Some reputable people in the pirating industry have actually cracked Level 1, which means they can decrypt 4K! :-)
Some reputable people in the pirating industry have actually cracked Level 1, which means they can decrypt 4K! :-)
Do you have a source for that? This page[1] says Firefox and Chrome on Windows, Linux, and Mac only go up to 720p. Chrome on ChromeOs goes up to 1080p, is that still L3?
https://addons.mozilla.org/en-GB/firefox/addon/netflix-1080p...
It seems that many streaming platforms disable 1080p by default, and I assume that this is only for performance reasons (some hardware struggles to run an obfuscated software video decoder...) - it's not a DRM limitation, and in netflix's case it can be re-enabled via trivial changes to the frontend JS.
All of the content I actually use Netflix for is available in 1080p on L3 (Which matters to me, since L3 is the highest supported level on desktop x86 Linux).
The mentioned addon works pretty reliably for me, watching 1080p in FF on Linux, at least for Netflix original content.
I wonder if google does something similar to bluray AACS where if a level 1 device is compromised they can revoke just that device (or manufacturer's key). If not, i wonder why they don't.
(To clarify my curiosity is in an abstract way, i am ideologically opposed to DRM)
If indeed level 1 has been breached, presumably it happened via one of those weaker secure enclaves.
mainly because it's hard to trace back which device key got leaked, especially if all you have to go on are whatever the ripped videos. if you had the tools it'd be much easier, but that's probably kept under tight wraps by the piracy groups.
I suppose if you have the entire decoding process in a secure enclave you could also make it watermark the resulting file with which key was used to decrypt.
That said it doesn't need to be that robust, since the pirate only has to slip up once to get caught and its hard to know for sure if you got the entire watermark out.
> The intent is to prevent all copying, both counterfeit copies and legal copies of one's own content (for example, format shifting).
>
> Verance claims on their website that, while the watermark is able to survive recording through microphones (such as recording a film in a movie theater with a camcorder), as well as compression and encoding, it is imperceptible to human hearing, as well as that the presence of the watermark does not affect audio quality.
A Herculean effort to create artificial scarcity. Thank you, capitalism.Having never heard of this before, I did the natural hackernews reader thing -- search for a bypass -- and came across this interesting forum discussion [1] from ~2014, in which a large number of people state that a reverb effect gets rid of it. The original author writes:
> get an program named Audacity open the converted audio file in freemake > and open the file in Audacity choose File>Open then Edit>Select>All > then go to Effect>GVerb > make sure to have the following configuration:
> roomsize (m):1.0 > reverb time (s): 0.1 > Damping: 0.0 > Input Bandwidth: 0.20 > Dry Signal (db): -7.0 > Early reflection level (db): 0.0 > Tail Level: -17.5
Other methods of bypass include using a player that doesn't check for the watermark, patching out the checking code in a firmware image, and simply swapping the HD-DVD / Blueray audio with one from a DVD.
[1] https://web.archive.org/web/20141208081801/http://club.myce....
---- Edit ----
Some further useful information -- and a statement that they've put the details in their patent!
> The Cinavia detection is sensitive to pitches and time sequence of features. The specific feature that detector looks for, is already clearly stated in Verance patent US5940135:
> [2] www.google.com/patents/US5940135
> If you study the patent document you will know the feature is delayed correlation. They also use hopping to change the delay of the correlation within the pattern of the same watermark. The actual delay, and the hopping pattern between delays, is their secret and security. That information I cannot disclose. Nor is it needed to defeat Cinavia.
> The fact of the matter is Cinavia added an artificial signal to rapidly change the delayed correlation in short time internals. Analysis the audio and you can see it causes an un-natural ripples in the frequency space. If you can see those un-natural ripples, you can smooth it out and remove it. Just remember, in real world, different frequency components of a sound does not change that rapidly. They generally decay over a fraction of a second, and human ear can not catch it if a frequency shows up and then rapidly goes away. So the way to defeat Cinavia is do not let any frequency component go in and out so rapidly. If it shows up, let it stay for a little while longer. Stretch it out a bit, before letting it decay out.
> That will defeat Cinavia for sure. Make everything vary more slowly and smooth out any ripples. It also beautifies the sound quality.
> When people sing, the pace of their singing is much slower than normal speech, right? A sentence that takes 3 second to speak, a singer will spend half a minute to sing the same sentence out. The slow varying is what makes music beautiful, and it is also what can kill Civania!
Nowadays the piracy groups seem to have found a way around this. Presumably they found a way to strip the watermark, but we can only speculate as the groups guard their methods closely for obvious reasons.
> Widevine's least secure security level, L3, as used in most browsers and PCs, is implemented 100% in software (i.e no hardware TEEs), thereby making it reversible and bypassable.
This line said level 3 originally, must have been edited; but it doesn't look like it was archived on the IA, so I can't prove it.
> In addition to this request, we have filed a separate Sensitive Data takedown request of this file: /widevine-l3-decryptor as it contains the secret Widevine RSA private key, which was extracted from the Widevine CDM and can be used in other circumvention technologies.
Recent instance of such a downgrade, causing a ton of (Philips) TVs to stop playing HD content apparently: https://www.reddit.com/r/netflix/comments/jq9wdb/netflix_cap...
This is the tracker from the screenshots by the way: https://t.me/s/wvcrl
The potential for a DOS-attack would be immense.
[1] search for "hdcp bypass" on ebay
Refer to the perfectly legal NeTV2 + trivial modification if you understand the HDL.