High Definition TiVo Bash Software Hack Claimed
crazyray writes "Fresh on the heels of Sunday's Washington Post's article about TiVo and the broadcast flag, a group calling themselves the 'HD TeAm' is claiming to have discovered a software-only exploit to enable bash on the new $1000 High Definition DirecTiVo.
Prior to this announcement, it was thought that this was only possible by desoldering and reflashing the PROM.
Perhaps most interestingly, 'HD TeAm' is offering to release the code to the world if enough donations are given to the Electronic Frontier Foundation."
Maybe that's a good way of doing it. Make sure you don't have any money to be sued for by the MPAA, but have money going to someone who might arrange your legal defense.
I had a sucky sig.
...on PROM night!
... oh wait, this is about a PROM?? uhhh... nothing to see here, move along!
and reflashing the PROM
well I have to say that brings back fond memories of prom night.
Today the US Senate announced pending legislation designed to curb the growing problem of Tivo hacking. The House is expected to take up a similar bill next week.
Senator Orrin Hatch, chief sponsor of the bill, was quoted as saying "This issue is of extreme importance to the future of America. What kind of message would we be sending to our children if we allowed this kind of wanton hacking activity to go on unchecked? I ask all politicians who value protecting our intellectual property laws to join me in support of this legislation."
"is offering to release the code to the world if enough donations are given to the Electronic Frontier Foundation"
Uh, why? Just release the code.
I remember a while back the gang of folks threatening to release hacks for the Xbox unless MS paid up - don't remember hearing what happened there. This seems to be similar but completely different - :)
I have to say that I'm against anything that might harm Tivo as a company; I'm a rabid fan who sees signs on the wall that Tivo may be in trouble within the next few years as the cable companies produce low-grade DVRs that do not give the database-powered juicy goodness that Tivo provides.
Just my two cents.
Let me be one of the first (today) to say that software-only hacks rule! There are a lot more people that can use that type of hack, then there are that would open the box and do stuff in order to get BASH, or what have you, to work. Having witnessed hardware xBox/TiVo hacks myself, I can attest that if you don't have nerves of steel, you could bump that soldering iron into something important.. and whoops! There goes the system.
stuff |
Still waiting for my bash shell.
What would you be able to do with a TiVo hacked in this way that you can't do now? Hook it up to a different hard drive and store more shows?
"Stop throwing the Constitution in my face, it's just a goddamned piece of paper!" - George W. Bush Nov. 2005
I wonder what the license will be, and why it wouldn't just be straight GPL'd.
"HD TeAm" has submitted a sw only exploit for evaluation
the license is restricted distribution - but only to prevent resale / hero abuse
the HD TeAm position:
"HD TeAm has a solution prepared and authorizes it's distribution via ddb once $1,000 has been collected. We request that all proceeds be donated to the EFF so that research of this nature remains legal in the future."
"It is our position that if the community, particularly the minority with the disposable income for hd-units, is unwilling to come together & donate this token sum to a worthy organization the hack is probably better kept private"
This is bash.
In 2004, a crack hacker unit will be sent to prison by a civilian court, for crimes they just barely understood themselves. These hackers promptly escaped from the maximum security MPAA holding room to their mothers' basements. Today, still wanted by Jack Valenti, they survive as coders of fortune. If you have an encrypted video stream, nobody else will touch it, and if you can find them, maybe you can hire the HD TeAm!
click click click click...
I had a sucky sig.
Something smells fishy!
Of course. It's penguin powered, after all.
(Actually, good point there.)
Perhaps most interestingly, 'HD TeAm' is offering to release the code to the world if enough donations are given to the Electronic Frontier Foundation.
Why are they waiting for the EFF to get more donations in order to show the code to the world? Please go easy on me.
Red Bull gave me wings and I flew into the ceiling fan.
"... Perhaps most interestingly, 'HD TeAm' is offering to release the code to the world if enough donations are given to the Electronic Frontier Foundation."
In other words, "We'd like our defense fund paid in advance before we release That-Which-Will-Get-Us-Sued-Out-Of-Our-Lives.
Great. Now the EFF is going to be linked to the terrorists and get a visit from Ashcroft and the gang.
Jesus was all right but his disciples were thick and ordinary. -John Lennon
Skipping commercials is nice, but I'd like a hack to allow a TiVo to record and show good programs. "I wish my television had a control to adjust the intelligence level. I tried the control marked 'brightness', but it didn't help at all."
One line blog. I hear that they're called Twitters now.
how is this blackmail?
they are trying to ensure what they did remains legal
It's not a dumb question. The primary reason is to extract shows. The secondary reasons are to add features and disk space.
This 'digital blackmail/digital terrorism' leaves a sour taste in my mouth. I hope the EFF does the right thing and encourages people not to donate for this cause. Or perhaps not give out how much money they've been donated. This should not be encouraged at all.
