Slashdot Mirror


Blu-ray Protection Bypassed

ReluctantRefactorer writes with an article in the Register reporting that Blu-ray copy-protection technology has been sidestepped by muslix64, the same hacker who bypassed the DRM technology of rival HD DVD discs last month. From the article: "muslix64's work has effectively sparked off a [cat]-and-mouse game between hackers and the entertainment industry, where consumers are likely to face compatibility problems while footing the bill for the entertainment industry's insistence on pushing ultimately flawed DRM technology on an unwilling public." WesleyTech also covers the crack and links the doom9 forum page where BackupBluRayv021 was announced.

31 of 407 comments (clear)

  1. Oh well... by Pojut · · Score: 5, Funny

    ...lasted a bit longer than CSS...maybe next time they might make it last a whole 6 months, maybe even ***gasp*** a whole YEAR before "pirates" start enjoying their blowjob while consumers just get a spiked dildo in the ass.

    1. Re:Oh well... by Ryan+Amos · · Score: 5, Funny

      It only lasted as long as it did because not enough people are using Blu-ray or HD-DVD to care.

    2. Re:Oh well... by killtherat · · Score: 5, Informative

      Actually both HD-DVD and Blu-Ray use the same DRM system, AACS, http://en.wikipedia.org/wiki/AACS

    3. Re:Oh well... by Tony+Hoyle · · Score: 4, Informative

      Satellite TV encryption is dynamic. Got the keys? They just got revoked. Worked out the encryption? A download just changed it.

      A DVD is a static medium and the players aren't normally connected to a source of data, so they can't update them so fast, and they can't invalidate the encryption without making your existing disks unplayable (=class action lawsuit)... so it's considerably easier to break (and re-break as they issue new disks).

    4. Re:Oh well... by elrous0 · · Score: 5, Funny
      I bet they're sobbing into their pillows right now.

      Close. They're actually face-down on the pillow and muslix64 is breaking out the K-Y.

      -Eric

      --
      SJW: Someone who has run out of real oppression, and has to fake it.
    5. Re:Oh well... by Goaway · · Score: 4, Informative

      This hasn't been "cracked" in any meaningful sense of the word. All they've done is implement a decrypter working from the format specs, and worked out a way to hack decrypted keys out of a software player.

      At any point, the player can have its keys revoked and code changed, and we'll be back to square one.

    6. Re:Oh well... by Ruprecht+the+Monkeyb · · Score: 5, Informative

      Hardly. DVD had the fastest penetration of any consumer electronic device in history -- faster than cell phones, faster than VHS, faster than PCs. It had very little to do with DeCSS; it had to do with the three things.

      (A) the players are much less complicated to produce than VCRs, so the retail price rapidly dropped to the point where you virtually got a DVD player with your happy meal.

      (B) The retail price of DVDs started low and got lower. I bought my first DVD for $20, and nowadays you can find B-list titles, used DVDs, etc. for $5 or less. VHS, on the other hand, started really expensive -- most titles were $90 or up in the early years -- and only started getting cheap when DVD arrived on the scene.

      (C) There was already an established model and infrastructure for rental. It didn't take too long when VHS started, but it did take several years before 'renting a video' became a universal experience. With DVD, that happened pretty much from day one. People didn't hesitate to adopt a format when they could get content on it quickly and cheaply from the start. And Netflix has done more for the adoption of DVD than DeCSS.

      Not to say that DeCSS hasn't been a boon, but even now most consumers don't have the expertise/wherewhithal/inclination to copy DVDs. Most of the pirated discs on the subway were initially mass-produced copies, not home pirated versions.

    7. Re:Oh well... by camperdave · · Score: 4, Insightful

      All they've done is implement a decrypter working from the format specs, and worked out a way to hack decrypted keys out of a software player.

      Once they've done that, they can hack decryption keys out of a hardware player. These cannot be changed without ticking off a whole bunch of consumers. Working out the decryption code was probably the hard part of the process.

      --
      When our name is on the back of your car, we're behind you all the way!
    8. Re:Oh well... by recursiv · · Score: 5, Funny

      inproper word


      This amuses me greatly.
      --
      I used to bulls-eye womp-rats in my pants
    9. Re:Oh well... by thedarknite · · Score: 4, Funny

      They're actually face-down on the pillow and muslix64 is breaking out the K-Y.

