zlacker

[parent] [thread] 9 comments
1. freeon+(OP)[view] [source] 2023-07-21 18:57:32
Fork chromium and have it return true. Problem, websites?
replies(3): >>progbi+Z >>jabban+l1 >>blibbl+sP
2. progbi+Z[view] [source] 2023-07-21 19:02:49
>>freeon+(OP)
It doesn't return boolean but an attestation certificate that the server can validate before sending you any content.
3. jabban+l1[view] [source] 2023-07-21 19:04:41
>>freeon+(OP)
It's signed?

Sure you can fake the results of an attestation in your fork, but your fork would be using your own key to sign the response, a key that the site can reject.

replies(1): >>freeon+4s
◧◩
4. freeon+4s[view] [source] [discussion] 2023-07-21 21:04:25
>>jabban+l1
Ah, we’ll also have to extract the key from chrome. It’s no worse than WideVine.
replies(4): >>jabban+nv >>gray_-+dJ >>jaunty+541 >>rezona+Gi1
◧◩◪
5. jabban+nv[view] [source] [discussion] 2023-07-21 21:18:41
>>freeon+4s
Has that been extracted already? I have to admit I'm behind on the current state of browser DRM...

Also I wonder if in the future this would require attestation of the entire chain: secure UEFI validated by key burned in CPU, validates secure boot os that prevents "hacking tools", which validates secure Chrome, which attests secure websites...

Truly royally screwed at that point...

replies(1): >>charci+bL
◧◩◪
6. gray_-+dJ[view] [source] [discussion] 2023-07-21 22:25:17
>>freeon+4s
There is no key in chrome, the signing is done via a 3rd party server.
◧◩◪◨
7. charci+bL[view] [source] [discussion] 2023-07-21 22:35:49
>>jabban+nv
The current state of DRM is that you have to find a hardware vulnerability in order to extract a certificate. With this you can now decrypt DRM content, but you have to be careful not to get that key blacklisted.
8. blibbl+sP[view] [source] 2023-07-21 23:02:32
>>freeon+(OP)
it doesn't help

the TPM does the attestation of the entire running environment, starting with firmware, through the OS, through the browser all the way down to the website

◧◩◪
9. jaunty+541[view] [source] [discussion] 2023-07-22 00:55:56
>>freeon+4s
I don't believe any of the HD widevine keys have been revealed.

I would practically guess the keys that did get revealed were deliberately leaked, low stake keys, that keep people still willing use to use widevine platforms at low res without being angry.

◧◩◪
10. rezona+Gi1[view] [source] [discussion] 2023-07-22 03:35:38
>>freeon+4s
No, you'll need to extract the TPM secureboot keys from Microsoft headquarters. Good luck with that
[go to top]