Markus Kuhn, 1995-11-12
I receive a lot of e-mail with questions about VideoCrypt and similar topics. As it becomes quickly very boring to answer these questions hundreds of times per month to Internet beginners, I have written this little text with the most frequent and important answers. Please read it carefully.
Q: Where can I get the latest Season?
On 1995-10-31, BSkyB has changed to a new secret encryption method which is built into the new series 10 card. This algorithm is not yet known and I do not know and can make no reasonable forecast when or even whether it will become public knowledge again. Therefore, it will not be possible to upgrade PC emulator software like Season7 and its derivates in the near future.
Q: Will I need a new adapter hardware for emulating the BSkyB 10 card?
No. Nothing in the decoder has changed, so you won't need a new ISO 7816 interface design. What looks like additional contacts on the new 10 card and what has confused many people which do not understand how a VideoCrypt decoder works is just the new chip module cover design of a different card manufacturer. There are no new contacts on the BSkyB 10 card. You won't need a new interface hardware design as long as the decoder is not modified.
Q: When will a hack of the series 10 BSkyB card be available again?
Probably not very soon. The exchange of the card means that practically all known secrets of the 09 card are useless now. Card emulators can not be simply constructed by just listening long enough the the data traffic of a genuine card. If you do not understand why, then please consult the Frequently Asked Questions List of the USENET group sci.crypt or any good introductory text about cryptography and make yourself familiar with secure hash functions, digital signatures, symmetric cryptosystems and other cryptographic concepts used in the VideoCrypt system.
Most likely, commercial hackers obtain the software in the microprocessor of each new smartcard generation by using very expensive chip test equipment (microprobing, electron beam testing, electron microscopes, etc.) and tricky analysis techniques. Of course the manufacturers of the security microprocessors which are used in the VideoCrypt cards work hard on making these attacks on the chip as difficult and expensive as possible and with each card generation they are getting better and better and hacking the cards becomes more difficult and expensive each year.
Please do not ask me whether the emulator algorithm for the BSkyB 10 card is already available. If the new code becomes publically known, you can be sure that this event will be discussed in detail on the USENET group alt.satellite.tv.crypt. Follow the discussions there if you want to stay informed about the latest progress and rumors.
Q: Where will I find new information about Season and VideoCrypt?
Read regularly the USENET newsgroup alt.satellite.tv.crypt. Please do not flood this group with questions before you have not read the various Frequently Asked Questions Lists (FAQs) posted there periodically and before you have not followed the discussions there for at least two weeks. Also, please check the following Internet servers for the latest information, before you start asking questions:
These servers have files with links to additional sources of information.
Remember: While asking a question on the network, you have a much better chance to get a valuable answer, if you demonstrate that you have done your homework and have checked already all available sources of information yourself.
Remember: Be very careful with starting unknown software downloaded from the Internet!!! Some people enjoy publishing files with interesting names like season10.zip which do nothing but destroying data on your harddisk when started. Such software is called a "Trojan Horse" and there have been many reported cases. If a virus scanner does not signal any danger, this does not mean that this software will do no harm. Never start dubious software without a full prior harddisk backup, especially if you use an operating system like DOS, OS/2 or Windows which has no protection mechanisms.
Q: Is there any way I can still watch Star Trek, the X-Files and the Simpsons on Sky1 even if the 10 card is not yet hacked?
Yes, there is! The technique is known as delayed data transfer and this is one of the security problems of VideoCrypt from which the system can not recover easily by a card exchange. It works as follows:
Someone with a genuine card records the data exchanged between the card and the decoder during the time when a very popular show is broadcasted. I have developed a special data file format called VCL (VideoCrypt Log) exactly for this purpose. People without a genuine card record the encrypted show on a good VCR at the same time. Later, the person with the genuine card posts his VCL file on a mailing list and all people without real cards load this VCL file with Season7 and then Season7 can reproduce the answers of the genuine card and this is sufficient for decoding this show even without knowing the secret cryptographic algorithm.
This works fine and has even been done when the 07 card was in use. It just needs a little bit cooperation on the network. The person recording the VCL file needs a adapter card which has a card connector, so that the adapter can be plugged between the decoder and card. In order to decrypted from a VCR, you'll have to make a special cable which allows to connect the VideoCrypt decoder between the VCR and the TV. This does not work with most IRDs. The technical details are explained in the manual of Season7 1.3 which is available on ftp.uni-erlangen.de.
Q: Is my card adapter broken or is just my emulator software not up to date?
If the VideoCrypt decoder keeps the power supply of the card on and continues to talk to the PC, but the image is not descrambled, then the secret cryptographic function has been changed in some way by Sky and the PC software has to be updated. In this case, you have no problem with the adapter hardware and also the protocol timing of the PC software is ok.
If the decoder quickly deactivates the power supply again for the card after the adapter has been inserted and displays YOUR CARD IS INVALID, then either you have a defect in the adapter, or the timing of the card emulation software on the PC is not correctly adjusted. Changes in the encryption process can not produce this effect.