Another AACS Device Key Found; How Will Studios Respond?

By Scott M. Fulton, III | Published March 5, 2007, 5:28 PM

Another user of the Doom9 Forum, whose members have been actively working to develop a system to subvert AACS copy protection, has apparently discovered in a memory dump a legitimate device key - the cryptographic element licensed to components in order to obtain the volume key automatically from high-definition HD DVD discs, according to a post yesterday. The source of the key appears to be CyberLink PowerDVD; and another forum user was able to use a published AACS formula to validate its authenticity.

At this rate, it may only be an academic matter before programmers there refine a method by which an independent program uses this or some other device key to decrypt and even play high-def content on computers, without the intervention of a licensed program.

In the DVD world, independents can develop software like ZoomPlayer that use published methods for invoking codecs and playing content, without developers fearing that the creation of such programs might be illegal or a violation of copyright.

In the high-def DVD world, content is encrypted, and content providers currently consider it a violation of copyright for individuals to subvert copy protection, even if they have no motive to distribute copied material to others.

A bill re-introduced in the US House of Representatives would make exceptions to the law so that individuals could subvert copy protection for personal purposes only, which would make it impossible for studios to prove copyright infringement violations against individuals unless they could prove their copying falls outside of fair use provisions.

With legislation such as the FAIR USE bill having a better chance of passage than ever before, content providers will certainly be searching for new legal precedent for charges against suspected violators. So yesterday's discovery of a real AACS-licensed device key lurking in memory could actually have some ominous portent, especially as Doom9 Forum users discuss the possibility of discussing the creation of freely distributed high-def disc players: Are device keys provided by the AACS Licensing Authority private property?

It will be difficult to prove they're not. After all, content providers are redistributing a segment of code for which they paid a fee. But an examination of the AACS LA Interim Content Provider Agreement indicates that the licensing authority considers the fee to be in exchange for the rights of so-called "adopters" to use the keys; they don't appear to be considered owners of the keys themselves, and the intellectual property foundation for their creation is certainly considered the property of AACS LA.

A device key may very well be someone's private property; the AACS LA would probably be first to lay claim to it.

Still, in the absence of a legal foundation for copyright infringement -- assuming the FAIR USE bill passes and is signed into law -- content providers may still attempt to make the case that the use of someone else's pilfered device key in an unauthorized freely distributed high-def media player could constitute a misappropriation of stolen property - even if it's not their own, and even if the end use of that property is exempt from legal infringement.

It would be uncharted waters for both plaintiffs and defendants in this hypothetical situation. Yet given that legislators may be on the verge of removing from the content industry's reach the most potent prosecutorial tool it has ever been given -- the far-reaching language of the Digital Millennium Copyright Act -- even the most well-meaning reverse-engineers cannot expect the content industry to respond by just shrugging its shoulders and walking away from the fight.

Other members of the Doom9 Forum over the past few days have expressed concern over whether AACS LA would invoke its revocation key to render devices whose keys have been exposed - including software using those keys to pretend to be those devices - incapable of playing discs. While knowledgeable members of the forum state that this is indeed possible, the makers of the popular shareware AnyDVD are reassuring users that its software has somehow been immunized by any revocation that AACS LA attempts, though the authors are not divulging how.

A new revision of AnyDVD now claims to be able to back up Blu-ray discs in addition to HD DVD, when the volume keys of those discs have been located.

Comments

View comments by with a score of at least

The sooner this copy protection is crippled or removed, the better. The studios have gone too far in this case and put too many limitations on how and when people can watch movies they've legally purchased. Doom9's efforts should be applauded, for the their success will bring back the 'fair use' that legislation can't enforce.

Score: 0

|

Exactly.

Score: 0

|

agreed, i am really tired of protection that limits what I do with what I spend my money on.

Score: 0

|

Thats my bro hard at work.

Sukit long'n'hard MPAA, RIAA and everyone else that thinks clamping down and pissing off consumers is the answer to fair use backups.

***PROUD MEMBER OF "the circle" on DOOM9***

Score: 0

|

Well said.

Hey, this reminds me of a time where I heard a sick and weak animal wailing off in the distance - I then turned to my wife and said "It's taking a long time to die, whatever it is."

Score: 0

|

After telling US to mind its own business, Kroes slaps caps on Rambus royalties

The holder of many patents worldwide pertaining to DDR memory offered to reduce its royalty stake in that technology, and today the EU said yes.

Why Apple succeeds, and always will

The company consistently plays by different rules, literally like David did in his battle against Goliath.

EC's Kroes to US senators: Mind your own business on Oracle + Sun

UPDATED The EU's antitrust chief told the United States Senate Tuesday that any merger that takes place in the world is more her affair than theirs.

Betanews Podcast: Rupert Murdoch and the buying stuff online problem

We'll have a more difficult time paying for online news if the underlying protocol for online payment has a big gaping hole in it.

In a peace offering to newspapers, Google offers a new news format

It's probably not a solution to the woes of major news publishers, but Living Stories may gather a few of those publishers together in search of one.

Google Maps doesn't prevent car accidents, only search accidents

This week, Google updated Maps for Android 3.3.1, adding topography, nearby points of interest, and error reporting.

DOJ: Microsoft interop docs are now 'substantially complete'

A major milestone in the US Government's oversight of Microsoft is passed, as the Justice Dept. is now saying the company's protocol documents make sense.

The $1 DVD rental debate: LA group says Redbox will lose movie makers $1B

A report from the Los Angeles Economic Development Corporation says cheap Redbox DVD rentals could seriously damage the movie business.

First impressions of Droid: Easy, breezy, friendly, if a little fat

Though it's not quite as well-polished as Apple's iPhone OS, the version of Android that Motorola's Droid phone sports is still a breeze to use.

Windows fix for TLS security bug still forthcoming, won't be Tuesday

Anyone looking for a fix for last month's discovery of a potentially serious security hole in TLS and SSL may have to wait until everyone is ready to act together.

Not the first, not the last, technology predictions for 2010

Carmi Levy | Wide Angle Zoom: The real truth is probably that what went around in 2009, will come around to haunt us next year.