SageTV Community  

Go Back   SageTV Community > General Discussion > General Discussion
Forum Rules FAQs Community Downloads Today's Posts Search

Notices

General Discussion General discussion about SageTV and related companies, products, and technologies.

Reply
 
Thread Tools Search this Thread Display Modes
  #921  
Old 06-25-2011, 01:06 PM
SWKerr SWKerr is offline
Sage Icon
 
Join Date: Jun 2008
Posts: 1,178
Quote:
Originally Posted by Narflex View Post
Don't waste your time. You won't be able to get it to work. Even if you had the identical hardware manufactured and put identical firmware on it; it still would not work. We're smarter than that. (just trying to save people from spending a lot of time trying to get that to work and failing)
You know they will just take this as a challenge now don't you.
__________________

Retired SageTV in favor of Plex\Emby and YouTubeTV.
Reply With Quote
  #922  
Old 06-25-2011, 04:54 PM
pez's Avatar
pez pez is offline
Sage Advanced User
 
Join Date: Aug 2004
Location: Arizona
Posts: 165
Quote:
Originally Posted by SWKerr View Post
You know they will just take this as a challenge now don't you.
The sigma SMP8654 (used in the HD300) has a dedicated security process that appears to sit behind a firewall. It also appears to have secure storage for keys (and possibly the program it runs) that only it can access. It is the traffic cop for boot loading (fw updates). The secure storage contains the keys to encrypt/decrypt and the public key of sagetv for authentication.

If Jeff is this sure, i would suspect that the sage servers authenticate firmware specific to each device. So unless you can get the keys from sage and also from the chip, that security process is not going to allow it to run. It shouldn't even allow it do be written to flash.

MS has a decent enough article on secure download boot loader here.
Reply With Quote
  #923  
Old 06-25-2011, 06:28 PM
wayner wayner is offline
SageTVaholic
 
Join Date: Jan 2008
Location: Toronto, ON
Posts: 7,491
Quote:
Originally Posted by MitchSchaft View Post
What a bunch of sell-outs. We are screwed, folks. Nothing good can possible come from this except for the owner making a lot of money from Google.
He could also make some additional pocket money selling remaining HD-300s at something north of $300 on eBay.
__________________
New Server - Sage9 on unRAID 2xHD-PVR, HDHR for OTA
Old Server - Sage7 on Win7Pro-i660CPU with 4.6TB, HD-PVR, HDHR OTA, HVR-1850 OTA
Clients - 2xHD-300, 8xHD-200 Extenders, Client+2xPlaceshifter and a WHS which acts as a backup Sage server
Reply With Quote
  #924  
Old 06-25-2011, 07:30 PM
Evil_Attorney's Avatar
Evil_Attorney Evil_Attorney is offline
Sage Expert
 
Join Date: Sep 2004
Posts: 632
Quote:
Originally Posted by pez View Post
The sigma SMP8654 (used in the HD300) has a dedicated security process that appears to sit behind a firewall. It also appears to have secure storage for keys (and possibly the program it runs) that only it can access. It is the traffic cop for boot loading (fw updates). The secure storage contains the keys to encrypt/decrypt and the public key of sagetv for authentication.

If Jeff is this sure, i would suspect that the sage servers authenticate firmware specific to each device. So unless you can get the keys from sage and also from the chip, that security process is not going to allow it to run. It shouldn't even allow it do be written to flash.

MS has a decent enough article on secure download boot loader here.
But is this the same security mechanism that the WDTV Live Plus uses? I think the wdlxtv folks were able to break it.
Reply With Quote
  #925  
Old 06-25-2011, 10:44 PM
pez's Avatar
pez pez is offline
Sage Advanced User
 
Join Date: Aug 2004
Location: Arizona
Posts: 165
Quote:
Originally Posted by Evil_Attorney View Post
But is this the same security mechanism that the WDTV Live Plus uses? I think the wdlxtv folks were able to break it.
The features are there in the chip. WD does not need to use those features or they only half heartedly used them on the WDTV. Jeff probably used them fully because he had more to protect.

If you're more interested in security look up a guy named Bruce Schneier. He's written a few books on the subject.

Now I don't know what is actually in the 8654 as i couldn't find the spec. But it is an older chip. So if it doesn't implement SHA256, it may be vulnerable. But it would be unlikely that it could be exploited to create a usable piece of firmware that would authenticate correctly. And even then I believe you would have to break it for each device separately.

