The i.MX8 cannot be deblobbed
devever.net
devever.net
Note that, despite this, you can still find basically any movie you want on popular websites – the only people who suffer are paying consumers.
See the licensing costs here.
What is the cost for express processing?
$5,000 USD per "Multiplier".
What is the smallest number of Device Key sets that can be purchased?
The quantities and prices for key orders are listed below:
Description Cost (USD)
HDCP 1.x Transmitter or Receiver Key - Qty of 10,000 $2,000 USD
HDCP 1.x Transmitter or Receiver Key - Qty of 100,000 $5,000 USD
HDCP 1.x Transmitter or Receiver Key - Qty of 1,000,000 $10,000 USD
HDCP 2.x Annual Source Key Fee - Up to 100/year $500 USD
HDCP 2.x Annual Source Key Fee - Up to 1K per year $1,000 USD
HDCP 2.x Annual Source Key Fee - Up to 10K per year $2,000 USD
HDCP 2.x Annual Source Key Fee - Up to 100K per year $5,000 USD
HDCP 2.x Annual Source Key Fee - Up to 1M per year $10,000 USD
HDCP 2.x Annual Source Key Fee - For quantities over 1M per year $20,000 USD
HDCP 2.x Receiver Key - Qty of 10,000 $2,000 USD
HDCP 2.x Receiver Key - Qty of 100,000 $5,000 USD
HDCP 2.x Receiver Key - Qty of 1,000,000 $10,000 USD
https://www.digital-cp.com/faqsthe DRM industry gets away with it since consumers don't care about openness or libre, they just want to watch videos in hi definition.
Now that I think of it: it (rampant piracy of audio and video) is a great practical example to teens why they should not share pictures of themselves naked. If someone wants to, it gets spread. Even if there's 'copyright protection'. In some circles, Snapchat is seen as seriously private. Which is very ignorant, and has lead to situations like blackmailing and retaliation porn.
Now I don't know how they could offer this, and I don't know how a new HDCP key is issued when a leaked one is blacklisted. I assume the engineer just didn't care or maybe the key was already old.
There are reportedly lots of HDMI "splitters" that defeat HDCP too.
Why does this also affect Display Port? Is the document elsewhere stating that both are intertwined?
It is depressing how “intellectual property” damaged computing. Just imaging a critical bug needs fixed in 15 years and the key signing utility is not available because ${RANDOM_CORP} disappeared. Don’t say that couldn’t happen: Nokia, Sun, DEC, Apple (nearly bankrupt 1998), 3DFX, Aureal and so on. And this lists only the ones where the employees are no longer available. Other just cancel support. Broadcom - which I know avoid - doesn’t care anymore about their BLE 4.0 chips and the (security) issues.
Seeing how Netflix and others succeeded with a flatrate model - which is the actual solution - this is completely unnecessary. The authorities missed to create institutional ways for creators to collect money, just awkward unfair taxes on harddisks and VHS-Tapes. Which streaming did?
I certainly agree that restrictive code signing practices like these are completely unacceptable. In my view, the 'right to repair' movement should encompass a right to any keys needed to fix bugs, though I am not optimistic about 'right to repair' being interpreted in this way.
Worth noting that while we usually think of DRM as a (patently ineffective) way to prevent piracy, in reality it seems to be much more about controlling end devices and the manufacturers of end devices. I explain more about this here: https://news.ycombinator.com/item?id=17588610
There's only one display interface capable of driving DP/HDMI on i.MX8M, so if they didn't do that they wouldn't have external HDMI port.
It doesn't even need to be a corporation disappeared; it could be they decide they don't want to sign things anymore. As a application developer you have to make a choice --- how long do you want your last and final build to work, knowing it's impossible to fix any client side issues after that, and you can't extend it later.
The worst part is what it did to indie/amateur musicians. The only models allowed to record at 44.1 were "professional" that cost a lot more than the very few consumer models that were only allowed to do 32k and 48k.
Back in the 1990's independent/aspiring musicians needed to make CD's to send out to labels/radio stations/sell to fans. CD Audio is fixed at 44.1KHz. Transcoding 48k to 44.1 generates undesirable artifacts, especially back then when you likely had to convert to analog first.
