Sony software updates breaks movie theater projectors
bsky.app
bsky.app
This is likely an expired certificate related to the encryption on the movie files.
But it's slightly weird because it's not yet the new year in UTC. This was posted several hours before that happening, and we've still got over 2 hours to go... (And the cinema is in New York, with almost 8 hours to go in local time, so it's not a local timezone issue either.)
10 years in cinema IoT, here. Features are encrypted by Key Delivery Messages (KDM), and those are per cinema server/projector "marriage". No KDM will be considered valid if the server certs are expired.
This should make 2024 interesting for me.
If Sony was still in the business, they would offer a certificate renewal for a small fee like the other manufacturers have done.
The root problem is that Sony exited the market and left a lot of cinema owners out to dry with the looming cost of $50,000+ per auditorium for replacement projectors.
You can't build a "time lock" with just encryption primitives. Even if you could build a time lock with just encryption primitives, we don't know when the copyright will expire until the original author has died, since copyright term is life + 70 years.
Someone would have to run a server that specifically chooses to start serving the keys on that date, which is an absurd notion given how absurdly long copyright lasts these days.
If the federal government were interested in passing a law that required this, I'm sure the Library of Congress could run such a server, but no such law exists.
Maybe not through crypto but otherwise perfectly achievable. No reason to achieve this within a file. If you really want to, some fancy solution involving blockchains and smart contracts is probably possible but there is no need.
Require by law all who desire copyright protection to register the work with a governmental agency and place a copy of the work in escrow at an archive as a condition. The archive knows when the copyright expires and starts serving the work to the public from that point forward. This is what to do if a state cares about public domain.
The status quo of corporations abandoning works to bit rot, actual rot, misplacement or fires for decades is strictly worse.
> Require by law all who desire copyright protection to register the work with a governmental agency and place a copy of the work in escrow at an archive as a condition.
You’re just repeating what I already wrote. By all means, call your representatives.
It's the same. "Fail closed" means you can "just" set the system time to be before the expiration date, "fail open" means you can just set the system time to be after.
Either way, having an expiring decryption key is just security theater that harms users.
Spoofing that now gets you in trouble with the FCC as well as the DMCA.
GP’s point stands, you can’t enforce a time lock with cryptography primitives. That’s the fundamental issue with DRM - you’re trying to restrict someone from getting your ciphertext, while at the same time allowing them to get to it if they meet certain (non-cryptographic) conditions, which standard cryptography just can’t do.
That's the point I was trying to make; if someone accidentally pushed a broken update, that sucks, but its not the first or the last time it will happen, and at least there's a clear path to it getting fixed and someone being paid to do it. The cert being expired and the only company who would have been in charge of fixing that not really caring anymore sounds to me worse from pretty much any possible point of view, and selling a product that will stop working if you decide to stop servicing it seems pretty terrible.
This kind of thing is all over the consumer world. In a way it's cathartic to see it hitting businesses too.
If you’re not in Central Texas, you likely have a similar, beautifully-restored old theatre available for similar rental arrangements.
The Beltonian: https://thebeltoniantheatre.com/
How frequently does Sony change its identity. They should have a 999 year cert expiration and then check a revocation list in the off chance they Sony gets its private keys rooted.
That needs to change before any trickle down effect to projector hardware can happen. But there’s no incentive for studios to change the way they given their IP because they benefit from the status quo
It's one thing if a projector breaks mechanically or due to a pre-existing bug; it's another thing when an update breaks it.
In an age where updates are increasingly the norm, I wonder if there's legislation needed to hold manufacturers accountable for updates that break otherwise perfectly-functioning hardware?
"Every update is a downgrade":
http://itre.cis.upenn.edu/~myl/languagelog/archives/000606.h...
> Notice, I'm no Luddite. I don't reject technology. I depend on it.
Even worse, something got updated that broke CEC integration with my sound bar on one of them, so now I can't use the built in volume control and need to use 2 remotes instead. I know it's a real first world problem, but it infuriates me that they can slowly ruin a TV that I own and I have no recourse.
