Live data from Hacker News

Microsoft PlayReady – Complete Client Identity Compromise

seclists.org

71–80 of 175 posts

Re: Microsoft PlayReady – Complete Client Identity Compromise

#71
post #39
post #11

Earlier quoted context omitted.

4K streaming content is hit or miss because most services lock that behind Widevine L1, which requires implementors to use a secure enclave and the entire signal path to use strong encryption. If an L1 implementation gets compromised it quickly has its keys revoked and is downgraded to L2/L3, so piracy groups have a limited time window to dump as much 4K content as possible. Those lower Winevines tiers are permanentl…

Couldn't scene groups just keep the exploits for decrypting streams for themselves? Is there any way for Netflix/Widevine/PlayReady to detect this?

There are no exploits for Widevine. The system operates by requiring a key, which is obtained from the unsecure hardware enclaves of some of the thousands of devices whitelisted by Widevine. When you access and share publicly 4K content, the keys for that specific device are blacklisted, necessitating the purchase of a new device to extract a new key.

Re: Microsoft PlayReady – Complete Client Identity Compromise

#72
post #70
post #68

Earlier quoted context omitted.

The only way to reduce piracy is to make access easier and cheaper - something the music industry figured out. Sure music still gets pirated but its a lot less.

Well, no, that isn't the only way to reduce piracy. Another way would be widespread collaboration between the largest tech corporations to lock down the pipeline from manufacturing to sale and onward If users continue to accept this path, which... they seem to, that is where we'll inevitably end up.

What about the analog loophole? At some point, the data needs to be manifested in the real world.

Re: Microsoft PlayReady – Complete Client Identity Compromise

#73
post #55
post #20

Earlier quoted context omitted.

L3 can do FHD on Linux but it's the services config that prevents that.

Why do they do that?

The lower levels of Widevine protection are weaker, so the content providers like Netflix only allow playback in standard definition or 720p at those levels.

They don't want the highest quality to be available on devices where the DRM can easily be broken.

Re: Microsoft PlayReady – Complete Client Identity Compromise

#74
post #9

Earlier quoted context omitted.

Denuvo mostly works. Allegedly they have a custom approach to each new game, so cracks can take months to appear, with some unpopular games never having been cracked at all. The price is lowered performance, of course.

> Denuvo mostly works. Not for users: https://gamerant.com/denuvo-outage-servers-down-persona-5-ro... > Allegedly they have a custom approach to each new game, so cracks can take months to appear, with some unpopular games never having been cracked at all From what I hear, it's cracked in a matter of days or weeks. I haven't checked whether this is true or not, so I can't say you are wrong about some (most?) cracks t…

Looking at the previous two years of uncracked Denuvo and only selecting games that seem notable:

    Dragon's Dogma 2 (2024)
    Like a Dragon: Infinite Wealth (2024)
    Suicide Squad: Kill the Justice League (2024)
    Street Fighter 6 (2023)
    Hi-Fi Rush (2023)
    Dead Space (2023)
    Star Wars Jedi: Survivor (2023)
    Persona 5 Tactica (2023)
    EA Sports FC 24 (2023)
    NBA 2K24 (2023)
    Assassin's Creed Mirage (2023)
    Atomic Heart (2023)
    Lost Judgment (2022)
    Sonic Frontiers (2022)
    Sonic Origins (2022)
    Persona 4 Arena Ultimax (2022)
    Persona 5 Royal (2022)
    Sniper Elite 5 (2022)
    Marvel's Midnight Suns (2022)
    Total War: Warhammer III (2022)
Going back further there's more high profile games that were never cracked. The system seems to work as intended in some cases.

Re: Microsoft PlayReady – Complete Client Identity Compromise

#75
post #54
post #21

Earlier quoted context omitted.

There's three Winevine tiers, L1, L2 and L3, which generally correspond to 4K, 1080p and 720p respectively though it depends on the service. L3 is what you get on Linux. L2 is supposed to be more secure than L3 but AFAICT it makes little difference to piracy groups, L1 is the only actual roadblock for them.

