5 ms·
I dislike that every single one of our displays utilizes an encrypted connection. And it doesn't protect me, I don't have the keys. And though it is fixed funct
by undersuit 3y ago
I dislike that every single one of our displays utilizes an encrypted connection. And it doesn't protect me, I don't have the keys. And though it is fixed function hardware I've often wondered about the waste we have introduced in this world so I can't copy a Disney video that I might watch hundreds of times.
- huytersd 3y agoI don’t understand. If you’re watching it the bits have been decrypted. Can’t you just get them from local memory?
- choeger 3y agoRealistically, no. You don't have access to the device that contains the decrypted content. Of course, you could try to open up or bypass the DRM module (e.g., via the GPU driver during hardware accelerated decoding), but that won't work with a TPM module and signed kernel space. If you look at the security technologies introduced into consumer decides over the last decades, it all serves the dual purpose of securing your hardware from ... you.
- justinclift 3y agoHDMI splitters have been a thing for years. Apparently they present as a compliant HDMI output to the source device, but they don't require HDCP or similar on the output they're passing it on to. From there, you're free to do whatever you want with the output.
- choeger 3y agoAt least in theory, HDCP keys can be revoced. Manufacturing non-compliant devices could become extremely risky.
- justinclift 3y agoWell, these things have already existed for years...
- huytersd 3y agoCouldn’t you just plug a capture card into the display out?
- holonsphere 3y agoHDCP.
- huytersd 3y agoWow, so the decryption happens in the monitor? Can’t the capture card replicate that?
- notRobot 3y agoNo, decryption keys are tightly held and inaccessible to general populations and small manufacturers and those used by illicit capture cards are regularly revoked iirc.
- metalcrow 3y agoIn regards to that, i assume that manufacturers have to apply for a cert for their device and then embed that cert, correct? Then if the device is found to be stripping HDCP the consortium can revoke that cert, but how? Sure you can do it for PCs and consoles, but are blu-ray players connected to the internet and auto-updated nowadays? Otherwise it'd be pretty easy for Chinese manufactures out of reach of the DMCA to just release one every few years and have it work for all devices prior.
- fxtentacle 3y ago"are blu-ray players connected to the internet and auto-updated nowadays?" Some blu-rays force you to update before you can watch them. Also, the key revocation lists can (I believe) be included in the blu-ray itself to make them work offline, too.
- 3y ago
- gruez 3y ago>Of course, you could try to open up or bypass the DRM module (e.g., via the GPU driver during hardware accelerated decoding), but that won't work with a TPM module and signed kernel space. Nope. Thanks to HDCP the data never hits the kernel or the host memory unencrypted. It doesn't even require TPMs or signed kernels.
- choeger 3y agoThat's not true, AFAIK. The DRM module (e.g., widevine) has to negotiate keys with the host and will decrypt the stream for decoding. The HDCP keys are static and independent from the streaming service. That decryption can happen with hardware support but it can also happen in software. I think most streaming services fall back from 4k to FHD or lower if their "security requirements" aren't fully met. Also, if the DRM module supports hardware decoding, the GPU will need to see a decrypted stream. The GPU memory is in principle accessible to the driver. So if you can manipulate the driver, or setup another kernel module, you might be able to grab that content.