The only hope is to find a hole in the implementation because there isn't one in the method (that I know of).
Reply With Quote
  #926  
Old 06-26-2011, 06:44 AM
jptheripper jptheripper is offline
Sage Fanatic
 
Join Date: Dec 2007
Location: Florida
Posts: 956
Since the wdtv live plus is already hacked, cheap (<$90) and runs linux, wouldnt it make more sense to try to run the linux client on it?
__________________
Gigabyte GA-MA770-DS3/4gb DDR2/AMD Phenom 955 3.2ghz Quad Core
Windows 7 64bit Home Premium
Hauppauge 1600/1850/2250/colossus/2650(CableCard 2 tuner)
8tb RAID5 storage/media/other &3tb RAID5 backup storage on a HighPoint RocketRaid 2680
1tb 3 disk Recording Pool
all in a beautiful Antec 1200
SageMyMovies/Comskip/PlayON/SageDCT/SRE
HD100/HD300 extenders
Reply With Quote
  #927  
Old 06-26-2011, 07:27 AM
ThePaladinTech's Avatar
ThePaladinTech ThePaladinTech is offline
Sage Aficionado
 
Join Date: Oct 2007
Location: South Lyon, MI
Posts: 452
And wouldn't it make more sense to discuss this on this thread?
http://forums.sagetv.com/forums/showthread.php?t=56134


We don't know all the details about how people are hacking the WD unit - perhaps they are only modding the existing code or something that allows the security to 'pass' , or perhaps WD didn't implement it as securely as mentioned above.

Does anyone think we could get the linux placeshifter client going on a WD live? and from my questions in other topics, would it even be worth it?
__________________
(current) SageServer: SageTV Open Source V9 - Virtual Ubuntu on Win10 HyperV MSI 970A-G46, AMD FX-8370 , SD Prime via OpenDCT, Donater ComSkip
Clients: HD-200, Nexus Player w/ Android miniclient
Storage: "nas" 16 drive Win10 w/ DrivePool running Plex, Emby, & SD PVR
Retired - Hava, MediaMVP, HD-100, HD-PVR, HVR-2250, Ceton InfiniTV4, Original (white) HDHomeRun Died - HD-100, HD-300

Last edited by ThePaladinTech; 06-26-2011 at 07:46 AM.
Reply With Quote
  #928  
Old 06-26-2011, 09:19 AM
drewg drewg is offline
Sage Icon
 
Join Date: Aug 2007
Location: Richmond, VA
Posts: 1,042
Quote:
Originally Posted by ThePaladinTech View Post
Does anyone think we could get the linux placeshifter client going on a WD live? and from my questions in other topics, would it even be worth it?
Not the "normal" miniclient, as it is for a totally different CPU arch (x86 vs mips). The only thing that has a hope to run is the client from the hd300, but Jeff says this would be impossible..

Drew
__________________
Server HW: AMD Ryzen Threadripper 2990WX 32-Core
Server SW: FreeBSD-current, ZFS, linux-oracle-jdk1.8.0, sagetv-server_9.2.2_amd64
Tuner HW: HDHR
Client: Nvidia Shield (HD300, HD100 in storage)
Reply With Quote
  #929  
Old 06-26-2011, 09:48 PM
reggie14 reggie14 is offline
SageTVaholic
 
Join Date: Aug 2003
Location: Maryland
Posts: 2,760
Quote:
Originally Posted by pez View Post
Now I don't know what is actually in the 8654 as i couldn't find the spec. But it is an older chip. So if it doesn't implement SHA256, it may be vulnerable. But it would be unlikely that it could be exploited to create a usable piece of firmware that would authenticate correctly. And even then I believe you would have to break it for each device separately.
I don' t know what security features are present in the Sigma chipsets, but I can tell you the crypto algorithms are unlikely to the weak link. You could do digital signatures (or just hashes) with SHA-1 without a practical problem- heck, you could probably do signatures with MD5 without a problem.

Generally speaking, a cryptographic exploit along the lines that you seem to be describing would require a second preimage attack on the hash function. SHA-1, MD5, even MD4 are all relatively safe if all you need is preimage resistance. Collision resistance is much tougher to get.
Reply With Quote
  #930  
Old 06-27-2011, 05:29 AM
lfilomeno lfilomeno is offline
Sage Advanced User
 
Join Date: Jan 2008
Posts: 210
Quote:
Originally Posted by wayner View Post
He could also make some additional pocket money selling remaining HD-300s at something north of $300 on eBay.
That is exactly my train of thought; If it is going to be difficult to port-over the extender firmware to other available boxes, then why not sell the extender stock they have available? The same way they make the Sage "exe's" available to license users should be done with the extenders! C'mmon Jeff!