For some reason I was thinking about it like nowadays when you just do the samplerate conversion ITB with hardly any degradation.
> Therefore, it is impossible to ever replace the HDMI blob used by this device. The device could be used without this blob, but you then forego use of the HDMI (or DisplayPort) functionality.
> Note about the MNT Reform: The MNT Reform went out of its way to avoid relying on this blob for its internal display. Rather than doing the obvious thing and connecting the i.MX8M's DisplayPort interface to the Embedded DisplayPort (eDP) display panel, they connected the internal display by using the i.MX8M's MIPI DSI interface (which is unaffected by this blob) to connect to a MIPI DSI to eDP converter chip, and then to the display (indeed, the fact that they went out of their way to ensure people can use the laptop without the blob certainly warrants praise). The external HDMI port can't be used without the blob, however.
The i.MX8's HDMI core has independent access to the DDR memory, peripheral buses, timers, DMAs, and who knows what else. It's probably even running an RTOS of some kind, which might or might not include network drivers. Malicious firmware could compromise the security of your entire device.
It's kind of the same problem that some folks have with Intel's IME. It could be fine and secure. Or maybe not, we just don't know.
Nobody's saying that the i.MX8's HDMI firmware is malicious. It's probably fine. But we also don't know, because we can't inspect it. So if you were designing that chip into a security-critical setting, you'd have to wonder what might be running without your knowledge.
The thing I keep thinking about are things like pace makers and other medical devices that become useless implants once biotech companies go under. May be today it seems like the company you're getting the blobs from will be around but one day it won't be (or won't care to be) and then what are you going to do? May be something like this or an SBC doesn't matter as severely as a pace maker but anytime anyone builds something with these socs they run the risk that their product will be a dead weight in 10 years.
But of course, that doesn't matter for most developers, just those of us who want to stop the endless technopollution in tech, make things that last, you know.
Eventually the technological barriers will be worked around, and if the legal systems around the world don't spring into action, that's it.
In general, the US is more lenient and has a broader definition of fair use.
Most countries' governments outside the US also assert copyright on their own works, which is ridiculous IMO, but is a good representation of the entire concept of the US: legitimacy is derived from the people themselves. The government can't have copyright because The People as a whole own the work.
Or, cleaner but less "realistic", the people making these things just sit down and decide to release the key, or make chips without the limitation. I mean it is all man-made, there is no physical law saying this can't be done. If you ignore the financial and IP dimensions for a second, just on technical merits, it is a no-brainer.
So the only realistic option is to wait for a new hardware revision that fixes this, or switch to another SoC.
Copyright is an automatic right (though I understand you still have registration in USA which increases damages available) but should not be applied to DRM works that haven't had DRM-free copies lodged with a government or authority (eg WIPO).
DRM encumbered works cannot ever enter the public domain and so cannot fulfill the requirements for copyright.
This is of course my own personal opinion, unrelated to my employment.
That's a curious legal theory. What evidence do you have for it being shared by anyone else, yet alone the legal system? What jurisdiction is it supposed to apply in?
But yeah, if you want to use the external HDMI port on the laptop, you need the blob.
Might have better luck with the Taiwanese hardware vendors - as I recall a major Taiwanese PC motherboard maker got hacked recently and UEFI secure boot keys were taken, so they probably weren't storing them in an HSM and don't have proper security practices in place for cryptographic material.
>Therefore, it is impossible to ever replace the HDMI blob used by this device. The device could be used without this blob, but you then forego use of the HDMI (or DisplayPort) functionality.
If you use the MNT Reform without the blob you can never use certain features of the device, namely the external HDMI port, so it's not as though the MNT Reform is without flaws. In any case the article is about the i.MX8M, not any specific device.
Perhaps if the last bullet point in the article said something about not being able to use HDMI or displayport without a converter chip, it would have been clearer to me.
So this particular HDMI/HDCP implementation is designed to require this signed blob in order for it to function. Could Cadence have designed it so you can use it without HDCP without this blob, or use an unsigned blob and forego HDCP support, probably. But they didn't, so that's the situation.
You can find old posts on the NXP forums talking about how disabling HDCP kills HDMI.
If the chip can do TB / DisplayPort, you could add a separate DP -> HDMI converter, but obviously that increases your costs.