Slashdot Mirror


AACS Specifications Released

An anonymous reader writes "AACS, the proposed key management scheme for HD DVD, has finally released preliminary (ver 0.9) specifications. The specs look like CSS on steroids: they use AES instead of proprietary crypto, but other than that they're basically the same. The main difference appears to be that AACS can revoke an entire player model if a hack appears against it, which I guess sucks if you own that kind of player."

94 of 486 comments (clear)

  1. Manufacturers by Joff_NZ · · Score: 5, Insightful

    The main difference appears to be that AACS can revoke an entire player model if a hack appears against it

    In that case, why would any manufacturer in their right mind produce anything under such terms? That would just be insane

    --
    The revolution will not be televised. It won't be on a friggin blog either
    1. Re:Manufacturers by Morlark · · Score: 2, Interesting

      Yeah it is insane, but it's just the latest in a long line of insanity. Notice how a lot of the technologies that are being touted recently are all about restricting what people can do with content. It's a growing trend, and I don't think it's right.

      --
      Santa's suicide mission go!
    2. Re:Manufacturers by Tx · · Score: 4, Interesting

      From the spec:

      If a set of Device Keys is compromised in a way that threatens the integrity of the system, an updated MKB can be released that causes a device with the compromised set of Device Keys to be unable to calculate the correct Km. In this way, the compromised Device Keys are "revoked" by the new MKB.

      If I read this right (which is not guaranteed this early in the morning), only hacked devices would be revoked. So it wouldn't be insane for manufacturers to use this scheme, and in fact would make them discourage hacks rather than making them easy as they do with many DVD players. Bad for fair use, but no problem for manufacturers.

      --
      Oh no... it's the future.
    3. Re:Manufacturers by GizmoToy · · Score: 4, Insightful

      Well, thousands of customers calling their support lines to figure out why their players no longer work is going to be a pretty big problem for them, I'd say.

      I'm not sure that creating a product that another entity can simply break is a great way to go. Can you imagine how irate all the innocent users would be? Man, I'd hate to be tech support at any of the companies that make these.

    4. Re:Manufacturers by BJH · · Score: 3, Insightful

      So hacking a piece of hardware (not software, mind - *hardware*) that you bought and own is now a crime?

      Let me guess what country you live in...

    5. Re:Manufacturers by RedWizzard · · Score: 2, Insightful
      Innocent users don't hack their devices. Not necessarily saying you're wrong otherwise.
      The point is that if you happen to own the same device that the hacker broke the keys for, you could be SOL. I.e. if someone cracks the keys for Sony's Model 99 HDDVD player, the DVDCCA can revoke those keys and everyone who owns a Model 99 now has a useless paperweight (well I guess they'd still play old discs, just not new ones). Now, whether they'd use that ability or not, who knows? It's the sort of thing that would have lawyers lining up to start class actions suits, I'd expect.
    6. Re:Manufacturers by Craig+Ringer · · Score: 4, Informative

      I'm afraid I think you read it wrong.

      "... with the compromised set of keys ..." is the key phrase. A given model, if this is the same as CSS, has a CSS key - not a given unit of that model. Revoking the key would revoke it for all units of that model since they all have the same key.

      Nasty. DVD is offensive enough already ("You may not skip this!"), this will just make it worse. Argh.

    7. Re:Manufacturers by nothings · · Score: 5, Informative
      You're not reading it right. If somebody pries out a key from a device and uses that in a DeCSS-like software, they want to make that key no longer work--they want to revoke that key entirely. That's the only way this makes any sense.

      With that in mind, it's clear that you can read what you quoted in the above sense, and indeed it's the plausible way to read it: it's not "causes a compromised device to be unable...", it's "causes a device with the compromised set of Device Keys to be unable...". Any device using this set of keys--whether it's superDeCSS or any particular machine of the sort that was compromised, or any other machine that shares the same set of keys--will no longer be able to view content--presumably only new content created after the revocation.

      Related, from the spec:

      The set of Device Keys may either be unique per device, or used commonly by multiple devices. The license agreement describes details and requirements associated with these two alternatives. A device shall treat its Device Keys as highly confidential, as defined in the license agreement.
    8. Re:Manufacturers by logicnazi · · Score: 3, Interesting

      Yes the key word here is 'comprimised set of device keys'

      The way this worked in CSS and probably works similarly here is that at the begining to the disk they encrypt a disk key with many different device keys. Then each device decrypts the disk key using their own device key.

      However if you work out the math it simply isn't plausible to include a seperate key for every HD DVD player that might ever be sold (imagine 128 bits for an AES key). Instead each manufacturer, or perhaps even DVD player model in this new system, gets one key. They can then 'revoke' these keys by just refusing to encrypt future DVD keys with these device keys but since each DVD player doesn't have its own key they can't disable movies player by player.

      On another point I would find it to be really unlikely that any major DVD player would truly get this penalty imposed against it. It would be a huge loss to be the first movie that doesn't work on sony blah players so no movie company is going to be the one who takes that first step.

      Instead this is really a measure to deter manufacturers from 'accidently' making their DVD players ignore copy protection or otherwise violate their rules. Thus it is likely to be used when a player first hits the market or not at all.

      --

      If you liked this thought maybe you would find my blog nice too:

    9. Re:Manufacturers by archeopterix · · Score: 2, Insightful
      Yeah it is insane, but it's just the latest in a long line of insanity. Notice how a lot of the technologies that are being touted recently are all about restricting what people can do with content. It's a growing trend, and I don't think it's right.
      Just out of curiosity... Are ther any consumer rights organizations in the US? Any half-decent consumer org should be up in arms about this.
    10. Re:Manufacturers by mollymoo · · Score: 2, Insightful
      [...] chargebacks are great for hurting retailers, not manufacturers.

      And we all know retailers (like, say, Wal Mart) have no power over their suppliers.

      --
      Chernobyl 'not a wildlife haven' - BBC News
    11. Re:Manufacturers by pe1chl · · Score: 2, Interesting

      Of course you can return your Model 99 HDDVD player to Sony for upgrade or refund, because they broke their part of the agreement by not protecting the device keys good enough to prevent pirates from extracting them.

      This is the manufacturer's fault. He provided you with faulty equipment and should repair it at his expense or refund your money.
      (under most consumer laws)

    12. Re:Manufacturers by micolous · · Score: 5, Insightful

      Yeah, and then the kind soul who cracked the code gets a new player or firmware to go and crack the code using a different key. New version of the player then gets blacklisted again, and repeat the process. All this does is annoy the users of the product with infinite amounts of replacements needed, and the process becomes very costly for the manufacturer having to replace the equipment.

