RealNetworks subsidiary's gaffe led to DVD crack

Hackers break 'unbreakable' DVD encryption


It hasn't been RealNetworks' week. Just as the company's scheme to nab Real Jukebox users' personal preferences data was exposed on Monday, yesterday it emerged that its engineers were responsible for the gaffe that allowed European hackers to crack the DVD encryption code.

According to Wired News, the hackers, from the Norwegian group Masters of Reverse Engineering (MoRE), said they'd been able to break through the uncrackable code because Xing Technologies' XingDVD software had failed to protect their decryption key as all DVD technology licensees are required to do.

Xing Technologies, you may recall, is a wholly owned subsidiary of RealNetworks. Whoops. DVD files are encrypted using 40-bit keys. While that's usually considered secure for most such transactions -- though it's still rather less than the standard for e-commerce transactions, which increasingly use 128-bit keys -- it is held to be difficult to crack unless you have a very powerful system and/or a lot of time.

Because Xing failed to encode its decryption key, MoRE was apparently able to figure out the format, and claim to have found over 170 other keys that will decrypt DVD files. Each DVD has 400 keys programmed in. All these keys are used by their 60K DeCSS application, which can copy the files from a DVD and save them in an unencrypted format on a hard drive.

Wired News found many of the movie and consumer electronics industries' trade organisations decidedly unwilling to comment of the news of the crack, so it's clear that they're rattled. However, such is the growing demand for DVD that a fix can't be far off, but implementing it quickly won't be cheap. Will RealNetworks be forced to pay for the work, we wonder? ®


Other stories you might like

  • Amazon warehouse staff granted second chance to vote for unionization

    US labor watchdog tosses previous failed result in the trash

    America's labor watchdog has given workers at Amazon’s warehouse in Bessemer, Alabama, another crack at voting for unionization after their first attempt failed earlier this year.

    “It is ordered that the election that commenced on February 8 is set aside, and a new election shall be conducted,” Lisa Henderson, regional director at the National Labor Relations Board, ruled [PDF] on Tuesday.

    “The National Labor Relations Board will conduct a second secret ballot election among the unit employees. Employees will vote whether they wish to be represented for purposes of collective bargaining by the Retail, Wholesale and Department Store Union.”

    Continue reading
  • It's the flu season – FluBot, that is: Surge of info-stealing Android malware detected

    And a bunch of bank-account-raiding trojans also identified

    FluBot, a family of Android malware, is circulating again via SMS messaging, according to authorities in Finland.

    The Nordic country's National Cyber Security Center (NCSC-FI) lately warned that scam messages written in Finnish are being sent in the hope that recipients will click the included link to a website that requests permission to install an application that's malicious.

    "The messages are written in Finnish," the NCSC-FI explained. "They are written without Scandinavian letters (å, ä and ö) and include, for example, the characters +, /, &, % and @ in illogical places in the text to make it more difficult for telecommunications operators to filter the messages. The theme of the text may be that the recipient has received a voicemail message or a message from their mobile operator."

    Continue reading
  • AsmREPL: Wing your way through x86-64 assembly language

    Assemblers unite

    Ruby developer and internet japester Aaron Patterson has published a REPL for 64-bit x86 assembly language, enabling interactive coding in the lowest-level language of all.

    REPL stands for "read-evaluate-print loop", and REPLs were first seen in Lisp development environments such as Lisp Machines. They allow incremental development: programmers can write code on the fly, entering expressions or blocks of code, having them evaluated – executed – immediately, and the results printed out. This was viable because of the way Lisp blurred the lines between interpreted and compiled languages; these days, they're a standard feature of most scripting languages.

    Patterson has previously offered ground-breaking developer productivity enhancements such as an analogue terminal bell and performance-enhancing firmware for the Stack Overflow keyboard. This only has Ctrl, C, and V keys for extra-easy copy-pasting, but Patterson's firmware removes the tedious need to hold control.

    Continue reading

Biting the hand that feeds IT © 1998–2021