Slashdot Mirror


HD-DVD and Blu-Ray AACS DRM Cracked

EGSonikku writes "According to this article on Endgadget, the AACS DRM used in HD-DVD and Blu-Ray has been cracked. The program allows one to decrypt and dump the video for play on a users hard drive, or it can be burned to a blank HD-DVD and played on a stand-alone player. According to the accompanying video, a source release for the program will be made available in January. Time to get that $200 Xbox 360 HD-DVD drive?" Warning: this link contains video.

29 of 432 comments (clear)

  1. Re:Cheers! by Anonymous Coward · · Score: 5, Insightful

    Not to me, it isn't. This will help speed up the adoption of these formats. I'd like them both to totally fail, due to their restrictive DRM. As long as the formats enjoy some success, the content providers will keep pushing for the strong DRM.

  2. Well and good... by Ekhymosis · · Score: 4, Insightful

    But I would like to know how this will affect the customer as well. I know short term that DRM is bad and all, especially with the "where there's a will, there's a way" mentality in cracking it, but seeing as how these companies invest (or rather waste) millions in copy protection schemes, will they jack the prices up to cover the cost of their mistakes? I think this practice has become mainstream, no?

    --
    Fighting over religion is like seeing whose imaginary friend is best.
  3. Re:Not really cracked, more like circumvented by FuturePastNow · · Score: 5, Insightful
    According to the program's creator:

    I was very surprise to realize that the title key is there, in memory!

    Older systems make Trusted Computing their bitch. Oh yeah.
    --
    Give a man fire, and you warm him for the night. Set a man on fire, and you warm him for the rest of his life.
  4. Why this may be good... by mitchell_pgh · · Score: 4, Insightful

    Basically HD-DVD and Blu-Ray aren't even options for me at this point as the DRM associated with it has me shaking my head. While I'm willing to pay $20+ for a movie, I want to be able to use the movie on my terms after the initial purchase.

    If this hack proves to be valid, I would actually consider investing in the technology as it opens the format up to Linux/Unix/OSX/etc.

  5. Re:It takes a while... by evilviper · · Score: 4, Insightful
    AACS was designed so that keys could be revoked fro future titles.

    So was DVD CSS...

    Would you care to guess how well that worked?
    --
    Slashdot gets worse every day... Pipedot: News for nerds, without the corporate slant
  6. HDCP by StreetStealth · · Score: 5, Insightful

    It seems to me most people are seeing this as a means to:

    A) Place-shift HD-DVD content (despite current storage constraints)
    B) Pirate HD-DVD content (despite current bandwidth constraints)

    when I see the much more immediately relevant issue being that of HDCP: If this crack can be rolled into something on the order of a VLC plugin, there's a chance I'll actually be able to use my technically-more-than-capable, yet not-a-member-of-the-HDCP-club LCD display to view commercial 720p content.

    --
    Your mind is clear / The things that you fear / Will fade with how much you / Believe what you hear
  7. Re:Mmm but would you do it? by TexasDex · · Score: 4, Insightful
    The point is with the Hi-Def media, it doesn't make as much sense to rip every movie you have and store it on your fileserver for the next year or two. This is awesome news but i am not sure i'll be ripping HD-DVDs/Blu-ray disks like i used to rip DVDs. These things take way too much space. Hollywood would have an edge if they priced the stuff at around 15-20$ - i'd buy one than let a movie take up 30GB on my machine.
    Wait 5 years and read that post again. I bet you'll laugh. "Only 24 gigs?" you'll say. "That's nothing!" I guarentee it.

    To put it in prespective: My old 486 had a hard disk with less than 400 MB of space. But it also had a CD-ROM drive. Your average CD back then held 650MB. Yes, it had an optical drive that was bigger than its hard disk. Nobody ever thought to even include copy protection on the CD because storing that much data was insane, and transmitting it over the internet even more so. With the advent of MP3 and bigger storage and broadband it became commonplace to trade music online.