      In the end, revoking player keys is stupid. It comes back to the whole point that DRM is not only a stupid idea but fundamentally flawed. It also creates an interesting situation for the key licensing organisation. Don't like a competitor or just want them to pay higher licensing fees? Threaten to cancel all their keys.

      If the consumer association in your country has any sense whatsoever, they won't play along with this at all.

      --
      SSdtIGFzIGJvcmVkIGFzIHlvdSBhcmUK
    13. Re:Manufacturers by DavidTC · · Score: 3, Insightful
      Yes, but there's no reason to assume that whatever let them crack the key on one player wouldn't let them do it on others.

      And I actually have a suspicion this is as much about 'region-less players' and whatnot as it is about copy protection.

      --
      If corporations are people, aren't stockholders guilty of slavery?
  2. Let me be the first to hack it.. by Anonymous Coward · · Score: 5, Informative

    Click here to get the specification without agreeing to the terms of access.

    1. Re:Let me be the first to hack it.. by Anonymous Coward · · Score: 2, Funny
    2. Re:Let me be the first to hack it.. by Poulpy · · Score: 5, Insightful

      Please do not crack it until its final and distributed in tons of players.

  3. Player Model? by NEOtaku17 · · Score: 5, Insightful

    "The main difference appears to be that AACS can revoke an entire player model if a hack appears against it, which I guess sucks if you own that kind of player."

    Player model? What if a hack comes out for PC that allows you to circumvent the copy protection: Does it revoke PCs altogether, only certain disk drives, or what?

    1. Re:Player Model? by Omkar · · Score: 2, Insightful

      Considering that one "hack" would be just capturing the signal sent to the TV, I think it's fair to say they're not going to be banning anything anytime soon.

    2. Re:Player Model? by nothings · · Score: 3, Informative
      "Circumvent the copy protection"? The data is encrypted. You can copy it all you want; but you can't play it without decrypting it.

      So they revoke a player model as follows (omitting lots of details that aren't important to the big picture, and oversimplifying):

      Each player model gets its own key ("set of Device Keys" in the specification). Data on the disc is encoded with a disc-specific data key. Given N player models, there are also N encrypted master keys, one for each (non-revoked) player model.

      If a player model is compromised and the key from it used in a DeCSS-like program, they will "revoke" that key and, on all future releases, not include a copy of the disc-data key encrypted for that player.

    3. Re:Player Model? by DrXym · · Score: 2, Interesting
      Which is great but my undertanding of DeCSS when it was released was that they said once they cracked one of the keys they could have gone on to crack them all. If this thing is CSS on steroids then what's to stop someone doing a concerted attack to grab one key, cracking a whole bunch of them from major manufacturers. Are they really going to risk the wrath of millions of consumers who discover their players don't work any more?


      At the end of the day, the disc data is encrypted once and the disc must have a multiply encrypted key where every model can grab the read the contents. Cracking that first key might be tough, but there are plenty of distributed efforts that do just kind of thing already.


      Besides most pirate DVDs I see have been recompressed anyway. Even if the crypto proves uncrackable, people will simply resample the disc contents and release them without any crypto.

    4. Re:Player Model? by benb · · Score: 2, Insightful

      > Given N player models, there are also N encrypted > master keys, one for each (non-revoked) player
      > model.

      All shipping with the disc, I presume. So, let's say there are 1500 different player models on the market. Each disc then ships with 1500 different asymetric encryptions of the symetric key used to encrypt the actual content. Let's say each takes 1 KB, that's 1,5 MB for all.

      Now what about future player models? The keys of the players released 2015 must be on discs released 2005, otherwise the future players won't be able to play the older discs.
      (Or are they going to skip over this as well and just only make the new prints of old releases include the new keys? Meaning that new models can't play used discs? How about "consumer protection" here?)

      Let's say there are 1000 models released per year, and that over 20 years, means 20000 keys. That's 20MB, still sounds reasonable for discs with 18GB capacity.

      Of course, that still doesn't sovled the discussed problem that each model will be sold thousands of times, and several thousand of customers who did nothing at all get punished for the one that was a "bad boy" and cracked the key of the device.

    5. Re:Player Model? by Monkelectric · · Score: 2, Informative
      Which is great but my undertanding of DeCSS when it was released was that they said once they cracked one of the keys they could have gone on to crack them all. If this thing is CSS on steroids then what's to stop someone doing a concerted attack to grab one key, cracking a whole bunch of them from major manufacturers. Are they really going to risk the wrath of millions of consumers who discover their players don't work any more?

      I know absolutely nothing about CSS, but do know a few things about encryption in general. Once you have a copy of the data you are TRYING to decrypt, you can do a "known plaintext" attack -- which is fancy words for, "ah ha fuckers! Now I know what im looking for!!" Which generally makes the search space for the cracking much smaller (faster).

      I dunno about anyone else but, Im sick of this bullshit. Its been 3 or 4 years since the decss fiasco and STILL linux support for dvds SUCK. I'm just not going to play ball anymore. Im not buying this hardware anymore.

      --

      Religion is a gateway psychosis. -- Dave Foley

  4. I accept? by Anonymous+Luddite · · Score: 3, Funny

    >> These documents are preliminary drafts and are subject to change without notice. To download the v0.90 specifications, please accept the above terms and conditions.

    No Thanks. I'll just wait for it to get posted to /.

  5. Mark my words. by Adult+film+producer · · Score: 5, Funny

    This scheme will not be broken for at least 20 years.

    There's no way they'll make the same mistake twice. DirecTV upgraded all their smart cards 2 or 3 years ago and it has yet to be broken. Bell Canada's expressvu is adopting the same technology because _everybody_ and their mom is pirating the signals.

    1. Re:Mark my words. by wolrahnaes · · Score: 5, Insightful
      This scheme will not be broken for at least 20 years.

      There's no way they'll make the same mistake twice. DirecTV upgraded all their smart cards 2 or 3 years ago and it has yet to be broken. Bell Canada's expressvu is adopting the same technology because _everybody_ and their mom is pirating the signals.

      Here's the big difference...

