Feeds

How gizmo maker's hack outflanked copyright trolls

Chumby NeTV: A triumph for mankind

Build a business case: developing custom apps

When the master encryption key locking down millions of Blu-ray players and set-top boxes was mysteriously leaked last year, Hollywood moguls worried their precious high-definition movies would face a new flurry of piracy.

Instead, it spawned the Chumby NeTV, a tiny, Wi-Fi-connected box that sits between a television and a set-top box or DVD player so email alerts, Tweets and other internet content are scrolled across the bottom of the screen – all without interrupting the flow of the video.

Making the NeTV break into the encrypted video stream passing through an HDMI cable required the elite hacking skills of Bunnie Huang, an engineer and co-founder of Chumby, the maker of net-connected alarm clocks that display weather forecasts, news headlines, and other internet content. Using the leaked master key at the heart of the HDCP, or high-bandwidth digital content protection, encryption scheme to modify the content was clever enough. Doing it without violating draconian copyright laws was nothing short of brilliant.

picture of Chumby NeTV

The Chumby NeTV in all its glory

That's because HDCP was created by Intel for the express purpose of thwarting piracy by restricting access to video passing between set-top boxes and TVs. It establishes a secret key that's unique to each pair of devices, creating a barrier for would-be pirates out to capture and copy the high-definition content. Tampering with this scheme runs the risk of violating the Digital Millennium Copyright Act, a law that carries stiff criminal and civil penalties for circumventing technology intended to prevent access to copyrighted material.

Ignorance is bliss

Faced with the challenge of crashing the party that only HDCP-compliant devices can join without running afoul of the DMCA, Huang employed the leaked master key in a way that allows the Chumby NeTV to use the shared secret key to inject Tweets and other content into the encrypted stream without decrypting the restricted video. His device intentionally remains oblivious to the protected work, a distinction he believes keeps it from violating the law's anti-circumvention provisions.

“It's important to note that nowhere in the pipelines is the video data decrypted,” Huang wrote in an email to The Register. “We don't use the master key to break any locks, or circumvent any copyright protection. We use it to enable interoperability and we do so without ever decrypting the source data: encrypted pixels are just replaced with different encrypted pixels.”

Huang's claims have been confirmed by two experts.

“What's interesting here is that although the device does have the keys needed to do decryption, it isn't actually doing that,” Keith Irwin, a professor of computer science at Winston-Salem State University in North Carolina, wrote in an email. “A conceptually simple means of modifying encrypted video would be to have the NeTV decrypt the video signal from the video device, modify it, then re-encrypt it. However, this isn't what the NeTV does.”

Cryptographer Nate Lawson, who heads the Root Labs security consultancy, has analyzed the open-source code that runs the NeTV and provides an analysis here.

Build a business case: developing custom apps

More from The Register

next story
The agony and ecstasy of SteamOS: WHERE ARE MY GAMES?
And yes it does need a fat HDD (or SSD, it's cool with either)
Apple takes blade to 13-inch MacBook Pro with Retina display
Shaves price, not screen on mid-2014 model
Kate Bush: Don't make me HAVE CONTACT with your iPHONE
Can't face sea of wobbling fondle implements. What happened to lighters, eh?
Apple to build WORLD'S BIGGEST iStore in Dubai
It's not the size of your shiny-shiny...
Steve Jobs had BETTER BALLS than Atari, says Apple mouse designer
Xerox? Pff, not even in the same league as His Jobsiness
Apple analyst: fruity firm set to shift 75 million iPhones
We'll have some of whatever he's having please
TV transport tech, part 1: From server to sofa at the touch of a button
You won't believe how much goes into today's telly tech
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 10 endpoint backup mistakes
Avoid the ten endpoint backup mistakes to ensure that your critical corporate data is protected and end user productivity is improved.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Rethinking backup and recovery in the modern data center
Combining intelligence, operational analytics, and automation to enable efficient, data-driven IT organizations using the HP ABR approach.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.