    My brother got one of the first computers that came equipped with a DVD drive, which has a capacity of 4.7 GB (I'm ignoring the whole multi-layer DVD format for sake of simplicity). It also came with a hard disk that could hold up to 2 Gigabytes. Now your average DVD can be recompressed without too much quality loss to, say, 1.5GB, and modern hard disks will store hundreds of them with ease, and you can download them in an hour or two on a good connection, or maybe a day on an okay one. Are you noticing a recurring theme here?

    The truth is that Blu-ray isn't all that big compared to the hard disks of today, especially not when you look at previous optical formats and how big they were in comparison to the hard disks of the era in which they were first made. Heck I could fit a Blu-ray disk or two on my iPod and have some space left over.

    Such is the progress of technology (by which I mean mostly storage space and bandwidth, but also compression technology and the processor power to implement it). A digital movie standard such as Blu-ray or HDDVD should be expected to last a decade. They will probably last even longer than that because hi-def technology has matured to the point where users couldn't possibly need higher resolution or more pristine sound effects. Where do you think magnetic storage will be in ten years? Heck, where do you think solid-state storage will be in ten years?

    The point is that technology changes, and people invent things like MP3 that let you squeeze more into smaller space. Which means movie format won't stop piracy because it's "too big".
    --
    The Cheese Stands Alone.
  8. Re:Not really cracked, more like circumvented by Bios_Hakr · · Score: 4, Insightful

    It's pretty early in the rollout. The execs will kill off the format and release a new system within a year. HD-DVD-2 or something like that.

    Then, they'll just not give the keys to PowerDVD.

    Note to all future hackers. Wait till you have critical mass before you release a crack.

    --
    I'd rather you do it wrong, than for me to have to do it at all.
  9. Will every player key be cracked? by dave1g · · Score: 4, Insightful

    So the player key is hard to get at, so this guy worked around it and just copied the title key from memory, which is encrypted on disc with every player key. Since you have the plain text (of the title key) and each of the cypher texts(the encrypted title key), aren't there attacks to figure out all the player keys? And actually its worse since you have many(possibly all?) title keys and all their corresponding encrypted versions that has to extremely limit the search space for the player keys. This would be an even worse problem since they cant just revoke every key. All the hardware would break! Lawsuits galore!

    Seems like the whole house of cards will fall down.

  10. Re:Sort of Cracked by Dachannien · · Score: 3, Insightful

    If that's how he's doing it - by distributing disc keys - then the studios will just start making shorter runs of the discs from the same master. There'll be, say, a hundred different disc keys for the same movie, and you won't know which one you have until you try them all. An individual or group would have to get hold of all 100 discs (or at least the portions of each that store the disc keys) to compile a complete list.

    While it's certainly a move in the right direction, unfortunately, it's far from ideal. The reason I feel no moral compunction about saying this is because of your astute observation that this DRM scheme utterly fails to prevent piracy and instead is unfairly limiting how legitimate customers can use the products they buy. It's likely that this was the primary intent all along.

  11. Re:Cheers! by msobkow · · Score: 4, Insightful

    I agree. We shouldn't have to risk harassment from the *AA for exercising rights that have been granted to us by precendence in different countries, especially those which find their root in UK/Commonwealth legal systems.

    It's unfair to expect the individual consumer to fend off such attacks, and insulting to the intent of law to allow the attacks to occur in the first place. The *AA and the various DRM fans are responsible for developing products and solutions/proposals that are compliant with the laws of their target markets, and should not be trying to shove their vision down our throats just to protect oligopoly and monopoly economic models.

    The same goes for all industries. Why else has the EU so soundly rejected US proposals to make their patent database a global starting point for managing IP? It's stuffed with speculative junk patents.

    --
    I do not fail; I succeed at finding out what does not work.
  12. Piracy not equal to Losses by kurt555gs · · Score: 4, Insightful

    I do not agree that piracy has anything to do with losses. Who is to say that those that watch movies without paying a fee would actually pay to see them in the first place?

    The only way there is a real loss is if some one is SELLING copied DVDs as if they are original. That is not what we are talking about here. We are in this insane mindset that if we see or hear something that we owe money to some one for it.

    Utter stupidity if you really think about the concept.

    The only way there is a real loss, is if you counterfeit the media and sell it to some one that actually WANTS to pay for it.

