Ishihara-san, MMC members,

We are actively reviewing these changes.  Of particular concern is the
following two items:

1) Allowing drives to support only a single AGID.  For DVD-ROM, this was
not noticable due to the exclusive and read-only nature of the media.
For AACS, this may become a problem due to the read-write nature of the
media.  This requires some additional study here within Microsoft, to
ensure the best customer experience is possible.

2) Preventing reads of the data.  I understand that this modification
was requested to prevent a title key attack, where the title key for an
encrypted film is provided via unauthorized means to decrypt the file.
I initially (in the first two hours or so) did not see significant
difficulty with this, but further thought has brought up some concerns:

This modification seems to add drive cost and limit reading speed due to
the necessary application of "encryption" of portions of sectors.  This
modification of sector data is further difficult as it will cause many
automated drive integrity tools(*) to incorrectly flag errors on these
sectors.  This modification will restrict the capability of backing up
and restoring the encrypted movie content, further restricting customer

I would like to challenge the benefit of encrypting the "movie" (or
other protected content -- but I will use the term movie) sectors.  For
example, if a title key for a movie has been found in the clear, then
the entirety of the contents of the movie are also, by definition,
available in the clear.  Once the content has become available on the
"dark net", then it is available.  Preventing the encrypted movie
sectors from being read from the media does not seem to add protection,
but simply adds another restriction for legitimate users of the movie.

With the previous versions of the specification, users would be able to
move their encrypted movies via defrag operations, recovery would be
possible if a sector was going bad without special "AACS-aware"
utilities, etc.  With the current modifications, users are now
prohibited from using many common tools on their movies (and indeed the
entire media) due to these restrictions.

It is possible that these changes will be acceptable, but significant
additional thought is required to be sure.  It is also possible that
another method that still allows the customer scenarios (and does not
put additional overhead on the file system, os, and other utilities)
will be possible.  As you know, MMC requires proposals to be provided
well in advance of the meetings in order to enable proper consideration
of the changes for all parties, as well as enable companies to consider
if attendance at a particular meeting is critical.

I would like to suggest that voting for the addition of these changes
into the MMC (and Mt. Fuji) specifications be delayed, to allow the
extra time necessary to fully understand the impact of these changes.


Henry Gabryjelski

(*) Driver verifier (verifier.exe) in Windows has such a tool that any
client may enable.  Also, some bus trace tools also enable this advanced
functionality for read-only devices.


