mili
05-20-2006, 05:25 AM
And I post what I was told. Remember I am only a parrot but a well informed one.
Nagra has changed the format of the decrypted CMD 07 video packet on some channels. Most likely, the rest of the channles will follow soon.
The old CMD 07 decrypted packet structure looked like this:
....09 01 ....100900AAAAAAAAAAAAAAAA110900BBBBBBBBBBBBBBBB.. ..
where AAAAAAAAAAAAAAAA was video control word 0 and BBBBBBBBBBBBBBBB was video control word 1. FTA boxes would simply use these keys to decode the audio/video. Echostar cams would encrypt these control words with the 16 byte session key and the IRD would simply decrypt them (redundant process designed to counter wedge hacks) to decode the audio/video.
The new CMD 07 decrypted packet structure now looks like this:
....09 01 ....100940aaaaaaaaaaaaaaaa110940bbbbbbbbbbbbbbbb.. ..
where aaaaaaaaaaaaaaaa and bbbbbbbbbbbbbbbb are not the actual control words, but some CONVOLUTED FUNCTION of the control words. Notice the cam is being instructed by 100940 and 110940 instead of 100900 and 110900. What this convoluted function is at this time is unknown. Most likely, a simple X-OR with some bytes in the Cam's RAM or IRD's firmware. This will pretty much eliminate all camless and standalone hacks that do not use echostar cards and receivers or possible both. The FTA factories in Korea will be idle very soon. It looks like the free (no pun intended) FTA ride will be over soon.
Expect Dish to implement the same countermeasures within the next few days. They also revised their cards. Only cards with the latest revision actually work now.
If the current revision cannot be unlocked, then it will be pretty much impossible for anything to work.
They are now sending down CMD04 packets whose decrypted payload is being used to X-OR the convoluted control words coming down in CMD 07. Without access to a dump of the latest revision, it is impossible to know how they are X-ORing the data. Even if one can theoretically decrypt CMD 04 (which we still can).
To re-iterate:
1. If the current revisions cannot be unlocked by nob14me, then NO stand alone hack is possible. Only a married-sub type hack will be possible.
2. If the current revisions are opened up, that still doesn't mean everything would work again because decrypting a CMD04 is very computationally intensive. Only the fastest devices would survive.
Rom10,11, Syndrome and Atmega are gone for sure because of speed limitations even if unlocking were successful. Actually, SYndrome may have worked but the designer is now behind the bars, so it is irrelavent. FTA are gone too because I doubt they could handle the speed either. All this is assuming someone can unlock the newest revision, which may not happen at all. Well, people may be watching black screens over the next couple of weeks.
mili
Nagra has changed the format of the decrypted CMD 07 video packet on some channels. Most likely, the rest of the channles will follow soon.
The old CMD 07 decrypted packet structure looked like this:
....09 01 ....100900AAAAAAAAAAAAAAAA110900BBBBBBBBBBBBBBBB.. ..
where AAAAAAAAAAAAAAAA was video control word 0 and BBBBBBBBBBBBBBBB was video control word 1. FTA boxes would simply use these keys to decode the audio/video. Echostar cams would encrypt these control words with the 16 byte session key and the IRD would simply decrypt them (redundant process designed to counter wedge hacks) to decode the audio/video.
The new CMD 07 decrypted packet structure now looks like this:
....09 01 ....100940aaaaaaaaaaaaaaaa110940bbbbbbbbbbbbbbbb.. ..
where aaaaaaaaaaaaaaaa and bbbbbbbbbbbbbbbb are not the actual control words, but some CONVOLUTED FUNCTION of the control words. Notice the cam is being instructed by 100940 and 110940 instead of 100900 and 110900. What this convoluted function is at this time is unknown. Most likely, a simple X-OR with some bytes in the Cam's RAM or IRD's firmware. This will pretty much eliminate all camless and standalone hacks that do not use echostar cards and receivers or possible both. The FTA factories in Korea will be idle very soon. It looks like the free (no pun intended) FTA ride will be over soon.
Expect Dish to implement the same countermeasures within the next few days. They also revised their cards. Only cards with the latest revision actually work now.
If the current revision cannot be unlocked, then it will be pretty much impossible for anything to work.
They are now sending down CMD04 packets whose decrypted payload is being used to X-OR the convoluted control words coming down in CMD 07. Without access to a dump of the latest revision, it is impossible to know how they are X-ORing the data. Even if one can theoretically decrypt CMD 04 (which we still can).
To re-iterate:
1. If the current revisions cannot be unlocked by nob14me, then NO stand alone hack is possible. Only a married-sub type hack will be possible.
2. If the current revisions are opened up, that still doesn't mean everything would work again because decrypting a CMD04 is very computationally intensive. Only the fastest devices would survive.
Rom10,11, Syndrome and Atmega are gone for sure because of speed limitations even if unlocking were successful. Actually, SYndrome may have worked but the designer is now behind the bars, so it is irrelavent. FTA are gone too because I doubt they could handle the speed either. All this is assuming someone can unlock the newest revision, which may not happen at all. Well, people may be watching black screens over the next couple of weeks.
mili