    This whole issue of IP ownership makes no sense if one steps back and clearly thinks about it.

    Cheers

    --
    * Carthago Delenda Est *
    1. Re:Piracy not equal to Losses by evilviper · · Score: 4, Insightful
      Who is to say that those that watch movies without paying a fee would actually pay to see them in the first place?

      The only way there is a real loss is if some one is SELLING copied DVDs as if they are original.

      Who is to say that those who buy cheaper illegal copies of movies would actually pay full price to see them in the first place?
      --
      Slashdot gets worse every day... Pipedot: News for nerds, without the corporate slant
  13. Re:Please improve the source code by Rufus211 · · Score: 4, Insightful
    A quickly glanced at the java sources.
    They are crap. No use of NIO, using Hashtable instead of HashMap and all sorts of strange quirks.
    I predict, a proper version will be *much* faster in decrypting the content.
    Please, someone with time on their hands: Improve this code

    Why would those things matter at all? 99% of your time will be spent in the java-provided AES decription routines. Optimizing a single hash lookup will make about 0 difference.

    Lookup premature optimization is and learn from others mistakes.
  14. Re:Wrong conclusion... by j-turkey · · Score: 5, Insightful
    The most basic acceptance test of any moral or social philosophy is whether it can be applied generally. Yours boils down to: I do what I think is correct. Okay, but please don't call the cops when someone punches you in the face and takes your wallet, because I am sure that it was a perfectly acceptable action to the perpetrator.

    You make a good argument, and I've heard it before. However, black and white interpretation of the law tends to fail (especially when you equate morality and law). I'll fall back on an analogy here: If you drive, do you ever speed? The law says that you cannot drive at a rate higher than the posted speed limit. However, on most major US highways, traffic tends to move at around 5% higher than the posted speed limit. Driving at the posted speed limit would cause a dangerous situation, whereas operating your vehicle in a manner consistent with the flow of traffic is a safer way to travel. Is speeding immoral? If so, should we just not drive until everyone else slows down?

    Many people make informed decisions to break the law. Whether or not this is a conscious act of civil disobedience, it is (in many cases) still a form of civil disobedience. Putting this into the context of the American alcohol prohibition, a large scale amount of civil disobedience fueled organized crime to fulfill the demand for alcohol, and the law was eventually shown to be unreasonable. A freedom limiting law was abolished because sufficient numbers of people chose to break that law. This did not cause any crumble of society, and did not turn morality upside down.

    In any case, I respect your position, but disagree with your absolute reasoning. IP license violation isn't the same as DUI, and it's not punching someone in the nose and running off their wallet. Laws like the American DMCA have unjust provisions. The grandparent poster is acting in good faith, and harming nobody. Perhaps the gpp is partaking in a phenomena of culture redefining law.

    --

    -Turkey

  15. Re:Cracker actually working for HD-DVD Consortium? by Weedlekin · · Score: 4, Insightful

    "given lackluster sales of hardware"

    The poor hardware sales are due to the following factors:

    1) Hi-def content is only of interest to the small minority of consumers who have a TV capable of displaying it, a screen big enough to notice any difference from up-scaled DVDs, and the requisite inputs, i.e. HDMI if they don't want to risk having future content down-scaled to a level that's worse than DVD.

    2) Even those who fall into (1) above are wary of the fact that there are two competing formats, so many will inevitably wait and see which of them finally wins (or alternatively, wait for a player that's compatible with both).

    3) Prices are extremely high at the moment -- for less money, one can buy a decent stand-alone DVD recorder with an integral DVR and editing system, which appeals to far more consumers due to being usable with a much wider range of TVs. The fact that DVD players are now available for less than the cost of newly released media for them does nothing to help this situation.

    4) A shortage of blue lasers means that even those early adopters who want HD-DVD or Blu-Ray players have difficulty finding one.

    5) There isn't a vast range of compelling titles in Hi-def formats, and some of those that are available don't actually look any better than the DVD version (in some cases they're worse). Furthermore, the fact that certain studios are aligned with HD-DVD while others favour Blu-Ray means that it's rare to see a movie released on both, meaning that those who opt for one format cannot view movies that only get released on the other one, thereby bringing us back to (2) above. By contrast, a $25 DVD player gives people access to a gigantic library of content, much of which is available for around $5, or can be rented, pirated, or made by individuals using cheap and readily available equipment.

