HOME

TheInfoList



OR:

A controversy surrounding the AACS processing key arose in April 2007 when the
Motion Picture Association of America The Motion Picture Association (MPA) is an American trade association representing the Major film studios, five major film studios of the Cinema of the United States, United States, the Major film studios#Mini-majors, mini-major Amazon MGM Stud ...
and the Advanced Access Content System Licensing Administrator, LLC (AACS LA) began issuing
cease and desist A cease and desist letter is a document sent by one party, often a business, to warn another party that they believe the other party is committing an unlawful act, such as copyright infringement, and that they will take legal action if the oth ...
letters to websites publishing a 128- bit (16-
byte The byte is a unit of digital information that most commonly consists of eight bits. Historically, the byte was the number of bits used to encode a single character of text in a computer and for this reason it is the smallest addressable un ...
)
number A number is a mathematical object used to count, measure, and label. The most basic examples are the natural numbers 1, 2, 3, 4, and so forth. Numbers can be represented in language with number words. More universally, individual numbers can ...
, represented in
hexadecimal Hexadecimal (also known as base-16 or simply hex) is a Numeral system#Positional systems in detail, positional numeral system that represents numbers using a radix (base) of sixteen. Unlike the decimal system representing numbers using ten symbo ...
as 09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0 (commonly referred to as 09 F9), a
cryptographic Cryptography, or cryptology (from "hidden, secret"; and ''graphein'', "to write", or '' -logia'', "study", respectively), is the practice and study of techniques for secure communication in the presence of adversarial behavior. More gen ...
key for
HD DVD HD DVD (short for High Density Digital Versatile Disc) is an obsolete high-density optical disc format for storing data and playback of high-definition video.
s and
Blu-ray Disc Blu-ray (Blu-ray Disc or BD) is a Digital media, digital optical disc data storage format designed to supersede the DVD format. It was invented and developed in 2005 and released worldwide on June 20, 2006, capable of storing several hours of ...
s. The letters demanded the immediate removal of the key and any links to it, citing the anti-circumvention provisions of the United States
Digital Millennium Copyright Act The Digital Millennium Copyright Act (DMCA) is a 1998 United States copyright law that implements two 1996 treaties of the World Intellectual Property Organization (WIPO). It criminalizes production and dissemination of technology, devices, or ...
(DMCA). In response to widespread Internet postings of the key, the AACS LA issued various press statements, praising websites that complied with their requests for acting in a "responsible manner" and warning that "legal and technical tools" were adapting to the situation. The controversy was further escalated in early May 2007, when aggregate news site
Digg Digg (stylized in lowercase as digg) is an American news aggregator with a curated front page, aiming to select articles specifically for the Internet audience such as science, trending political issues, and viral phenomenon, viral Internet iss ...
received a DMCA
cease and desist A cease and desist letter is a document sent by one party, often a business, to warn another party that they believe the other party is committing an unlawful act, such as copyright infringement, and that they will take legal action if the oth ...
notice and then removed numerous articles on the matter and banned users from reposting the information. This sparked what some describe as a digital revolt or "cyber-riot" in which users posted and spread the key on Digg, and throughout the Internet ''en masse'', leading to a
Streisand effect The Streisand effect is an unintended consequences, unintended consequence of attempts to hide, remove, or Censorship, censor information, where the effort instead increases public awareness of the information. The term was coined in 2005 by ...
. The AACS LA described this situation as an "interesting new twist".