Wow, do you people even know how to read? ("you people" referring to the idiots equating this to some type of blackmail)
For the reading impaired, there was a collection being taken to offer as a reward for anyone who could hack (crack, whatever) the HD Tivo. The HD Team merely offered to donate their reward to the EFF if it reached $1000. If it didn't, they'd keep the hack to themselves, and the reward money would be returned.
How the hell is that blackmail?
I bet they hit that mark easily by tomorrow.
"HD TeAm has a solution prepared and authorizes it's distribution via ddb once $1,000 has been collected. We request that all proceeds be donated to the EFF so that research of this nature remains legal in the future."
"It is our position that if the community, particularly the minority with the disposable income for hd-units, is unwilling to come together & donate this token sum to a worthy organization the hack is probably better kept private"
> The secondary reasons are to add features and disk space.
Disk space can be added to TiVos without shell access. Many people have already upgraded their HD TiVos' hard drives, while only a handfull have shell access to them.
not if it means getting service for FREE and TiVo losing money. hacks like this can allow this alteration, and it's just not good for the company and it's investors
You ignorant Troll. Intelligent creativity by finding a unique solution to a problem is part of free speech (much to the chagrin of Bushies). These hackers are not threatening death of a human life form. Get your perspectives straight.
How do you see a connection between "we'll do something nasty and evil if you don't do what we want" and "we'll do something nice if you choose to do what we want"?
Think more along the lines of Stephen King's experiment with online publishing, where he released the chapters for free but if he didn't get paid enough money, he'd stop writing them.
what is this bashing method? And why is there no mention of the preferred bat or sledgehammer to do so?
If you've RTFA, you'd realize:
The forum offered a bounty for a software hack.
The bounty was funded by donations.
The TeAm just asked for the bounty to be redirected to the EFF instead of to themselves.
So basically, the big deal is that the bounty needs to reach $1000 before they'll release the code, but when it does, they're just going to give the bounty to the EFF anyway. What's wrong with that?
This isn't terrorism, you idiot - write the code yourself if you want it. The comparison "leaves a sour taste in my mouth".
Argh. Mod parent: flamebait.
I [may] disapprove of what you say, but I will defend to the death your right to say it.
We don't need people associating the EFF with blackmail.
I wish they wouldn't do this.
-- A cat is no trade for integrity!
The EFF gets the money before Tivo has a change to patch the exploit.
not if it means getting service for FREE and TiVo losing money. hacks like this can allow this alteration, and it's just not good for the company and it's investors
NO! This is especially true in this case. Corporate America needs to be taught that "we will make money as long as we contol the use of our product after we sell it" is a bogus business plan.
Capatalism demands that any company that tries this be run out of business. Darwin tells us that any investor that supports a company with such a business plan will have their money taken away (and this is a good thing)
I'm sick and tired of the "companies and investors DESERVE to make mony no matter how lame their business plans are" crowd. FSCK that. If a company can't figure out how to make money w/o inventing new limitations on what consumers can do with their product then it is VITALLY IMPORTANT that that company be allowed to fail. It may hurt in the short term, but we are all better for it in the long term.
They are asking for donations (to a non-profit organization!) and in return they will release a hack that THEY CREATED into the public domain.
How is offering to release something that you created in exchange for donations, blackmail?
If it is, then I guess every business that sells goods or services is guilty of blackmail too *roll eyes*
What exactly do you consider flamebait? Comments that you disagree with? This is why I meta mod all flamebait mods as unfair.
idiot
So they took a bounty from the forum, and turned it into a political statemnet. They changed it form a friendly wager into a form of blackmail: "Buy our hack by supporting some cause" the direction TURNED it into something less than good. That's just geat eh?
The better way would have been collect the bounty, and THEN donte it to EFF. same result, just they would have been showing support instead of forcing support. Lot more up-and-up
AB HOC POSSUM VIDERE DOMUM TUUM
This 'digital blackmail/digital terrorism' leaves a sour taste in my mouth.
Blackmail involves the withholding of information in return for a fee. If providing information in return for a fee is blackmail, then we'll have to jail all the programmers and scientists.
I didn't even get my dress off on prom night, I had to peel it off 18 hours later when I woke up underneath a volkswagon jetta that somehow made it into my garage. And there were opened boxes from undercarriage lighting kits... I felt so... dirty.
THIS THING CAN TURN ON A DIME, MACROSSZERO STYLE ALSO FUCK BETA, ~NYORON
There are no trails. There are no trees out here.
i think there's a subtle difference between doing what you want with your hardware and requiring the system they put on that hardware to allow you to do so. i really don't know much about the details of the tivo hardware, but my impression is that it's possible to run your own linux install on it (though not very useful). as such, while you're free to do what you want with the hardware you've bought, it's the service running on it that's limited, and given the nature of tivo's business, i don't fault them for that.
The better way would have been collect the bounty, and THEN donte it to EFF. same result, just they would have been showing support instead of forcing support. Lot more up-and-up
Maybe. But the original comment was that it was "digital blackmail/digital terrorism." It is not blackmail to offer to release something for free once enough donations are received by a 3rd party. It is not terrorism to to release one's own work, once someone else meets certain conditions.
