Slashdot Mirror


Analyst Says Blu-ray DRM Safe For 10 Years

Mike writes to let us know that a poster on the AVS forum says that the latest issue of HMM magazine (no link given) contains a quote from Richard Doherty, a media analyst with Envisioneering Group, extolling the strength of the DRM in Blu-ray discs, called BD+. Doherty reportedly said, "BD+, unlike AACS, which suffered a partial hack last year, won't likely be breached for 10 years." He added that if it were broken, "the damage would affect one film and one player." As one comment on AVS noted, I'll wait for the Doom9 guys to weigh in.

35 of 493 comments (clear)

  1. That's the article... by Anonymous Coward · · Score: 5, Insightful

    A link to a forum that quotes a magazine quoting a guy... something doesn't seem right here.

    1. Re:That's the article... by jnguy · · Score: 2, Insightful

      the slashdot article it quotes has to be about the article that is quoting it....

  2. famous last words by ErichTheWebGuy · · Score: 5, Insightful

    I give it two weeks tops. The gauntlet has been thrown down.

    --
    bash: rtfm: command not found
    1. Re:famous last words by sg_oneill · · Score: 4, Insightful

      The spec has a brilliant little hole in it already.

      The VM's have an ability to run native code, oestensibly to 'patch' a compromised decoder.

      So.................., it seems the first step to cracking blueray has been identified. What a fuck up.

      From here theres a 60 instruction VM.Rebuild the VM firmware using the native code execution capacities, and make sure the new VM cant 'see' its outside changes, and you may well have a (near) perfect irreversible hack.

      This babys gunna sink in months.

      --
      Excuse the Unicode crap in my posts. That's an apostrophe, and slashdot is busted.
    2. Re:famous last words by Myria · · Score: 3, Insightful

      We still can't mathematically prove that ciphers are unbreakable, but that doesn't mean that a modern cipher like AES is going to be broken.
      You don't need to break the algorithm to break the DRM. The key is in software or hardware somewhere; all you need to do is find it.
      --
      "Screw Sun, cross-platform will never work. Let's move on and steal the Java language." - Visual J++ Product Manager
    3. Re:famous last words by Sobrique · · Score: 2, Insightful
      No, it's not. Passwords are the key to open the door. If you get the key, then your security is functioning as intended, when someone can use it to open the lock.

      Security through obscurity hides how the lock works. After all, you can't pick a lock, if you don't understand how it's tumblers are arranged.

      The weakness of this approach, is that you prevent legitimate review of the mechanism - a 'good' algorithm can be mathematically proven as 'strong' (e.g. PGP).

      Now, that's not to say that it's _not_ worth 'hiding' stuff - hacking a network is significantly harder if information on it is 'obscured' however if your security won't stand alone against someone who _does_ know everything about how it works, then it's fundamentally flawed.

      Of course, DRM is all about giving someone a locked box. And then giving them the key to that locked box, so they can use the content. And at the same time, trying to control how/where/when they open the box.

      It's not all that hard, to encrypt something such that it's 'computationally infeasible' to brute force crack. It's significantly harder to do so, whilst at the same time giving away a decryption key.

  3. Always keep your words soft and sweet... by OmniGeek · · Score: 5, Insightful

    In case you have to eat them.

    To quote Bruce Schneier, "Making bits not copyable is like trying to make water not wet." I dunno 'bout those Doom9 guys, but I know enough of Bruce Schneier's work to trust his opinion on this one. I don't know what the digital-media landscape will look like when all this settles out, but I *don't* think it'll be neatly and unbreakably wrapped in DRM containers with price tags on.

    --

    "My strength is as the strength of ten men, for I am wired to the eyeballs on espresso."
  4. The funny thing with these quotes... by Jugalator · · Score: 3, Insightful

    It's that they make movie execs happy, but they scare away the customers.

    Who're the most important in the success of a product?

