Nagravision confirms smartcard compromise

Status
Please reply by conversation.

HokieEngineer

Proud Staff Member
Original poster
Oct 13, 2003
2,289
0
http://www.infosat.lu/Meldungen/index.php?msgID=17140

The "Aladin" system is the guts of Nagravision2...

13.09.2005


by Chris Forrester

Encryption specialist Nagra Kudelski says its 'Aladin' smart card version has been compromised. There have been widespread reports of a hack, especially in Spain where it is the card of choice for Sogecable's DTH service Digital+. CEO Andre Kudeski confirmed two weeks ago that Aladin represents some 70% of its business, as of June 2005. The company's biggest customer is Echostar's DiSH DTH system in the US, while Canada's Bell ExpressVu is another major. Between them they have taken some 11.7m cards.

A report from investment bankers Credit Agricole Cheuvreux talked last week of Kudelski planning electronic counter measures to cure the hack: "It is still very possible that the hack will not stand up to the electronic countermeasures," said the bank's note. However, the bank warns of several negative implications for Kudelski, not least the firm's basic reputation given that much has been staked on this iteration, as well as churn amongst clients with players like NTL and Telewest planning on switching to the system.

"Under Kudelski's new rental model," said the bank report, "the cost of swap-outs, which would be automatically triggered by piracy, is borne by Kudelski. We estimate that around 11-12 million cards are currently on the rental model (including the Premiere and Canal+ platforms)." These direct costs could amount to SFr50m, suggests the bank.

A Nagra source, speaking at IBC, said the original 'Aladin' card was issued in 2000, and was now in its 5th year of use for some clients. "We are already well advanced with swapping out and upgrading that card with only a few hundred thousand cards to go. This was always planned to be completed by about the end of this year." Our source said that 'Aladin' was a suite of products on which there had been a "small" problem. "This is never a small problem for our clients, however. We spoke to our customers in a timely fashion, and initiated our upgrade plan."
 
Interesting. A hacker or virus writer can be found responsible for all damages they cause including extra man hours, and other costs related to fixing the issue.

But a person that discovers a flaw or security hole in a system including encryption system isn't responsible for the costs to fix it. This is because they coudl be trying to make the system better by simply pointing out the flaws.

As this points out though, simply pointing out this flaw will cost milliions of dollars to fix. So do the hacker pay for it if they aren't exployting it?

Bottom line is I think we will all end up paying for this eventually somehow. Hm, maybe they will decide not to fix it and live with any losses as maybe that would cost less...

I hate paying more to play fair when others pay less to play unfairly. Don't reward those that break the law or cheat the system.
 
the big questions is how long will it last? hopefully for at least a few weeks so the FTA receivers can go back down in price. i keep telling myself i am going to get one and was just about to until the prices went up.
 
UIf it stays down for 2 weeks I will be happy. :) Imagine if its down for two weeks then hackers get in again for a week and dish shuts them dfown for another 2 weeks. A lot of folks would probably give up hacking and to me that would be a GREAT thing.

There is a lot on Free To Air to watch. In fact lately I find myself screwing around with my FTA stuff more then my Dish equipment.
 
NO HACK TALK ALLOWED>> WHOOPS (JOKING) I too am glad that dish has finally fixed this.. I just hope its a perminate thing.. I allready pay too much for programming.. It sucks at the same time too because I just put my fortec star FS 5900 up on ebay..
 
Scott Greczkowski said:
In fact lately I find myself screwing around with my FTA stuff more then my Dish equipment.

I hear ya. The only thing I wish for is an HD version of a FTA box. Then of course I can start bitchin about the lack of HD FTA channels :)
 
There is just get your self a FTA PC card. :)

I was watching PBS HD the other night, there was a great Lindsey Buckingham concert on. :)
 
korsjs said:
the big questions is how long will it last? hopefully for at least a few weeks so the FTA receivers can go back down in price. i keep telling myself i am going to get one and was just about to until the prices went up.

Hmm, about 24 hours hehe. Oh well.

Scott, what software are you using with PBS-HD? Thats my next goal.. Then like whoever else said it, I will bitch about not enough FTA HD channels like dish HD channels :D
 
[emerges from lurk mode]

It was more like two days instead of two weeks. Seems like the pirate boats have already set sail again and the compromised FTA's are back up. As for that "news story" there's question of it's legitimacy. I've seen it posted on several other boards and most people seem to doubt that it's a real story. Of course, we all know the truth anyway. I have a feeling this little cat and mouse game between Charlie and the hackers will be going on for a while. *waiting for his subscription cost to go up*

[returns to lurk mode]
 
Status
Please reply by conversation.

Users Who Are Viewing This Thread (Total: 0, Members: 0, Guests: 0)

Who Read This Thread (Total Members: 1)