Blu-ray copy protection group criticised over hack
By Simon Aughton,
A leading advocate of the Blu-ray next-generation optical storage format has spoken publicly to criticise the group responsible for the AACS copy protection technology used with both Blu-ray discs and the rival HD DVD format, following online reports that the encryption key had been hacked and is being distributed online.
'Josh', who runs the Blu-ray.com website, said that the decision by the AACS LA [Advanced Access Content System Licensing Authority] to send 'cease and desist' letters to websites that posted or linked to an encryption key for HD DVD discs has been entirely counter-productive. Instead of suppressing distribution of the key, it has succeeded only in proliferating it.
'The key was posted, and then numerous hacker sites posted the key to spread the word,' he wrote on the Blu-ray.com website. 'While it was available, it was contained to that relatively small group of individuals. Then AACS started issuing cease and desist orders, and that is when mainstream media caught on. Now, the code is everywhere - even on t-shirts - and it has become impossible to stop the virus. How one organisation can be so sloppy is beyond me, but one thing is sure: AACS has failed.'
It was after Digg.com removed links to the key after receiving one of the AACS LA missives that the extent to which the cease and desist campaign would misfire became clear. The news website was overwhelmed by angry users posting multiple instances of the code, forcing its founder Kevin Rose to backtrack and promise never in future to delete stories or comments containing the code.
Josh argues that the problem is not simply that the AACS key was so easily and widely distributed, but that the system itself is clearly flawed.
AACS, he says, 'has proven to be as effective as a screen door on a submarine. The first Title Key was discovered on the Web in January, and it took them three months to address the issue - not exactly the definition of a prompt response.'
More recently, a method was discovered using an HD DVD drive for an Xbox 360 to partially bypass the AACS system - you do not even need to have the encryption key to copy the disc content. This, Josh claims, indicates that future applications could 'bypass the system completely, meaning any key change would have zero effect on the drive's ability to read and copy media'.
Any shortcomings in AACS's ability to protect discs would appear to have greater implications for HD DVD then it would for Blu-ray. The Blu-ray Disc Association (which is not affiliated to Blu-ray.com) responded to the AACS hack by announcing that it would accelerate the introduction of BD-Plus, which promises much tighter controls on copying by uniquely encrypting individual discs, rather than applying just one key per title. The first BD+ discs are expected to be released in June.
AACS LA has been asked to comment.
You may also like...
advertisement
Latest Security Features
Q&A: The ID card commissioner talks cards and controversy
We spoke to ID card commissioner Sir John Pilling about his thoughts on the identity scheme and why we might all think he's a bit of prat down the line.
- So you've been hacked, now what?
- The problems facing Internet Explorer
- Year in Review: 2009 in your words
- Top 10 security predictions for 2010
- Year in Review: Top tech stories of 2009
- The worst IT disasters of 2009
- Five free security software suites
- How to stay safe shopping online
- Is it time to switch to IPv6?
Latest Security Reviews
Symantec Backup Exec 2010 review
Rating: ![]()
advertisement
Most popular
- Your Views: Google Street View across the UK
- Reviews round-up: Windows Phone 7 and Firefox Mobile
- Q&A: Conrad Wolfram on communicating with apps in Web 3.0
- Why is Microsoft accelerating Service Pack 1?
- Palm 'disapointed' by results, Pre sales
- Google updates Chrome, awards security bonus
- Report: Macs cost less to run than Windows PCs
- A guide to BlackBerry Messenger 5.0
- Windows Phone 7 review ? hands on
- HTC Legend review
Latest News Videos in Security
Video: Why security is everybody's responsibility
Rik Ferguson, senior security advisor at Trend Micro says it's up to all of us to make security work.
Whitepapers
Want more background on today's hottest IT trends?
Visit IT PRO's whitepaper library for more on virtualisation, encryption and other topics.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.