I'm so sick of the tech industry I hope the whole thing collapses. We need major legislation updates to make tech companies liable for all awful they're doing to the world.
They choose a processor that’s barely sufficient to run the software it releases with, and proceed release a constant stream of updates with nothing of value to the user. Meanwhile every update has the device running 5% slower, making it noticeably sluggish after a couple years.
It almost feels intentional, but I’m sure no bean counter is going to permit spending a few dollars extra per unit for something they probably see as reason for people to upgrade.
Wouldn't the license agreement that you agreed to when you installed the software specify any responsibilities of the vendor and define what recourse you might have? Why would government action be needed?
There's a major free-market failure because there's no negotiation over the agreement. There's no representative for consumers pushing back. So that representative needs to be the government.
This is the entire reason for consumer protection laws.
It is great that the government protects consumers. Otherwise, everyone would need to spend hours researching everything before making a rare purchase.
> Otherwise, everyone would need to spend hours researching everything before making a rare purchase
On this issue specifically, these projectors seem to be in the tens (possibly hundreds) of thousands of dollars so some research and due diligence doesn't seem that far fetched.
Indeed, which is why people may choose to band together in a bigger bargaining block to improve their position and possibly even achieve greater power than the other party. For example, they could choose to form a single block that represents the citizens of an entire country.
It happens all the time across many domains (look up the Uniform Commercial Code, for more general examples, or laws around vehicle sales).
I have less inclination to be involved in business to business transactions, but there’s absolutely a societal debate to be had around what laws and regulations we have on transactions of software.
Society runs smoother, with more transactions, and this economic wealth, when consumers can assume a reasonable baseline of behavior that is being regulated by the government. If every purchase and every transaction requires deep due diligence there will be far fewer transactions.
The government is not some foreign third actor, we live in a democratic society and as such, the way in which we do things is subjected to the desires of the public.
If enough people consider the government should intervene, then the government should intervene.
They will filibuster and or beaurocrat-ize away any will to pursue lawsuits, or they will offer token trivial compensation (which doesn’t nearly reflect the actual lost income)
Your “meh” apathy is what leads to the abuse of power by the larger parties
If your argument is that Sony is too big and has a monopoly on projectors - then antitrust laws exist.
We already have simple systems that handle "you broke my stuff" fairly well - why would we want to lean on something as slow and complex as antitrust laws to resolve this? The Epic vs Google lawsuit started in 2020. 3 years is a long time to wait to collect damages for broken projectors.
It's a business transaction where contracts are the norm. Sony may not be very flexible on terms, but no one is forced to buy their projectors and agree to the terms.
> why would we want to lean on something as slow and complex as antitrust laws
We would if consumers had no other choice but to buy Sony projectors only - that doesn't seem to be the case, though.
I don’t know how much choice movie theaters have. As I understand it, these projectors read directly from a hard drive, and are heavily regulated to avoid piracy. According to the Wikipedia article [1] there are only 4 approved manufacturers, and until very recently Sony had the only 4k model.
[1] https://en.wikipedia.org/wiki/Digital_cinema (see the projectors for digits cinema section)
Just because a law is created doesn't mean a new crime with criminal penalties is created.
Courts are our mechanism for sorting out the details, not legislation.
https://en.m.wikipedia.org/wiki/Sony_BMG_copy_protection_roo...
Maybe there should be a law that says:
1. Upgrades may be performed but never behind the user's back.
2. In particular, the user determines exactly when an upgrade is performed.
3. The user may roll back any update at any time.
4. Any services which the software depends on should be compatible with all versions of the updated software.
EDIT: 5. Security backports should be made available. However, the user should always be in control over whether they are installed. Sometimes working code is more important than 100% secure code. Also this rule will prevent companies from quickly forcing an update and sweeping security breaches under the rug.
For example, support for downgrades means you a security vulnerability can be reintroduced by a malicious user which may not be desirable. Writing software that’s backwards and forwards compatible across all releases can be extremely expensive to impossible (eg a feature in your application that requires a new OS or you need to use a now removed API when running on older releases).
