On CBS.com: You a Survivor Fan?Play Survivor Fantasy
BNET Business Network:
BNET
TechRepublic
ZDNet

February 25th, 2007

Another nail in the AACS coffin

Posted by Adrian Kingsley-Hughes @ 4:54 pm

Categories: Blu-ray, DRM, HD-DVD

Tags:

A hacker has put another nail in the coffin of the HD encryption scheme AACS - the device key for WinDVD 8 has been found.

Does having a working crack for AACS make HD-DVD/Blu-ray more attractive?

View Results

Loading ... Loading ...

A hacker going under the pseudonym of ATARI Vampire has discovered the device key for WinDVD 8 and posted their findings on the Doom9 forum

About 35,000 bytes into the file I extracted a 16 byte value that was able, using the constant as the d value, to create the processing key. If my interpretation of the AACS specification is correct, I have found a device key. Here is the device key, along with the memory offset where it can be re-discovered assuming that you dump memory in WinDVD 8 early enough in the runtime process. By the way, psuspened helps tremendously with slowing processes down so that pmdump can accurately dump memory!

[WinDVD 8]

Device Key: AA856A1BA814AB99FFDEBA6AEFBE1C04
Found at memory location: 0×000089EC

Device Key: AA856A1BA814AB99FFDEBA6AEFBE1C04
Found at memory location: 0×00008A20

Another prominent AACS hacker on Doom9 called Arnezami explains the significance of this finding:

We need a Private Host Key (to get volume ids) for fully independent decryption of all existing discs. I'm working 24/7 on this (and hopefully others do too) but haven't had any luck yet . My ecdsa crypto setup is working now though (eg. can verify stuff using pub keys from drive and/or host) and its quite speedy now. Using openssl.

The above sub device key has the same value as the Processing Key atm. But its nice to have a (sub) Device Key . More Device Keys (although nice) won't help decrypt existing discs (since we already have the Processing Key and on every disc this same Processing Key is used).

Given how fast these hackers are breaking down AACS, I don't think it's going to be long until they have a private host key. 

Adrian Kingsley-HughesAdrian is a technology journalist and author who has devoted over a decade to helping users get the most from technology. He also runs a popular blog called The PC Doctor. See his full profile and disclosure of his industry affiliations

Want to get in touch? Got a tip? Feel free to drop me a note! I ALWAYS respect anonymity. I'm also on Twitter (@the_pc_doc)

Right to Reply: Should any industry representatives wish to comment on any posts on Hardware 2.0, I will be happy to publish their reply verbatim on this blog.

Subscribe to Hardware 2.0 via Email alerts or RSS.

  • Talkback
  • Most Recent of 2 Talkback(s)
These people are hackers, not pirates.
AFAICT, they are breaking AACS, not distributing illegal copies of HD movies. (Read the rest)
Posted by: Zogg Posted on: 02/26/07 You are currently: a Guest | | Terms of Use
Gotta love dem pirates  klumper | 02/25/07
These people are hackers, not pirates.  Zogg | 02/26/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

Click Here
advertisement

Recent Entries

advertisement

Archives

ZDNet Blogs

White Papers, Webcasts, and Downloads

Meet Doc

  • Here to help you with your Document Management Needs
  • Doc is an enigma. Born to a Russian ballerina and a German electrical engineer, he grew up in various locations in the United States. He’s seen the insides of more brands, versions, and generations of printer and printer-related hardware than almost anyone.
  • To learn more about this mysterious figure check out his blog on ZDNet and his Workspace on TechRepublic. You’ll be glad you did.
  • Produced by
    ZDNet and