Background

Because the encryption key may be used as part of circumvention technology forbidden by the
DMCA The Digital Millennium Copyright Act (DMCA) is a 1998 United States copyright law that implements two 1996 treaties of the World Intellectual Property Organization (WIPO). It criminalizes production and dissemination of technology, devices, or ...
, its possession and distribution has been viewed as illegal by the AACS, as well as by some legal professionals. Since it is a
128-bit General home computing and gaming utility emerged at 8-bit word sizes, as 28=256 Word (computer architecture), words, a natural unit of data, became possible. Early 8-bit CPUs (such as the Zilog Z80 and MOS Technology 6502, used in the 1977 Co ...
numerical value, it was dubbed an illegal number. Opponents to the expansion of the scope of
copyright A copyright is a type of intellectual property that gives its owner the exclusive legal right to copy, distribute, adapt, display, and perform a creative work, usually for a limited time. The creative work may be in a literary, artistic, ...
criticize the idea of making a particular number illegal. Commercial HD DVDs and Blu-ray discs integrate copy protection technology specified by the AACS LA. There are several interlocking encryption mechanisms, such that cracking one part of the system does not necessarily crack other parts. Therefore, the "09 F9" key is only one of many parts that are needed to play a disc on an unlicensed player. AACS can be used to revoke a key of a specific playback device, after it is known to have been compromised, as it has for WinDVD. The compromised players can still be used to view old discs, but not newer releases without encryption keys for the compromised players. If other players are then cracked, further revocation would lead to legitimate users of compromised players being forced to upgrade or replace their player software or
firmware In computing Computing is any goal-oriented activity requiring, benefiting from, or creating computer, computing machinery. It includes the study and experimentation of algorithmic processes, and the development of both computer hardware, h ...
in order to view new discs. Each playback device comes with a
binary tree In computer science, a binary tree is a tree data structure in which each node has at most two children, referred to as the ''left child'' and the ''right child''. That is, it is a ''k''-ary tree with . A recursive definition using set theor ...
of secret device and processing keys. The processing key in this tree, a requirement to play the AACS encrypted discs, is selected based on the device key and the information on the disc to be played. As such, a processing key such as the "09 F9" key is not revoked, but newly produced discs cause the playback devices to select a different valid processing key to decrypt the discs.


Timeline of AACS cracking


2006

On December 26, 2006, a person using the alias ''muslix64'' published a utility named BackupHDDVD and its
source code In computing, source code, or simply code or source, is a plain text computer program written in a programming language. A programmer writes the human readable source code to control the behavior of a computer. Since a computer, at base, only ...
on the DVD decryption forum at the website '' Doom9''. BackupHDDVD can be used to decrypt AACS protected content once one knows the encryption key. muslix64 claimed to have found title and volume keys in main memory while playing HD DVDs using a software player, and that finding them is not difficult.


2007

On January 1, 2007, muslix64 published a new version of the program, with volume key support. On January 12, 2007, other forum members detailed how to find other title and volume keys, stating they had also found the keys of several movies in
RAM Ram, ram, or RAM most commonly refers to: * A male sheep * Random-access memory, computer memory * Ram Trucks, US, since 2009 ** List of vehicles named Dodge Ram, trucks and vans ** Ram Pickup, produced by Ram Trucks Ram, ram, or RAM may also ref ...
while running WinDVD. On or about January 13, a title key was posted on pastebin.com in the form of a riddle, which was solved by entering terms into the
Google Google LLC (, ) is an American multinational corporation and technology company focusing on online advertising, search engine technology, cloud computing, computer software, quantum computing, e-commerce, consumer electronics, and artificial ...
search engine. By converting these results to hexadecimal, a correct key could be formed. Later that day, the first cracked HD DVD, '' Serenity'', was uploaded on a private torrent tracker. The AACS LA confirmed on January 26 that the title keys on certain HD DVDs had been published without authorization. Doom9.org forum user ''arnezami'' found and published the "09 F9" AACS processing key on February 11: This key is not specific to any playback device or DVD title. Doom9.org forum user ''jx6bpm'' claimed on March 4 to have revealed CyberLink's PowerDVD's key, and that it was the key in use by AnyDVD. The AACS LA announced on April 16 that it had revoked the decryption keys associated with certain software high-definition DVD players, which will not be able to decrypt AACS encrypted disks mastered after April 23, without an update of the software. On May 17, one week before any discs with the updated processing key had reached retail, claims were reported of the new keys having been retrieved from a preview disc of '' The Matrix Trilogy''. On May 23, the key 45 5F E1 04 22 CA 29 C4 93 3F 95 05 2B 79 2A B2 was posted on Edward Felten's ''Freedom to Tinker Blog'' and confirmed a week later by ''arnezami'' on Doom9 as the new processing key ( MKB v3).


