Live data from Hacker News

Update on HTML5 Video for Netflix

techblog.netflix.com

181–190 of 524 posts

Re: Update on HTML5 Video for Netflix

#181

Earlier quoted context omitted.

Yes, the world was better when Flash and Silverlight were the media of choice for delivering video.

The problem is DRM has been used for more than digital rights management. We've seen it used to surveill the user and collect information - and restrict actions on the users' computer when it thinks you're doing something illicit (not allowing you to burn things to disc, restricting the ability to screenshot videos, uninstalling/deleting programs, adding rootkits, etc). Far outside the scope of providing authorized a…

The idea that Netflix could tell the movie and TV industries what to do is laughable and woefully ignorant of how those industries work.

Why do you think Netflix et al invests so much in original content ? Because they have zero leverage and are beholden to the whims of Hollywood.

Re: Update on HTML5 Video for Netflix

#182
post #2

Translation: Netflix successfully lobied DRM into what is supposed to be the OPEN web standard, to the point where even Firefox couldn't afford not to support it. Dark days for the free exchange of information enabled by the web.

I don't know if I'm just looking too far into your comment, but I don't see why you're blaming Netflix (or it seems you are) or how you got to them being the bad guys for this? They're not the ones that make the content. If it was up to Netflix, they would just release their shows DRM-free on Netflix for any platform. Unfortunately, that's not how things work and they have to bow to the demands of the content distrib…

> If it was up to Netflix, they would just release their shows DRM-free on Netflix for any platform.

That is SO UNTRUE. Netflix would never want their content to be distributed by anyone other than them, which is the point of DRM; absolute control over distribution, not copy protection.

If Netflix was against DRM, then why release their first party content DRM ensnared?

Re: Update on HTML5 Video for Netflix

#183

Earlier quoted context omitted.

Yes, the world was better when Flash and Silverlight were the media of choice for delivering video.

The problem is DRM has been used for more than digital rights management. We've seen it used to surveill the user and collect information - and restrict actions on the users' computer when it thinks you're doing something illicit (not allowing you to burn things to disc, restricting the ability to screenshot videos, uninstalling/deleting programs, adding rootkits, etc). Far outside the scope of providing authorized a…

> What's terrible is Netflix could have used it's considerable influence to tell _that_ _Industry_ that we won't walk this walk anymore.

Why do you assume they didn't? And if they did and the industry said no, what should they have done? Walk away, lose access to all its content, see a large part of their subscriber base move to different services that do support DRM and therefor get the content and eventually have to start firing employees as their income drops?

Just about any streaming service has this exact same problem. They don't love DRM nor want to support it, it's annoying and cumbersome. But it's how you get access to the content. And unless you can survive purely on your own content you don't really have the option to walk away over your ideals.

If you want DRM out of the system, convince the content/rights holders that DRM isn't in their best interests, i.e they can make more money without it or at the very least won't lose money over not having it. If you're hoping that somehow a significant enough size of the population will boycott it for the industry to change, based on the ideals of the open web and open access, you'll be waiting a long time.

Re: Update on HTML5 Video for Netflix

#184

This is the strategy Microsoft tried over a decade ago with ActiveX. And Firefox saved us. It was starting to be normalized, to have to install ActiveX controls to view certain content. Companies like CinemaNow[1] offered Netflix-like streaming movie services using Microsoft's ActiveX based Janus DRM over a decade ago. Thankfully, the community had more of a backbone back then. Firefox and Linux were not broken becau…

> Now, the same thing is happening again, except that Mozilla is on board with it.

Mozilla doesn't have as much leverage now that a large part of "the community" has abandoned Firefox for Chrome. If you care about these issues, stop and consider the effect of your choice in user agent.

> It's only a matter of time until Firefox is just a wrapper for webkit

It will be a very cold day in hell before this happens. Mozilla is only investing more in its browser engine tech with Quantum and Servo.

Re: Update on HTML5 Video for Netflix

#185

Earlier quoted context omitted.

Yes, the world was better when Flash and Silverlight were the media of choice for delivering video.

The problem is DRM has been used for more than digital rights management. We've seen it used to surveill the user and collect information - and restrict actions on the users' computer when it thinks you're doing something illicit (not allowing you to burn things to disc, restricting the ability to screenshot videos, uninstalling/deleting programs, adding rootkits, etc). Far outside the scope of providing authorized a…

The major EME providers are PlayReady, which is Microsoft, and Widevine, which is Google.

You've already given those two companies pretty broad permission to run binaries on your computer (unless you use Firefox on Linux) so I'm not sure what the incremental security issue really is.

Re: Update on HTML5 Video for Netflix

#186
post #2

Translation: Netflix successfully lobied DRM into what is supposed to be the OPEN web standard, to the point where even Firefox couldn't afford not to support it. Dark days for the free exchange of information enabled by the web.

I don't know if I'm just looking too far into your comment, but I don't see why you're blaming Netflix (or it seems you are) or how you got to them being the bad guys for this? They're not the ones that make the content. If it was up to Netflix, they would just release their shows DRM-free on Netflix for any platform. Unfortunately, that's not how things work and they have to bow to the demands of the content distrib…

Wait, who is forcing Netflix to use DRM for Netflix-produced content?

