is easies than getting devices or processing key, right?
I don't think so. In the beginning days software players were not much secure and because of that it was "easy" to find the VUKs, but security was improved, now everything is well encrypted.

Another question, if hackers find device keys or processing key, and they just release VUKs, how does aacs know which devices should be revoked?
They can't. But AACS has introduced proactive renewals, every couple of months they enforce new keys (currently only for software players).

But if hacker can get devices keys from any hardware, the device keys will not be revoked, since aacs don't know which hardware is the leak source, what can they do?
Not sure if i understand you correctly, do you mean they have different sets of device keys from different hardware? They can start using Sequence Key Blocks and try to identify them... or revoke all keys and enfore updates for every single player ;). Or do you mean to combine device keys from different sets? For this to work you need a huge number of devices to fully hide their identities.

:rolleyes:

FoxDisc
29th February 2008, 15:08
AACS has introduced proactive renewals, every couple of months they enforce new keys (currently only for software players).

One problem that AACS has with the proactive renewal scheme for software players is that once a bad guy has figured out how to get keys from a specific version of software player, he's most of the way towards finding the next set of proactively renewed keys. They're hidden the same way and he can find them the same way. To prevent this, the new set of keys have to be hidden or encrypted using a new method. It's easy to change the keys - it's much harder to find a new way to hide them, and it's even harder if you aren't sure which software player was compromised and all the software companies have to change their encryption scheme every time.

If one software player company has a great encryption scheme, when they change, they might make it weaker. I suspect this is an additional reason AnyDVD went to the oracle method - to help hide which player was attacked.

BTW, I'd love to see you write up an AACS and BD+ for Dummies thread. Even a brief summary of the current state of HD decryption with comments on BD+ and AnyDVD's oracle method would be a welcome addition to the tail end of the Understanding AACS thread or serve as a good start for another sticky.

mikeathome
29th February 2008, 20:32
Just a site note (no intent to hijack the thread):

I think it'll be hard to ever get a reliable solution. ASA SK's are introduced the amount of effort a regular mike will have invest to make a single copy will not justify it and will make it worthless. The technical challenge you'll be facing and the required hardware will be overwhelming. I see hardware coming which just grabs the HDCP output of a HDMI and captures that. This IS possible. Spatz had a device which was removed from there product portfolio a while ago. The Chinese will take this idea when there's a payout. See the LC SAT receivers floating the market.

There's ONE really good thing about all this AACS, BD+, shit:
If nobody will be able to rip the HD content anymore and put it on P2P who will be blamed for declining BD sales? Will we see higher quality then at fair value to attract consumers?

I leave the question open for you guys to answer, as I have my own opinion about a likely scenario. Maybe a few CEOs need new jobs in near future.

mike

bcrabl
29th February 2008, 20:33
Foxdisk, do we have any public info about what parts of the mts files are "encrypted" with BD+? Obviously only a part of the file is encrypted and maybe the reason is that the vmware would be unable to do full decryption on the fly? Have they invested so much in security by obscurity?

Another question, do you know where the Xbox360 has its device keys and if each xbox has the same or different keys? Furtheremore does the Xbox360 drive read the KCD when plugged into the xbox instead of the PC?

Finally do we know if every Blu-ray drive has different drive keys or not and if they are in a flashable area of the firmware?

FoxDisc
29th February 2008, 22:19
Foxdisk, ....?

You asked a bunch of excellent questions. I'd love to have definitive answers for each. I've spent a lot of time looking at AACS and HD-DVD, but not much looking at Blu-ray and BD+, so I've got no answers there.

As to the XBox - I hesitate to say much. None of this was my work, so I'm not the one who should decide to release it. Given the market shift to Blu-ray I'd encourage the release of most of the information, but it's not my call.

Peer van Heuen
29th February 2008, 22:48
perhaps. but i am puzzled about what its driver(AnyDVD.sys) does.

Have you ever wondered, how AnyDVD makes an encrypted HD-DVD/Bluray (od CSS encrypted DVD with protection) actually look like a completely unprotected disc to Windows? (so you can actually copy it using xcopy, if you feel like it, instead of requiring a ripping tool)? ;-)

No big secret behind that driver, really.

Peer van Heuen
29th February 2008, 22:52
Foxdisk, do we have any public info about what parts of the mts files are "encrypted" with BD+? Obviously only a part of the file is encrypted and maybe the reason is that the vmware would be unable to do full decryption on the fly? Have they invested so much in security by obscurity?

Only itsy bits of video are scrambled (not necessarily encrypted). Just enough to make the protected video totally unwatchable.

The BD+ VM replaces those parts with valid ones - and also has the potential ability to use "variants" as a watermark (similar to sequence keys with AACS).

bcrabl
29th February 2008, 23:12
Only itsy bits of video are scrambled (not necessarily encrypted). Just enough to make the protected video totally unwatchable.