      A real pirate wouldn't use K-Y.

      "You see this K-Y, I'm not going to use it but I wanted you to know that I have it. On the other hand, this sandpaper condom..."
      --
      A game has objectives and is competitive, anything else is just play
    10. Re:Oh well... by Lumpy · · Score: 4, Informative

      Dude, Sattelite TV has been cracked for decades.... DECADES!...

      You can buy on ebay a china Mpeg2 reciever with a firmware on it that receives all Dish network programming without paying. and every time it stops working you get the new key on your PC via one of the rss feeds out there. IT is brain dead easy and dirt cheap.

      Sattelite Tv has been broken hard for a really long time, longer than DVD... I remember helping a friend pull the epoxy off a VideoCipherII board in college to mod the prom so it would descramble everything (Playboy channel is what we were after)

      The sattelite TV hack stuff is so pervasive it makes guys like me that are into FTA mpeg2 TV fight to find real info for our hobby. Every search turns up 60% hack and crack and 40% real FTA info.

      --
      Do not look at laser with remaining good eye.
    11. Re:Oh well... by monsted · · Score: 4, Informative

      Blu-Ray actually uses BD+ as well.

  2. Just doing his job by gEvil+(beta) · · Score: 5, Funny

    Sounds like Muslix is doing his part to help keep the entertainment industry regular.

    --
    This guy's the limit!
  3. This won't kill DRM by suv4x4 · · Score: 5, Interesting

    Microsoft and Apple are smart. Disk based DRM is doomed since you can't actually upgrade disk drives and disk media that easily, even with encryption programs written dynamically on the disk.

    So as disk-based DRM is consistently wrecked, but can't be updated until the next hardware cycle (~7-8 years at least), which alternative becomes obvious?

    Software based DRM via network downloads. You can update the DRM-ed player in the next software patch, automated via Internet distribution. Apple is covered with their iTunes store, and Microsoft has been working frantically on heavy DRM in Vista and WMP.

    Now you know why.

    1. Re:This won't kill DRM by arodland · · Score: 4, Insightful

      Interesting premise, but think about it. For that to be effective you need to tell people that they can't watch the latest movies or whatever on any sort of player that isn't connected to the internet. If you release anything on HD-DVD or Blu-Ray, it's going to hit this "hole", get converted to some unencumbered format, and away it goes. And "Rocky 9, available today on AppleMovieThing" is locking a lot of people out.

  4. One can hope..... by acomj · · Score: 4, Insightful

    That these cracks and counter DRM attempts cause enough compatability problems that the Consumer electronics industry gives up on DRM, and the studios would have to follow if they wanted there content sold at hi def prices....

    One can dream that they'll come to there senses. There is nothing more annoying than petty restrictions on the content you buy..

    Why shouldn't I be able to watch my dvd/hd movie on my ipod OR computer OR TV. This is getting stupid. The thing is the studios are unified in there stance by the MPAA, maybe consumers should start lobbying or just stop buying..

  5. The CPS unit key must be know by rminsk · · Score: 4, Informative

    From the article "The early version of this utility only supports the decryption of Blu-ray discs whose CPS unit key is known." ... "A powerful crypto attack was used to analyze the memory dump obtained from a Blu-ray Disc software player (such as WinDVD or PowerDVD). The crypto attack helped to identify the encryption keys that are needed for decrypting the video files." So it has not been cracked as the keys still need to be found. This just decodes the contents once the keys are found.

  6. It's not cracked, not yet at least by FlunkedFlank · · Score: 5, Interesting

    Again, as with HD-DVD, all that's happened so far is: - he has implemented decryption using the fully public specs - he has recovered some per-disk keys (using a clever technique) by finding them in the memory of software players Neither format should be considered cracked until a standalone software player could play all disks (independent of an online key database) a la DeCSS. That said, major props to him for actually getting done what he got done. The plaintext attack he used to recover the software keys, as described in one of the forum posts, was a nice touch.

