Live data from Hacker News

How Stuff Gets eXposed

sgx.fail

11–20 of 47 posts

Re: How Stuff Gets eXposed

#11
post #9
post #5

Good. This concept of continually restricting the owner of a processor from controlling the code that executes on his machine is a futile attempt at providing "products" which are nothing more than theft. The only reason this is a requirement for POWERDVD is because they insist on treating people like thieves and locking down the ability to watch high quality movies behind a wall that keeps the user from seeing and c…

> everyone should be ashamed for using Intel hardware when AMD chips do not abuse the user AMD has their own analog to Intel's Management Engine. Maybe they don't have SGX or something like it, but AMD is no saint either. In theory, SGX can be used for good: see Signal's use to avoid seeing users' contact lists. Granted, their scheme is pretty broken given how broken SGX is (and probably for other reasons), but I thi…

You say we can't force companies to not use tech in anti user ways, but then you'll give them your money becuase you can't find a laptop with an AMD chip. And I assume you just haven't shopped for a laptop long enough or you'd find one that matches your needs without Intel taking a dump on your chest while pretending to care about anything more than your money.

Re: How Stuff Gets eXposed

#12
post #5

Good. This concept of continually restricting the owner of a processor from controlling the code that executes on his machine is a futile attempt at providing "products" which are nothing more than theft. The only reason this is a requirement for POWERDVD is because they insist on treating people like thieves and locking down the ability to watch high quality movies behind a wall that keeps the user from seeing and c…

> making users pay for CPU features while shipping the exact same chip to everyone

This is already a pretty common practice IIRC, it's just that the features are usually disabled at the hardware level.

Re: How Stuff Gets eXposed

#13
post #5

Good. This concept of continually restricting the owner of a processor from controlling the code that executes on his machine is a futile attempt at providing "products" which are nothing more than theft. The only reason this is a requirement for POWERDVD is because they insist on treating people like thieves and locking down the ability to watch high quality movies behind a wall that keeps the user from seeing and c…

AMD has the PSP too.

Re: How Stuff Gets eXposed

#14
post #8

Earlier quoted context omitted.

No, but if you buy proprietary razors, they will sure as heck try to make sure you only use their blades. ;) But seriously... I agree. I get that DRM is meant to prevent "casual copying," but right now, that's just called "Downloading from 1337x." Unfortunately, I think that the only lesson movie studios are going to learn from this... is that they should phase out physical media and use Widevine and FairPlay hardwar…

> Widevine its pretty widely available how to get around this now. I have my own implementation actually. I wont say its "easy", but it is doable. And you can get quite a lot even with just an L3 CDM. Also at least one public Widevine proxy is now available, as well as a content key database.

Sure, but without the keys that someone extracted from devices there is no way to "get around this". L3 CDM from browsers is easy to extract as its just sitting in .dll/.so file behind AES whitebox but they downgraded it to content with low quality on most streaming platforms.

> Also at least one public Widevine proxy is now available, as well as a content key database.

Public? Can you share some info?

Re: How Stuff Gets eXposed

#15
post #14
post #8

Earlier quoted context omitted.

> Widevine its pretty widely available how to get around this now. I have my own implementation actually. I wont say its "easy", but it is doable. And you can get quite a lot even with just an L3 CDM. Also at least one public Widevine proxy is now available, as well as a content key database.

Sure, but without the keys that someone extracted from devices there is no way to "get around this". L3 CDM from browsers is easy to extract as its just sitting in .dll/.so file behind AES whitebox but they downgraded it to content with low quality on most streaming platforms. > Also at least one public Widevine proxy is now available, as well as a content key database. Public? Can you share some info?

[deleted]

Re: How Stuff Gets eXposed

#16
post #8

Earlier quoted context omitted.

No, but if you buy proprietary razors, they will sure as heck try to make sure you only use their blades. ;) But seriously... I agree. I get that DRM is meant to prevent "casual copying," but right now, that's just called "Downloading from 1337x." Unfortunately, I think that the only lesson movie studios are going to learn from this... is that they should phase out physical media and use Widevine and FairPlay hardwar…

> Widevine its pretty widely available how to get around this now. I have my own implementation actually. I wont say its "easy", but it is doable. And you can get quite a lot even with just an L3 CDM. Also at least one public Widevine proxy is now available, as well as a content key database.