      Gaining access to DirecTV's signal requires hacking proprietary hardware. If PC-based players are ever allowed, reverse engineering will be along the same lines as last time around. It's just so easy to monitor everything your computer is doing in real-time, especially with the help of emulators like QEMU, Bochs, VMware, or Virtual PC.
      --
      I used to get high on life, but I developed a tolerance. Now I need something stronger.
    2. Re:Mark my words. by sTalking_Goat · · Score: 2, Insightful

      you're kidding right? Client side encryption is dead. So Unless DVD players have to dial in to decrypt the movie this is a joke.

      --

      My days of not taking you seriously are certainly coming to a middle...

    3. Re:Mark my words. by mattkinabrewmindspri · · Score: 3, Insightful
      Consider the source.

      "Adult film producer"

    4. Re:Mark my words. by Frank+T.+Lofaro+Jr. · · Score: 2, Funny

      Just press the "easy button".

      --
      Just because it CAN be done, doesn't mean it should!
    5. Re:Mark my words. by Lord+of+Ironhand · · Score: 5, Funny
      If they *really* want an unbreakable scheme, let them encrypt all HDDVD's using one-time pad encryption, then securely delete the key.

      If they do it right, pirate copies will be truly impossible. Granted, no one will be able to play the legit copies either, but it's my impression that this is only a minor concern to the companies involved.

  6. Okay, DVD Jon... by kwoo · · Score: 4, Funny

    You have your work cut out for you!

    Just kidding. :)

    1. Re:Okay, DVD Jon... by TravisWatkins · · Score: 2, Insightful

      Jon broke the iTunes DRM, lots of people based their work off his, then he started working on one of the projects.

      --

      "But I'm still right here, giving blood and keeping faith. And I'm still right here."
  7. What will the packaging say? by The+New+Andy · · Score: 5, Interesting
    Suppose player X has been revoked. Now, I'm assuming that any disks released after this won't work on it right? So, does the packaging for the disk say: "Plays on any player except blah"?

    Now, how does this scale, suppose players AAA through ZZZ have been revoked. Do we need larger DVD cases just so we can fit a list of all the players that won't work on it?

    1. Re:What will the packaging say? by J.+Random+Luser · · Score: 3, Informative

      Playable on all Licensed Players
      see Figure 1-1 page 2 (12) of the Advanced Access Content System: Pre-recorded Video Book.
      It's your job as user to figure out if your player is still licenced.
      Now that's not to deny enterprising souls the right to devise methods to play it on unlicensed players, but there may be some fine print about such methods violating your EULA with the content provider...
    2. Re:What will the packaging say? by Anonymous Coward · · Score: 2, Insightful

      It'll probably just be done in designations. So, players will say: "Plays DVDs designated A00AA-L13PI" and any DVDs that come out with a newer designation will require a newer player to work.

      I have to say if this what they're thinking, then they're insane. As it is, I buy a ton of DVD movies, but if they do this, then I'm pirating everything for sure.

  8. Re:I, for one... by Lehk228 · · Score: 2, Funny

    THis new standard will probably require 15 lines

    --
    Snowden and Manning are heroes.
  9. Owning a model player that get's revoked .... by Anonymous Coward · · Score: 5, Insightful

    Well, what happens to the customers that have a player-model that gets, by no fault of themselves, revoked. Are they reembursed (getting (part of) their money back), or are they just left with a piece of worthless, but costly junk ?

    Even worse : you have no way of knowing if the player you are going to buy is on the list of players shortly-to-be-revoked, or worse yet : allready revoked.

    How's the "you should be able to use a bought commodity for a reasonable time"-law come in play here ?

    1. Re:Owning a model player that get's revoked .... by l0b0 · · Score: 4, Insightful
      Well, what happens to the customers that have a player-model that gets, by no fault of themselves, revoked. Are they reembursed (getting (part of) their money back), or are they just left with a piece of worthless, but costly junk ?
      This can't possibly work on the global scale, so it'll just be the final kick in the balls before all consumers learn how to pirate movies. That is, if the movie industry doesn't realize that it's their worst move of all times.
    2. Re:Owning a model player that get's revoked .... by Anonymous Coward · · Score: 4, Funny

      They start the healing process by investing the money they would have spent on new players in some of the fine products made by Barrett Firearms Manufacturing, Inc., and the information provided by fine financial periodicals such as the Wall Street Journal.

    3. Re:Owning a model player that get's revoked .... by aztracker1 · · Score: 2, Insightful

      Will probably take off about as well as the original divx @ circuit city, where you have "rented" disks, or however the format worked, iirc...

      I think it will backfire in the end, and the first batch of dvdhd players to get revoked will have civil watchdog groups pouncing by the thousands.. pretty much every local and national tv station will pounce on this, and it will really backfire on the media industry.

      --
      Michael J. Ryan - tracker1.info
    4. Re:Owning a model player that get's revoked .... by pe1chl · · Score: 2, Insightful

      The media industry wouldn't know anything backfired on them. They would just going on moaning about reduced sales and blaming it all on someone else.

      That is what they have done for years now. It is the fault of the pirates, the fault of the Internet, the fault of anyone but themselves that revenues are dropping.

      The fact that they are over-spending and over-paying of course is not the reason, in their vision.

    5. Re:Owning a model player that get's revoked .... by WIAKywbfatw · · Score: 2, Insightful

      I can't see this working in the EU.

      Imagine being sold a DVD player that stops playing any new releases a year, a month or even a day after you bought it. Under EU law you'd almost certainly be entitled to a refund from the vendor, and I can't imagine European vendors willingly leaving themselves that wide open to millions in claims.

      Expect sanity to prevail when the reality of how dumb this would be in practice is finally hammered home to those who hope use this system.

      --

      "Accept that some days you are the pigeon, and some days you are the statue." - David Brent, Wernham Hogg
    6. Re:Owning a model player that get's revoked .... by DavidTC · · Score: 2, Funny
      'Sir, people keep pirating our movis!'

      'Quick! Find some honest customers and kick them in the balls by breaking their DVD player!'

      I.e., the beatings will continue until morale improves.

      What's that rule again? Any organization's behavior can be predicted if it is assumed to be controlled by a secret cabal of its enemies out to discredit it?

      --
      If corporations are people, aren't stockholders guilty of slavery?
  10. Well then... by mattkinabrewmindspri · · Score: 4, Funny

    Go Blu-Ray!

