Live data from Hacker News

Microsoft PlayReady – Complete Client Identity Compromise

seclists.org

121–130 of 175 posts

Re: Microsoft PlayReady – Complete Client Identity Compromise

#121
post #19
post #11

Earlier quoted context omitted.

4K streaming content is hit or miss because most services lock that behind Widevine L1, which requires implementors to use a secure enclave and the entire signal path to use strong encryption. If an L1 implementation gets compromised it quickly has its keys revoked and is downgraded to L2/L3, so piracy groups have a limited time window to dump as much 4K content as possible. Those lower Winevines tiers are permanentl…

> so everything is immediately available in at least 1080p. Aren't the lower tiers only 720p? At least all the streaming services give Linux users only 720p. (There is a workaround for one particular service to still get 1080p - I'm paying for it so I better can watch it in 1080p! The moment this stops working I cancel my subscription.)

[deleted]

Re: Microsoft PlayReady – Complete Client Identity Compromise

#122

Earlier quoted context omitted.

> Sure, there’s some piracy - but even at the end of the day, pirates would watch a smartphone recording to save a buck. I spend a lot of money on hard drives and Usenet to have quality rips. It's a service problem, not about the money

Yes, yes, the Gabe Newell quote - even though that quote was only an explanation for why piracy happened. Commonly lost in translation, that quote never once said piracy was justified or acceptable, nor did he encourage piracy under any circumstances.

I never claimed he did? I was just responding to your incorrect assumption

Re: Microsoft PlayReady – Complete Client Identity Compromise

#123
post #19
post #11

Earlier quoted context omitted.

4K streaming content is hit or miss because most services lock that behind Widevine L1, which requires implementors to use a secure enclave and the entire signal path to use strong encryption. If an L1 implementation gets compromised it quickly has its keys revoked and is downgraded to L2/L3, so piracy groups have a limited time window to dump as much 4K content as possible. Those lower Winevines tiers are permanentl…

> so everything is immediately available in at least 1080p. Aren't the lower tiers only 720p? At least all the streaming services give Linux users only 720p. (There is a workaround for one particular service to still get 1080p - I'm paying for it so I better can watch it in 1080p! The moment this stops working I cancel my subscription.)

So it turns out chrome os ships with a shared library to support L2 (since it's entirely in software). There's a patch to get it working on other Linux distributions.

Re: Microsoft PlayReady – Complete Client Identity Compromise

#124
post #82
post #46

Earlier quoted context omitted.

If you take the capitalistic lust of the corporate executive to its logical extreme, given the massive costs of the DRM tech you'd think that at least one of them would realize that they could make more money if they didn't have to pay for something that doesn't work. The economics of distributing the copies are such that it doesn't actually matter if it's easy or hard for 1 or 100,000 people to break the protection.

I work for a large streaming service and a significant part of my work is content protection. Honestly, tech folks misunderstanding of DRM and content protection is significant. There's some assumption that people are inherently honest and that we're just money grabbing. In the years that I've been doing this I've seen a lot of things and nothing has convinced me that if we turned off DRM we'd: 1) save money 2) not h…

The argument from the other side is at least as frustrating.

> ...nothing has convinced me that if we turned off DRM we'd: 1) save money 2) not have issues with piracy proliferation

> That night our anti-piracy team took down 20,000+ illegal streams

You already have enormous issues with piracy proliferation. The money you spend on DRM may be "relatively insignificant", but it's still money being wasted on "protection" that has already proven to be utterly ineffective.

I am in neither of your three groups. I want to pay for content. I pay for a lot of music, for example. But you're not going to bully me into paying for your shit by making it as user hostile as possible. As a paying customer I expect at least the level of service that piracy groups have no trouble providing, but instead I'm treated like an enemy every step of the way.

In practice this means I avoid TV shows and movies, but when I do want to watch one I have absolutely zero moral qualms pirating a product that is not for sale. I'll even go out of my way to look for a DRM-free copy I can pay for first. This takes more time than pirating it once I inevitably find out that's not available.

Re: Microsoft PlayReady – Complete Client Identity Compromise

#125
post #5

Given how horribly all major companies, MS most certainly included, confuse authentication vs. authorization, this is almost certainly able to be paired with a 'vulnerable' (all) endpoint to retrieve/post/update player information. The horizontal pivot from DRM/crypto-managed Identity to a session token, an unassumingly-kosher redirect, or just omitting the "AUTHENTICATION" header itself is a trivial exercise for the…

I don't understand a word you've said.

Find an endpoint that checks the validity of the DRM token they have broken.

See if that endpoint just hinges on that DRM token, since its crypto-secure, why check any other fields?

Spoof other fields.

10k+ 0-day exploit.