    --
    Beware: In C++, your friends can see your privates!
    1. Re:The funny thing with these quotes... by dAzED1 · · Score: 4, Insightful

      the real customers, not the fringe folk who even know what DRM is.

      The real customers care about what format has the most movies available.

      The movie execs care about what format they feel protects and enhances their product the most.

      Tada. Riddle solved. If the target audience for HD-DVD is going to be limited to "those who care about the DRM being cracked" then...HD-DVD is very, very doomed.

  5. 2, 4, 6 8... by MBCook · · Score: 4, Insightful
    Quotes from the PDF linked to by the forum post (emphasis mine):

    The recent release of a licensing program for BD+, the coveted second line of defense against piracy...

    He said BD+ offers four times the safeguard on top of AACS against piracy.

    "If you see an apartment in a rough part of L.A., and the door has six locks on it, you're not breaking into that apartment," Doherty said. "Having those extra locks, even if you are not sure [they all work], is part of the magic of BD+..."

    BD+, unlike AACS, which suffered a partial hack last year, won't likely be broken for 10 years,...

    Hmm, they seem to have skipped 8. The amount of gall in this little article (which is the PDF) is amazing. AACS was "partially" cracked. BD+ is a second line of defense, four times as safe, and just like six weak locks that you don't think work, which, by the way, is magic.

    What is this guy smoking?

    --
    Comment forecast: Bits of genius surrounded by a sea of mediocrity.
    1. Re:2, 4, 6 8... by Anonymous Coward · · Score: 1, Insightful

      "If you see an apartment in a rough part of L.A., and the door has six locks on it, you're not breaking into that apartment," Doherty said.

      Pffft. Someone truly determined to break into an apartment is not going to be put off by a mere six locks on one of the ways in. Whatever way you look at it, it's just a matter of someone putting in enough time and/or effort to get in there.

  6. Perhaps they just want some additional QA... by Anonymous Coward · · Score: 1, Insightful

    The best way to find holes is to throw down the gauntlet to the hacker community and let them attack. This will give BluRay time to eliminate mistakes before players start rolling out the door for next xmas...

  7. Re:In some ways yes... by figleaf · · Score: 4, Insightful

    execute native code, possibly to patch an otherwise insecure system

    Or to execute malicious code and send all your private information to somebody.
    Stay away from Blu-ray computer players.

  8. In other news by Torodung · · Score: 2, Insightful

    Widespread Blu-Ray adoption not likely for 10 years.

    Coincidence? Possibly.

    --
    Toro

  9. Thanks for by future+assassin · · Score: 2, Insightful

    letting me know how hard you worked to make a product that restricts my use of it after I would bought it. I'll stick to dvd's for now till a company comes out with a storage media that where I wont be buying cripple ware.

    --
    by TheSpoom (715771) Uncaring Linux user here. I have nothing to add to this but please continue. *munches popcorn*
  10. What is the true purpose of the message? by CrazyJim1 · · Score: 4, Insightful

    1) Don't even try hackers
    2) Go ahead, hacker, I am taunting you.
    3) Consumer, buy Blu-ray discs because your local pirate won't be stocked for years.
    4) Vendor, HDDVD is hacked, go with us for more sales instead of losing untold billions in piracy.

    I'm sure there is an actual reason.

  11. Re:In some ways yes... by poopdeville · · Score: 2, Insightful

    If they're using a small virtual machine, the right security protocol would be to make an MD5 (or SHA-1 or whatever) hash of each essential component of the virtual machine and on board software that enforces DRM. It would then be a matter of storing a private key somewhere on the machine, after encrypting the hashes using the private key, comparing to an encrypted list stored on the disc.

    This would make cracking the machine a nightmare. Recovering the list of keys from the disc might not be too hard. But even then, you'd have a very hard time writing a "liberated" firmware that hashes to the same value as the original. (You could also try to change the private key, but that sounds even harder)

    --
    After all, I am strangely colored.
  12. Re:In some ways yes... by SCPRedMage · · Score: 2, Insightful

    Or you could, I don't know, write a program to examine the BD+ program, and determine the appropriate method of descrambling the audio/video without actually having to RUN the BD+ program...

