Log in

View Full Version : HDCP master key leak consequences


SpliFF
17th September 2010, 14:29
With all the (mostly misinformed) discussion of the HDCP master key leak/crack the /. discussion and articles I've read have been focused on how it relates to piracy. Most of this is confusion between the purpose of HDCP and AACS.

However I'm more interested in what seems to have been largely overlooked here, which is what effect will public access to the key have on device manufacture, revocation and signing?

What I really want to know is whether someone with this key can disable or cripple hardware with fake revocation lists? Also is the inverse possible, un-revoking a banned device?

Also what does this mean for imported HDCP equipment. Can cheap Taiwanese/Chinese imports now create their own keys to emulate other manufacturers and protect themselves from revocation?

What other things can the master key be used for?

What other sorts of fallout and exploits can we expect to see in the near future? Will we need to start virus scanning our blu-ray content now?

mariush
17th September 2010, 14:54
As far as I understand, from this master key you can create tons of vendor keys and subkeys so if you make a device with a random key generated from this master key, other devices will accept it.

The only resort the HDCP consortium have is to blacklist this particular key and send it to various existing devices through firmware updates but then that rogue manufacturer can just generate another key from the master key and replace it in the new devices he makes and maybe even update the older ones through firmware updates.

So the master key can be used to create devices that will be able to receive content from another device, using HDCP between them. From that point the device may do whatever it wants with the content, as it's raw, unencrypted content - it could be dumped to disk or converted to DVI, to VGA and so on (currently, I think video players are required to downgrade the quality if they output to analogue output like VGA).

For example if you still have a 21" CRT monitor around, with one of these hacked HDMI (with hdcp) to VGA converter, you could have crystal clear 1920x1080 output from your console/blu-ray player and so on. I believe the current ones only support HDMI without the HDCP encryption.


What other sorts of fallout and exploits can we expect to see in the near future? Will we need to start virus scanning our blu-ray content now?


I'd personally expect some countermeasures from Hollywood in the realm of watermarking, like the attempts they have now with Cineavia or whatever it's called. So they won't care if you copy the raw data going through the HDMI, but they'll impose on display manufacturers to update firmwares to detect a hidden watermark in any video input they receive through hdmi connector and if that watermark is found after about 10-15 minutes do some weird stuff to the video shown on screen, like making it grayscale or invert colors.

No need to worry about viruses though - this HDCP is all about the encryption between something that outputs video and a device that receives video - can't see how you'd infect anything

Ghitulescu
17th September 2010, 14:57
It's like CSS. It's a childplay to decrypt it, yet it's illegal as it counts, at least in EU as technical means for protecting the content.
The issue is that they knew it, so they lobbied hard and long various commissions and committees and now it's enough that a medium displays: Press A to continue. A human can press A and it's legal, a software that simulates "Press A" is illegal.

Ghitulescu
17th September 2010, 14:59
Will we need to start virus scanning our blu-ray content now?


No need to worry about viruses though - this HDCP is all about the encryption between something that outputs video and a device that receives video - can't see how you'd infect anything

I think he meant BD-live that requires a live internet connection ...

SpliFF
17th September 2010, 15:08
No need to worry about viruses though - this HDCP is all about the encryption between something that outputs video and a device that receives video - can't see how you'd infect anything

I thought revocation lists got propogated from blu-ray disks to the player firmware (or even right up the chain). If so couldn't a disc revocate the player itself (forcing it to downgrade or disable itself on future discs)? If I'm correct in this wouldn't that mean you can create a rogue disc that could at the very least break the ability of a player to play back hi-def content and at worse brick the device by sending a malformed list? Not that I want to do this mind you, I'm just curious about how much power the key has over HDCP devices.

Ghitulescu
17th September 2010, 15:19
Don't confound the key (which is a value) with the algorithm, which is a function. 6 is a value, cos() is a function.
The key cannot be used by consumers, as they don't have access to the intern functions, but from "damn pirate" developers, that want to "steal" Hollywood movies, pretending to do this for people that own older gear rendered useless by Hollywood.

SpliFF
17th September 2010, 16:05
Please elaborate. In what way is a disc made by a rogue entity (developer, consumer, manufacturer, street vendor, torrent author, whoever) signed with the master key different from an official disc signed with the master or sub-key?

