Subscribe to EDN

AACS 0wn3d? An Update*

December 30, 2006

In late 1999, hackers discovered an unprotected CSS key in the object code of the Xing DVD player. Shortly thereafter, a flood of CSS-circumventing DVD ripping programs emerged. Before I continue, I'll elaborate on key portions of the prior two sentences:

  • "Back in late 1999": This was roughly four years after the DVD standard was approved, and approximately three years after the first DVD players went on sale.
  • "Circumventing": The CSS algorithm wasn't cracked. Due to human coding error, an encryption key was left exposed, and the whole house of cards promptly came tumbling down.

Now fast-forward to the present. This past Thursday evening (eight months after Toshiba began selling its HD-A1 HD DVD player), I alerted you to the first reports of a possible crack of the AACS encryption algorithm at the core of HD DVD (and, for that matter, Blu-ray). Since then, I've uncovered a few more nuggets that I think you'll find interesting. And things may get even more interesting if the hacker known as Muslix64 follows through with the promise made at the Doom9 forum thread which linked to the decryption routine:

I already have a version that works with volume key instead of title keys. Even more powerfull! Version 1.0, with volume key support should be out on january 2

Question 1: Did Muslix64 crack AACS? Actually, it appears he/she didn't; instead the hacker circumvented it, relying on the same sort of human error that crippled CSS over seven years ago. The FAQ that accompanied BackupHDDVD mentioned CyberLink's PowerDVD, and the YouTube video Muslix64 made (which is, I must say, quite entertaining) also shows the program running. CyberLink hasn't responded to my requests for comment, but several anonymous and well-placed sources indicate that the program is the source of the leak. Apparently, Muslix64 figured out how to find the unencrypted title keys in system RAM.

Question 2: Is Blu-ray immune? Yes, at least for the moment. But probably not for long. Muslix64 indicates that he/she doesn't own a Blu-ray drive; an Xbox HD DVD drive like the one I wrote about earlier this month was used to read discs on the PC (coincidentally on Christmas Eve, prior to hearing about the hack, I obtained my own copy of Cyberlink PowerDVD Ultra). However, although my original post on this topic suggested that Blu-ray's beyond-AACS BD+ might protect it, several other anonymous and well-placed sources indicate that BD+ is not yet finalized and therefore not yet implemented; existing Blu-ray titles are protected only by AACS. PowerDVD also supports Blu-ray. So if someone else can figure out how Muslix64 found the title keys (or, alternatively, if Muslix64 gets his or her hands on a Blu-ray drive) it's not a stretch to imagine Blu-ray discs also being compromised. On that note, I owe the HD DVD Promoters group an apology; I probably should have instead titled my original post "AACS Encryption Cracked?".

Question 3: Is this circumvention recoverable by HD DVD's backers? Unclear. Revocability is at the core of AACS and similar modern DRM schemes, and AACS's cryptographic validation procedure incorporates a handshaking protocol between keys embedded in the media and those within the client (PC-based software, dedicated player, etc). The client key for PowerDVD could be added to the 'revoked' list for future HD DVD media, preventing playback until users upgraded to a newer, fixed version of the program. But I'm pretty sure that all already-pressed media is vulnerable. Also, please note that Muslix64 promises a 'volume key' version of BackupHDDVD in a few days. I believe that he/she means 'volume identifier', which is well described in this AACS document (PDF). The distinction between volume and title keys is small (they both span only a single disc) but may be significant.

Frankly, at the end of the day, whether or not AACS has been crippled means absolutely nothing to organized pirates. They have plenty of other avenues at their disposal to obtain high-quality A/V sources, including leaks from movie studio insiders and high-def video cameras in theaters. However, just as the original P2P version of Napster put the hurt on the music industry, the defeat of AACS will encourage computer-savvy individuals to obtain their movie fixes from copyright-infringing Internet sources. Yes, a high-def film is a massive download payload. See one of the many reasons why I'm closely following the fiber rollout, not to mention the plummeting prices and burgeoning capacities of HDDs? Ars Technica's recent observations (picked up by Slashdot) on piracy's increasing popularity at the expense of legal video acquisition are quite timely in this regard.

I'll close with a personal plug. In researching this piece, I reacquainted myself with a feature article I wrote back in early 2000 on digital rights management. It's quite comprehensive, if I do say so myself, and still scarily relevant. Give it a read and then tell me, and the other denizens of Brian's Brain, what you think.

And now I'll lighten up; check out Gizmodo's top 5 hacker videos. Enjoy!

*0wn3d

Digg This | Slashdot This

Posted by Brian Dipert on December 30, 2006 | Comments (14)

February 5, 2010
In response to: AACS 0wn3d? An Update*
Install Software commented:

Another great post. Thanks for the tips and help. Everyone, bookmark this site.


February 5, 2010
In response to: AACS 0wn3d? An Update*
Install Software commented:

Another great post. Thanks for the tips and help. Everyone, bookmark this site.