  7. Here's what will kill DRM... by PHAEDRU5 · · Score: 5, Funny

    "Honey, I have to reboot the TV because it's just gotten a security bios update and TiVo won't record until it sees the update. Oh, and I'm sorry the DVD player doesn't work: the last automatic update turned it into a spam-bot and I had to turn it off or get sued under CAN-SPAM 2.1"

    --
    668: Neighbour of the Beast
    1. Re:Here's what will kill DRM... by User+956 · · Score: 5, Interesting

      Honey, I have to reboot the TV because it's just gotten a security bios update and TiVo won't record until it sees the update.

      Your post is more true than you realize.

      --
      The theory of relativity doesn't work right in Arkansas.
  8. The network is now the problem... by plazman30 · · Score: 4, Funny

    With 20+ GB downloads of HD movies, we're going to need much faster pipes in order to continue to illegally download movies. Verizon should help fund these guys, as it will help sell the 15 Mbit FIOS intetnet option.

    Andy

  9. Re:/. Jeopardy by spun · · Score: 4, Funny

    Nevermind, you guys can finish the joke properly.

    No, I don't believe we can. Sorry.

    --
    - None can love freedom heartily, but good men; the rest love not freedom, but license. -- John Milton
  10. The drawback people have spotted here by goldcd · · Score: 5, Interesting

    is that you can't just run the program to decrypt all your Blu-Ray(or HD-DVD) disks, you need to locate the key and use that to get the unprotected data.
    This sounds like a right pain in the arse. I'm used to buying DVDs willy-nilly and just shoving films onto servers, PSPs, iPods, XBMC etc as the mood takes me. It always works, I just press a couple of buttons and away I go.
    Reading these stories have made me think - I'm now even less likely to buy a HD disk than I am a standard DVD. I buy a HD disk in the shop and I've now got to worry, can I get the key for this disk? will it be for the right region? will it be the right version (you can be sure once a disk is cracked they'll shove new keys on all future pressings).
    I don't think I can be arsed with all this really.. much easier just to download un-encrypted and know it'll work on everything I own, forever. FFS I'd pay more for the pirate version than the legit one given the chance.
    My next prediction is the appearance of a site that'll serve keys. You put your HD disk in your machine, run a util that gets a hash from it, searches online and decrypts the disk automatically.
    *scampers off to register hd-keys.com*

  11. Re:People can pick locks too... by sqlrob · · Score: 4, Insightful

    It needs to be open, non-intrusive (for the owner) and allow fair use.

    The only difference between some fair use and illegal copying is intent. Not a system in the world can discern that.

  12. Could be good news for Sony. by Rimbo · · Score: 5, Funny

    Now that Blu-Ray can be pirated, there's a chance the format might take off. This could have a positive benefit for PS3 sales.

  13. Yes it IS a crack by ratboy666 · · Score: 5, Interesting

    The crypto is only as strong as the algorithm, and the method used for key management.

    The argument that DRM is "workable" breaks down because the encrypted message is delivered to a party who is expected to BOTH decrypt the message, and NOT know the keys. But the keys had to be used to effect the decryption!

    Basically, it makes very little sense.

    The only way that DRM can work is if the playback device does not trust its user. Which means that it CANNOT be a general purpose computer.

    The next generation of "DRM Operating Systems" cannot support general purpose computing. Pretty much the only way to guarantee that DRM will work is for such a computer to not allow ANY non-DRM compliant software while DRM content is playing.

    In other words, while the DRM movie is playing, your spreadsheet won't.

    But, since music playback while working is common, we can safely predict that DRM restrictions will be lifted from music. Movies? The next generation may well support "single tasking while movie is playing" mode.

    If this is not done (as well as locking out all non-DRM approved drives and kernel extensions), the keyset can be recovered from the player software.

    This crack just demonstrates this particular weakness. When I probe a cryptosystem, I look at the algorithm used (are there errors in the implementation? is it a good crypto algorithm? etc.), the keys (key length, is brute force possible or is the key recoverable from a known encyrpted plaintext, was the key produced by someone sane, or an idiot, etc.) and key management (where and how are keys stored and published etc.).

    Remember "Spaceballs": the code is: "1", "2", "3", "4".