Doesn't this release give anybody who makes a disc the power to revocate consumer hardware? I'm not saying they can write malicous code (can they?) I'm asking if they can create malicous "trusted" data and if so what the potential damage can be.

For example I can't imagine manufacturers would have many checks in the firmware for the validity of data created with a signed key, since presumably anything that's signed by a master or producer key is supposed to have been created by a trusted party bound to HDCP consortium rules. Presumably with the release of this key the "trusted data" is now anything someone can smuggle onto a disc and trick you into playing.

Ghitulescu
17th September 2010, 16:15
Master keys are not used in the disks.
With the current technology, any "malicious" BD-content-provider (of course, authorised) can revoque your player, no need for the master key.

SpliFF
17th September 2010, 16:31
Yes I understand you can create manufacturer keys from the master key but that's not the question. The point is these keys are supposed to be trustworthy, and now they're not. Are you saying devices will accept an unsigned revocation list? That doesn't seem right.

So the questions I'm asking are:

* Can a rogue signed disc revoke your hardware?
* If that happens can it be un-revoked?
* Is the master key used to sign revocation lists?
* Do revocation lists propagate and/or persist?
* Could a fake list potentially be used to create buffer overflows in firmware and software players?
* Is the master key used for anything else not already discussed?
* What effect will this have on the hardware market?
* What effect will it have for open-source linux?
* What other consequences does this release have?

I'm hoping people who understand what the key can do could shed some light on how it could be potentially abused for purposes other than simple piracy (which happens anyway) - and what the loss of a chain of trust might mean for people downloading or purchasing "pirate" blu-ray content or connecting corrupted second-hand "signed" devices to their home theatre system.

Ghitulescu
17th September 2010, 16:42
Read more about HDCP then we'll talk about :)

SpliFF
17th September 2010, 17:01
That's a poor excuse for not answering the question. So far you haven't told me anything I didn't already know and some of the things you said are just plain wrong.

For example, You said any blu-ray content producer can sign revocation lists but I know that's incorrect. The WP article says "Each revocation list is signed with a digital signature using the DSA; this is designed to prevent malicious users from revoking legitimate devices."

So is this master key the "digital signature" mentioned above or not? Can it create the digital signature?

You also said only pirates have interest in this but I don't believe that at all. For example until now there haven't been any "signed" linux based players. Now there will be and presumably that will allow linux users to watch legal hi-def movies on their legal hi-def devices without ripping it first.

Now please, can somebody answer the actual questions or am I simply in the wrong place. I always thought doom9 was where the experts hung out. Frankly I'm no idiot myself, I've done basic homework but so far it's failed to clarify these questions or I wouldn't have bothered to ask. :(

Ghitulescu
17th September 2010, 17:07
That's a poor excuse for not answering the question. So far you haven't told me anything I didn't already know and some of the things you said are just plain wrong.
Actually I'm on work and it's the end of the week, and I don't have the time to explain everything.
For example, You said any blu-ray content producer can sign revocation lists but I know that's incorrect. The WP article says "Each revocation list is signed with a digital signature using the DSA; this is designed to prevent malicious users from revoking legitimate devices."
I am right. Read again what I said. The definition of malicious is not fixed, legitimate people may be pirates or not, according to the desired policy. George Washington would have been a first grade terrorist should the Patriot act existed that time.
So is this master key the "digital signature" mentioned above or not? Can it create the digital signature?
No, the master key is used to obtain pairs of keys, something similar in idea to PGP, but of course different.
You also said only pirates have interest in this but I don't believe that at all.
You failed to see the sarcasm. :) :) Of course there are legitimate users, but since they interfere with the DRM policies they are treated as pirates.

Ghitulescu
17th September 2010, 17:11
Now please, can somebody answer the actual questions or am I simply in the wrong place. I always thought doom9 was where the experts hung out. Frankly I'm no idiot myself, I've done basic homework but so far it's failed to clarify these questions or I wouldn't have bothered to ask. :(

The discussion is irrelevant for you, unless you happen to own a chip factory and/or a developer team. A simple consumer has no access to this level.

