<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Why Blu-Ray scares me</title>
	<atom:link href="http://securityblog.org/brindle/2008/01/24/why-blu-ray-scares-me/feed/" rel="self" type="application/rss+xml" />
	<link>http://securityblog.org/brindle/2008/01/24/why-blu-ray-scares-me/</link>
	<description>The ramblings of security neophyte Joshua Brindle</description>
	<pubDate>Sat, 17 May 2008 04:48:28 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5</generator>
		<item>
		<title>By: Wilfred</title>
		<link>http://securityblog.org/brindle/2008/01/24/why-blu-ray-scares-me/#comment-27390</link>
		<dc:creator>Wilfred</dc:creator>
		<pubDate>Mon, 31 Mar 2008 17:34:25 +0000</pubDate>
		<guid isPermaLink="false">http://securityblog.org/brindle/2008/01/24/why-blu-ray-scares-me/#comment-27390</guid>
		<description>On the other hand, the mpeg-stream in hd-dvd is non spec compliant i believe...</description>
		<content:encoded><![CDATA[<p>On the other hand, the mpeg-stream in hd-dvd is non spec compliant i believe&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steve C</title>
		<link>http://securityblog.org/brindle/2008/01/24/why-blu-ray-scares-me/#comment-22998</link>
		<dc:creator>Steve C</dc:creator>
		<pubDate>Tue, 29 Jan 2008 23:01:17 +0000</pubDate>
		<guid isPermaLink="false">http://securityblog.org/brindle/2008/01/24/why-blu-ray-scares-me/#comment-22998</guid>
		<description>That VM concept will last about as long as it takes someone to write a 'processor module' for IDA Pro and then learn how to hook all the OS dependent external linkages in their VM. It only takes one person to make an entire DRM system obsolete because they are 'logically' flawed by design. Its just security through obscurity, and nothing more. If they actually do change the hardware settings or flash memory of someones machine in the process of viewing a DVD they may make that one geek mad enough to do it. Its only a matter of time IMHO. These media companies need to learn that you can't fix a "social problem" with technology.</description>
		<content:encoded><![CDATA[<p>That VM concept will last about as long as it takes someone to write a &#8216;processor module&#8217; for IDA Pro and then learn how to hook all the OS dependent external linkages in their VM. It only takes one person to make an entire DRM system obsolete because they are &#8216;logically&#8217; flawed by design. Its just security through obscurity, and nothing more. If they actually do change the hardware settings or flash memory of someones machine in the process of viewing a DVD they may make that one geek mad enough to do it. Its only a matter of time IMHO. These media companies need to learn that you can&#8217;t fix a &#8220;social problem&#8221; with technology.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joshua Brindle</title>
		<link>http://securityblog.org/brindle/2008/01/24/why-blu-ray-scares-me/#comment-22813</link>
		<dc:creator>Joshua Brindle</dc:creator>
		<pubDate>Sun, 27 Jan 2008 16:32:16 +0000</pubDate>
		<guid isPermaLink="false">http://securityblog.org/brindle/2008/01/24/why-blu-ray-scares-me/#comment-22813</guid>
		<description>Bob:

Good catch, I misunderstood the VM part of BD+ but my main point, that the creators of BD+ felt that patches end user devices was appropriate, stands true. 

It seems from what you wrote on your site that you see this as an advantage of BD+, which scares me more. For the record I'm not adverse to DRM, I am very adverse to the notion that the content produces feel it is their right to modify the firmware on my device to meet their needs.</description>
		<content:encoded><![CDATA[<p>Bob:</p>
<p>Good catch, I misunderstood the VM part of BD+ but my main point, that the creators of BD+ felt that patches end user devices was appropriate, stands true. </p>
<p>It seems from what you wrote on your site that you see this as an advantage of BD+, which scares me more. For the record I&#8217;m not adverse to DRM, I am very adverse to the notion that the content produces feel it is their right to modify the firmware on my device to meet their needs.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bob Weber</title>
		<link>http://securityblog.org/brindle/2008/01/24/why-blu-ray-scares-me/#comment-22802</link>
		<dc:creator>Bob Weber</dc:creator>
		<pubDate>Sun, 27 Jan 2008 14:07:05 +0000</pubDate>
		<guid isPermaLink="false">http://securityblog.org/brindle/2008/01/24/why-blu-ray-scares-me/#comment-22802</guid>
		<description>I don't believe that the VM used for BD+ is based on Java nor do I believe that it is the same interpreter used for interactivity. see the sources cited in 
http://www.managingrights.com/2007/03/bluray_bd.html

also, see CRI's pending patent application,

http://appft1.uspto.gov/netacgi/nph-Parser?Sect1=PTO1&#38;Sect2=HITOFF&#38;d=PG01&#38;p=1&#38;u=%2Fnetahtml%2FPTO%2Fsrchnum.html&#38;r=1&#38;f=G&#38;l=50&#38;s1=%2220070033419%22.PGNR.&#38;OS=DN/20070033419&#38;RS=DN/20070033419

which suggests that "TRAP" calls from the security VM are used to access other functions.</description>
		<content:encoded><![CDATA[<p>I don&#8217;t believe that the VM used for BD+ is based on Java nor do I believe that it is the same interpreter used for interactivity. see the sources cited in<br />
<a href="http://www.managingrights.com/2007/03/bluray_bd.html" rel="nofollow">http://www.managingrights.com/2007/03/bluray_bd.html</a></p>
<p>also, see CRI&#8217;s pending patent application,</p>
<p><a href="http://appft1.uspto.gov/netacgi/nph-Parser?Sect1=PTO1&amp;Sect2=HITOFF&amp;d=PG01&amp;p=1&amp;u=%2Fnetahtml%2FPTO%2Fsrchnum.html&amp;r=1&amp;f=G&amp;l=50&amp;s1=%2220070033419%22.PGNR.&amp;OS=DN/20070033419&amp;RS=DN/20070033419" rel="nofollow">http://appft1.uspto.gov/netacgi/nph-Parser?Sect1=PTO1&amp;Sect2=HITOFF&amp;d=PG01&amp;p=1&amp;u=%2Fnetahtml%2FPTO%2Fsrchnum.html&amp;r=1&amp;f=G&amp;l=50&amp;s1=%2220070033419%22.PGNR.&amp;OS=DN/20070033419&amp;RS=DN/20070033419</a></p>
<p>which suggests that &#8220;TRAP&#8221; calls from the security VM are used to access other functions.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