Re: Microsoft PlayReady – Complete Client Identity Compromise

#126
post #5

Given how horribly all major companies, MS most certainly included, confuse authentication vs. authorization, this is almost certainly able to be paired with a 'vulnerable' (all) endpoint to retrieve/post/update player information. The horizontal pivot from DRM/crypto-managed Identity to a session token, an unassumingly-kosher redirect, or just omitting the "AUTHENTICATION" header itself is a trivial exercise for the…

And it paints an even bigger target on domestic Windows machines used for media content. Who wants to "steal" their _own_ keys? Microsoft's broken DRM scheme creates objects of value which it then tries to store on the client's machine deliberately beyond the owners control and security management. It is adversarial to the user. This is clearly a no-win situation... hence the snarky sign-off about vendors "raising th…

I'd agree, but licensed content can be revoked - MS is pretty good at publishing digests of "known-compromised" ID's/Serials/Private Keys.

I'd be more concerned about any other, more important facets of a user's account/assets/property that assumes the DRM is secure, and leans on that.

Re: Microsoft PlayReady – Complete Client Identity Compromise

#127
post #70

Earlier quoted context omitted.

Well, no, that isn't the only way to reduce piracy. Another way would be widespread collaboration between the largest tech corporations to lock down the pipeline from manufacturing to sale and onward If users continue to accept this path, which... they seem to, that is where we'll inevitably end up.

No, that's where we are now. Not in the future, right now. It isn't working. You fundamentally can't prevent someone copying your file. It isn't possible, full stop. You can only make it maximally inconvenient. You can't encrypt a user's eyeballs, so the media has to be transmitted in the clear at some level. Be it intercepting the LVDS signal to your TV panel or just pointing a camcorder at the screen. The current t…

I wish I shared your certainty. I certainly don't share your faith in capitalism to solve anything.

Re: Microsoft PlayReady – Complete Client Identity Compromise

#128
post #74

Earlier quoted context omitted.

> Denuvo mostly works. Not for users: https://gamerant.com/denuvo-outage-servers-down-persona-5-ro... > Allegedly they have a custom approach to each new game, so cracks can take months to appear, with some unpopular games never having been cracked at all From what I hear, it's cracked in a matter of days or weeks. I haven't checked whether this is true or not, so I can't say you are wrong about some (most?) cracks t…

Looking at the previous two years of uncracked Denuvo and only selecting games that seem notable: Dragon's Dogma 2 (2024) Like a Dragon: Infinite Wealth (2024) Suicide Squad: Kill the Justice League (2024) Street Fighter 6 (2023) Hi-Fi Rush (2023) Dead Space (2023) Star Wars Jedi: Survivor (2023) Persona 5 Tactica (2023) EA Sports FC 24 (2023) NBA 2K24 (2023) Assassin's Creed Mirage (2023) Atomic Heart (2023) Lost Ju…

Many denuvo games are eventually released without denuvo and are then instantly pirated. Looks like the cost of denuvo is high enough for game publishers to stick to it just enough to reach profitability and then ditch it.

Re: Microsoft PlayReady – Complete Client Identity Compromise

#129
post #82

Earlier quoted context omitted.

I work for a large streaming service and a significant part of my work is content protection. Honestly, tech folks misunderstanding of DRM and content protection is significant. There's some assumption that people are inherently honest and that we're just money grabbing. In the years that I've been doing this I've seen a lot of things and nothing has convinced me that if we turned off DRM we'd: 1) save money 2) not h…

That's all beside the point. Hardware belongs to the user and should be under the user's control. Treacherous computing should be highly taboo and illegal. The "sustainability" of Disney's profits are not important. To suggest otherwise on a site literally named Hacker News is comical.

Why would bringing up sustainability of any business be comical at Hacker news?

How do you make money? Why should it not be for free? Your sustainability is important?

We agree on hardware belonging to the user by the way.

Re: Microsoft PlayReady – Complete Client Identity Compromise

#130
post #82
post #46

Earlier quoted context omitted.

If you take the capitalistic lust of the corporate executive to its logical extreme, given the massive costs of the DRM tech you'd think that at least one of them would realize that they could make more money if they didn't have to pay for something that doesn't work. The economics of distributing the copies are such that it doesn't actually matter if it's easy or hard for 1 or 100,000 people to break the protection.

I work for a large streaming service and a significant part of my work is content protection. Honestly, tech folks misunderstanding of DRM and content protection is significant. There's some assumption that people are inherently honest and that we're just money grabbing. In the years that I've been doing this I've seen a lot of things and nothing has convinced me that if we turned off DRM we'd: 1) save money 2) not h…

I understand your points and I wish you all the best with your job. But please tell your bosses to let me buy single episodes of the series I like or every movie in history. No monthly subscriptions. I stay months without watching anything, then maybe two or three series at once, one episode per week each. The industry business model doesn't fit my habits.
Post reply on HN