Live data from Hacker News

Pirates Plunder 4K Hateful Eight, but Did They Crack DCP?

torrentfreak.com

1–10 of 242 posts

Re: Pirates Plunder 4K Hateful Eight, but Did They Crack DCP?

#3
post #2

Did the studio send a 4K master to Okko (which appears to be in Russia BTW) even though they only need HD?

Time will tell. DCP has a lot of security built-in. Both in hardware (FIPS certified, anti-intrusion, etc.) and in Software -- encryption up the wazoo.

Studios rely on a lot of insecure distribution and storage mechanisms for the big DCP file and instead rely heavily on the secure key exchange.

If they have cracked DCP, somehow, then it is a major coup.

Re: Pirates Plunder 4K Hateful Eight, but Did They Crack DCP?

#4
It's worth noting that the DCP format doesn't have a master key - each "reel" of an encrypted film has its own content key, which is decrypted by each DCP player's private FIPS protected key combined with a public Key Delivery Message from the distributor.

So if the DCP was indeed cracked, it was either because they gained access to the FIPS module in a DCP playback server, or they gained access to the plaintext content keys where the KDMs are generated. If they have the server's private key, they will be able to decrypt every other film that they have a KDM for and we should expect to see more DCP releases.

Re: Pirates Plunder 4K Hateful Eight, but Did They Crack DCP?

#5
I'm no expert on DCP or encryption. But from what I've read DCP uses AES 128, they probably didn't crack that. But also each projector gets its own unique key to decode the movie. Which I assume is somehow combined with the key in the projector to create the real decryption key.

So my first guess is that they had the ability to snoop on multiple key exchange messages and some how used that knowledge to find a shortcut to solve AES based on the gleaned knowledge from all the gathered keys, or they broke into a projector and took its internal key.

Re: Pirates Plunder 4K Hateful Eight, but Did They Crack DCP?

#6
post #3
post #2

Did the studio send a 4K master to Okko (which appears to be in Russia BTW) even though they only need HD?

Time will tell. DCP has a lot of security built-in. Both in hardware (FIPS certified, anti-intrusion, etc.) and in Software -- encryption up the wazoo. Studios rely on a lot of insecure distribution and storage mechanisms for the big DCP file and instead rely heavily on the secure key exchange. If they have cracked DCP, somehow, then it is a major coup.

Presumably the studio sends a master to Okko and then Okko transcodes it into various formats for streaming. Imagine an insider sets the transcoder to output 4K H.264 and then leaks the resulting file. It sounds like encryption won't help here.

Re: Pirates Plunder 4K Hateful Eight, but Did They Crack DCP?

#7
post #5

I'm no expert on DCP or encryption. But from what I've read DCP uses AES 128, they probably didn't crack that. But also each projector gets its own unique key to decode the movie. Which I assume is somehow combined with the key in the projector to create the real decryption key. So my first guess is that they had the ability to snoop on multiple key exchange messages and some how used that knowledge to find a shortcu…

It sounds like no projectors are involved here.

Re: Pirates Plunder 4K Hateful Eight, but Did They Crack DCP?

#9
post #7
post #5

I'm no expert on DCP or encryption. But from what I've read DCP uses AES 128, they probably didn't crack that. But also each projector gets its own unique key to decode the movie. Which I assume is somehow combined with the key in the projector to create the real decryption key. So my first guess is that they had the ability to snoop on multiple key exchange messages and some how used that knowledge to find a shortcu…

It sounds like no projectors are involved here.

Some of the projectors are connected to the DCP playback server via encrypted HD-SDI. The content is link-encrypted between the server and projector using Texas Instrument's "Cinelink" technology. If the TI "Enigma" module's private key was leaked, this would enable recording the plaintext SMPTE 292M video stream in real-time. The audio is un-encrypted obviously and easy to record, but it is watermarked so they would be able to trace back the recording to a specific KDM.

Re: Pirates Plunder 4K Hateful Eight, but Did They Crack DCP?

#10
I wonder if there's any way to measure the actual financial impact on this movie, which I'm guessing is close to zero (and the MPAA will tell you is millions of dollars). The amount of work and security put into these encryption schemes is sizable to say the least. But is anyone that wouldn't pirate it later going to pirate it now?
Post reply on HN