On Windows, recover the Adobe ADEPT user key from an installed/activated
Adobe Digital Editions and use it automatically, so ADEPT EPUBs decrypt
with no --key argument. Ported from adobekey.py:
* Build the DPAPI entropy byte-for-byte: system-volume serial number,
CPUID leaf-0 vendor (EBX|EDX|ECX) and leaf-1 signature, and the ADE
username, packed as ">I12s3s13s".
* CryptUnprotectData (DPAPI) recovers the key-encryption-key from the
HKCU\Software\Adobe\Adept\Device "key" value, then each per-credential
privateLicenseKey under ...\Activation is AES-128-CBC decrypted and the
DER RSA key taken from byte 26 onward.
Decryption now lazily auto-extracts and retries when no supplied key fits,
and newly found keys are written back to the TOML config so later runs are
offline. Uses the `windows` (DPAPI/volume info) and `winreg` crates behind
cfg(windows); pure-Rust crypto unchanged.
Verified end-to-end on a real ADEPT EPUB: the key was extracted from the
local ADE and the book decrypted to a valid, DRM-free EPUB (rights.xml and
encryption.xml removed, content readable).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
DRMLibre is a standalone, single-binary Rust CLI that removes DRM from
Amazon Kindle and Adobe Digital Editions ebooks. The decryption logic is
ported from DeDRM_tools (GPLv3); this project is GPL-3.0-or-later.
This commit covers the first three milestones of the plan:
* Phase 0 - workspace scaffold (drmlibre-core engine + drmlibre-cli),
native TOML config, magic-byte/zip-content format detection, and the
remove/passhash/config CLI surface with atomic output handling.
* Phase 1 - Adobe ADEPT EPUB: RSA (PKCS#1 v1.5) and PassHash book-key
unwrap, RMSDK>=10 hardening, AES-128-CBC content decryption, and IETF/
Adobe font de-obfuscation. Verified end-to-end with a real RSA key.
* Phase 2 - Kindle MOBI/AZW/AZW3: PC1 cipher, type-1 and type-2 DRM,
serial->PID derivation, EXTH header patches, and trailing-data handling.
Verified end-to-end and against the upstream golden vectors.
All crypto is pure Rust (RustCrypto), so the release binary has no
third-party runtime dependencies. 42 tests pass; clippy and rustfmt clean.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>