    It is also good to remember that once a single digital copy is "cracked", the work doesn't have to be done for that title again.

    --
    Just another "Cubible(sic) Joe" 2 17 3061
  14. This guy beat you to it: by Gordo_1 · · Score: 5, Informative
  15. Content industries don't care about this by Stuntmonkey · · Score: 4, Insightful

    To call it a "cat-and-mouse game" is overstating I think. Why should the content sellers care about someone cracking Blu-Ray or HD-DVD encryption? They know that piracy is inevitable. They just want to keep it underground so the average consumer doesn't participate. And for that, under the DMCA any proprietary encryption system will do just fine. The DMCA gives them the permanent legal right to go after anybody who doesn't license their decryption technology, or who tries to circumvent it in an unauthorized way.

    DVD is a great example. DeCSS has been around for years, but it hasn't had a material impact on DVD sales because DVD copying isn't widespread. (At least in the USA; parts of Asia like China are a different story.) Threat of legal action backed by the DMCA has kept DVD backup software generally unavailable to Joe Consumer, despite the widespread prevalence of DVD-R drives and media.

    Bottom line: You could break their encryption and print up all the geeky De-AACS T-shirts you want, but it won't materially affect content sales.

  16. The DVD launchpad by meringuoid · · Score: 4, Insightful
    I'm always curious though... DVD never really took off (it was popular, but not in-every-living-room popular) until CSS was cracked and people could copy their own DVDs (or rather buy copied DVD movies for $5 from the kid down the hall.) That was the real death knell for VHS.

    I'd say DVD took off once the Playstation 2 came out. Before that, DVD players had been expensive and VHS was good enough for most. PS2 put millions of DVD players in people's living rooms as a side-effect of something they were going to buy anyway. Before PS2, DVDs were confined to a small slice of shelf space in video stores; once PS2 came out, they increased very rapidly indeed.

    Things may have gone differently elsewhere, but in the UK the Playstation 2 was a major force behind mass-market acceptance of the DVD format.

    I used to think that the Playstation 3 would have the same effect for Blu-Ray, but now I'm far from sure. Quite apart from the price, it's just too late; it's this generation's N64. In the NES and SNES days I was a total Nintendo fanboy, but if my parents hadn't had a fit of generosity and got a PC, I'd have given up waiting for N64 and bought a Playstation, and I'm sure many others did the same. How many people have already given up waiting for PS3 and gone out and bought a 360?

    --
    Real Daleks don't climb stairs - they level the building.
  17. Why I won't buy... by bjk002 · · Score: 4, Insightful

    I WANT to buy, I REALLY DO! I think there is some great content out there that I WANT to own LEGALLY...

    But I'll be damned if I am going to go through all the hassle of taking my ITMS DRM crap and converting it to a stardard mp3 format so I can play it on my "other" players. Same with movies... Its TOO MUCH HASSLE...

    I'll just grab the pre-decrypted, ready-to-use, no DRM, no hassle, play anywhere, play anytime torrents, ftp files, usenet d/ls, etc... (hell I can automate this with a few scripts for God's sake)..and deal with the guilty conscience of cheating an artist out of a penny...

    Its not that I WANT to cheat the artist out of his/her penny, but if you strip everything away it comes down to a pretty simple economic equation:

    H = Hours of MY time spent converting DRM'd crap
    V = Value of my time
    X = Number of content files
    AEC = Artist earnings per content file

    So... you end up comparing H*V*X vs. AEC*X, and in MY mind the answer is always:

    H*V*X > AEC*X

    You go ahead and plug in your own numbers, I have, and to me, its just not worth it. My time is money, and if you think you are going to not only charge me money to buy your content, but then turn around and charge me (indirectly) to modify your content for my purposes, you're nuckin futs!

    --
    Opinion:=TMyOpinion.Create(Me);
  18. Re:Oh FFS by Cheesey · · Score: 4, Interesting

    We are probably going to find out that posting a 32 byte encryption key for a movie on your website does count as a DMCA violation, even though the key is only useful to people who own the disc.

    Common sense be damned. Could an encryption key be the world's shortest copyrighted work?

    --
    >north
    You're an immobile computer, remember?