Hacker News new | ask | show | jobs
by repelsteeltje 778 days ago
Yup.

Basically the means to forge an authenticated cookie.

[Update]

It's a bit more subtle: Having the keys to forge a license request and decrypt server response allows you to emmulate or re-implement a DRM client.

Because the server is oblivious to this fake, it will respond as though it's taking to a genuine "secure" client thereby ultimately exposing the content decryption key.