DVD CSS Cracked  

Weak Crypto
DVD's CSS Encryption Cracked
0600 Hrs 02 November 1999

The encryption on DVD's Content Scrambling System has been hacked. The encryption algorithm appears to be weak. Though a cracker program for DVD had been in circulation for some time, the algorithm and the code was only released last week on a Linux DVD development mailing list. This means that Linux users can play DVD without having to boot back into Microsoft Windows. It would also make the whole concept of the current regionalised copyrights void.

The DVD Forum has apparently come up with a system where they assign a unique key to each manufacturer and then include a corresponding key in each DVD. Thus, the demented logic goes, if a manufacturer's key is compromised, that corresponding key can be dropped from new DVDs so that they will not play. However the DVD Forum must not have counted on having its CSS algorithm subjected to scrutiny. Someone should have explained to them that "Security By Obscurity" is a euphemism for "Hackable".

The first indications were the leaking of the code used in Jon Johansen's DeCSS program.  The publication of a successful attack on CSS showed that it was possible to use a brute force attack of 2^16 complexity using six bytes of the output on the algorithm which would significantly reduce the time required to crack a key.

In order for a Linux DVD player, it was necessary to understand how the DVD CSS works. Given the abilities and skills of the Linux community, it was to be expected that such an event would occur sooner rather than later. However the stupidity of the DVD Forum is highlighted by their amazing incomprehension of even the most basic tenets of security. It is far easier to protect a crypto-system in hardware than software. In software, it is possible to extract the critical data. The widespread availability of Windows based DVD player software made the task easier. The fact that an Open Source player exists means that most of the safeguards that DVD had boasted can easily be circumvented.

One of the main benefits of DVD for the movie producers is that the copyrights areas can be forced. Thus a US region DVD should not be playable in a European region DVD player. However this protection was removed in hardware a long time ago and fixes are readily available. In software, it is a lot simpler. Whereas with ordinary video tape, there was an isolation between the US and Europe (different broadcast standards), DVD has no such isolation. It is also possible to buy DVDs from online sites like www.amazon.com which have not officially been released on video tape in Europe yet.

A Linux DVD HOW-TO

Derek Fawcus' CSS Site

 

Section: Hack News

[GSM Keys In 60 Seconds 07 November 1999] 
[DVD's CSS Cracked 02 November 1999] 
[
GSM Hacked - Phone Cloned 13 Apr 1998]
[GSM - Security By Idiocy 14 Apr 1998]
[GSM Simcard Emulator Released 25 Apr 1998]


© 1999 Hack Watch News
McCormac's Hack Watch News, Hack Watch News and Syndicated HackWatch are trademarks of Hack Watch News 

 

 Front Page
 Hack News
 Irish iNews
 Legal Action
 Telecoms
 Business
 Digital TV
 Cryptography
 BookReviews
 Linux News
 Security
 Microsoft
 Software
 Internet
 Black Book
 BookShop
Section Index