The BD+ VM replaces those parts with valid ones - and also has the potential ability to use "variants" as a watermark (similar to sequence keys with AACS).

Damn this protection sceme costs some gazillion dollars.
:stupid:

Sharktooth
1st March 2008, 01:18
... and the customers pay ... for something they dont want...
another reason HD-DVDs are (or better: were) cheaper than BDs...
i really hope some crazy heads will crack BD+ to the bone and fast, so those mobs will pay for what they're doing...

LoRd_MuldeR
1st March 2008, 02:20
i really hope some crazy heads will crack BD+ to the bone and fast, so those mobs will pay for what they're doing...I totally agree, but I'm less confident that BD+ will be cracked (permanently) very soon. Same applies to AACS. My biggest hope is that BlueRay will get massive pressure from Video-on-Demand services and will finally have to drop some of their customer-offensive restrictions in order to survive. Major online music stores starting to sell "unprotected" MP3 files (at acceptable bitrates) after years of DRM-infected crap is one step to the right direction. Maybe we will see a similar move in the video sector some day...

Shinigami-Sama
1st March 2008, 03:19
I totally agree, but I'm less confident that BD+ will be cracked (permanently) very soon. Same applies to AACS. My biggest hope is that BlueRay will get massive pressure from Video-on-Demand services and will finally have to drop some of their customer-offensive restrictions in order to survive. Major online music stores starting to sell "unprotected" MP3 files (at acceptable bitrates) after years of DRM-infected crap is one step to the right direction. Maybe we will see a similar move in the video sector some day...

either that or we get some hot head electrical engineers to crack HDMI
just cut out all the BS with aacs/bd+ totally
and unlock a lot of consumer sat receivers as well

bshep
2nd March 2008, 17:27
On breaking HDCP:
http://www.freedom-to-tinker.com/?p=1005

From reading the article, you can break HDCP if you get 40 secret vectors, either by probing devices or buying licenses, once that is done HDCP is broken for good since you can create your own secret vectors just like the LA.

BTW the article is pretty old so its likely that this has been done already.

EDIT: I also found this article: http://cryptome.org/hdcp-4attacks.htm

Ajax_Undone
3rd March 2008, 03:06
I think an rebuilt firmware with hacked driver could give access to all the keys you could ever want... And might be the solution for BD+ for complete removal...


And if that dosent work then don"t buy BD+ Shows yeah it might kill you but it would force them to either drop BD+...

They can't sell what you don't buy...

kcynice
3rd March 2008, 07:45
Have you ever wondered, how AnyDVD makes an encrypted HD-DVD/Bluray (od CSS encrypted DVD with protection) actually look like a completely unprotected disc to Windows? (so you can actually copy it using xcopy, if you feel like it, instead of requiring a ripping tool)? ;-)

No big secret behind that driver, really.

Perhaps, but it's strange that the driver file is so large!(up to 88KB). And the new version is almost 1 KB bigger than the old version!

Peer van Heuen
3rd March 2008, 08:55
Perhaps, but it's strange that the driver file is so large!(up to 88KB). And the new version is almost 1 KB bigger than the old version!

If you really think that a 88kB driver that handles decryption and deprotection of 3 totally different systems (DVD, HD-DVD and Bluray) is large, then start thinking about certain mouse (!) drivers that come with installers of up to 15 MB.

Now that you mention it and knowing what kind of algorithms, decryption tables, lookup tables, ... are packed into this driver, it makes me pretty proud that it is so tiny. :)

Wombler
3rd March 2008, 09:46
If you really think that a 88kB driver that handles decryption and deprotection of 3 totally different systems (DVD, HD-DVD and Bluray) is large, then start thinking about certain mouse (!) drivers that come with installers of up to 15 MB.

Now that you mention it and knowing what kind of algorithms, decryption tables, lookup tables, ... are packed into this driver, it makes me pretty proud that it is so tiny. :)

Actually I've always thought that was an exceptional piece of programming.

Not only have you managed to do the job better than anyone else from a functionality point of view but the efficiency of the coding is second to none.

Takes me back to my early programming days on the Sinclair ZX81 where coding efficiency was paramount. :)

Getting all that down to 88kB is a phenomenal programming feat. :cool:


Wombler

kcynice
3rd March 2008, 10:30
If you really think that a 88kB driver that handles decryption and deprotection of 3 totally different systems (DVD, HD-DVD and Bluray) is large, then start thinking about certain mouse (!) drivers that come with installers of up to 15 MB.

Now that you mention it and knowing what kind of algorithms, decryption tables, lookup tables, ... are packed into this driver, it makes me pretty proud that it is so tiny. :)

I am not sure. I only guessed.:D