    1. Re:Well then... by bentcd · · Score: 2, Informative

      While your opinion on the Beta/VHS case is only implied, I would like to point out that VHS was technically superior to Beta (in the areas of interest to the consumer) and this was the reason for its success. Specifically, VHS had a 2-hour recording time whileas Beta had only 1. This difference made all the difference to the consumer who could then record an entire movie without having to change tapes in the middle.
      There are other things to say about this particular story, of course. There is a nice summary towards the end of this article:
      here

      --
      sigs are hazardous to your health
  11. Content scrambling is stupid... by jleq · · Score: 5, Insightful

    It may be the strongest encoding out there, but who cares? What stops me from plugging the video output of a dvd player into my video capture card and recording off of it? Sure, the quality won't be as good, but it will still work.

    I wish they simply wouldn't scramble content in the first place. 99.9% of the people who buy the dvd and would need to break the encoding have a LEGITIMATE reason to break said encoding (backup, copying to laptop so it's not necessary to carry discs on trips, etc).

    1. Re:Content scrambling is stupid... by TheRaven64 · · Score: 3, Informative
      Analogue Macrovision works by sending a high-power signal during the TV's flyback period. A high-power signal is interpreted as black, but that doesn't actually make a difference, since the electron gun is turned off during the flyback period.

      When a video recorder receives the signal, it normalises the incoming signal, resulting in the signal sent in the flyback period (which is not used for the image) being awarded most of the signal bandwidth, and the image proportion being awarded approximately none.

      Bypassing such a system is left as an exercise to the reader, however it should be fairly obvious.

      --
      I am TheRaven on Soylent News
    2. Re:Content scrambling is stupid... by ajs318 · · Score: 3, Informative

      Here's a clue: you'll need an LM1881 sync separator, a 4053 bilateral switch {or preferably something with more bandwidth}, and either a PIC microcontroller or a stack of TTL chips. The 1881 has an output which tells you when the field starts, and another output which pulses on every line. You need to count off 20 or so lines {look at the picture signal with an oscilloscope to see where the real picture starts}, during which time you must output a dummy black level with artificial hsync pulses. {You can get a clean hsync output from the 1881; use this to turn on a transistor and pull the black level down to 0V. Your dummy black needs to be as close as possible to true black, otherwise the very top and bottom of the screen will be some shade of grey. But you'll have thought of that and wired in a potentiometer to adjust it}. Switch over to the unadulterated picture signal for about 270 lines. Then go back to your dummy black for the remaining {22.5 or thereabouts} lines of picture.

      If you need adjustability, use a PIC with a decent number of I/O lines. Or try using an open-drain I/O line with a capacitor to 0V ..... pull it low to discharge the capacitor; let it float, allowing the cap to charge through a pot; and time how long it takes to begin reading high. The paddle controller inputs on the Atari 2600 worked exactly like that.

      Or, you can get a proper time base corrector from a professional video equipment supplier. It'll probably cost you more than buying a load of original videos, though ..... :)

      --
      Je fume. Tu fumes. Nous fûmes!
  12. Is this legal? by Foktip · · Score: 2, Informative

    In many countries (such as will probably be with Canada soon), there will be laws stating that bypassing DPM's (digital protection measures) is allowed, and legal, if it is of legal intent. SUch as fair use, backing it up, etc.

    So, if you use it fairly in a country where its legal to do so, and they "block you", is that legal too? Is their EULA more powerfull than non-American laws?

    1. Re:Is this legal? by ta+bu+shi+da+yu · · Score: 4, Informative

      In Australia it now is, we are not allowed to create any copy protection circumvention mechanisms. To all you Americans: thanks for nothing.

      --
      XML is like violence. If it doesn't solve the problem, use more.
    2. Re:Is this legal? by krautcanman · · Score: 2, Interesting

      Don't blame me, I voted for Bush!

      First, Austrailia != USA
      Second, blame the industry (i.e. MPAA et al.) for whining about "lost profits" due to pirated discs.
      Third, G'day mate!

  13. Can Slash stop with the obscure acronymns by zymano · · Score: 4, Informative

    Content Scrambling System = CSS.

    AACS= Advanced Access Content System.

    Maybe I am an idiot but i had to actually read the article to know what the posted article was talking about.

    1. Re:Can Slash stop with the obscure acronymns by csrster · · Score: 5, Funny

      I must admit that I thought an encryption standard based on the Cascading Style Sheet specs was a clever idea. Should be almost impossible to decipher.

  14. So I roll the dice by JohnnyGTO · · Score: 2, Interesting

    drop big bucks on equipment hoping someone does happen on a hack? Yea right and they wonder why only the sheeple fall for this shit.

    --
    Si vis pacem, para bellum! For evil to succeed good men need only do nothing!
  15. key revocation by Anonymous Coward · · Score: 4, Insightful

    If they can revoke keys, then we can DoS the keyspace. There's no need to crack any crypto. All we gotta do is trick them into deprecating keys.

    How many people are still running windows 98? How many people know how to set the clock on their vcr?

    You DoS the keyspace eventually people won't be able to play commercials. Then the productions don't get their money. Then the system does either of 2 things. 1: every screen goes black and there is no tv or 2: they give up and take off the crypto so the ads work again.

    Key revocation is a bigger security risk than keys in software dvd players because you can do more than opening up a file to everybody. You can lock everybody out of it as well.

    This idea (starting with hdcp I guess) just opens up more vectors for attack. Now we have a social engineering vector and a keyspace vector in additon to a locally stored key vector (css).

    1. Re:key revocation by rjh · · Score: 2, Insightful

      No, you can't DoS the keyspace.

      They're using AES. That means it has (potentially) a 256-bit keyspace. You have neither the time, nor the energy, nor the computing power, to exhaust that keyspace. You can't even make a dent in that keyspace. A really monstrously huge distributed.net effort that runs for a decade might be able to create 2^80 bad keys. Okay, fine, great, that's a lot.

      Now take 2^256 and subtract 2^80. What do you get?

      Why, roughly 2^256. 2^80 is so insignificant in comparison to 2^256 that you're basically subtracting zero from the total keyspace.

      People who do not understand just how large a keyspace is should not talk about how easy it is to exhaust a keyspace.

    2. Re:key revocation by Anonymous Coward · · Score: 5, Insightful

      Nobody said anything about exhausting the keypace.

      We're talking about attacking the subset of deployed keys. We don't need these keys at all to get them revoked.

      The device itself will decrypt the stream. All you need is access to the output to reencode and share. Copyright cops detect the share, lift whatever watermark may be in the stream, finger the device and revoke the key.