I'm specifically talking about Widevine L1 in this case, which protects 1080p and 4K streams - not Widevine L3 which will always be vulnerable to some form of software-related attack. My remarks were mainly about how Widevine L1 has been shown to be much more protective in general against broadly-distributed attacks than AACS 1 and 2, even if pirates have secret workarounds.

Re: How Stuff Gets eXposed

#17
post #8

Earlier quoted context omitted.

> Widevine its pretty widely available how to get around this now. I have my own implementation actually. I wont say its "easy", but it is doable. And you can get quite a lot even with just an L3 CDM. Also at least one public Widevine proxy is now available, as well as a content key database.

I'm specifically talking about Widevine L1 in this case, which protects 1080p and 4K streams - not Widevine L3 which will always be vulnerable to some form of software-related attack. My remarks were mainly about how Widevine L1 has been shown to be much more protective in general against broadly-distributed attacks than AACS 1 and 2, even if pirates have secret workarounds.

> 1080p

I dont think you (and the public in general) realize that several sites offer 1080p, even with L3.

Re: How Stuff Gets eXposed

#18
post #14
post #8

Earlier quoted context omitted.

> Widevine its pretty widely available how to get around this now. I have my own implementation actually. I wont say its "easy", but it is doable. And you can get quite a lot even with just an L3 CDM. Also at least one public Widevine proxy is now available, as well as a content key database.

Sure, but without the keys that someone extracted from devices there is no way to "get around this". L3 CDM from browsers is easy to extract as its just sitting in .dll/.so file behind AES whitebox but they downgraded it to content with low quality on most streaming platforms. > Also at least one public Widevine proxy is now available, as well as a content key database. Public? Can you share some info?

contact me on Discord - check my bio

Re: How Stuff Gets eXposed

#19
post #14
post #8

Earlier quoted context omitted.

> Widevine its pretty widely available how to get around this now. I have my own implementation actually. I wont say its "easy", but it is doable. And you can get quite a lot even with just an L3 CDM. Also at least one public Widevine proxy is now available, as well as a content key database.

Sure, but without the keys that someone extracted from devices there is no way to "get around this". L3 CDM from browsers is easy to extract as its just sitting in .dll/.so file behind AES whitebox but they downgraded it to content with low quality on most streaming platforms. > Also at least one public Widevine proxy is now available, as well as a content key database. Public? Can you share some info?

There are quite a few platforms that still offer e.g.1080p with L3, which I'm still looking for a replacement source for. The NHK uses it for time-limited content, such as interviews with manga authors which I've ripped for people to fansub. There's much more out there than just Netflix, Disney Amazon et al.

Re: How Stuff Gets eXposed

#20
post #5

Good. This concept of continually restricting the owner of a processor from controlling the code that executes on his machine is a futile attempt at providing "products" which are nothing more than theft. The only reason this is a requirement for POWERDVD is because they insist on treating people like thieves and locking down the ability to watch high quality movies behind a wall that keeps the user from seeing and c…

AMD has the PSP too.

The PSP is not the same as SGX. That's more like the management engine, and while I agree that both Intel and AMD are shipping that antiuser "feautue" and that AMD had its own implementation of a trusted execution environment like SGX, the current AMD chips do not ship with it. AMD is not perfect, but it's sad that people can choose one or the other and still prefer to hand Intel their money when Intel goes out of their way to take advantage of their users.

- Intel wanted to lock users to RamBus RDRAM which was incompatible with AMD chips and a patented technology which AMD would not be able to use.

- Intel shipped the aforemtioned CPU identifier. Intel did the management engine first.

- Intel locks its chips from frequency tuning so they can charge more for overclocking.

- Intel locks the amount of RAM that is addressable by their chips arbitrarily rather than basing it on hardware support in order to squeeze more money out of you.

- Intel and NVIDIA locked their GPU linking technology (SLI) while AMD allows Crossfire to run on both Intel and AMD processors.

These are just the ones I remember off the top of my head. Not all of them may be current, but it's obvious that Intel has no problem extorting money from their customers in a million ways where AMD doesn't play this disgusting game.

Post reply on HN