3 ms·
Here's an aside / funny thing about jar signing on blurays. The Blu-Ray spec only really enforces jar certificate verification for encrypted blurays (i.e. AACS
by compsciphd 6y ago
Here's an aside / funny thing about jar signing on blurays. The Blu-Ray spec only really enforces jar certificate verification for encrypted blurays (i.e. AACS). non AACS blurays (i.e. decrypted), ignore the certificate chain. i.e. a self signed certificate that uses its own key to sign the jars works fine per the spec.
The only reason people can take blurays (with java menus) and make them reliably playable when decrypted (in real players, ignoring things like VLC which can easily ignore the cert chain) is because the bluray spec tells them to explicitly ignore the certificate chain. This enables decryption programs to rewrite the java bytecode (and resign the jar's with a self signed certificate) removing any protection mechanisms (think screenpass) that are in the java code itself.
While I sort of understand the reason for it (you want to be able to test discs before mastering without encryption and without the need for signing), it really killed what could have been an effective security model. Basically the standard strong security vs convenience dilemma.
- AnthonyMouse 6y agoI half suspect they do things like that on purpose, because the alternative is to create demand for players that disregard the restrictions, and by that point they're also going to disregard all of the other ones and let the user fast forward through commercials etc. So if they let the thing they don't want people to do be hard but not too hard, it satisfies demand from the people determined to do it instead of creating a market to solve the problem which would make it more convenient.
- compsciphd 6y agoI don't know. perhaps, but they've shown a large willingness to force the hardware players to enforce security mechanisms that can't really be avoided nicely (ex: cinavia, there are ways to avoid it, but very few on disc based players)