Last edited by lfilomeno; 06-27-2011 at 05:41 AM.
Reply With Quote
  #931  
Old 06-27-2011, 05:31 AM
lfilomeno lfilomeno is offline
Sage Advanced User
 
Join Date: Jan 2008
Posts: 210
Quote:
Originally Posted by Narflex View Post
Don't waste your time. You won't be able to get it to work. Even if you had the identical hardware manufactured and put identical firmware on it; it still would not work. We're smarter than that. (just trying to save people from spending a lot of time trying to get that to work and failing)
Jeff,

Save us the grief then! Give us access to purchase the extenders!
Reply With Quote
  #932  
Old 06-27-2011, 06:34 AM
n9cqs n9cqs is offline
Sage User
 
Join Date: Apr 2007
Posts: 69
Quote:
Originally Posted by lfilomeno View Post
Jeff,

Save us the grief then! Give us access to purchase the extenders!
I second that. An "amnesty" period to purchase extenders, licenses and such is not going to cut into Google's purchase one bit. My guess is that the Google use of Sage (whatever it may be) will appeal to a very different audience than the current SageTV base.
Reply With Quote
  #933  
Old 06-27-2011, 06:34 AM
BobPhoenix BobPhoenix is offline
SageTVaholic
 
Join Date: Oct 2004
Posts: 3,152
I think they need what they have for warranty replacements. They might sell the remaining stock in a year but not before.
Reply With Quote
  #934  
Old 06-27-2011, 07:04 AM
frontlinegeek frontlinegeek is offline
Sage Advanced User
 
Join Date: Sep 2007
Location: NB, Canada
Posts: 184
Quote:
Originally Posted by BobPhoenix View Post
I think they need what they have for warranty replacements. They might sell the remaining stock in a year but not before.
That may be true to an extend but they must have had to order enough to cover what sales they originally forecast. Release those for purchase by us that want them.

Or a better idea for them would be to put up a survey that requires the use of something unique to vote with so that we can indicate to them how many HD300s we want to buy. I want one more but procrastinated one week too long.
__________________
My contribution to the internet: https://www.youtube.com/user/frontlinegeek
Reply With Quote
  #935  
Old 06-27-2011, 07:47 AM
lfilomeno lfilomeno is offline
Sage Advanced User
 
Join Date: Jan 2008
Posts: 210
Quote:
Originally Posted by frontlinegeek View Post
That may be true to an extend but they must have had to order enough to cover what sales they originally forecast. Release those for purchase by us that want them.

Or a better idea for them would be to put up a survey that requires the use of something unique to vote with so that we can indicate to them how many HD300s we want to buy. I want one more but procrastinated one week too long.
Agreed. In the mean time, I have a mini-itx board that will serve as a client for the time being. I have a client license that I used for testing purposes so it is time for it to joint the Sage network!
Reply With Quote
  #936  
Old 06-27-2011, 08:43 AM
BobPhoenix BobPhoenix is offline
SageTVaholic
 
Join Date: Oct 2004
Posts: 3,152
Quote:
Originally Posted by frontlinegeek View Post
That may be true to an extend but they must have had to order enough to cover what sales they originally forecast. Release those for purchase by us that want them.
Correct but that is what they will use over the next year to fulfill waranty replacements. They don't want to have to order ANY more just to statisfy the waranty. Once the year has passed and they have some available they can sell them but not before.

Quote:
Or a better idea for them would be to put up a survey that requires the use of something unique to vote with so that we can indicate to them how many HD300s we want to buy. I want one more but procrastinated one week too long.
I want to replace the 3 HD200s I currently have but I was waiting until next Tax Refund time to do it. I thought HD400s might be out by then and I would be skipping the HD300s completely. Oh well.
Reply With Quote
  #937  
Old 06-27-2011, 09:49 AM
can3gxw can3gxw is offline
Sage Advanced User
 
Join Date: Sep 2008
Location: NB, Canada
Posts: 219
Quote:
Originally Posted by BobPhoenix View Post
Correct but that is what they will use over the next year to fulfill waranty replacements.
What happens when the next year passes, warranty replacements are fulfilled, and then they start selling the remainder off? They STILL need to be able to provide a FULL warranty on those units since they are brand new. That doesn't make any sense.

