DVD ENCRYPTION CRACKED

What's the scoop?

What is CSS?

Download the source

Useful Links

DVD ENCRYPTION CRACKED (from 2600.com)

11/12/99

The November 25, 1997 edition of Off The Hook (relevant portion 21 minutes into show), reported that DVD copy protection had been defeated. The method involved a C program that hooks into the device drivers from Zoran's SoftDVD player to intercept decoded DVD data. Three years later, the encryption itself has been cracked.

Contents Scrambling System (CSS) is used in DVD copy protection to encode movies. Each DVD player, both software and standalone home theater systems, needs to have a key to decode the movie. Last week the Norwegian group Masters of Reverse Engineering (MoRE) discovered that the DVD player XingDVD did not encrypt its key for decrypting DVDs.

As a result they were able to create DeCSS, a free DVD decoder, that not only facilitated the creation of previously unavailable open source DVD players for Linux - also allowed people to copy DVDs. After the discovery of Xing's key they were able to derive over a hundred additional keys due to the weaknesses of the encryption algorithm. The ease in which this was accomplished can be blamed not just on Xing's sloppiness, but on the United State's notoriously antiquated encryption export laws that forced DVD manufactures to use weak encryption (40 bit) in the first place.

In the last few days there have been numerous reports of movie industry lawyers shutting down sites offering information about DeCSS. 2600 feels that any such suppression of information is a very dangerous precedent. That is why we feel it's necessary to preserve this information. We do feel sympathy for the DVD industry now that their encryption has been cracked. Perhaps they will learn from this. We hope they apply that knowledge in a constructive way. If they choose to fall back on intimidation, we'll just have to deal with that.

The above is taken from 2600.com. Please follow the link for more information.

But it's gone further than that! MPAA SEEKS TO OUTLAW LINKING TO DECSS

What is CSS?

CSS is a scrambling system used in the distribution for movies on DVD ( Digital Versatile Disc ) a high capacity CD like storage system. Its main purpose is to prevent the unauthorized duplication of disc contents. This is achieved through encrypting the files, and storing keys in hardware. Here we will describe the system, and show that even if the keys can be securely stored in hardware, the data will not be protected from unauthorized copying. Severe weaknesses in the ciphers effectively voids the need for the hardware keys when decrypting the content. This text was taken from http://crypto.gq.nu/

Here are the files!

DeCSS.zip

css-auth.tar.gz

css-auth directory of unpacked source files

Links

2600.com the site that seems to be in the center of it all. This site has so much more than just DVD stuff. Home of the 2600 magazine, the 'hackers quarterly' (great publication BTW) it has information about the hacking community and is home of the Off the Hook archives - a radio show devoted to hacking with an official focus on the telephone side of things.

http://crypto.gq.nu/ gives detailed technical information about css

http://www.opendvd.org/ exist ..to protect the right to reverse engineer and the right to fair use of materials from being trampled by the corporate establishment and big business interests. We don't want to pirate anything, we just want to watch DVDs on our computers, without having to use Microsoft Windows. This is our legal right, and we are fighting to protect it.

http://www.free-dvd.org.lu/ centers on the linux side of the arguement. Many interesting links.

http://www.pzcommunications.com/decss/main.htm All the information you could want about the deCSS utility

http://www.mpaa.org What does the MPAA have to say about the matter??




Back to my Homepage