      There you go. You just DoS'd a production run of playstations from decrypting movies. All without having any knowlege of any keys.

      When I say DoS the keyspace I don't mean exhausting the theoretical keyspace of a 128 bit cryptosystem. You're right, that'd be hard. You don't have to discover keys to DoS the subset of deployed keys via third party revocation. You need only make it seem as if the key was compromised to the revocation authority, thus prompting revocation.

      So long as the stream will exist in a decrypted form so the user can watch it, then no knowlege of keys is needed to perform this attack.

      Also. If the revocation authority becomes wary of such attacks it acts as a bunny rabbit attack. When keys are legitimately compromised they may do nothing thinking it's just another dupe.

      The keyspace isn't the weakness here. It's people.

    3. Re:key revocation by Siener · · Score: 4, Insightful

      No, you can't DoS the keyspace.

      You don't need to DoS the whole keyspace, or even any significant fraction of it. You only need to DoS the keys that are actually in use.

      Imagine there are 100 different models of DVD player on the market. You just get those 100 keys revoked and suddenly no-one can watch any DVDs

  16. Hey... If there are hacks against it? by DaedalusLogic · · Score: 4, Insightful

    In that case isn't the cat already out of the bag? Not like they can on the fly say that all your HD-DVDs won't work in the morning... The only thing that they can do is prevent future media from playing on that model of HD-DVD player.

    We have seen that play before, cripple the next hot DVD to hit the market and what do you get? A ton of product returns and pissed off customers. The encryption may be more advanced, but when you want to give everyone consumer devices with the universal key to the castle... It's only a matter of time before someone figures out a way to copy it.

    1. Re:Hey... If there are hacks against it? by Anonymous Coward · · Score: 5, Insightful

      This is a very insightful concept. The above post should be modded up.

      I think this will be the major reason that you _won't_ see key revocation, ever. It sounds like a very costly ordeal for all involved. The costs of tech support at the DVD player manufacturer and customer service at the disc producer will be enormous.

      This would also be unwise for the branding concept as a whole. Branding, say, with the DVD-Video logo, is supposed to assure consumers that the product they get is system-interoperable with the other products bearing said brand. Imagine if there was a "hard incompatibility" issue between two products.

      I think the first key revocation will be a seriously expensive endeavour, and the lawsuits will fly fast and furious. Customers will initiate class-action suits against the player manufacturers and disc producers, and the trademark owner who's assurance of interoperability has been proven a false representation. Player manufacturers will in turn sue the licensing authority for the harm their trademarks will suffer, as well as costs of tech support and lawsuits.

      Disc producers may be SOL as far as suing anyone: They chose to release the discs without the complete keyset. Retailers will demand that returned product must be refunded; despite the fact that it is currently not industry practice. (Laws will force retailers to accept returned product that is defective.)

      This is really a train wreck in the making. Bad medicine.

  17. This isn't new news... by harmless_mammal · · Score: 5, Interesting

    Here's analysis of AACS that was blogged last December. One interesting point mentioned is that there is no requirement to wait for keys to get compromized before revocation begins. They can revoke keys whenever they want, publicly claim it was due to hackers, and stimulate new equipment sales any time they want.

    1. Re:This isn't new news... by Anonymous Coward · · Score: 2, Insightful
      One interesting point mentioned is that there is no requirement to wait for keys to get compromized before revocation begins.
      Yes, there is. There are the warranties of merchantability and fitness for a particular purpose. Better yet, in the USA at least, collusion between player and movie makers to breach a warranty would probably run afoul of the Racketeer Influenced and Corrupt Organizations Act.

      This garbage is doomed to die. Either they will have to conspicuously advertise the players as unreliable and the movies as not watchable on all players, or they get their asses sued into the ground.

  18. Re:Protecting everyone's interests. by Dwonis · · Score: 4, Insightful

    Consumers' best interests would be best served my using NO crypto. All that crypto hardware/software costs money to develop and manufacture. Guess who pays for it in the end?

  19. Re:It's all about firmware? by Frank+T.+Lofaro+Jr. · · Score: 3, Insightful

    Then DVDs will die.

    Most people won't even know what you are talking about.

    Now having new DVDs automatically update the firmware is easy, stealthy, evil, and effective. I think some DRM systems use such an idea.

    The user merely watches a movie, and their player gets reflashed in the process. That could work.

    Expecting the average movie watcher to even know what to do with a USB cable and how to boot something off an external drive won't.

    --
    Just because it CAN be done, doesn't mean it should!
  20. Industrial sabotage possibilities? by TheOriginalRevdoc · · Score: 3, Insightful

    Seems to me that a manufacturer could sabotage another manufacturer's products by hacking them (under cover, of course) while they're still available new. That would make the players almost impossible to sell.

    Aaah, now I see their dastardly plot... in order to avoid this, manufacturers will be forced to make their products hack-proof. Tricky, eh?

  21. When will they learn? by rips123 · · Score: 5, Insightful
    Remember when macrovision changed the hsync/vsync patterns of the video signals to stop VCR's copying tapes?

    Remember Apple IIe games that wrote bad sectors or extra sectors and other such nasties to try and stop people copying 5-1/4 inch floppies?

    Remember SecureROM and others making CD copy protection by intentionally leaving broken sectors on CDs - making them unburnable in nearly all of the burners at that time?

    Remember that DVD's were once uncopyable?

    Remember when Pay TV signals were encrypted by obfuscating their signal with some analogue hardware?

    Remember when they started using proprietary digital encryption for Pay TV (Irdeto)?

    Every time someone offers up content in some protected form, someone is going to break it. Period. Even if they can't break it, someone will use a legitimate DVD player and screen/sound grab their favorite movies using a capture card.

    The only difference I see now is that the companies implementing these measures are monopolies whereas they used to smaller players in their respective markets. This might mean that they can push some legislation through to discourage copying but nothing will ever stop it IMHO.

  22. Definition of insanity? by DMouse · · Score: 4, Insightful

    Keeping on doing the same thing, and expecting a different result.

  23. Not with the Free Trade Agreement They/We Can't! by thecampbeln · · Score: 2, Informative

    The Aussi-Gringo FTA fucked allot of things for the Aussi's (though they thankfully avoided the worst on their government prescription drugs program). From what I saw and heard, the FTA has little to nothing in it for Aussi's (loss of domestic TV programs, lingering threats to their PBS, etc). And the DCMA-esque copyright "equivalents" required by the FTA are headed their way (if not already implemented, life +70 years anyone?). The FTA is the only reason Australia has troops on the ground in Iraq, because the misguided "head jerks" wanted that fucking thing so damned bad for whatever reason ("Oh, oh, we can mitigate problems between the US and China because of our relationships with the two countries!" - so what? When two elephants dance, all you can do is get the hell out of the way).