    6) Early adopters with money to burn tend to read lots of reviews, and will therefore know about the problems each of the small number of available players have with some disks. These issues might be acceptable with a $25 no-name DVD player, but those who spent between $500 and $1000 on a new hi-def system will be feeling very pissed off indeed if one of the only five movies they want to watch on it doesn't play properly.

    Problems (3) and (4) will disappear fairly quickly because the lack of blue lasers is a short-term phenomenon, and once production ramps up, competition between manufacturers will progressively lower prices and ensure that dual-standard players come on to the market, possibly (i.e. not definitely) some time during the next year, and this competition will also mean problem (6) won't be (much of) an issue in a year's time. Even so, realistically speaking, the requirement for a large high-definition TV set will mean that adoption rates will remain low for a few years yet, so the range of titles will be significantly more limited than those for DVD, and sales / rental outlets will therefore devote less shelf space to them than their DVD equivalents, as indeed was the case with DVDs when VHS was the dominant format. However, unlike the VHS / DVD situation, it's easy and cheap for manufacturers to equip blue laser players with the ability to read standard DVDs, so those with existing collections aren't forced to re-buy everything in the new format, and this will probably help adoption rates once the price drops to an acceptable "impulse buy" level (i.e. below $150/Euros) and equipment is supplied with "dongles" (internal or external) that ensure output doesn't become degraded when connected to non-HDCP compatible displays (the fact that no media have HDCP yet is a short-lived phenomenon, because the media companies wouldn't have insisted it be there unless they intended to use it).

    So the probability of this crack having been unofficially sanctioned by the industry (hardware or media) is very remote indeed, because the slow hardware sales aren't in any way linked to DRM, and even if they were, hardware companies in particular could easily circumv

    --
    I'm not going to change your sheets again, Mr. Hastings.
  16. Re:Not really cracked, more like circumvented by javilon · · Score: 5, Insightful

    When a couple or three keys for _hardware_ players leak the content providers will have to make their minds up and decide if they revoke them.

    If they decide to do so, I can tell you that the whole scheme will go down. There will be people with bought and paid hardware made useless. This will be a very good example when explaining to people why DRM is a problem.

    Also, if I have learned something in this thread is that if you hack a player, you just have to keep it secret and only release the disk keys for every disk that comes out to the market. If the RIAA doesn't know what player has been hacked, they can't revoke its key. Having one player hacked will invalidate the whole schema as long as the RIAA doesn't know wich one is it.

    I am the owner of a High Definition 50 inches TV, with only DVI input. That I see as a good thing. I will not be tempted by the new High Definition *paid* content. There is no way I will be paying another 3000 for a new set just because the content providers refuse to show their content on my perfectly good one. This is also a good way to explain people what DRM is about.

    --


    When his defense asked, "Which computer has Jon Johansen trespassed upon?" the answer was: "His own."
  17. Re:Not really cracked, more like circumvented by Splab · · Score: 3, Insightful

    if it's already possible to decrypt blueray/hd-dvd, won't they have to wait for next generation untill next round? The fun thing is, the DRM guys gets one swing at it, while the hackers can poke around untill they beat it. It's a lost war.

  18. Re:Sort of Cracked by RAMMS+EIN · · Score: 4, Insightful

    ``But instead of extracting their player key and publishing that, he played a disc in a debug environment and extracted the 'disc key' for that specific title.''

    So now the next step is to disallow running software in a debugger, just like in The Right to Read

    --
    Please correct me if I got my facts wrong.
  19. Re:Cheers! by WhatAmIDoingHere · · Score: 4, Insightful

    DVD had more to offer over VHS compared to HD-DVD and BluRay over DVD. DVD offered no rewinding, special features, easy chapter browsing.. All things that VHS lacked. That's why DVD won over VHS. All they're offering in HD-DVD and BluRay is Slightly Higher Def, which is lost on like 95% of the TV owning public. Oh, and restrictive phone-in DRM.