Why are Linux users limited to L3?

L1/L2 requires a third party who could be liable to sign that the drivers are unmodified to the hardware.

On a general purpose Linux installation who would do that?

(And who in the Linux using community wouldn't take any efforts by someone to try as an afront, bluntly).

Re: Microsoft PlayReady – Complete Client Identity Compromise

#76
post #46

Earlier quoted context omitted.

As long as it stops even 100,000 people from not downloading videos off of Netflix, from an executive’s perspective, it pays for itself. To them, it’s like saying Speed Limit signs are useless, because cars can go faster than the number posted by literally pressing a button. That’s not the point.

If you take the capitalistic lust of the corporate executive to its logical extreme, given the massive costs of the DRM tech you'd think that at least one of them would realize that they could make more money if they didn't have to pay for something that doesn't work. The economics of distributing the copies are such that it doesn't actually matter if it's easy or hard for 1 or 100,000 people to break the protection.

I think DRM works fine for the actual customers, the companies that are distributing video who need to convince the movie producers that they are taking it all very seriously, so they need to check some “our platform uses DRM” box. It all looks very odd from us downstream. But, still, most people don’t break DRM so it must be doing something.

For a long time the industry worked by shipping movies off the theaters, to be run in projection room secured by kids doing after-school jobs. I think they aren’t concerned with perfection.

Re: Microsoft PlayReady – Complete Client Identity Compromise

#77

Is there any video DRM scheme which successfully protects video content appearing on the pirate bay within 24 hours? I really don't see why so many millions (billions?) of dollars have been spent on technologies which so far have never kept the bad guys out.

The DRM clearly does work in preventing "casual piracy" - where average users do things like downloading a file and keeping it forever (even after cancelling a subscription) or copying the file to a friend.

Re: Microsoft PlayReady – Complete Client Identity Compromise

#78
post #13

Earlier quoted context omitted.

> have never kept the bad guys out Careful who you call the bad guys. A lot of "piracy" comes from the people who spend the most money on the content they pirate. I personally think the best DRM approaches are those that keep "the honest people honest:" IE, metadata that identifies copyright owners, flags that identify content that has restrictions due to copyright, and casual protections. (Think of a "do not enter"…

Funny thing is that most streaming platforms only have DRM because content owners pressure them. It's expensive and a huge hassle to get right. While indeed DRM barely contributes in fighting redistribution over Pirate Bay, it does prevent stream sharing. Ie.: the platform saves a lot of CDN bandwidth by forcing that onto torrents.

I think this is not entirely true, because HBO and Netflix have DRM on their own shows.

Re: Microsoft PlayReady – Complete Client Identity Compromise

#79
post #9

Is there any video DRM scheme which successfully protects video content appearing on the pirate bay within 24 hours? I really don't see why so many millions (billions?) of dollars have been spent on technologies which so far have never kept the bad guys out.

Denuvo mostly works. Allegedly they have a custom approach to each new game, so cracks can take months to appear, with some unpopular games never having been cracked at all. The price is lowered performance, of course.

> Allegedly they have a custom approach to each new game, so cracks can take months to appear

It's because it's tedious to crack it, it's not really a rocket science, they just generate new VM for the binary so you can't automate it, they inject A LOT of code paths which you need to manually follow and change. That's the only reason why games stay uncracked for months. It's a war of attrition.

> with some unpopular games never having been cracked at all

That's not exactly true actually, you need to pay for Denuvo license every year, that's why after some months or a few years it's removed from most of the games.

Re: Microsoft PlayReady – Complete Client Identity Compromise

#80

Is there any video DRM scheme which successfully protects video content appearing on the pirate bay within 24 hours? I really don't see why so many millions (billions?) of dollars have been spent on technologies which so far have never kept the bad guys out.

At this point, video DRM is more of a legal protection than a technical protection.
Post reply on HN