    --
    My sig can beat up your sig.
  13. Well, one player is enough... by gweihir · · Score: 2, Insightful

    I assume this means one player type, but even if not, a system break can also be done by generating an automatic procedure that breaks every instance.

    Even if it means exaclty one player, with P2P filesharing that is already enough. Look at the preview copies. That is one original instance and a few days latter you can get them everywere.

    Then there still is the ''analog hole''. Fit an LCD driver (i.e. the thing that drives the pixel) with high-speed A/D converters (not difficult, and signals cannot be encrypted at this level) or read the bus between display controller and driver chip (may or may not be difficult, depending on whether there is encryption here, but does not need the A/D converter, so it would give a better signal). I expect this is a relatively cheap project any good EE or electronics tinkerer can do. Again a single copy of a movie is enough.

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  14. It simply doesn't matter... by msauve · · Score: 5, Insightful

    how secure they make the media. Cracks will follow the path of least resistance. If every form of media moved to some form of uncrackable quantum encryption tomorrow, it wouldn't matter. Someone would crack HDCP, and the content would be available there.

    If not HDCP directly, then the processor to LCD data path for some el-cheapo monitor which supports HDCP. There's always some point in the chain where protection is weak, or simply doesn't exist.

    It is simply a futile endeavor as long as the consumer ultimately gets access to (i.e. can view/listen) to the content. Of course, they have no product if the consumer can't.

    --
    "National Security is the chief cause of national insecurity." - Celine's First Law
    1. Re:It simply doesn't matter... by dgatwood · · Score: 2, Insightful

      From what I've read, HDCP is about as powerful as ROT13 for content protection. I'm pretty sure it is already as good as broken... COMPLETELY broken... as in snoop the handshake between a small number of devices a few times and you can compute a single device key. Repeat for a fairly small number of distinct device keys (40) and you can then compute any possible key. All it takes is one modestly secure digital media format and you'll see HDCP strippers available in the back of Video Magazine or whatever for $30 apiece....

      Protecting content with BD+ is solely intended to damage the fair use of individual consumers to make backup copies of their own media that they lawfully obtain. Anyone doing commercial piracy has been able to break HDCP and reencode trivially for a long time.... When are the media companies going to learn that playing games with technology to try to prevent legal copying only pisses off the customers?

      --

      Check out my sci-fi/humor trilogy at PatriotsBooks.

  15. Re:In other news... by westlake · · Score: 4, Insightful
    I'm with you. This is most definitely not what they should be saying if they want me to buy a Bluray player.

    But neither of you are the market. Blu-Ray has Disney and A-list titles like The Incredibles. It is content that drives sales, not cracked DRM.

  16. So HD-DVD is better for me as a consumer? by MattW · · Score: 4, Insightful

    BD+, unlike AACS, which suffered a partial hack last year, won't likely be breached for 10 years. So what he's saying is, if I'm a consumer, HD-DVD is better for me, if I don't like vendors telling me how I can view content I buy?
  17. Re:In other news... by Anonymous Coward · · Score: 1, Insightful

    the DVD format is good enough for me. I won't buy this kind of "protection." I'll just keep buying DVDs

    But you're still buying DVD's. If you weren't such a hypocrite, you'd stop watching that too. Oh, but DVD's are cracked, so despite all the posturing, it's not about the why, it's about the how. So your "the DVD format is good enough for me" REALLY means "it's good enough for me until one or both of the other formats are cracked" or "since the content is the same and though I have HD tv's, I got cheap ones so I can't even really tell the difference between upscaled 480i and a real 720p plus my eyes are going out from staring at /. all day long".

  18. How will they do software playback? by Kadin2048 · · Score: 2, Insightful

    Question for you, since you seem knowledgeable:

    How do you implement a security system like this in software? Or do you just not do it at all?