February 5, 2010
In response to: AACS 0wn3d? An Update*
Install Software commented:

Another great post. Thanks for the tips and help. Everyone, bookmark this site.


January 2, 2007
In response to: AACS 0wn3d? An Update*
Brian Dipert commented:

Thank you, 1ee7 h4x0r, for that vote of confidence. I'm reassured to know it's not true that I "obviously don't have a clue" ;-)


January 2, 2007
In response to: AACS 0wn3d? An Update*
1ee7 h4x0r commented:

0wN3d and its variants are all perfectly acceptable. Using pwn and its variants would mark you as a computer game nerd, and nothing more.


January 1, 2007
In response to: AACS 0wn3d? An Update*
Tumelo commented:

I'm always amused by the constant attempts by studios to upgrade or update the encryption they use on the endproduct, If as you say, people's players are likely to end up being blackmailed for deigning to utilise non-proprietary products, or products whose proprietary software has been revoked by pirates, then why on earth would anyone want to buy directly from the studios, I certainly might be motivated to buy pirated material. Right there, is something that turns normally law abiding people into criminals, when will they learn??


January 1, 2007
In response to: AACS 0wn3d? An Update*
efnethore commented:

Allow me to take this opportunity to praise you for your level of professionlism. There is truely nothing like having leetspoke in a news article, Brian. Tips for you though, you can say '0wnt' or 'pwnt', but never '0wn3d', alternating capitalization aside. Concerning the 2nd of your 'prior two sentences', I believe you should do a little research before making a statement as facts. The authentication process used by CSS involving title key and bus key, were successfully reverse engineered by linux interest groups long before DeCSS came to be. If you don't think that qualifies as a crack, let me inform you that there are also birthday attacks that can literally crack the 5 byte key that CSS uses. The encryption algorithm can thus be cracked in 2^16 tries, another method can retrieve the disk key hash in 2^25 tries. Now, please let everyone know that CSS was indeed cracked. I'm not even going to say anything to your AACS comments, seeing that you obviously don't have a clue. If you don't think we can crack AACS, watch us work.


December 31, 2006
In response to: AACS 0wn3d? An Update*
Brian Dipert commented:

It's a Brave New World, Mike....;-)


December 31, 2006
In response to: AACS 0wn3d? An Update*
Mike commented:

Imagine a Friday night where you pop in a HD-DVD you just rented, sit back, and get the error "This HD-DVD Player has been blacklisted. Please download new firmware or call us during business hours to have updated firmware mailed to you."


December 31, 2006
In response to: AACS 0wn3d? An Update*
Brian Dipert commented:

Thanks, Marcos and Toni, for your comments, and my apologies for any difficulty with our comments system. I've been aware of the formatting bugs for some time now and have reported them to the folks who run our website; I hope they'll get fixed soon.


December 31, 2006
In response to: AACS 0wn3d? An Update*
Toni commented:

When will the companies understand that, by purchasing expensive copy protection systems, they are being lured in a fraudulent scheme? Since we have general-purpose systems, copy protection is theoretically impossible. In order to allow legitimate users to access the product, you must provide the content, an implementation of the algorithm and the key. So you're also providing it for others. It's intrinsecally unsecure, no matter how obscurely you implement the decryption process. So it's only a matter of time until someone finds his/her way through. A second step is cracking the actual code. Also, just a matter of time and more powerful computers. Although in this case the "time" involved could be years (or millions of years


December 30, 2006
In response to: AACS 0wn3d? An Update*
Marcos commented:

Nothing personal, but your commenting system sucks. =) Perhaps this is ironic, given the topic.


December 30, 2006
In response to: AACS 0wn3d? An Update*
Marcos commented:

OK, read your article. Much of it was over my head technically, but I think I got the gist.

I also picked up on some implications, whether they were intended or not. The Studios sell a product that we can call an entertainment/cultural product. If the use of this product (for example movies and music) becomes too onerous, the consumer will move to other products, perhaps completely different categories of entertainment/cultural products. People will go to where the fun value is and spend their money accordingly. Look at the success of the Wii this holiday season, where the money went to the product with the best fun/cost ratio.


December 30, 2006
In response to: AACS 0wn3d? An Update*
Marcos commented:

My formatting disappeared!

POST A COMMENT
Display Name
captcha

Before submitting this form, please type the characters displayed above. Note the letters are case sensitive:

Advertisement
Advertisement
Advertisement
About EDN   |   Site Map   |   Contact Us   |   Subscription   |   RSS
© 2011 UBM Electronics. All rights reserved.
Use of this Web site is subject to its Terms of Use | Privacy Policy

Please visit these other UBM Canon sites

UBM Canon | Design News | Test & Measurement World | Packaging Digest | EDN | Qmed | Pharmalive | Appliance Magazine | Plastics Today | Powder Bulk Solids | Canon Trade Shows