There are difficult technical issues involved and trying to legislate specifics may not be the best idea vs other approaches that improve real freedom (eg you have to release sufficient details to your customers that they can write their own software for your hardware).
And there are regulated industries where a software update could be the fulfillment of a recall.
Actually, yes they are. I'm not a big fan of legislation, but the upgrade crazyness has to stop at some point!
> For example, support for downgrades means you a security vulnerability can be reintroduced by a malicious user which may not be desirable
What if "I, the user" deem it "desirable"?
I'm holding to bios with known vulnerabilities so I can work around "security features" that are "for my own protection" like 1) preventing me from underclocking (to keep the security features of the now-dead SGX) 2) using any M2 WWAN or NVMe that I want
It's gone to a point where it's not desirable for me to upgrade, and to prefer the risks that come with an exploit as at least I know my freedom to use my hardware the way I want will not suddenly become limited.
Another example: getting root on android with mediatek was considered a "bug" and work a mandatory "upgrade" that prevent users from being able to get root that way.
But I want to be root!
Only if said operator signed a contract. No contract=no liability.
Here in the US, the Supreme Court has made it clear that law enforcement agencies are not required to provide protection to the citizens cf https://www.nytimes.com/2005/06/28/politics/justices-rule-po...
If even the police isn't liable, why should I be liable or have any kind of duty to protect your system?
Your system, your problem.
You are using loaded words to 1) imply I would support some questionable actions where you assume intent and 2) refer to negative externalities, but I'll suppose you are not trolling interact in good faith with you.
Both the actions you define are ignoring property rights: your well, your parking lot = I can't do that, unless you allow me (with a contract!)
My well, my parking lot = I can do that, and you don't get to say what I do with my property, unless we have signed a contract which creates liability.
Many people seem to have a strong desire to be able to force ME to update MY browser/operating system/bios/whatever else to be up to THEIR standards, because it has consequences on THEIR liability.
I care a bit about them, but I care way more about MY freedom: I do what I what with MY computers.
Note that intent matters: I have no desire to cause bad things to other people. I'd be very sad if my computer was used as "part of a botnet" like someone else said. I might even try to avoid that - but only as far as it puts my freedom first, and there's not even a requirement that I try (because I might have better things to do lol)
Should bad things like botnets happen, 1) it wasn't my intent, as preserving my freedom was my intent 2) the negative externality is sad, but it's not my liability: you should secure your property, or said differently "your problems aren't my problem"
This whole interaction feels very strange to me. By any chance, are you European? Europeans seem to have very different concepts of freedom and liability than we do.
But we're talking about you deliberately not securing or even actively reducing the security of your property in a manner that could reasonably be predicted to lead to harm to other's property, and that harm occuring, through no fault of the harmed party. You're not supposed to store loaded guns unsecured on your front porch (not around here anyways).
>By any chance, are you European? Europeans seem to have very different concepts of freedom and liability than we do.
No, I'm from the US.
>You are using loaded words to 1) imply I would support some questionable actions where you assume intent and 2) refer to negative externalities, but I'll suppose you are not trolling interact in good faith with you.
I'm asking whether you would, not suggesting that you do. But yes, the acts in question were significantly more questionable than those in my previous comment, since your answer to that was more extreme than I expected. So how about the middle ground: Do you believe that the EPA should impose restrictions on companies' or citizens' right to dump whatever toxic waste they want into rivers? If you think the physical commons should be protected from predictable harm by negligence or reckless disregard, why not the digital?
We have different preferences about what's the right security/freedom ratio.
> You're not supposed to store loaded guns unsecured on your front porch (not around here anyways).
I don't think the government or anyone has any say about where or how I may keep my guns.
People believe they might have a say, so there are laws on the books, but they're frequently taken down by the courts.
> So how about the middle ground: Do you believe that the EPA should impose restrictions on companies' or citizens' right to dump whatever toxic waste they want into rivers?
I believe it shouldn't, but that's just my opinion.
You may not believe it, but in terms of efficiency and keeping the environment, it doesn't matter (see below)
> If you think the physical commons should be protected from predictable harm by negligence or reckless disregard, why not the digital?
