Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Even Widevine L1 is effectively broken

Is there any evidence that Widevine L1 itself is actually broken, instead of let's say Netflix still offering legacy routes to provide HiRes content to some STB's and other devices (routes which are then used by pirates to download the content)?



CVE-2018-6242 allows dumping keys from affected Nvidia Tegra processors that are used, for example, in Nvidia Shields. That hardware flaw is unpatchable in existing units and revoking their keys would mean rendering a large swath of media center devices unable to do their job.


Which basically makes devices with this processor the mentioned "legacy route for HiRes content", until content-providers decide to flag those trust-chains as broken and fall back to Widevine L3 (SW-based).

This happened more often in the past than people may realize, especially on devices from Xiaomi, Oppo, OnePlus.

Netflix is actively monitoring this and are escalating to device-vendors as soon as they see suspicious load and are about to flag the devices.


... all to the detriment of paying customers who happen to use these devices.


Those keys were downgraded to L3.


Oh! I was not aware that happened. Right now I can't find anything on that matter (not that it would be highly advertised). I'm not doubting this, but do you have a reference for that?


What? That should be illegal. They changed the rules after you already purchased the device


Got to keep consumers in their toes.

You're supposed to buy new devices, consume.



That's L3, not L1.


Quote from the Article

> That said, there is also a free L1 Content Decryption Module posted in the ‘LenovoTB-X505X-L1-KEY’ repository. A trusted source confirmed to TorrentFreak that this CDM is indeed working. However, as Widevinedump also notes, it may not be active for much longer.


That key was revoked the day the article was published.


A noble sacrifice. Some paying customers will be affected, but it's for the greater good.

The streams will continue to get dumped, with different keys.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: