Security of Advanced Access Content System: Difference between revisions

Content deleted Content added
Citation bot (talk | contribs)
Alter: template type, author. Removed parameters. | Use this bot. Report bugs. | Suggested by AManWithNoPlan | #UCB_webform 1171/1563
Link suggestions feature: 3 links added.
Tags: Visual edit Mobile edit Mobile web edit Newcomer task Suggested: add links
 
(8 intermediate revisions by 7 users not shown)
Line 1:
The '''security of [[Advanced Access Content System]]''' (AACS) has been a subject of discussion amongst security researchers, high definition video enthusiasts, and consumers at large since its inception. A successor to [[Content Scramble System]] (CSS), the [[digital rights management]] mechanism used by commercial [[DVD]]s, AACS was intended to improve upon the design of CSS by addressing flaws which had led to the [[DeCSS|total circumvention of CSS]] in 1999. The AACS system relies on a [[Tree_Tree (set_theoryset theory)|subset difference tree]] combined with a [[certificate revocation list|certificate revocation]] mechanism to ensure the security of high definition video content in the event of a compromise.
 
Even before AACS was put into use, security researchers expressed doubts about the system's ability to withstand attacks.
Line 21:
| 128-bit
|-
| style="background:#EAEAEA;"| '''[[Certificate revocation list|Certificate revocation]]'''
| No
| Yes
Line 62:
Microsoft later claimed that the paper contained various factual errors.<ref>{{cite web|url=http://windowsvistablog.com/blogs/windowsvista/archive/2007/01/20/windows-vista-content-protection-twenty-questions-and-answers.aspx|title=Windows Vista Content Protection - Twenty Questions (and Answers)|url-status=dead|archiveurl=https://web.archive.org/web/20130121121652/http://blogs.windows.com/windows/archive/b/windowsvista/archive/2007/01/20/windows-vista-content-protection-twenty-questions-and-answers.aspx|archivedate=2013-01-21}}</ref><ref>[[Peter Gutmann (computer scientist)#Criticism of Peter Gutmann.27s analysis of Vista DRM]]</ref>
 
While great care had been taken with AACS to ensure that content was encrypted along the entire path from the disc to the [[display device]], it was discovered in July 2006 that a perfect copy of any still frame from a film could be captured from certain [[Blu-ray]] and [[HD DVD]] software players by using the [[Print Screen]] function of the Windows [[operating system]].<ref>{{cite web
| url = http://hardware.slashdot.org/article.pl?sid=06/07/07/1255224
| title = Work Around for New DVD Format Protections
Line 89:
| date = 2007-01-26
|accessdate=2007-05-02
|work=[[BBC newsNews]]}}</ref><ref>{{cite web
| last = Block
| first = Ryan
Line 125:
|last=Yam
|date=2007-01-17
|work=DailyTech}}</ref>
|archive-date=2007-02-19
|archive-url=https://web.archive.org/web/20070219103102/http://www.dailytech.com/article.aspx?newsid=5747
|url-status=dead
}}</ref>
The Processing Key for the first Media Key Block version, which could be used to decrypt any AACS protected content released up to that point, was found and published on the Internet at the [[Doom9]] forums. AACS Licensing Authority sent multiple [[DMCA takedown notice]]s to web sites hosting the key.<ref>{{cite web
|url=http://www.chillingeffects.org/notice.cgi?sID=3218
Line 150 ⟶ 154:
|accessdate = 2007-05-02
|date=2007-05-02
|work=[[BBC newsNews]]}}</ref>
 
{{DetailsFurther|AACS encryption key controversy}}
 
[[Cyberlink]], the company which sells the [[PowerDVD]] player, stated that their software could not have been used as part of these exploits.<ref>{{cite web
Line 166 ⟶ 170:
}}</ref>
 