I don't believe in in the physical word, and I don't believe it in the digital world either.
Regardless of my beliefs, there's a nobel prize winner who's shown that it doesn't matter how the rights are initially assigned, as long as parties can negotiate with no transaction costs.
Check the Coase theorem.
The EPA imposing restrictions create transaction costs, so I think we're better off without them
Even the author of the “theorem” you cite indicated that he didn’t believe it to be practical.
Backports exist because of this reason. Just added them as a requirement to the list of rules above.
Were you keeping your personal files in the usual "Documents" and "Videos" and such laid out by Microsoft? Or somewhere else?
3 - Maintaining a data path forward is tricky enough. Demanding that users be able to downgrade at anytime would be a very tall ask if user data has to survive the downgrade.
4 - This seems outlandishly expensive to do. This effectively reads “nobody can ever deprecate an api on anything”. This also seems to be broadly incompatible with fixing certain security vulnerabilities - would everybody have to maintain TLS 1.1 or plaintext api endpoints for old clients? Would a social media network have to maintain api endpoints that leaked more data than users were comfortable with?
This also seems to be broadly incompatible with fixing certain security vulnerabilities - would everybody have to maintain TLS 1.1 or plaintext api endpoints for old clients?
Or they would forced to produce an update that doesn't do anything other than e.g. upgrade the TLS version --- and has absolutely nothing else.
I don't see how an automatic update setting is incompatible with 2. If a user says "go ahead and install updates as needed" that is the user expressing their desire to receive updates.
I also think the phrasing in 1 is a little needlessly aggressive though I believe it comes from a place of frustration. The difference in my mind between saying "this thing updated behind my back" and "this thing updated automatically for me" is whether the user has registered the update as being beneficial or not, and depending on the device, that's a WIDE spectrum. I know my smart outlets update their firmware all the time, and an extremely small handful of times I do notice, because sometimes they end up not reconnecting to the wifi quite right and need to be reconnected. However if they updated and, for example, broke HomeKit support and no longer worked, I'd be angry the next time I tried to use them.
> 3 - Maintaining a data path forward is tricky enough. Demanding that users be able to downgrade at anytime would be a very tall ask if user data has to survive the downgrade.
I mean, this is just an engineering problem pure and simple. Most of the time, in my experience, graceful downgrade just isn't prioritized because, well, who can even do it for starters? Installing old software oftentimes means you need to do some really intense stuff, like wiping whatever device entirely, so the retention of data is moot.
If this was mandated I see no problem with getting it done in my industry. It's simply a matter of making it a priority IMO.
> 4 - This seems outlandishly expensive to do. This effectively reads “nobody can ever deprecate an api on anything”.
With certain products I can definitely see it being an advantage, and the first place my mind goes to is again, smart home products and appliances, automotive hardware, that sort of thing. Large, expensive items that incorporate software that the user interacts with can be an absolute nightmare when the OEM randomly decides that the way something's worked for years and years for you is now just not an option, or worse still, locks it behind a paywall. And what are your options here? Buy a new car or dishwasher? Or eat shit and pay them $20 a year that they have not earned and are providing no value for?
This is why the newest car I have is a 2018 Corvette, because I know all it's software and have access to it, and there's no system that's going to lock my heated seats behind a Chevrolet Premiere+ subscription where I have to give chevy money to permit my car to engage a damn relay for me.
Continuous updates continue to permeate, including into things that are still surprisingly connected to the internet in the first place.
I think that in time, forced updates will cause enough trouble that people will become more conscious of and dislike them. For some, one bad update is all it will take.
So, I think it's worth waiting to see if anti-update competitors appear before regulating this.
Make them a bit terser, and maybe “Right to repair” will heave them out of the science fiction tarpit.
> 2. In particular, the user determines exactly when an upgrade is performed.
Haha, at last, yes !! Take that stupid windows XP countdown to reboot !!
For number 3 if we allowed for people to roll back any update that can include Teslas where they are doing OTA safety updates so that wouldn’t work out.