    --
    Not a Twitter sockpuppet... but I wish I was.
  20. Re:Not really cracked, more like circumvented by pla · · Score: 4, Insightful

    Of course, it's always going to be the case the key is in memory during playback, finding the address would be the pain

    Not really... Even without any better strategy, you can narrow the potential range down QUITE a bit (within one process' address space), and exhaustively try every machine-aligned keylength-block in just a few seconds. And it would surprise me greatly if we can't do a whole lot better than that



    and revoke keys in future pressings and force upgrades to software users.

    Revocation accomplishes nothing (except, as with most DRM, annoying legitimate users) if the cracker can get the key dynamically. This problem WILL result in the eventual blacklisting of XP for HD content, at which point the protection of AACS will reduce to the security of Vista's kernel (ie, already cracked).



    It's all about demonstrating clear intent to violate DMCA and take legal rather technical measures to 'deal' with the problem.

    Bingo. Although it does look like they at least tried to make it somewhat hard this time, no solution (not even quantum) exists to the cryptography problem where "Bob" and "Carol" (the "man-in-the-middle") count as the same entity.

  21. Re:Cheers! by aplusjimages · · Score: 4, Insightful

    Always look to the porn industry. Where is the porn industry at right now? Still on DVD and downloadable content. Downloadable content is the future. Sing it with me "Downloadable Content is the way to go."

    --
    Can I bum a sig?
  22. OK. . . by kimvette · · Score: 3, Insightful

    NOW I am willing to buy hi-def DVDs since I can:
      - Take advantage of Fair Use (make backups, format-shift to my PocketPC, keep copies of the movies on my HDD)
      - Play DVDs on Linux
      - Not worry about downsampling output on non-HDCP video cards

    Now the Blu-Ray vs. HD-DVD format war does not matter so much. Does anyone here care WHICH one wins now that both have been cracked?

    Thanks guys, you rock!

    --
    The Christian Right is Neither (Christian nor right). See: Matthew 23, Matthew 25, Ezekiel 16:48-50
  23. Re:It takes a while... by IamTheRealMike · · Score: 4, Insightful

    Yes. The major difference between AACS and CSS is that every player in the world can have a unique key, rather than just the 20 or so keys that CSS used. If PowerDVD is not adequately protecting the key then it will be barred from accessing new titles and a software upgrade will be required for PowerDVD players. For hardware DVD players, the key is usually far better protected anyway, but if it is somehow extracted then a firmware reflash and/or a physical hardware swap (paid for by the manufacturer) is the way it'll be done.

    Basically, the summary is totally misleading, as per usual with Slashdot + DRM. AACS has not been cracked. A single badly protected player was cracked and its key will be revoked, as the AACS spec provisions for. The scheme was designed to be "damage resistant" and that's what we're seeing at work.

  24. Re:Cheers! by NormalVisual · · Score: 4, Insightful

    It's also interesting in that the porn industry sees by far the most copyright infringement, but seems to care about it a lot less than the **AA does. Even with all that copying going on, they still somehow are able to make quite a bit of money without whining about it and suing people left and right.

    --
    Please stand clear of the doors, por favor mantenganse alejado de las puertas
  25. Re:Not really cracked, more like circumvented by Splab · · Score: 3, Insightful

    The movie is encrypted with a single key, so if only the movie key gets put on the intarweb, they can't figure out what key to revoke. And as lots of others has pointed out, while in theory it sounds like a good solution to revoke a key, you can't do that in the real world.

    Perhaps in the US where the consumer watch dogs are less fierce than those in my neck of the woods you can cripple a paid for product. But here in Denmark the company would be forced to ship replacement units should the key be revoked, and let's see how many times you can go do that until the consumers demand their money back (yeah, you can do that here if the product is broken for up to two years).

    Even with the trusted hardware paths it's only a matter of time until the consumers realize what a bad thing DRM is. It's a lost fight, they should spend their money on making a better product rather than trying to find the holy grail.