On April 16, 2007, the AACS consortium announced that it had revoked the Device Keys used by both Cyberlink PowerDVD and InterVideo [[WinDVD]], and patches were made available for users which provided uncompromised encryption keys and better security for the keys.<ref>{{cite web
|url=http://www.aacsla.com/press/
|title=Press Messages: AACS - Advanced Access Content System
|accessdate=2007-05-02}}</ref>
|archive-date=2007-04-30
|archive-url=https://web.archive.org/web/20070430070403/http://www.aacsla.com/press/
|url-status=dead
}}</ref>
<ref>{{cite web
|url=http://dailytech.com/AACS+Responds+to+Cracked+HD+DVD+and+Bluray+Disc+Protections/article5879.htm
Line 206 ⟶ 214:
|archivedate = 2007-09-27
}}</ref>
but they will release no details on their implementation. Users at Doom9 claim that the program makes use of the host certificate of [[PowerDVD]] version 6.5,<ref> {{cite web
| url = http://forum.doom9.org/showthread.php?t=122272
| title = AnyDVD method of operation
Line 212 ⟶ 220:
| date = 2007-02-15
| author = evdberg
| work = Doom9.net Forums }} </ref>
but SlySoft has claimed that the program would be unaffected by the AACS revocation system.<ref>{{cite web
|url = http://forum.slysoft.com/showpost.php?p=15263&postcount=10
Line 226 ⟶ 234:
 
