My understanding of AACS is that old cracked keys can be disabled at the player level via firmware:
QUOTE
"The approach of AACS provisions each individual player with a unique set of decryption keys which are used in a broadcast encryption scheme. This approach allows licensors to "revoke" individual players, or more specifically, the decryption keys associated with the player. Thus, if a given player's keys are compromised by an attacker, the AACS licensing authority can simply revoke those keys in future content, making the keys/player useless for decrypting new titles."