SpliFF
17th September 2010, 18:00
As a consumer the capabilities of others who do have these things affects me. As I said this is simple intellectual curiousity combined with caution over what I should be loading and connecting to my home theatre system 12 months from now. Also what opportunities might come out of it beyond simple piracy (or fair-use).

I took your advice and read the HDCP spec and it just confirms my suspicions - that large parts of the handshake protocol simply assume that all devices with valid keys must have been manufactured by authorised Digital Content Protection LLC licensees and by extension all devices in the chain follow approved proceedures and enforced limits dictated by the consortium.

The spec pretty much tells vendors not to bother validating certain values because it's assumed those values will always be safe.

Very few devices these days are simple electronics. Most consumer electronics have a large amount of internal software and configuration, often upgradeable, and that makes them susceptible to software exploits when the basic assumptions they rely on to function turn out to be false.

I appreciate that you personally don't want to spend your Friday night explaining the HDCP protocol and your sense of sarcasm to a forum newcomer but nonetheless I'm still hoping for detailed answers from the rest of the doom9 community before this thread gets completely derailed.

I can't be the only one who feels that bypassing content protection won't be the only outcome of this event. If I'm wrong I'd like to know why, even if I don't completely understand the answers.

Ghitulescu
17th September 2010, 18:14
I appreciate that you personally don't want to spend your Friday night explaining the HDCP protocol and your sense of sarcasm to a forum newcomer but nonetheless I'm still hoping for detailed answers from the rest of the doom9 community before this thread gets completely derailed.
Sorry, you understood it completely wrong. I said sarcasm regarding the definition of the pirates.
The key cannot be used by consumers, as they don't have access to the intern functions, but from "damn pirate" developers, that want to "steal" Hollywood movies, pretending to do this for people that own older gear rendered useless by Hollywood.
I personally don't care who will invalidate my gear. Should I be more indulgent with Hollywood? Sorry for my impertinence to consider you (here comes Fox, Warner, Sony etc.) guilty for my misfortune, you're the good guys, I'll pay once more 1500€ for another Denon.... They make my life miserable (unskippable commercials and trailers, PUOs everywhere, invalidate my gear, make a heavy-loaded-java-bd load in hours, prevent my right to a working copy, disable the analog output, watermarks and so on) and I should be afraid of hackers? You must be kidding ...:)

I don't have connections with the pirates/hackers, however, I never had myself nor heard form a third person something bad done by them. I heard however a lot about companies that mimic the pirates and they do a lot of harm.

A nice comparison being the authors of freeware vs. the so-called free software, those that fill up hundreds of pages in google. The latter earn their money by hijacking your PC, while the first earn their money by donations.

Ghitulescu
17th September 2010, 18:19
As a consumer the capabilities of others who do have these things affects me. As I said this is simple intellectual curiousity combined with caution over what I should be loading and connecting to my home theatre system 12 months from now. Also what opportunities might come out of it beyond simple piracy (or fair-use).
Exactly. So use a not-watermark-aware player and use the backup copies only.
I took your advice and read the HDCP spec and it just confirms my suspicions - that large parts of the handshake protocol simply assume that all devices with valid keys must have been manufactured by authorised Digital Content Protection LLC licensees and by extension all devices in the chain follow approved proceedures and enforced limits dictated by the consortium.

The spec pretty much tells vendors not to bother validating certain values because it's assumed those values will always be safe.

Exactly again. It's what I said. Legitimate malicious vendors. One doesn't need a MK for that. Reread my posts too ;).

SpliFF
17th September 2010, 18:28
Sure but that's a largely ideological debate. We all know vendors can be evil but there's going to be limits to what the DCP LLC will tolerate before revoking your (presumably hideously expensive) manufacturer key. On the other hand some bored 15-year old kid or Russian consortium aren't going to have any limits on what they do, probably just deciding to brick peoples television sets for a laugh. To my knowledge there have been no cases of "legitimate malicious vendors" doing anything more evil* than adopting the protocol in the first place. It's seems like it's a whole new ballgame now.

EDIT: *By which I mean via HDCP, not via their lawyers and crap content.

KenD00
17th September 2010, 22:23
Ok, it looks like there is some great confusion about that HDCP Master Key, especially the Blu-Ray using people seem to mix here something up.

