Go Back   Techwatch Support Forums: Digital & Satellite TV, FTA, Cable, Computers, Mobile Phones, Apple and General Tech Forums > Tech Forums > Digital TV > UK Cable > Cable TV Chat



Cable TV Chat Discuss all aspects of the cable tv world

Reply
 
LinkBack Thread Tools
Old 06-12-09, 03:27 PM   #41 (permalink)
Underground Crew Member
 
TheCoder's Avatar
 
Join Date: May 2009
Location: Undrground
Posts: 2,149
Thanks: 15
Thanked 1,691 Times in 933 Posts
Default Re: Christopher Tarnovsky, could these methods be used to hack nagra 3???

Quote:
Originally Posted by sr20 View Post
Are you saying if you were given the code destined for a 'top level trader' you'd not implement and rel it for £1M?

Although I still disagree that the top level traders wouldn't do it for say even 1 mil euros...I think CS is the only logical way forward
What i'm saying is that your very unlikely to get that code in the first place !

The kind of people that would be extracting to embed in their own boxes/cams probably know more about security that the whole of Kudelski/NDS put together.

These people would not be interested in selling this info for any realistic price when they have the opertunity of controlling access, and therefore price, over an extended timeframe. They may sell you the present operational keys for an exorbitant sum but, as we all know, those keys can be changed in just a few hours !
TheCoder is offline   Reply With Quote
Old 02-01-10, 11:00 PM   #42 (permalink)
Junior Member
 
Join Date: Dec 2009
Posts: 14
Thanks: 0
Thanked 8 Times in 4 Posts
Default Re: Christopher Tarnovsky, could these methods be used to hack nagra 3???

There are a few threads on here piquiing my interest, this being a decent example of them.

Unfortunately it seems the average forum type hasn't really moved on one iota since 2005.

Nagra3 is not an encryption system, it's a Conditional Access System. The encryption systems is uses range from DES to RSA to IDEA to AES etc, but Nagra3 (or any Nagra technolgy) is not encryption.

All DVB-C signals are encrypted with CSA. The Control Words to decrypt MPEG2 video encryped using CSA are protected by Nagra's Conditional Access System (N3 being the latest iteration)

The box gets an ecrypted Video Stream, it asks the card for the Control Words to decrypt the Video Stream, and if it's entitled to them it gets them. If not, it doesn't (black screen)

That hasn't changed since the first DVB-C (and DVB-S for that matter, if we're talking about NDS in the same thread, since VideoGuard is the Conditional Access System used by NDS who protect SKY UK programming)

The encryption, like TheCoder mentioned, has never been broken (earlier, shortey-key implementations of RSA have been cracked, but even then it was only via bruteforcing, and still took ages!)

The Video Stream is encrypted using the CSA.

The CW's to decrypt it are passed to the card via EMM's encryped with a variant of RSA

The Box will ask the card for these CW's and if it's entitled to view (either via a legit sub or via a hacked sub i.e. a MOSC or emu) it will receive them. The card will pass them to the box AFTER first encrypting them using DES, with the box key as the common encrypt/decrypt key.

This happens every 8 seconds or so.

The various implementations of Nagra (1, 2, 3 etc) are systems which USE encryption, but also systems which use various command/response instructions from the Box<>Card to determine whether that encryption will be used to provide or deny programmes i.e a TV picture.

The first variant, N1, has lots of flaws in it's makeup and those are reflected in the many exploits and attacks available to hackers (CMD03 exploit in earlier times, glitching etc)

N1 here means both the actual programs in ROM/EEPROM on the cards and the processors on the cards themselves. The physical hardware was susceptible to certain attacks, glitching being one of them.

N2 was more of the same, but with better protection against attack via both the processors and the programs on them in ROM/EEPROM.

N3 is again more of the same, except with yet more protection in HW and SW (technically FirmWare)

The Conditional Access System is the implementation which utilises the hardware (the smartcard processor and some circuitry in the box too), the software/firmware (the ROM/EEPROM) and also encryption, it's not encryption itself.
wellytronic is offline   Reply With Quote
The Following 4 Users Say Thank You to wellytronic For This Useful Post:
PerryCox (03-01-10), pje (03-01-10), Robbo (04-01-10), xpn08 (30-05-10)
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
new cards barry22 Other Cable Boxes 40 15-11-09 04:10 PM
New homebrew hack coming DONT update your consoles!! Danielle Microsoft Xbox 18 13-08-09 07:55 PM


All times are GMT +1. The time now is 08:46 AM.


Powered by vBulletin® Version 3.8.5
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.6.0 ©2011, Crawlability, Inc.