    --
    "1984" was ment to be a warning, not a guidebook. You hear that Kim Jong-il!? BushCo?!
  24. people will just go old school then by davesag · · Score: 3, Insightful

    well i guess it's back to the old school - telecini a projection of the dvd onto an HD recorder. if it can be seen and heard, it can be copied. and one open copy is enough.

    --
    I used to have a better sig than this, but I got tired of it
  25. better crack the PS3 first ;-) by cheekyboy · · Score: 2, Funny

    to piss of sony, after all they are part of the consortium , ahhaahahahha

    --
    Liberty freedom are no1, not dicks in suits.
  26. Contary to consmer laws... by Anonymous Coward · · Score: 3, Insightful

    So I have a popular player. Someone hacks it. They revoke the key. I buy a new DVD. It doesn't play. I return it to the shop as faulty - it is clearly a faulty disc as my player plays all other discs fine. This bounces back on the producers as retailers don't want the hassle - I can't see them wanting to deal with the flood of customer returns.
    Trading standards [insert the name of your country's equivalent consumer protection agency] could take the view that the retailer is knowingly selling faulty goods. The retailer would just refuse to stock any revoked discs in future.

    I think the risks of revoking keys are just too great for them to actually do.
    If they were dumb enough to do it, I can see huge global hacking effort to compromise as many players as possible, which would make the scheme unworkable.

    If a major player maker's keys are revoked, they could easily appease customers by slipping them a firmware upgrade with alternate keys - maybe in the guise of a firmware disc intended for a new model that 'just happens' to also work on the older units.

  27. It doesn't suck - it's perfect! by cheros · · Score: 4, Interesting

    Just think about it: to which extend can you abuse consumers? To the point where they discover they don't like the product.

    At that point the bottom will fall out of the market.

    Proof: see what DVD players sell best: those with zone restrictions or those without. The irony is that that does not happen because of piracy (pirated DVD appear to be generally set to zone 0 so zone selection is irrelevant) but because of legitimate purchases made elsewhere in the world.

    So, in summary, let them progress down this route. Eventually the market will die as alternatives pick up the revenue.

    As an example: how many of you buy protected contents or media in non-Open formats?

    I have looked at pirated DVDs and they are indeed not worth the money - if you're in a country with sane media prices. If they really, really, really wanted to address piracy all they need to do is become more sensible with the prices, that has already proved to work (hello MS, are you listening?). The increase in revenue more than offsets the expenditure they have to put in on lobbying, researching formats that don't work or get broken in a rainy weekend by a couple of bored teenagers.

    Hell, it'll probably even keep them in cocaine and limos.

    --
    Insert .sig here. Send no money now. Owner may sue, contents will settle. Batteries not included.
  28. They aren't trying to stop piracy. by mcc · · Score: 5, Insightful

    They don't care about piracy. This isn't, and never has been, about piracy.

    What they care about is control.

    They care about linux distributions adding support to play HD-DVD movies, but not paying license fees to the DVD forum.

    They care about HD-DVD players cropping up that allow you to fast-forward past the trailers at the beginning of the movie, the ones where a licensed player, when you say "fast forward", says "no".

    They care about people making players behind their back which openly flaunt the "region locking" mechanisms that make regional price discrimination possible.

    They care about products like DVDXCopy which allow consumers to exercise their fair use rights and do God knows what with the products they purchase.

    These are the things they're trying to stop or hinder. Their choice of technology simply reflects that. AACS will do little in the short run and nothing in the long run to prevent piracy. But the legal barriers the media companies paid to erect will allow AACS to keep all four of the above things off of the general commercial market.

    1. Re:They aren't trying to stop piracy. by DrHyde · · Score: 2, Interesting

      Originally, different countries in the EU were going to be in different DVD regions. This was illegal, and so the 15 EU countries were all put in the same region. The solution, therefore, is for the EU to admit a few third world backwater jurisdictions to membership. I propose Sao Tome, Pitcairn Island, Bhutan, Kaliningrad, Rhode Island, and Macao. Hey presto, no region locking.

    2. Re:They aren't trying to stop piracy. by milosoftware · · Score: 3, Insightful

      You forgot the chinese - or whatever place they make those - players that probably didn't care about license fees - they're not open source but they're free. As in freedom of speech.

      And they care about their contracts with the big manufacturers, which in return allows the biggies to lock out newcomers. How are you, as a startup DVD player manufacturer ever going to get a key for your device? Of couse any manufacturer can get a key, free of charge. You just have to pay the gazillion dollar "administration" fee. Just like MP3 - it costs only $2.50 per user license to sell an MP3 encoding device. But there's a minimum of 15000 per year, which makes it impossible for shareware authors to include MP3 encoding at reasonable cost.

      And without the protection mechanism, there would have been much less fees to pay, to begin with.

      --
      Musicians don't die. They just decompose.
  29. Actual quotes by mattr · · Score: 5, Insightful
    From AACS_Spec-Common_0.90.pdf

    Page 24: Each compliant device is given a set of secret Device keys when manufactured. ...The set of device keys may either be unique per device, or used commonly by multiple devices. ...The [Media Key Block] system is based on a large master tree of keys, with each set of Device Keys being associated with a leaf node of the tree... Further, corresponding to every sub-tree in the master tree is another set of system keys... Thus, the subset-difference tree has to store one encryption per Device Key set revoked, and occasionally additional encryptions to pick up non-revoked sets not covered by the smaller sub-trees. On average, there are 1.28 enrcryptions per revocation.

    The document goes on to mention around pages 27 and 28 that devices obtain key conversion data by mechanisms called out in the AACS liscense, and recording devices must verify the signature and determine by its version number field whether a Media Key Block is more recent than the one currently on the media. "Each time the AACS LA changes the revocation, it increments the version number and inserts the new value in subsequent Media Key Blocks."