DMCA notices and Digg

As early as April 17, 2007, AACS LA had issued
DMCA The Digital Millennium Copyright Act (DMCA) is a 1998 United States copyright law that implements two 1996 treaties of the World Intellectual Property Organization (WIPO). It criminalizes production and dissemination of technology, devices, or ...
violation notices, sent by Charles S. Sims of Proskauer Rose. Following this, dozens of notices were sent to various websites hosted in the United States. On May 1, 2007, in response to a DMCA demand letter, technology news site
Digg Digg (stylized in lowercase as digg) is an American news aggregator with a curated front page, aiming to select articles specifically for the Internet audience such as science, trending political issues, and viral phenomenon, viral Internet iss ...
began closing accounts and removing posts containing or alluding to the key. The Digg community reacted by creating a flood of posts containing the key, many using creative ways of disguising the key, by semi-directly or indirectly inserting the number, such as in song or images (either representing the digits pictorially or directly representing bytes from the key as colors) or on merchandise. At one point, Digg's "entire homepage was covered with links to the HD-DVD code or anti-Digg references." Eventually the Digg administrators reversed their position, with founder Kevin Rose stating:


Legal opinions

Lawyers and other representatives of the entertainment industry, including Michael Avery, an attorney for
Toshiba is a Japanese multinational electronics company headquartered in Minato, Tokyo. Its diversified products and services include power, industrial and social infrastructure systems, elevators and escalators, electronic components, semiconductors ...
Corporation, expressed surprise at Digg's decision, but suggested that a suit aimed at Digg might merely spread the information more widely. The
American Bar Association The American Bar Association (ABA) is a voluntary association, voluntary bar association of lawyers and law students in the United States; national in scope, it is not specific to any single jurisdiction. Founded in 1878, the ABA's stated acti ...
's '' eReport'' published a discussion of the controversy, in which Eric Goldman at
Santa Clara University Santa Clara University is a private university, private Jesuit university in Santa Clara, California, United States. Established in 1851, Santa Clara University is the oldest operating institution of higher learning in California. The university' ...
's High Tech Law Institute noted that the illegality of putting the code up is questionable (that
Section 230 of the Communications Decency Act In the United States, Section 230 is a section of the Communications Act of 1934 that was enacted as part of the Communications Decency Act of 1996, which is Title V of the Telecommunications Act of 1996, and generally provides immunity for ...
may protect the provider when the material itself is not copyrighted), although continuing to allow posting of the key may be "risky", and entertainment lawyer Carole Handler noted that even if the material is illegal, laws such as the DMCA may prove ineffective in a practical sense.


Impact

In a response to the events occurring on
Digg Digg (stylized in lowercase as digg) is an American news aggregator with a curated front page, aiming to select articles specifically for the Internet audience such as science, trending political issues, and viral phenomenon, viral Internet iss ...
and the call to "Spread this number", the key was rapidly posted to thousands of pages, blogs and
wiki A wiki ( ) is a form of hypertext publication on the internet which is collaboratively edited and managed by its audience directly through a web browser. A typical wiki contains multiple pages that can either be edited by the public or l ...
s across the Internet. The reaction was an example of the
Streisand effect The Streisand effect is an unintended consequences, unintended consequence of attempts to hide, remove, or Censorship, censor information, where the effort instead increases public awareness of the information. The term was coined in 2005 by ...
.
Intellectual property Intellectual property (IP) is a category of property that includes intangible creations of the human intellect. There are many types of intellectual property, and some countries recognize more than others. The best-known types are patents, co ...
lawyer Douglas J. Sorocco noted, "People are getting creative. It shows the futility of trying to stop this. Once the information is out there, cease-and-desist letters are going to infuriate this community more." Outside the Internet and the
mass media Mass media include the diverse arrays of media that reach a large audience via mass communication. Broadcast media transmit information electronically via media such as films, radio, recorded music, or television. Digital media comprises b ...
, the key has appeared in or on T-shirts, poetry, songs and music videos, illustrations and other graphic artworks, tattoos and body art, and comic strips. The
Linux Linux ( ) is a family of open source Unix-like operating systems based on the Linux kernel, an kernel (operating system), operating system kernel first released on September 17, 1991, by Linus Torvalds. Linux is typically package manager, pac ...
kernel also incorporated a copy of the key for 17.5 years, originally added in 2007 by David Woodhouse as part of the red zone logic and subsequently removed as a routine cleanup in 2024. On Tuesday afternoon, May 1, 2007, a
Google Google LLC (, ) is an American multinational corporation and technology company focusing on online advertising, search engine technology, cloud computing, computer software, quantum computing, e-commerce, consumer electronics, and artificial ...
search for the key returned 9,410 results, while the same search the next morning returned nearly 300,000 results. On Friday, the
BBC The British Broadcasting Corporation (BBC) is a British public service broadcaster headquartered at Broadcasting House in London, England. Originally established in 1922 as the British Broadcasting Company, it evolved into its current sta ...
reported that a search on Google shows almost 700,000 pages have published the key, despite the fact that on April 17, the AACS LA sent a DMCA notice to Google, demanding that Google stop returning any results for searches for the key. Widespread news coverage included speculation on the development of user-driven websites, the legal liability of running a user-driven website, the perception of acceptance of DRM, the failure as a business model of "secrecy based businesses ... in every aspect" in the Internet era, and the harm an industry can cause itself with harshly-perceived legal action. In an opposing move, Carter Wood of the National Association of Manufacturers said they had removed the "Digg It" link from their weblog: Media coverage initially avoided quoting the key itself. However, several US-based news sources have run stories containing the key, quoting its use on Digg, though none are known to have received DMCA notices as a result. Later reports have discussed this, quoting the key.
Current TV Current TV was an American television channel which broadcast from August 1, 2005, to August 20, 2013. Prior INdTV founders Al Gore and Joel Hyatt, with Ronald Burkle, each held a sizable stake in Current TV. Comcast and DirecTV each held a small ...
broadcast the key during a ''Google Current'' story on the Digg incident on May 3, 2007, displaying it in full on screen for several seconds and placing the story on the station website. On May 1, 2007,
Wikipedia Wikipedia is a free content, free Online content, online encyclopedia that is written and maintained by a community of volunteers, known as Wikipedians, through open collaboration and the wiki software MediaWiki. Founded by Jimmy Wales and La ...
locked out the page named for the number "to prevent the former secret from being posted again". The page on HD DVD was locked as well, to keep out "The Number". This action was later reversed. No one has been arrested or charged for finding or publishing the original key.