If that were the case, then I just had a terroristic plumber that, get this, demanded that I agree to pay him before he'd fix a leaky pipe. Horror of horrors, he didn't give away his work for free without conditions. How evil can you get.
But I will agree that they didn't handle their wish that people would donate the EFF for using the code in a manner that calcualted for good PR.
Learn to love Alaska
(Tell-Sell mode)
The latest TiVo hack... Soon coming to a Freenet or MUTE node near you... It's amazing!
(/Tell-Sell mode)
A little later, it'll be all over the general file-sharing networks, without ever having left a trace to its origin. At that stage, the cat is irrevocably out of the bag.
The point you raise is interesting: it doesn't matter that anonymous networks like Freenet or MUTE are not currently used by a lot of users; they _are_ used by ~1000-~10000 users. When more than a view of those start sharing it at high-usage filesharing networks, the cat is out of the bag. I can indeed imagine really high-profile hacks (say: like the utopical patch that'll break DRMS and/of TCPA in a few years, or so ;) to be "released" in either the two-stage way I just described, or by using virusses (as a last resort).
Interesting...
Support a Europe-related section on Slashdot!
A bounty was offered. They developed a hack. Then they said they wouldn't release it unless they got a larger bounty.
This isn't a simple "we're donating our bounty to charity", it's a "pay more or else" situation. It's extortion, plain and simple.
I would have contributed to a bounty (I have an HDTiVo), but I don't pay extortion money. So they get nothing from me.
Awww great. Now the EFF will be considered a terrorist organazation and threat to Our Way Of Life.
(Hackers who support organazations who disaprove of Orwellian futures? They MUST be terrorists!)
You had an agreement already that you get paid for the work you will do.
If I come to you and say I'll mow your lawn for $5, then mow your lawn, you owe me $5. If I just come up and mow your lawn without talking to you first and then go to you and say "give me $5", you are under no obligation to pay me. If I try to make you do so anyway, it is extortion.
They will release the code if people donate to the EFF- that is, they will not release the code unless money has been given to an organization which is able to defend them in court when Tivo does what Tivo will.
-- 'The' Lord and Master Bitman On High, Master Of All
How is this "forcing support"? If you don't want to support it, don't. If few enough bother to support it, they keep the hack private. Since the hack is their IP, they can do that.
"I do not agree with what you say, but I will defend to the death your right to say it"
Ever notice how people claim they want intellectual shows, while in reality braindead shows (Babewatch, soaps, shoot-em-ups) do great? Calvin & Hobbes had a great strip on that, where Calvin is complaining about the state of TV, and his dad suggests reading a book or going out instead. Calvin (still watching TV) says "So I lied. Sue me."
;)
Of course, I only want intellectual shows
Kjella
Live today, because you never know what tomorrow brings
extortion... but backwards.. weird
The war with islam is a war on the beast
The war on terror is a war for peace
Is it just me, or does anyone else think it's weird that I can make a meaning out of that headline :p.
Rumor has it that TiVo will patch it within the next week, starting possibly Wednesday.
Khmmm...
In Soviet Washington the swamp drains you.
If you've RTFA, you'd realize:
Obviously RTFA didn't help you understand why the principle of this offer is flawed. Bascially this is like saying "If you donate money to GreenPeace we will torch some Hummers." They are using a premeditated illegal action as a sort of endorsement for an organization. Therefore the correct response is for the EFF to denounce illegal activites regardless of wheather or not they believe the laws are constitutional.
Thisba is bash.
A little known fact, it seems, is that you don't even need a PC to add a second hard drive -- despite what searching the web seems to suggest. While poking around in the TiVo's startup scripts, I found that the command to initialize a new hard drive (if present) is already there along with a comment of "No, we didn't remove this..." So, just plug in the second drive and it should work. No PC necessary!
> I found that the command to initialize a new hard drive (if present) is already there along with a comment of "No, we didn't remove this..." So, just plug in the second drive and it should work. No PC necessary!
Wrong. Those commands cause it to add a blessed drive to MFS, not to bless a blank drive. You still need to set up the basic partition table in a PC.
Oh yes, because torching Hummers and talking to your HDTiVo are equivalent.
Disobeying unjust laws are the only way unjust laws get changed. The state cannot afford to put away 95% of it's population, as the top 5% of the population isn't going to pay for their incarceration (crap, they scream and whine about their own transgressions, just look at Kenneth Lay).
Hmm. Bummer. I figured it would take care of that too. I guess that's why I'm just executing the hacks instead of creating them... :-) Not yet anyway.
nice job, skippy.
that's not me. i'm no webcam whore.
THIS THING CAN TURN ON A DIME, MACROSSZERO STYLE ALSO FUCK BETA, ~NYORON
Yeah, it's a bit more grey than my first knee-jerk reaction. But, What I saw was the creater of the hack causing those who may not believe in a casue (free software) to donate to it if they want the hack. "If you want my hack, support my cause" . It's not quite that bad, but it's still not pretty from all angles.
AB HOC POSSUM VIDERE DOMUM TUUM