  26. Re:Cheers! by ajs318 · · Score: 4, Insightful

    Betamax VCRs never really became "shiny pieces of garbage" in the way Blu-Ray / HDDVD machines will. The crucial thing is, video cassettes were always recordable. You can still watch all your old recordings of Charles and Di's wedding, Fawlty Towers, It's A Wonderful Life and the entire Carry On series, and even record new programmes (VHS tape is the correct width, 12.7, to be wound into worn-out Beta cassettes; but note that you do need to keep the original metallic leader tape, since Beta and VHS used different auto-stop mechanisms and clear plastic leader won't trigger it). As I've hinted elsewhere, Betamax has better resolution and better colour reproduction.

    The problem with play-only formats is exactly that: they are play-only, and so there can come a point where nobody is making any new material to play on them.

    --
    Je fume. Tu fumes. Nous fûmes!
  27. Re:Cheers! by NormalVisual · · Score: 3, Insightful

    Or put another way, the porn industry has a business model that is more resilent to outside influences beyond their control without having to buy off politicians. Yeah, you don't players in the porn scene that are multi-millionaires to the degree of someone like Tom Cruise, but in general they seem to do well when compared with the average American.

    --
    Please stand clear of the doors, por favor mantenganse alejado de las puertas
  28. Re:Wrong conclusion... by ajs318 · · Score: 3, Insightful

    When I buy a DVD, I buy a disk that has a movie on it - not a license.

    I believe the company that manufactured that disk disagrees with you.

    What the company that manufactured that disc thinks is irrelevant. They accepted payment for it; it's not their property anymore. According to the Law of the Land, what anybody does with it from that moment on is None Of The Manufacturer's Damn Business.

    You might not realize this but but your statement doesn't do anything to clarify what you own

    No, but consumer protection law is quite clear on the matter. Your right to use any article purchased at retail by you for its Rightful Purpose is protected by the Law of the Land. If you purchase a DVD at retail, its Rightful Purpose includes private home viewing by the owner, their friends and family and for which an admission fee is not charged. If the goods you have purchased are not fit for their Rightful Purpose, then you are entitled to return it to the place of purchase and receive a full refund of the purchase price paid.

    Do you actually own the disk?

    You paid money for it. It's your property.

    Can that ownership be revoked?

    That would be called Theft.

    Are you entitled to a copy of the disk if that disk is damaged or destroyed?

    Not necessarily. It is your property and you are generally responsible for taking proper care of it. However, unauthorised, deliberate damage by a third party may constitute Criminal Damage.

    Do you own the contents of that disk? Are you licensed to watch the contents of that disk?

    Watching the contents of the disc would be considered the Rightful Purpose of the disc. Your right to use your own property for its Rightful Purpose is protected by the Law of the Land. You do not need any other licence to watch it.

    Are you no longer a licensed viewer of the contents of that disk when that disk is no longer viewable (destroyed/damaged)?

    You do not need any licence to view the contents of the disc. Your right to do so stems directly from your ownership of the disc. If the disc is covered by an insurance policy, the original disc will become the property of the insurer when they pay out (and therefore you would no longer have the right to view its content) -- however, they may give it to you anyway, in order to transfer any obligations regarding proper recycling of waste onto you.

    Are you licensed to show the contents of that disk to non-licensed viewers?

    You do not need any licence to view the contents of the disc. Refer to established case law regarding viewing of recordings. Generally, it is OK to show it to your friends and members of your family if an admission fee is not charged; and a licence can be arranged for a small fee (payable through a royalties collection agency) to allow showing it in a workplace or to members of a club or society (which is deemed beyond Rightful Purpose, and so requires permission from the copyright holder or their authorised agent [i.e. a royalties collection agency]).

    Can you charge non-licensed viewers for the privilege of viewing the contents of that disk?

    You have to obtain a special licence for exhibition other than to friends and members of your family or for which an admission fee is charged. A licence permitting the general Public to attend the viewing (which certainly exceeds Rightful Purpose) is generally more expensive than a licence for a viewing restricted to a workplace or members of a club or society.

    Can you derive profit from displaying ads from showing the contents of that disk?

    Yes, if you are properly licenced to do so. See above.

    Can you copy the contents of that disk? Can you copy and change the format of the contents of that disk?

    --
    Je fume. Tu fumes. Nous fûmes!