http://apache.dataloss.nl/~fred/www.nunce.org/hdcp/hdcp111901.htm
HDCP’s linear key exchange is a fundamental weaknesses. We can:
* Eavesdrop on any data
* Clone any device with only their public key
* Avoid any blacklist on devices
* Create new device keyvectors.
* In aggregate, we can usurp the authority completely.
The weaknesses are not easy to repair. Two proposed modifications are broken and still susceptible in $ O(n^2)$ work and $ n$ sets of keys to:
* Eavesdrop on any data
* Clone any device with only their public key
* Avoid any blacklist on devices
好像真的比想像好破….
這樣的話就會變成:
1. 無法阻止沒有得到licence的廠商copy已經發行的public key
2. 這個device即使照HDCP的規定實做black list功能,實質上也可以讓black list更新功能無力化。
於是以後發行的媒體就這樣….?
順道,XBOX360 HD-DVD Drive似乎是這個狀況的代表。_A_