    This says to me that the DVDs you buy will in fact be the transport mechanism for updated revocation keys, and presumably your player will be able to store a lot of them. So movie production companies and distributors must conspire to continually subvert the functionality of a consumer's device, and this does not require the player to be online nor will a firewall help. Once you get yourself locked into the prison of this coded delivery system, your own buying habits will keep adding additional chains to your cage. It is quite insidious, not only are they using military-level technology to control movies, the system is founded on the complicity of the entertainment industry, the electronics industry, and consumers themselves (and the consumer's PC if used) with constant policing and injection of targeted death-messages into the distribution channel. It also looks like the drive can potentially disable media (page 41) and even report hacked hosts/drives by recording onto the media (it seems kind of vague but it is writing a concatenation of the "Binding_Nonce", "Drive_Nonce" and "Host_Nonce" to the protected data area, whatever these things are), which if this is indeed true would I suppose be reported through other PCs/drives of people to whom you lend the media, or maybe through even a shared Internet connection, if you want to try extrapolating this.

    Sorry I got ahead of myself. Page 55 talks a lot about online connections, online enabled content and streamed content. It talks about Title Keys and says "the word 'title' is often overloaded. For example a title can refer to a full-feature movie, a TV program, a music album, etc. ... however [we] .. define Title to be a distinct path.. That is, a Title is a logical grouping of content material to be presented in a specific order in time." It also mentions an "Enhanced Device" that is online and can then provide full access to Enhanced Titles that require online connections or extended player functionality. Page 56 mentions a Cacheable Permission that expires after a certain amount of time or include a "do not play until" date, and the XML based Title Usage File is based on global, not local time, which if used must be based on a "secure clock" whatever that is. Oh yeah, on page 59 it mentions the default connection protocol can operate (by https) over Ethernet, firewire, WLAN, etc. so you know this is not just about an HD DVD format but looks like it is trying to take over every device in the vicinity as well. How much you want to bet this will police titles not actually loaded in the player?

    I think the cutest part is page 61, where it shows how you can go online with a PIN number and a remote Clearing House server can offer a title

  30. Re:It's all about firmware? by CdBee · · Score: 2, Interesting

    Find the EEPROM chip which houses the firmware, copy data off it into an EPROM of similar size and install in the original chip's socket.

    (EEPROM can be electrically erased, EPROM can't be reflashed by software). This depends on the ROM chip being a standard type rather than custom. Otherwise we're down to third-party modchips.

    --
    I have been a user for about 10 years. This ends Feb 2014. The site's been ruined. I'm off. Dice, FU
  31. framebuffer by Anonymous Coward · · Score: 2, Insightful

    There must be decoded framebuffer somewhere to be blitted (and which can be memcpy to somewhere else, frame by frame). This can be then converted and repacked from raw. If going hardcore, then stepping some dvd player in debugger. Same goes for sound. I guess we won't see computer implementation of the thing.

  32. Extortion Opprotunity by TobascoKid · · Score: 4, Interesting

    With that in mind, it's clear that you can read what you quoted in the above sense, and indeed it's the plausible way to read it: it's not "causes a compromised device to be unable...", it's "causes a device with the compromised set of Device Keys to be unable...". Any device using this set of keys--whether it's superDeCSS or any particular machine of the sort that was compromised, or any other machine that shares the same set of keys--will no longer be able to view content--presumably only new content created after the revocation.

    To me, this seems to be a golden opprotunity for organized crime, assuming they hire hackers good enough to reverse engineer a particular DVD player.

    For example, say Sony make a really popular player, so organized crime get the AACS code hacked and then turn around and extort Sony - give us a lot of money or we'll release the key. If they release the key and this device blocking kicks in, Sony are going to have a lot of angry custumers demanding their money back.

    --
    At some point, somewhere, the entire internet will be found to be illegal.
    1. Re:Extortion Opprotunity by Jack+Pirate · · Score: 2, Funny

      I was thinking organized crime in a different way:

      1. Sony hacks and releases the codes for their competitors
      2. ???
      3. Profit!

    2. Re:Extortion Opprotunity by XMyth · · Score: 3, Interesting

      A real popular player like the Playstation 3?

      Imagine if that got its keys revoked....

    3. Re:Extortion Opprotunity by HeroreV · · Score: 2, Insightful

      The PlayStation 3 will use Blu-Ray discs, which were developed partially by Sony. It wouldn't make any sense for them to include a costly seperate drive to play the competing format.

      I know there's been talk about Blu-Ray disks using AACS, but there hasn't been any confirmation about that yet as far as I know.

      Just an FYI for those that might have been confused by the parent poster.

  33. Re:wtf? by Halo1 · · Score: 4, Informative
    why is the usa to blame for what australia does?
    Have a look at e.g. this. More via Google. Of course, Australia could have said "no" to it or demanded different conditions, but that's not the easiest thing to do if a 500 pound gorilla wants to have it another way. Trade policy is a very strong weapon between so-called "developed" countries.
    --
    Donate free food here
  34. So they are using AES? by pesc · · Score: 4, Funny

    Here is why using a stronger crypto or longer keys is not always the answer. The design of the system around it matters too.

    --

    )9TSS
  35. There is no warranty on hardware in U.S.? by Maljin+Jolt · · Score: 3, Interesting

    I can't imagine hardware vendors would accept that kind of technology abuse. In almost all European countries there is legally enforcable 2 years warranty for hardware products. Even if non-Europe manufacturer provides less time for warranty, retailer shop must comply with full time period.

    So, that would be a legal massacre of retailers/vendors/manufacturers by consumers/consumers organisations.

    --
    There you are, staring at me again.
  36. Re:Protecting everyone's interests. by TheRaven64 · · Score: 2, Insightful

    An open source DRM system could not possibly work. DRM systems work entirely on the basis that the decryption system is a black box - or at the very least that the user has no way to access the key. If the user could decrypt the stream and output it to disk, then the DRM has failed. To make matters worse, only one user in the entire world needs to be able to do this for the DRM to have failed, since they can then distribute their copy to everyone else.

    --
    I am TheRaven on Soylent News
  37. Re:Higher unit cost for Blu-Ray by mattkinabrewmindspri · · Score: 4, Informative
    Blu-Ray seems to have more support from the companies that matter right now: Sony is using Blu-Ray in the next Playstation, and blu-ray.com lists many the companies in the Blu-Ray Consortium as "Apple, Dell, Hitachi, HP, JVC, LG, Mitsubishi, Panasonic, Pioneer, Philips, Samsung, Sharp, Sony, TDK and Thomson", which points to Blu-Ray's support in the PC industry. And with Sony's support in the gaming industry, and Dell, HP, Sony, Apple and others' support in the PC industry, I think people will be more likely to have a BD-ROM(Blu-Ray) in their house.