=== Media key block renewals ===
{{Expand section|with=missing details, especially media key blocks #13–#64|small=no|date=December 2022}}
{{Outdated_section|date=December 2015}}
{| class="wikitable"
|-
Line 242 ⟶ 250:
| colspan="3" | Never used<ref>{{cite web |url=http://forum.doom9.org/showthread.php?p=1009643#post1009643 |title= New Processing Key found!! (MKB v3 is now open) |accessdate=2007-11-02 |author=aKzenT |date=2007-06-01 |work=doom9.org forums}}</ref>
|-
| [[AACS_encryption_key_controversyAACS encryption key controversy#2007|3]]
| [[The Matrix Trilogy|The ''Matrix'' Trilogy]]
| 2007-05-22
| 2007-05-17<ref>{{cite web |url=http://www.engadgethd.com/2007/05/17/newest-aacs-circumvented-the-matrix-trilogy-set-free/ |title=Newest AACS circumvented: The Matrix Trilogy set free |accessdate=2007-11-02 |author=Thomas Ricker |date=2007-05-17 |work=engadgethd.com}}</ref>
|-
| [[AACS_encryption_key_controversyAACS encryption key controversy#2008|4]]
| ''[[Transformers (film)|Transformers]]'', ''[[Spider-Man 3]]''
|
| 2007-10-30
|-
Line 255 ⟶ 263:
| colspan="3" | Never used<ref name="forum.slysoft.com">{{cite web |url=http://forum.slysoft.com/showthread.php?t=15550 |title=AVP: Requiem/Alvin and the Cipmunks logfiles |accessdate=2008-04-09 |author= |date= }}</ref>
|-
| [[AACS_encryption_key_controversyAACS encryption key controversy#2008|6]]
| colspan="3" | Never used<ref name="forum.slysoft.com"/>
|-
| [[AACS_encryption_key_controversyAACS encryption key controversy#2008|7]]
| ''[[Alvin and the Chipmunks (film)|Alvin and the Chipmunks]]'', ''[[Aliens vs. Predator: Requiem]]''
| 2008-04-06<ref>{{cite web |url=http://forum.slysoft.com/showthread.php?t=15550 |title=AVP: Requiem/Alvin and the Cipmunks logfiles |accessdate=2008-04-09 |author= |date= |publisher=}}</ref>
| 2008-04-11<ref>{{cite web |url=http://forum.slysoft.com/showthread.php?t=15698 |title=AnyDVD (HD) 6.4.1.1 released |accessdate=2008-04-11 |author= |date= |publisher=}}</ref>
|-
| [[AACS_encryption_key_controversyAACS encryption key controversy#2008|8]]
| ''[[The Forbidden Kingdom]]''
| 2008-08-26<ref>{{cite web |url=http://forum.slysoft.com/showthread.php?t=19612 |title=The Forbidden Kingdom (2008) - MKBv8 - Update server down? |accessdate=2008-04-09 |author= |date= |publisher=}}</ref>
| 2008-08-26<ref>{{cite web |url=http://forum.slysoft.com/showthread.php?t=19612 |title=The Forbidden Kingdom (2008) - MKBv8 - Update server down? |accessdate=2008-04-11 |author= |date= |publisher=}}</ref>
|-
| [[AACS_encryption_key_controversyAACS encryption key controversy#2009|9]]
| ?
| Approximately 2008-09-03<ref>{{cite web |url=http://forum.slysoft.com/showthread.php?t=19806&highlight=MKBV9 |title=Blu-ray YELLOW DRAGON'S COLORS Read Error |accessdate=2009-03-28 |author= |date= |publisher=}}</ref>
Line 274 ⟶ 282:
|accessdate=2009-03-28 |author= |date= |publisher=}}</ref>
|-
| [[AACS_encryption_key_controversyAACS encryption key controversy#2009|10]]
| ?
| ?
Line 284 ⟶ 292:
| ?
|-
| [[AACS_encryption_key_controversyAACS encryption key controversy#2009|12]]
| ''[[Body of Lies (film)|Body of Lies]]'', [[Baraka (film)|Baraka]]
| 2008-10-09
| 2009-04-06<ref>{{cite web |url=http://forum.doom9.org/showpost.php?p=1270338&postcount=156 |title=Disc using MKBv12 decrypted
|accessdate=2009-04-06 |author= |date= |publisher=}}</ref>
|-
| 13
|
|
|
|
|-
| 14
|
|
|
|
|-
| 15
|
|
|
|
|-
| 16
|
|
|
|
|-
| 17
|
|
|
|
|-
| 18
|
|
|
|
|-
|
|
|
|
|-
| 61
|
|
|
|-
| 62
|
|
|
|-
| 63
|
|
|
|-
| 64
|
|
|
|-
| 65
| ?
| Approximately 2018-06-19<ref>{{cite web |url=https://forum.doom9.org/showthread.php?p=1844914#post1844914 |title=Public MKBs |accessdate=2022-12-22 |date=2018-06-19}}</ref>
| ?
|-
| 66
| ?
| Approximately 2018-11-20<ref>{{cite web |url=https://forum.doom9.org/showthread.php?p=1858010#post1858010 |title=Public MKBs |accessdate=2022-12-22 |date=2018-11-20}}</ref>
| ?
|-
| 67
| colspan="3" | Never used<ref name="doom9-post1868374">{{cite web |url=https://forum.doom9.org/showthread.php?p=1868374#post1868374 |title=Public MKBs |accessdate=2022-12-22 |date=2019-03-11}}</ref>
|-
| 68
| ?
| Approximately 2019-03-11<ref name="doom9-post1868374" />
| ?
|-
| 69
| colspan="3" | Never used<ref name="doom9-post1878517">{{cite web |url=https://forum.doom9.org/showthread.php?p=1878517#post1878517 |title=Public MKBs |accessdate=2022-12-22 |date=2019-07-04 |work=doom9.org forums}}</ref>
|-
| 70
| ?
| Approximately 2019-07-04<ref name="doom9-post1878517" />
| ?
|-
| 71
| ?
| ?<ref>{{cite web |url=https://forum.doom9.org/showthread.php?p=1887549#post1887549 |title=Public MKBs |accessdate=2022-12-22 |date=2019-10-15 |work=doom9.org forums |quote=…&nbsp;MKBv71 was identical to MKBv70 as far as HRL/DRL&nbsp;…}}</ref>
| ?
|-
| 72
| ?
| Approximately 2019-10-15<ref name="doom9-post1887549">{{cite web |url=https://forum.doom9.org/showthread.php?p=1887549#post1887549 |title=Public MKBs |accessdate=2022-12-22 |date=2019-10-15 |work=doom9.org forums}}</ref>
| ?
|-
| 73
| colspan="3" | Never used<ref name="doom9-post1906427">{{cite web |url=https://forum.doom9.org/showthread.php?p=1906427#post1906427 |title=Public MKBs |accessdate=2022-12-22 |date=2020-04-05 |work=doom9.org forums}}</ref>
|-
| 74
| colspan="3" | Never used<ref name="doom9-post1906427" />
|-
| 75
| ?
| ?<ref name="doom9-post1970801">{{cite web |url=https://forum.doom9.org/showthread.php?p=1970801#post1970801 |title=Public MKBs |accessdate=2022-12-22 |date=2022-06-24 |work=doom9.org forums |quote=…&nbsp;I found out that MKBv75 does exist. However, HRL/DRL is identical to MKBv72}}</ref>
| ?
|-
| 76
| ?
| Approximately 2020-04-05<ref name="doom9-post1906427" />
| ?
|-
| 77
| ?
| Approximately 2022-06-24<ref name="doom9-post1970801" />
| ?
|-
| 78
| ?
| Approximately 2022-08-02<ref name="doom9-post1972563">{{cite web |url=https://forum.doom9.org/showthread.php?p=1972563#post1972563 |title=Public MKBs |accessdate=2022-12-22 |date=2022-08-02 |work=doom9.org forums}}</ref>
| ?
|}
 
==See also==
* [[AnyDVD]]
 
==References==