Feeds

HD DVD anti-rip encryption cracked

First test of AACS key-switching system

Choosing a cloud hosting partner with confidence

Has the HD DVD next-generation optical disc format's anti-rip technology been cracked? That's certainly what's being claimed by a programmer going by the name muslix64 who has posted a Java-based app he maintains will free the video on a disc from its encryption shackles.

HD DVD used the AACS copy-protection system to encode content. So does the Blu-ray Disc format, though it adds a couple of extra anti-piracy techniques to boost its level of protection. According to muslix64's posting on a Doom9 forum, nosing around his PC's memory, he found his test disc's title encryption key and was able to use to copy the movie to his hard drive and decrypt the video.

Enter BackupHDDVD, his Java-coded utility that gets a movie's key from memory, possibly via the player software, and then uses it to copy the movie over to the hard drive in an unencrypted form. There's a caveat: muslix64 admitted the code - for which he's provided the source - is highly unstable. It's also open to question how generic all this is as it only seems to work with one title.

The programmer added that he's also found the disc's overarching volume key, and is preparing a BackupHDDVD update for 2 January that will allow users to extract other files from an HD DVD.

Muslix64 posted his utility just before Christmas, so it's taken a little longer than usual for hackers and other users to evaluate the coder's claims. But it remains a potentially major embarrassment for the HD DVD format's supporters in the content and hardware industries, coming just ahead of a big Consumer Electronics Show (CES) push to drive the format ahead of its rival, Blu-ray Disc.

After the DVD format's more basic encryption technology, Content Scrambling System (CSS), was cracked by 'DVD Jon' Johanssen, AACS was heralded as a much bigger hurdle for hackers.

However, AACS does more than boost the complexity of the encryption. It adds techniques for ditching compromised keys, and it remains to be seen how not only the AACS organisation but also the HD DVD camp respond to this. Keys can be tweaked to force users to update their software if they want to be able to play future titles, and that may be what happens in this instance. ®

Website security in corporate America

More from The Register

next story
Man buys iPHONE 6 and DROPS IT to SMASH on PURPOSE
Yarrrgh! 'Tis Antipodean insanity, ye crazy swab
Oi, Tim Cook. Apple Watch. I DARE you to tell me, IN PERSON, that it's secure
State attorney demands Apple CEO bows the knee to him
4K-ing excellent TV is on its way ... in its own sweet time, natch
For decades Hollywood actually binned its 4K files. Doh!
Your chance to WIN the WORLD'S ONLY HANDHELD ZX SPECTRUM
Reg staff not allowed to enter, god dammit
Phones 4u website DIES as wounded mobe retailer struggles to stay above water
Founder blames 'ruthless network partners' for implosion
Monitors monitor's monitoring finds touch screens have 0.4% market share
Not four. Point four. Count yer booty again, Microsoft
DARPA-backed jetpack prototype built to make soldiers run faster
4 Minute Mile project hatched to speed up tired troops
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.