Re: Update on HTML5 Video for Netflix

#187
post #2

Translation: Netflix successfully lobied DRM into what is supposed to be the OPEN web standard, to the point where even Firefox couldn't afford not to support it. Dark days for the free exchange of information enabled by the web.

I don't know if I'm just looking too far into your comment, but I don't see why you're blaming Netflix (or it seems you are) or how you got to them being the bad guys for this? They're not the ones that make the content. If it was up to Netflix, they would just release their shows DRM-free on Netflix for any platform. Unfortunately, that's not how things work and they have to bow to the demands of the content distrib…

"I don't know if I'm just looking too far into your comment, but I don't see why you're blaming Netflix (or it seems you are) or how you got to them being the bad guys for this? They're not the ones that make the content. If it was up to Netflix, they would just release their shows DRM-free on Netflix for any platform. Unfortunately, that's not how things work and they have to bow to the demands of the content distributors (not creators, like some people have stated in other comments)."

We did a book study on a book called Clean Code where I work, and I reminded of a similar situation that the book explains when describing why we all write dirty and bad code.

Why do we write bad code? Because our stakeholders and our product owners require it. Well, they push deadlines and expectations on us that mean we have to cut corners to make their promises become reality within the unrealistic time provided.

But if you ask the stakeholder why they pust that on you, the stakeholder will say "well, it's the client". Or they'll say "marketing made a promise to the client".

It's always upstream. There's always an upstream concern.

In the book they talk about making a stand, as a developer. That you have a responsibility to explain to your stakeholders and the people above you that doing something the RIGHT way is worth it. That you are the subject matter expert, that it is your responsibility to raise these concerns and thus your responsibility to write good code.

Netflix can pass the buck. "We do what we have to".

But they have a responsibility as one of the premiere web companies to do more than pass the buck.

A Good Internet doesn't happen accidentally, and it doesn't happen when stakeholders pass the buck. It happens when people make a stand for what's right and operate according to their values.

So yes, it is Netflix's responsibility not to bend Mozilla into accepting a Studio's IP demands, but to bend the Studio into accepting humanity's internet demands.

Why do we assume that Netflix can persuade Mozilla, but not a rightsholder?

Re: Update on HTML5 Video for Netflix

#188
post #53

Earlier quoted context omitted.

You're not getting EME extensions from Apple, you're getting them from the third-party that developed the extensions. You can count on terrible security vulnerabilities being found in these. Movies aren't important. Netflix isn't important. The open web, the ideology (or as you put it pejoratively, "purity") behind it, is important.

What do you mean by "open web"? From the beginning or near the beginning it was possible and not uncommon to put things on the web with restricted access. The HTTP protocol itself supports a couple of login mechanisms which were intended to be used to restrict access to content, and these have been there since at least as early as 1996.

The OP is using the phrase "open web" in the standard way.

Re: Update on HTML5 Video for Netflix

#189

Earlier quoted context omitted.

Yes, the world was better when Flash and Silverlight were the media of choice for delivering video.

The thing is that there is (for all intents and purposes) no difference between ECE and plugins. Actually, ECE is a plugin. The only difference is that it helps web-designers switch plugin providers. That's it. No more security. No more standardization. As a user, you still depend on the goodwill of the ECE provider throw you a bone. If you use a slightly niche OS (say, OpenBSD on ARM), you're out of luck. If Adobe d…

I completely understand and sympathize with your point, however this:

"If you use a slightly niche OS (say, OpenBSD on ARM)"

Is rather hilarious - calling OpenBSD on ARM a 'slightly niche' OS in the context of 'operating systems people use to watch video on the web' is rather ambitious, don't you think? OpenBSD on ARM would have to increase it's user base in this arena by a couple orders of magnitude to elevate itself to 'slightly niche'....

Re: Update on HTML5 Video for Netflix

#190
post #57

Earlier quoted context omitted.

Meaning anyone can implement the technology that can show a web page. You can't show Netflix's web page, unless they preapprove of your DRM.

And that's different from a web page that won't allow you to access it without a password, how? In both cases, a business decision by a third party limits what you're able to access. I understand that you don't want to run code Netflix approves of and that you're not permitted to read in its original source form. And that's fine, a good reason not to subscribe to Netflix. But how is that any more an offense to "the o…

What you're missing is that passwords don't require blobs. The ContentDecryptionModules used for DRM on the Web are blobs.

For a browser to run a blob, there needs to be an interface between the browser and the blob. Flash and Silverlight blobs used a standard interface: NPAPI. Any browser implementing NPAPI could run the blobs (assuming the blob was compatible with the host OS).

CDMs have no such standard browser/blob interface (note that EME relates only to the Javascript environment not the actual browser code). In fact, the only browsers able to run these blobs are the ones that the CDM provider 'trusts' and is willing to provide proprietary information to in order for browser developers to get their blob working. Your independent Firefox fork will almost certainly never be able to support any major CDM; the CDM provider doesn't trust, nor care about your browser.

Therefore, CDM providers arbitrarily _select_ which browsers can have access to their Web content. This is unprecedented. Content on the Web, in whatever form, has always been accessible by _any_ browser; it was merely a matter of that browser implementing the necessary standards. This is the idea of the open Web. CDMs are literally the opposite idea.

Post reply on HN