It took 7 years though:
Having 2 Sony projectors wouldn't help here though...
Arguably the hardware still functions perfectly, it’s the software that’s broken.
Went to start the procedure, machine reports it’s ready to work, all set up, assistant presses start, cryptic error messages. No way to fix. Turns out our license has improperly expired for reasons unknown. No way to override.
It’s past 5 pm Friday of the New Year’s weekend. No one on call for the company has any idea how to fix. Took three hours repeatedly phoning the company to finally get put through to an engineer who gave us magic series of button presses and codes to get the machine working.
We used to have a purely mechanical machine, maintained in house by an on site engineer. Now we have to deal with this. There is only one company making these machines, so no competition. Progress.
Of course with the recent Polish train debacle (https://news.ycombinator.com/item?id=38788360) stories of DRM schemes where incomplete defeat causes subtly worse behaviour (rather common in games), and the ability to engineer a system with plausible deniability in mind, like some of Apple's hardware-locking attempts, one does wonder whether medical devices may have such logic bombs too.
https://www.vice.com/en/article/3azv9b/why-repair-techs-are-...
> I wonder how much longer until we have a military device that doesn't work killing people...
And
> I wonder how much longer until we have a medical device that doesn't work, killing people...
Perhaps someone can share what is needed here and why it's connected.
But Sony hasn’t made projectors in a while. I suspect this was something like an expired certificate rather than an actual software update.
Keys are sent separately, and are valid only for a certain date-range, and for a specific cinema server. In this case, Sony servers only work with Sony projectors, and vice-versa. Each device has its own certs, but for encrypted feature encoding, the standard is Key Delivery Messages, which unlock the feature Digital Cinema Package (DCP). DCPs are a general purpose cinema package, and is also used to deliver unencrypted clips like ads and trailers.
But the key is the Key. It's only valid for the specific cinema server, and the cinema server is "married" to the projector by encryption. This protects against on-site MITM attacks.
If there's a server update that doesn't update the certs on either the server itself, or the projector (in Sony's case), then the marriage breaks, and the silver screen stays dark.
Nothing anyone else can do about it, either, since any valid certs would have to be issued by Sony, and nobody has the private keys except Sony.
Although you can use them for non DRM showings.
Not having my phone locked up to only play music is awesome, being able to use voice control to play specific songs and have them play throughout the house is awesome. Bluetooth is a pain, not being able to use Instagram (or any other app that wants control of audio) while my daughter listens to a song sucks.
Where are you getting your information? Sonos speakers that support bluetooth don't need an internet connection to use bluetooth. They only need an internet connection when you want them to stream music from the internet.
This TMS is also not connected to the internet in most cases. Digital cinema is locked down tight as an ATM. Most theaters have pretty meager on-site IT, so email and thumb-drives and hard-drives still rule.
I work in cinema IoT including KDM and DCP delivery and ingestion to TMS or cinema server, and our solution is to have a separate agent inside the private cinema network that can broker communication with cinema devices like projectors, calibrators, and audio processors. Some of these have their own UIs in the local network, or if you've got the company VPN, but in general for monitoring we just rely on SNMP or server API.
The cinema servers are different. They all have APIs that provide varying levels of monitoring, control, and automation for the server, itself, as well as connected devices including limited monitoring and control of projectors and audio. They all support RDP or VNC, so if you're behind the same firewall you can get to their UI. Same with TMSes... they have UIs that you can access remotely, if you're on the company VPN.
But the projector itself? Never on the internet. It's "married" to the cinema server, and will only work with that particular server, based on their respective certs.
In Sony's case, it sounds like the projector certs have expired, so now they are invalid when used with the updated server certs.
http://www.film-tech.com/vbb/forum/main-forum
Expired cert. Some players refuse, some ignore it.
Affected - Sony (XCT-M10) / GDC SR-1000 - "15-08-2011 18:10:59 UTC 31-12-2023 00:00:00 UTC (expired)"
There was a known Y2K24 bug that needed software updates to fix around certs, unsure how/if related -
http://www.film-tech.com/vbb/forum/main-forum/26517-dolby-do...