View Full Version : Microsoft's DRM 'cracked'
Gargoyle
29 Aug 2006, 03:02pm
Microsoft's digital rights management (DRM) for Windows Media protected files has been broken, according to news sources. A new program can strip the protection from the files, leaving them with unrestricted uses. That is, until Microsoft closes the hole.
A program called Fairuse4wm has been posted on the net and is apparently capable of breaching Microsoft's Digital Rights Management (DRM) system.
It could spell problems for internet music shops, potentially enabling users to download unlimited files.
However, an analyst said Microsoft was probably working to "close the hole".
And Microsoft will close the hole. Their DRM system can be dynamically, seamlessly updated. What's significant about this development is not just that people can "free" their restricted files for the next few days until Microsoft fixes the problem. It also means that now that DRM has been cracked once, more hackers will likely get into the game, and breaches of DRM could become more common. Perhaps most importantly, it is a clear signal the people are not ready to kick the free (or at least, unrestricted) music habit anytime soon, and companies that embrace that fact may be putting themselves in a more realistic position.
In a related story, the world's largest music group is allowing its music to be downloaded for free from an advertisement-supported service: Link (http://news.bbc.co.uk/2/hi/business/5294842.stm)
Source: BBC News (http://news.bbc.co.uk/2/hi/technology/5294750.stm)
Thrax
29 Aug 2006, 03:25pm
Something to note: The DRM schema can't be updated unless you let it update your licenses and files.
Gargoyle
29 Aug 2006, 03:51pm
Would that happen automatically if you're using a service like Napster? When I start Napster up, it gives some ambiguous messages like "updating library."
airbornflght
29 Aug 2006, 04:26pm
DRM will always be cracked, it is just a game of cat and mouse imo...
Thrax
29 Aug 2006, 09:08pm
Okay, it's officially been patched. Anyone who was connected to the internet and launched their respective DRMed service late last night had an updated DRM control downloaded to their PC. Author is working on version 1.2. Only way to avoid it was to back up the old DLL, and use a hex editor to update the version # to the new version while leaving the old hackability.
muddocktor
29 Aug 2006, 11:01pm
I'll just stick with Tunebite for now and avoid all the mess. :D
Recracked. Version 1.2 strips the newest blackbox keys by Microsoft for WMA10 and 11, as well as V1 copyright protection that a user might accidentally place on their CD when they rip it with WMP10/11.
airbornflght
5 Sep 2006, 06:56pm
yay
Justin
5 Sep 2006, 07:11pm
Mudd knows best. Tunebite>DRM.
Yeah, except you lose a hell of a lot more quality going through the internal loopback than you do with a WMA -> MP3 conversion.
airbornflght
5 Sep 2006, 11:39pm
yeh, DRM sucks, plain and simple. This almost makes me want to redownload all 6,000 tracks from napster again. oh well, I record at 192kb/s, and it sounds pretty good to me. and that is all that really counts. Still not sure if DRM is gonna work in the long term or not. It just keeps getting cracked...
Kwitko
6 Sep 2006, 12:02am
Apple iTunes 6 DRM has also been cracked. (http://www.engadget.com/2006/08/29/hymn-is-back-fairplay-on-itunes-6-finally-cracked/)
Gargoyle
6 Sep 2006, 12:07am
Still not sure if DRM is gonna work in the long term or not. It just keeps getting cracked...
Since the people out there cracking and haxing music files out there are the minority, the biggest factor will be how much money the DRMed services make. If Napster and iTunes keep making a profit, they won't change their ways unless they think they'll make more money.
muddocktor
6 Sep 2006, 03:13am
Yeah, except you lose a hell of a lot more quality going through the internal loopback than you do with a WMA -> MP3 conversion.
I've actually been pretty impressed with the quality of the rip with Tunebite. I've played the original DRM'ed WMV file and then followed it with the mp3 rip back to back and honestly, I can't tell the difference between them And that is with playing either through my Z5500's or through my Bose headphones. I do rip to 192 kb/s to preserve as much quality as possible though. I can definitely hear the difference between a 192 rip or 128 rip.
mephisto
22 Sep 2006, 04:24pm
I've purchased [link removed] and it's worth buying.
Kwitko
22 Sep 2006, 05:16pm
I've banned mephisto and he's worth banning.
profdlp
22 Sep 2006, 10:57pm
I laughed at KwitCo™'s last comment and it was worth laughing. ;D
airbornflght
26 Sep 2006, 02:54am
Patched.
I find it funny how microsoft can not fix a zero day vulnerability in a reasonable amount of time, yet they can patch this within days.
Thrax
26 Sep 2006, 03:12am
No, it's still unpatched. ;)
airbornflght
26 Sep 2006, 04:11am
No, it's still unpatched. ;)
Is it? engadget (http://www.engadget.com/2006/09/25/microsoft-claims-successful-patch-against-fairuse4wm-1-2/) is reporting that it is fixed. and wmp crashed while trying to extract the key, where it worked 2 nights ago. so im guessing he will find a workaround in a a couple of days.
Gargoyle
26 Sep 2006, 08:26pm
...so im guessing he will find a workaround in a a couple of days.
Viodentia (http://www.engadget.com/2006/09/25/the-engadget-interview-viodentia-creator-of-fairuse4wm/) seems to think so.
What do you think of Microsoft's latest memo, which claims to patch version 1.2?
I'll reserve full commentary until I've had a chance to examine the new IBX in more detail. I'll release a new version sometime this week.
Thrax
27 Sep 2006, 07:11pm
RE: RE: RE: Cracked.
v1.3 is out, and gets around Microsoft's newest patch.
Private_Snoball
27 Sep 2006, 08:24pm
RE: RE: RE: Cracked.
v1.3 is out, and gets around Microsoft's newest patch.
It looks like unless MS reworks the DRM scheme from the ground up he will just continue to fill in the blanks they leave with every patch.
airbornflght
27 Sep 2006, 11:38pm
RE: RE: RE: Cracked.
v1.3 is out, and gets around Microsoft's newest patch.
OH GOODY, I've been waiting!
Thrax
27 Sep 2006, 11:51pm
I don't know what you've been waiting for. As long as you have Automatic Updates disabled in Windows, you don't use WMP, and you don't download that update when you go to MS Update, they can never patch you.
airbornflght
28 Sep 2006, 03:46am
yeh, but napster automatically sends me the updates; how nice of them.:aol:
Thrax
28 Sep 2006, 03:56am
They didn't send me the updates.
airbornflght
28 Sep 2006, 04:51am
They didn't send me the updates.
mine did, soon as I logged in, because 1.2 ceased working, started throwing errors, and automatic updates are indeed off. I just hope this keeps up, I saw that microsoft has subpoenaed him, and are filing charges. The accuse him of stealing source code or something. he just used their api. would be a pretty good news story to follow.
vBulletin® v3.7.3, Copyright ©2000-2009, Jelsoft Enterprises Ltd.