I think the greatest source of this confusion is that most people do not know the following equation: HDCP != AACS

Yes, thats right, HDCP has absolutely nothing to do with AACS. You can check the specification, HDCP isn't even mentioned a single time.

AACS is inside your Blu-Ray drive, PowerDVD, Arcsoft, ...
HDCP is inside your graphics card, display, receiver, ...
I have not mentioned the hardware players because these in fact contain both, but still both systems are not related in any way.

What the OP has described in this thread is the revokation scheme of AACS. Thats true, new discs contain this fancy stuff that can render your Blu-Ray drive and/or player software useless. But this can only affect your AACS components, nothing more. Thats the important fact, there is no mechanism included that your PowerDVD or whatever can reprogram your graphics card or the like!

AFAIK HDCP does not support active revokation like AACS at all. As already mentioned HDCP is in hardware only, usually burned into chips. You can't modify silicium ;). However HDCP supports passive revokation through revokation lists. These lists are burned into the chips during manufacturing.

Now if you buy a NEW device it might be possible that it carries a list that revokes your OLD device. So this new device doesn't work with your old device. However, your old device still can operate with any other device that does not contain this new revokation list.

:rolleyes:

mariush
17th September 2010, 23:44
The point is if some company starts making a hdcp stripper and assigns a different key to each device, it will be almost impossible to blacklist hundreds of thousands of devices. The only problem is chip factories are expensive...

SynchronousArts
18th September 2010, 00:21
The point is if some company starts making a hdcp stripper and assigns a different key to each device, it will be almost impossible to blacklist hundreds of thousands of devices. The only problem is chip factories are expensive...

While not a trivial design task, it is possible to do this in an FPGA chip, (Field Programmable Gate Array). See http://en.wikipedia.org/wiki/FPGA for an overview of the technology.

SA

mariush
18th September 2010, 01:17
Do these chips have the bandwidth available to process the HDMI signal? I know Gigabyte used FPGA chips (a Spartan one) to make their i-Ram ram drive but that used something build on purpose in the processor, not some generic input port...

Ghitulescu
18th September 2010, 07:22
Ok, it looks like there is some great confusion about that HDCP Master Key, especially the Blu-Ray using people seem to mix here something up.

I think the greatest source of this confusion is that most people do not know the following equation: HDCP != AACS

What the OP has described in this thread is the revokation scheme of AACS. Thats true, new discs contain this fancy stuff that can render your Blu-Ray drive and/or player software useless. But this can only affect your AACS components, nothing more.

As already mentioned HDCP is in hardware only, usually burned into chips. You can't modify silicium ;). However HDCP supports passive revokation through revokation lists. These lists are burned into the chips during manufacturing.
Yes, it struck me too the idea that the OP might refer actually to AACS.

This is why I said.
The discussion is irrelevant for you, unless you happen to own a chip factory and/or a developer team. A simple consumer has no access to this level.

The point is if some company starts making a hdcp stripper and assigns a different key to each device, it will be almost impossible to blacklist hundreds of thousands of devices. The only problem is chip factories are expensive...

These HDCP-strippers existed since HDMI, I've seen myself some 20 models, that was before they became illegal. They were no cheap at all...the simplest HDMI->DVI cost at the time some 150€.

CZroe
19th September 2010, 03:39
Ok, it looks like there is some great confusion about that HDCP Master Key, especially the Blu-Ray using people seem to mix here something up.

I think the greatest source of this confusion is that most people do not know the following equation: HDCP != AACS

Yes, thats right, HDCP has absolutely nothing to do with AACS. You can check the specification, HDCP isn't even mentioned a single time.

AACS is inside your Blu-Ray drive, PowerDVD, Arcsoft, ...
HDCP is inside your graphics card, display, receiver, ...
I have not mentioned the hardware players because these in fact contain both, but still both systems are not related in any way.

What the OP has described in this thread is the revokation scheme of AACS. Thats true, new discs contain this fancy stuff that can render your Blu-Ray drive and/or player software useless. But this can only affect your AACS components, nothing more. Thats the important fact, there is no mechanism included that your PowerDVD or whatever can reprogram your graphics card or the like!

AFAIK HDCP does not support active revokation like AACS at all. As already mentioned HDCP is in hardware only, usually burned into chips. You can't modify silicium ;). However HDCP supports passive revokation through revokation lists. These lists are burned into the chips during manufacturing.

Now if you buy a NEW device it might be possible that it carries a list that revokes your OLD device. So this new device doesn't work with your old device. However, your old device still can operate with any other device that does not contain this new revokation list.

:rolleyes:

Even if this were all about AACS, revoking a key doesn't "take" anything from the devices the disc is used in! It means that AACS-protected discs made since the revocation will not operate on the device/manufacturer that was revoked. The hardware still has all the same keys, they just no longer work for new content.

This isn't some kind of key to create executable malicious DRM.

What does it mean for we consumers? That there will be underground HDCP-strippers much like there were analog Macrovision strippers back in the VHS-dubbing days. As a consequence, we will also have converters that integrate them (HDMI>VGA, DVI>Component, etc) and even capture devices (do not expect to capture bit-for-bit digitally perfect copies of a decompressed video/audio stream; expect to make an encode). These devices weren't common in the VHS world and I don't expect them to be too prolific in today's. In fact, HDMI/DVI capture devices for non-HDCP protected digital outputs functionally do not exist for consumers, though there's more incentive to make them now. I've seen dongles for converting HDCP-protected outputs to VGA and component for a long time, though I assumed that they used stolen keys which could get revoked.

I want an HD digital DVR for my game consoles but... *shrug*

Ghitulescu
19th September 2010, 08:50
In fact, HDMI/DVI capture devices for non-HDCP protected digital outputs functionally do not exist for consumers, though there's more incentive to make them now.

I'm afraid you're a bit outdated. I know several models, that all of them can capture non-encrypted HDMI. Considering Blackmagic being a pro card, still remain at least 2 companies that do business for consumers.

HDMI can now only be captured as non-HDCP. Assuming the pro use HDMI (which is no way the case), they still do not encrypt the signal. HDCP is for distribution formats. An HDMI-capturing device is not popular for other reasons than DMCA: HDMI is in "clar" and is extremely resource-demanding, and most HD sources a consumer has can be otherway be transported (BD, memory card, AVCHD disks etc.).

Apu
19th September 2010, 13:59
Various tech sites state the HDCP master key is only valuable for chip designers/manufacturers and not for hackers or pirates. Is that true? I mean, wouldn't it be possible to emulate a HDCP capable device in software? For example tell your PC that a HDCP LCD ist connected to a virtual DVI Output, but the whole thing is just a piece of software which actually writes any video throughput to HDD? It is possible with virtual DVD/BD Drives, so why not with Monitors...?!

I know this is not very usefull atm, as we can decode pretty much anything anyway. But let's say someday there will be some new Blu-Ray or AACS revision which is not cracked within some weeks, then maybe this will become usefull.

2Bdecided
20th September 2010, 12:08
HDMI can now only be captured as non-HDCP.Obviously I'm not going to provide links, but there are a couple of companies who claim to offer boxes that take HDCP protected HDMI signals and, er, do things with them that they shouldn't! I've also seen forum posts from people who claim to have bought these devices, reporting that they work as advertised.

This was long before the recent leak. They claimed to be using keys from a well known CE manufacturer - keys they claim were very unlikely to be revoked because they were embedded in hardware in so many legitimate devices.

I don't know if any of this is true. I have no reason to spend ~$300 on one of these things to find out.

Cheers,
David.

Ghitulescu
20th September 2010, 12:30
Sorry, I wasn't probably clear enough.

All the cards I know do capture non-HDCP HDMI videos. There is none AFAIK that does capture HDCPed videos. There is no incentive within the pro league and the consumers shouldn't be able to do this.

With HDCP-strippers you can capture HDCPed HDMI because the card would capture the non-HDCP signal that is output from the stripper. ;)

It's like copying macrovision-infected VHS tapes using a TBC/macrovision-remover in between, the video recorder itself does record only Macrovision-free signals.

c2h5oh
29th September 2010, 13:59
While I don't know how we can grab HDCP encrypted stream we do have means to decode it with just software: http://www.cs.sunysb.edu/~rob/hdcp.html