    Seems like the way that both DVD's CSS and AACS were broken involved software players. Unless Sony simply plans to just prohibit playback on general-purpose PCs, they'll have to create some sort of software implementation of the player hardware, which would mean the VM.

    If they only allow playback on dedicated hardware, then I can see how this might make cracking somewhat harder, but that seems like a high price to pay: it eliminates the entire HTPC concept.

    --
    "Ladies and gentlemen, my killbot features Lotus Notes and a machine gun. It is the finest available."
  19. Re:It's not really just an encryption scheme, thou by Anonymous Coward · · Score: 3, Insightful

    Not quite. While you raise, on first view, many interesting points, most are just straw men: no substance.

    What does this mean for people attempting to defeat the security?
    Well it means that a full crack of BD+ will require crackers to implement a virtual machine which acts in exactly the same way as the hardware VM would act. [...] In this case, you have to come up with something which can determine the full dynamic runtime execution path of a static binary
    You started on the right path. Then you went completely off! Crackers will simply have to do that: make a VM that's compatible with BD+. None of this full dynamic analysis hogwash.
    Thing of all the video game systems and arcade machines. The video games on them had protection schemes, yet, can't emulators play these games? Yes they can. This is no different.

    Just putting the same source code through a randomizing [...] makes the challenge immensely harder.
    Again, no, crackers don't care. Emulate the protection layer!

    The other major problem is that the challenge-response authentication made by the program contained in the disc against the embedded hardware will require a "real" cert to succeed.
    Yes, with client certs witch can be stolen: people have physical access to the hardware. No amount of silicon will change that. Even IBM's expensive crypto pci cards for bank machines have been successfully attacked. The costs required to even attain a fraction of their security (batteries, temperature and x-ray sensors, etc) would, in a retail unit, be well over what the market would be willing to bear.

    [...] or someone with a previously unheralded supercomputer or mathematical technique breaks the key from a known subset of challenge/response pairs... - or, it will remain unbroken.
    To be completely broken yes, but that is unnecessary. One just has to have broken everything released up to that point.

    What's really interesting about all this is if someone DOES find a way to break BD+, there is really strong incentive for them to use it to break & release movies rather than release code which performs the break.
    While I do agree with you, I do for different reasons. Assuming the break was done by stealing a device key, such output only releases would be better, since it would be more difficult to discover exactly witch client key was stolen.
    As far as breaking VMs? Who cares: they break it; a bug report gets filled; a week later a patch comes out.

    BD+ allows the entertainment companies to react instantly to breaks at timeline point X[...]
    Yes, well that is to say just as instantaneous as the response to the recent ACCS breach: a couple months. The only thing they can do is make security better for future disks (or reprints). They can't change the past.

    Like all the best posts on /., posted at zero, headed for minus one. ttfn!
    It would have been better this way. While there were a bunch of great links to papers, they we missuesed. Your post was a great troll, by the way.
  20. A message for BD+ developers by Whuffo · · Score: 2, Insightful
    A shared secret is no secret at all. It doesn't matter how carefully you wrap your secret in an enigma - at the end of the day, no matter how secure your lock, you also supply the end user with the key that opens the lock.

    So you'll print off thousands and millions of these discs that contain both the lock and the key - and distribute them to anyone who has the price of purchase - and you think it's going to take how long for just one person to open your lock?

    Once that one person has compromised your protection then it's done. From that one compromise, copies will flood the internet. Will BD+ prevent your movies from being shared? Nope, no chance of that. But it might slow things down a little - just a little, mind you.

    We hope you've spent as much time working up a plausible excuse for the failure of this system as you did in promoting it to unsuspecting media companies. They're not going to be happy when they discover you've sold them a bill of goods...