    Also, contrary to what you may have heard, Blu-Ray discs will not require a cartridge. Blu-Ray discs should be more scratch-resistant than even current CDs and DVDs.

    And about capacity: HD-DVD can only hold 30GB(15GB per layer), but Blu-Ray can hold 54GB(27GB per layer). In the future, Blu-Ray discs could even hold up to 200GB.

  38. Isn't it about time we lobbied for a fair use law? by akc · · Score: 4, Insightful

    The monopoly given to content owners to determine what others can do with content is subject to some "fair-use" caveats.

    Isn't it about time that we, the people who are paying for this content get our fair use rights looked after. Anyone putting DRM controls in place should have a legal obligation to ensure that if if a customer has paid for the right to have access to the content that they also get their fair use rights as well.

    It seems to me that the sorts of controlling technologies that are being envisaged here do not safeguard those rights. Isn't it about time we pressurised our democratic representives to ensure that we don't lose them?

  39. Re:It's all about firmware? by RKBA · · Score: 2, Interesting

    Or just clip off the write enable pin on the EEPROM and ground it (or pull it high depending on the logic).

  40. Re:Protecting everyone's interests. by finkployd · · Score: 2, Insightful

    They can use all the open crypto methods they want, that does not hide the fact that the flawed concept that is DRM depends completely on security by obscurity. It is not the crypto, it is the fact that you have to give the user the private key to unlock the data (because it has to reside on his machine) but you want to keep it hidden from him so that he cannot use it to decrypt the data at will. Someone WILL eventually find the key and extract it. If not from the hardware then from a software based player.

    Finkployd

  41. force obsolescence == forced "upgrades"!! by JonTurner · · Score: 3, Insightful

    Think about it. For most people, their first DVD player is their *last* DVD player. Which is only replaced if something wears out or breaks. Now, with this nifty key-expiring system, the DVDCCA can "break" DVD player's by edict.

    What better way to keep people purchasing hardware than to force obsolescence?

  42. Why hack the decryption keys? by Xoder · · Score: 2, Funny

    I think hacking the revocation keys could be more interesting.

    A: Dude, I got this great new movie, wanna see it?
    B: Yeah!
    [A puts in an HD-DVD-R with all major revoke keys on it]
    A: Oh shit, its not working man.
    [A enjoys the little prank he played on B who will never be able to watch a movie again on his player...]

    --
    The previous sig has been removed due to /. protecting your best interests
  43. Look to your own house by FreeUser · · Score: 4, Insightful

    In Australia it now is, we are not allowed to create any copy protection circumvention mechanisms. To all you Americans: thanks for nothing.

    Last I checked US troops aren't marching house to house in Australia, or occupying the Australian parliament.

    Blame your own gutless politicians for your own mess. I don't blame Aussies for Bush being in office, despite the fact that one right-wing Aussie happens to own FOX and had no small part in running the propoganda machine that conviced approximately 50% of the US voters to vote the moron back into office.

    You're responsible for your own mess, and the sooner you take your own leaders to task for it, rather than blaming a foreign power, the sooner you'll get it fixed. The same goes for us, by the way. The sooner we start blaming our own leaders for the current mess, rather than boogeymen in caves and Al Q'aide, the sooner our mess here in the states will get sorted out.

    I don't expect either country's population to do this anytime soon, however.

    --
    The Future of Human Evolution: Autonomy
  44. NOT HOW IT WORKS!!! by xphaedrus · · Score: 5, Informative

    I'm a cryptographer, posting belatedly. I don't know if anyone will see this or read it but I had to comment.

    Almost all of the assumptions in this thread are wrong. The system does not work cryptographically in the way people imagine. The technology makes it possible to efficiently revoke INDIVIDUAL DEVICES, not entire model lines. Every device can have a unique key, even if there are millions of them. There is no necessity or desire to make people's non-hacked players stop working. As others have pointed out, this would be INSANE. That's not how it works!

    Cryptographically, this system allows the data to be encrypted to any of millions or even billions of devices, using a very short encrypted key block. What happens is that if some of those (individual!) devices get revoked, the size of the key block increases. Amazingly, the size is dependent on how many devices get revoked, not on how many devices there are. If extracting keys from a device is complicated and expensive, and not too many need to get revoked over the lifetime of the system, it will be a success.

    The cryptographic technique is described in a paper from Crypto 2001 called Revocation and Tracing Schemes for Stateless Receivers by Naor et al and is available from http://www.wisdom.weizmann.ac.il/~naor/PAPERS/2nl_ no_fig.pdf. I will describe an over-simplified version.

    Imagine creating a binary tree with enough leaf nodes to hold all of the devices (again, this is individual devices, not model lines). Each device is associated with a particular leaf node of the tree. Now we assign a random AES key to every node of the tree, leaf nodes and internal nodes.

    At manufacture time, each device is given all of the keys corresponding to its branch of the tree; that is, the key for its leaf node, and the keys for the parent, grandparent, etc. of that node, all the way back to the root node of the tree. As long as the disk is encrypted to one of these keys, the device can play the disk. Note that even if there are a billion device nodes in the tree this is only about 30 keys that a device has to hold, which is trivial.

    Now, to create a disk, initially it is encrypted to the root node of the tree. All devices have the key for that node so all devices can play it. The key block is very short. But now suppose that someone manages to extract the secret device keys in their device, they get published on the internet (as happened initially with DeCSS), and everyone is able to use them to decrypt HD-DVDs. (BTW this system is also being used for Blue-ray! Don't think that's going to be any different!) Now what do we do?

    What happens is that new disks are no longer encrypted to the root key. Instead, we partition the tree into subtrees that include every leaf node except the one which got its keys published. Now we encrypt the disk data to the root nodes of those subtrees, rather than to the root node of the whole tree. This will allow every other device still to decrypt the data, but that one hacked device can no longer decrypt new disks. The size of the key block grows based on the number of hacked players.

    This is an oversimplified version because the size of the key block is bigger than desired. The paper above shows a more complex system, which is actually being used, which makes the size of the key block linear in the number of hacked systems. Assuming that hacking them remains relatively difficult, this should be an effective and efficient content protection system.

    Basically this is the same method being used in current satellite TV systems, and for the past few years it has been successful enough that satellite piracy in the U.S. at least is largely a thing of the past.