← Back to context

Comment by codebje

13 hours ago

If the phone support issued the decrypt code, you could just replay that same code for every CD stamped from the same master.

If phone support issued an encrypted decrypt code that could only be used with your challenge code to decrypt the decrypt code, replay wouldn't be as trivial.

Every CD is identical, so no matter how iD went about this there's only ever one decryption key (per title, I assume) and those keys must either have been encoded in iD support's response, or already stored on the CD. TestDrive sold iD on the notion that the process was too hard for hacker groups to reverse engineer, and it wasn't.

There was some replay protection as described in the article, but in the end the system was flawed enough that it didn't matter.