  21. Re:MOD PARENT UP by Amiga+Trombone · · Score: 2, Insightful

    Yeah, must be a pretty thin news day for Slashdot to be posting stories based on somebody's quotes. Not to mention the only thing remarkable about the quote is it's staggering stupidity:

    Doherty reportedly said, "BD+, unlike AACS, which suffered a partial hack last year, won't likely be breached for 10 years."

    How many times have you heard that? My money says it's hacked before this story rolls off of Slashdot's front page.

  22. laughable by geekoid · · Score: 2, Insightful

    I can alway grab it after it is decoded, big whoop. Encryption, even 'perfect' encryption doesn't matter at all if someone, at sometime, needs to actually be able to understand it.

    --
    The Kruger Dunning explains most post on /. http://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect
  23. Re:It's not really just an encryption scheme, thou by logicnazi · · Score: 5, Insightful

    Since I actually do research in recursion theory (basically the mathematical study of the halting problem) let me start by saying this has ABSOLUTELY NOTHING AT ALL TO DO WITH THE HALTING PROBLEM. The halting problem, or as you stated it determine the full execution path of a static binary, is provably unsolvable because programs can take arbitrarily long before deciding to halt. Given you know a program halts (on a given input) it's trivial to determine the full execution path. Just run it and see what it does.

    In this situation there is nothing at all like this going on. We know that the code on the BluRay disk produces whatever output lets you view the disk not only in finite time but after a very short time.

    In fact this situation offers no additional security over a well designed public crypto system AT ALL except for obscurity. The instructions for the virtual machine are just a very complicated sort of key, one that anyone who can crack the base level encryption can view. The memory footprints and all that jazz are only fancy ways of implementing a private key.

    There are damn good reasons that the people who implement public key systems and symetric ciphers don't use VM instructions as their keys. A good crypto system is built around SIMPLE and well known mathematical problems because extra complications just provide more places an attacker can find a clever short circuit that you didn't think about. The only reason to think a crypto system is secure is because you think that the attacker doesn't have any shortcuts to compute things in the other direction much faster than brute force. The more complications in your system the more places he could discover a clever trick to undermine your security.

    As I argued in my other post the benefits of the BD+ VM aren't really about security but about control. It doesn't make things much harder for the hackers but it does let the content producer execute more control over when things are decrypted. The only security advantage BD+ brings is obscurity and possibly the use of a better underlying crypto system than what AACS uses (the part that decrypts the VM at the beginning).

    --

    If you liked this thought maybe you would find my blog nice too:

  24. Re:Break BD+ ? Inconceivable! by Scudsucker · · Score: 2, Insightful

    I don't think that word means what you think it means.

  25. Re:Sigh, I hate to burst your bubble... by Jah-Wren+Ryel · · Score: 2, Insightful

    The SPDC VM is not Java. I don't think you've asked the right questions of your "people at IBM who wrote the JVM used to play BD+". So he's wrong, but not completely off his rocker.

    The person I know who's involved with BD+ co-designed BD+. I guess even the devil has friends, eh?
    --
    When information is power, privacy is freedom.
  26. Re:In some ways yes... by RzUpAnmsCwrds · · Score: 2, Insightful

    The response has been signed using a public key, and that's sitting in circuits covered in epoxy.


    Ooh. Epoxy. Because that stopped iOpener hackers. And XBOX hackers.

    And what about software players? How is the key hidden there?

    Perhaps Blu-Ray discs won't play on PCs? Guess what? HD-DVD just won.
  27. Re:DVD Macrovision requires composite input on TV by SCPRedMage · · Score: 2, Insightful

    Even allowing for that exception, there was still WAY more of a market for DVD than there currently is for HD DVD/Blu-ray. There just aren't enough people willing to shell out the $1500+ for an HDTV and the $600+ for the player for adoption rates to be anywhere NEAR that of DVD's.

    --
    My sig can beat up your sig.
  28. Re:Hacked soon by Lord+Apathy · · Score: 2, Insightful

    Red flag, Red flag meet bull.

    --

    Supporting World Peace Through Nuclear Pacification