AACS LA reaction

On May 7, 2007, the AACS LA announced on its website that it had "requested the removal solely of illegal circumvention tools, including encryption keys, from a number of web sites", and that it had "not requested the removal or deletion of any ... discussion or commentary". The statement continued, "AACS LA is encouraged by the cooperation it has received thus far from the numerous web sites that have chosen to address their legal obligations in a responsible manner."
BBC News BBC News is an operational business division of the British Broadcasting Corporation (BBC) responsible for the gathering and broadcasting of news and current affairs in the UK and around the world. The department is the world's largest broad ...
had earlier quoted an AACS executive saying that
blog A blog (a Clipping (morphology), truncation of "weblog") is an informational website consisting of discrete, often informal diary-style text entries also known as posts. Posts are typically displayed in Reverse chronology, reverse chronologic ...
gers "crossed the line", that AACS was looking at "legal and technical tools" to confront those who published the key, and that the events involving Digg were an "interesting new twist".


See also

* DeCSS * DVD Copy Control Association * FCKGW (
Microsoft Windows Windows is a Product lining, product line of Proprietary software, proprietary graphical user interface, graphical operating systems developed and marketed by Microsoft. It is grouped into families and subfamilies that cater to particular sec ...
) * HDCP master key release * Illegal number * PlayStation 3 homebrew § Private key compromised *
Security through obscurity In security engineering, security through obscurity is the practice of concealing the details or mechanisms of a system to enhance its security. This approach relies on the principle of hiding something in plain sight, akin to a magician's slei ...
*
Streisand effect The Streisand effect is an unintended consequences, unintended consequence of attempts to hide, remove, or Censorship, censor information, where the effort instead increases public awareness of the information. The term was coined in 2005 by ...
* Texas Instruments signing key controversy


References


External links


Doom9's Forum
original focus of the controversy *
09 f9: A Legal Primer
' —
Electronic Frontier Foundation The Electronic Frontier Foundation (EFF) is an American international non-profit digital rights group based in San Francisco, California. It was founded in 1990 to promote Internet civil liberties. It provides funds for legal defense in court, ...
(EFF)
Original images posted
Some of the images that accompanied the Digg articles on the front page from the day of the user revolt. {{DEFAULTSORT:Aacs Encryption Key Controversy Advanced Access Content System Compact Disc and DVD copy protection History of cryptography Key management Motion Picture Association Digital Millennium Copyright Act takedown incidents Cryptography law Technological controversies