The "real" sense would be to unload all the remaining HD300 stock to start (because you KNOW they would sell out "instantly"), and then get that one year ticking and put behind them. No warranty replacements, but rather repair, patch, duct tape them until the end of the one year warranty.

Then they can move on knowing that there is NOTHING outstanding that could possibly need warranty service.
__________________
Gregg
Reply With Quote
  #938  
Old 06-27-2011, 10:30 AM
joematt's Avatar
joematt joematt is offline
Sage Advanced User
 
Join Date: Apr 2004
Location: Starks, LA
Posts: 100
People! Just ass-u-me that there will be no more sales of anything and get on with your life.
__________________
Mine's bigger then yours!
Reply With Quote
  #939  
Old 06-27-2011, 12:15 PM
Fuzzy's Avatar
Fuzzy Fuzzy is offline
SageTVaholic
 
Join Date: Sep 2005
Location: Jurupa Valley, CA
Posts: 9,957
Quote:
Originally Posted by can3gxw View Post
What happens when the next year passes, warranty replacements are fulfilled, and then they start selling the remainder off? They STILL need to be able to provide a FULL warranty on those units since they are brand new. That doesn't make any sense.
After the year, they will be liquidated as-is, no warranty included. This is not uncommon practice. Google/sage will not sell them directly, they will go off to some 3rd party liquidation warehouse to be sold out, probably for much less than the original list price.
__________________
Buy Fuzzy a beer! (Fuzzy likes beer)

unRAID Server: i7-6700, 32GB RAM, Dual 128GB SSD cache and 13TB pool, with SageTVv9, openDCT, Logitech Media Server and Plex Media Server each in Dockers.
Sources: HRHR Prime with Charter CableCard. HDHR-US for OTA.
Primary Client: HD-300 through XBoxOne in Living Room, Samsung HLT-6189S
Other Clients: Mi Box in Master Bedroom, HD-200 in kids room
Reply With Quote
  #940  
Old 06-27-2011, 12:26 PM
Flash69 Flash69 is offline
Sage Advanced User
 
Join Date: Dec 2007
Posts: 102
Quote:
Originally Posted by joematt View Post
People! Just ass-u-me that there will be no more sales of anything and get on with your life.
I understand what you are saying however that does not help the people that need more extenders. I was about to order more extenders since I need 3 more. I was hoping for a new version soon; so I waited on ordering them.

This caught us ALL off guard and people are not happy about being abandoned.

The extender was the main reason I stayed with SageTV. I compared the major players at the time and found I liked SageTV. I built a dedicated server and started with a single client on my workstation. I started putting together a plan to build clients when the extender came out. It was perfect. So perfect I see building/using PC clients as a waste of time and resources.
You have to spend too much money to even get close to the usefulness of the extender.

I honestly had no idea SageTV would go anywhere. I guess I was living with my head in the sand... LOL

Oh well, not that it matters now...Google TV is testing 'fishtank' box already anyway...
__________________
Flash
Sage Server: Gigabyte P35-DS3L, Core2Duo E6300 v1, 4GB, XP Pro SP2, Radeon X1550, Sage 6.6.2, 2 HD-PVR, 2 HDHR 4xOTA, Hauppauge HVR-1600 1xOTA and 2xDish ViP211 Receiver, USB-UIRT, 3x640GB WD6400AAKS, headless
Sage Client: 1xSage HD200 HD Extender
Sage Client: 2xSage STX-HD100 HD Extender
Reply With Quote
Reply

Tags
acquisition, beer, google, googletv


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
SageTV 3rd Party Devs & Google Acquisition Brent The SageTV Community 34 06-28-2011 10:17 AM
SageTV Acquired by Google-More info on geektonic.com Narflex Announcements 1 06-21-2011 09:40 PM
Google Music Search - Possible Use in SageTV? Brent General Discussion 4 06-13-2010 02:55 PM
Google Desktop Slowing SageTV? abexman SageTV Software 0 02-10-2007 05:36 AM


All times are GMT -6. The time now is 06:38 AM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2023, vBulletin Solutions Inc.
Copyright 2003-2005 SageTV, LLC. All rights reserved.