« High performance clus… | Home | Layers in IT security… »

Secret key 09-f9-11-02-9d .....



The past weeks something happened on the Internet which can be classified as the Streisand Effect. Singer Barbra Streisand sued a photographer when he put photo's of Streisand's house on a web page with houses of famous people.

Although the photo's were only seen by a few people at first, the publicity of the court order took many people to the site. This caused much more damage to the image of the singer, than the original publication of the photo's did.

The latest incarnation of the Streisand Effect is cuased by the so-called AACS encryption key, of which the first numbers are in the title of this article.

Background

Commercial HD-DVD's and Blu-Ray discs contain a copy protection system (Advanced Access Content System, AACS). Internally in the system, a secret key is used for decrypting movies. When this key is known, modified software-based DVD players can show these movies on PC's and the movies can be copied using the PC's.

Of course, using secret keys is a bad idea. When a key is compromised, the security is broken and cannot easily be repaired. It is an excellent example of "Security by Obscurity".

The key

A few weeks ago the key was found by a few hackers in the RAM memory of a software DVD player for PC's. The 16 byte hexadecimal key (starting with 09-f9-11-02-9d...) was published on the Internet on the website doom9.org. The AACS-LC, the organisation managing the security, did something foolish: Through a lawyer firm, they threatened to take legal steps, because the key fell under the American Digital Millennium Copyright Act (DMCA).

This way, the secret key became so called “Secret Information”. This means it is now illegal to speak about- or discuss the key. Creative publishing of the key, for instance by using riddles with the key in it, of using colors to represent the key, are also prohibited.

The effect on the Internet was that lots of people began to publish the key on lots of websites and blogs. The secret key was out on the web and could not be removed anymore.

A recent search in Google on the key delivered more than 1.1 million hits!

A nice piece of Streisand Effect!

There is also a complete website dedicated to the key.



No comments:


About Sjaak Laan

Sjaak Laan

I am 45 years old and married with Angelina. We have 3 children of 12, 7 and 5 years old. We live in The Netherlands, in a place called Drachten

I work for Logica as Principal IT Architect. I have 20 years IT experience.

I own the following certificates:

ITAC Master Certified IT Architect

CISSP_logo CISSP (Certified Information Systems Security Professional)


TOGAF8_Certified_web TOGAF Certified Architect



I am a member of the:


I manage my business contacts using Linkedin.


I can be reached through sjaak.laan [ a t ] gmail [dot] com.

This site states my opinion only, and not nessecarily the opinion of my employer or of the clients I work for.