A hacker claimes to have decrypted the next gen DRM standard for high definition DVDs. Called Advanced Access Content System, or AACS, this standard has been adopted by most of the major Hollywood and music studios to protect the newest DVDs and CDs. The tools and title keys used were posted on the Internet and a video of the decryption was posted on YouTube.
How Much is 'Free' Costing You? Learn how DaveRamsey.com saw a 567% uplift in ROI with Omniture. This complimentary guide and webinar cover the most important factors in selecting an analytics solution. Download Now.
A hacker who calls himself Muslix64 has Hollywood and music studios on edge this New Year's Eve weekend as they wait to see whether their latest digital rights management software standard will work as designed.
Muslix64 has posted on the Internet the tools and title keys he said he has used to decrypt the next generation DRM standard for high definition DVDs.
Called Advanced Access Content System, or AACS, this standard has been adopted by most of the major Hollywood and music studios to protect the newest DVDs and CDs. Muslix64 also posted a video of the decryption on YouTube.
Story Still Unfolding
Muslix64's claims are only the first part of the story, though, which is still unfolding, Greg Coticchia, senior vice president and chief marketing officer of Cloakware, a DRM provider, told TechNewsWorld.
In contrast to earlier DRM standards such as Content Scramble System, or CSS, he said, AACS was developed to allow licensers to revoke the title keys when a hack occurred in order to protect future content. "People have been predicting this crack [of AACS] for some time. Now we will see how AACS responds."
To work as it should, AACS has to overcome a few challenges first, though.
It is true that AACS has a built-in ability to revoke individual players or groups of players, unlike earlier systems such as CSS, Carter Laren, senior security architect at Cryptography Research told TechNewsWorld.
"The main difficulty that AACS will have in responding to this attack, however, will be determining which player(s) to revoke. Muslix64 has not actually released any player keys or detailed information about how the keys were obtained," he said, noting that the source code that was released simply implements AACS decryption, but doesn't include keys.
Also, in the YouTube video, it was implied that title or player keys was obtained from Cyberlink's PowerDVD -- at least that is what was used in the demonstration video to play the content, Laren said.
"We shouldn't be too quick to jump to that conclusion: the keys could just have easily come from a different HD DVD player, and the Cyberlink player may have just been a convenient way to demonstrate playback," Larem continued.
"If the hacker only releases title keys, tracking the hack down will remain tough. Nevertheless, I'm sure at this very moment the handful of companies that make HD DVD players are updating their software in an attempt to make extracting keys more difficult," he concluded.
Hacked or Not?
All the fuss over the hack, though, may be for nothing. It is not entirely clear that AACS was cracked in the first place, according to Laren.
"Instead, keys appear to have been extracted from a specific implementation of an HD DVD player, and to my knowledge the AACS group never officially claimed that stealing keys was impossible -- that would be a silly thing to claim," he claimed.
Mary Litchhult, vice president of TitleMatch Entertainment Group, a company that produces DVDs of most movie titles on demand, is among those hoping Muslix64's claims are overblown, even though the DVDs it produces are not high definition and are protected by the CSS standard.
"These hackers operate, it seems, for the thrill of the kill," she told TechNewsWorld. "They want to be able to say they cracked a difficult-to-hack standard."
CSS, for instance, was cracked soon after it was introduced by the infamous "DVD Jon."
The end result is increased costs for both movie studios, and eventually, consumers, she said.
"This has become a cat and mouse game for the movie studios," Coticchia explained. "No matter what you put out, there will be someone who will try to figure out how to get around it."
The latest school of thought for copyright protection is to make security inseparable from the source, such as with the AACS standard. "That is seen as the key to security as long you are not preventing ease of use," Coticchia added. "That is the balance content providers are trying to strike."
When will the fools behind DRM come to their senses and stop this insanity? It's already been ...
Next Article in Security
'Happy New Year' Worm Spawns Computer Zombies December 29, 2006
Verisign is warning of a new worm that travels via e-mail with the subject "Happy New Year!" Users who open an attached executable file trigger installation of several different malicious code variants on their computers, which then execute mass mailings. The worm, which is already being heavily spammed, is being sent via over 160 domains, the security company said.
Related Stories
New NEC Chipset Crosses HD DVD, Blu-ray Divide October 12, 2006
NEC this week revealed that is has developed a new chip that is compatible with both Blu-ray disc and HD DVD technology. NEC hopes it will spur development of computers, televisions and other electronics hardware that bridge the divide between the competing, high-definition media formats.
The Skinny on High-Def Formats October 05, 2006
No significant technological differences separate Toshiba's HD DVD player from Samsung's Blu-ray unit. Ultimately, the winner of this format war may be determined not by consumers but by the content masters.
Warner Bros. Seeks Patent for Hybrid High-Def DVD September 20, 2006
Warner Bros. has filed a patent application for a single disc that can store regular DVD, HD DVD and Blu-ray content. "Multiple formats of DVD discs create retail and consumer confusion as to which format(s) to acquire or buy," the firm's patent document stated.
Related News Alerts
More by Erika Morphy
Ballmer Gives Shareholders - and Dell - Cause for Optimism November 20, 2009
Microsoft CEO Steve Ballmer was all smiles at the company's shareholders meeting, as he touted the early success of Windows 7. Ballmer's cheer may have been contagious; after posting a massive earnings decline for the third quarter, Dell needed some good news to latch onto, and the prospect of broad enterprise adoption of Windows 7 could spur PC sales.
AA.com Sucks the Fun Out of Trip-Planning November 20, 2009
Using AA.com to book a flight was a painful experience. Densely packed, disorganized information was displayed in an unattractive format. On the plus side, it did seem as though the deals American Airlines advertised were real and not mere bait-and-switch lures. For anyone who wants a travel-planning Web site to inject a little pleasure into the experience, though, I say look elsewhere.
Salesforce.com Pumps Up Volume of Workplace Chatter November 19, 2009
Salesforce.com has developed a collaboration platform that puts social networking to work. Salesforce Chatter facilitates employee collaboration on projects through Facebook-like profiles, status updates, feeds and groups. The question remains whether employees will be as open to social networking in the workplace as they are in their personal lives.