Live data from Hacker News

Update on HTML5 Video for Netflix

techblog.netflix.com

401–410 of 524 posts

Re: Update on HTML5 Video for Netflix

#401
post #2

Translation: Netflix successfully lobied DRM into what is supposed to be the OPEN web standard, to the point where even Firefox couldn't afford not to support it. Dark days for the free exchange of information enabled by the web.

Sorry, but as someone who spent nearly a decade founding and building a premium content VOD service, and 6 of those years fighting fiercely against DRM and making great content available without DRM, I have both the knowledge and moral authority to say that you're living in a fantasy world. You might as well say that anyone who is not living an RMS-sanctioned ascetic technology lifestyle is hurting the cause of free…

Any evidence?

Re: Update on HTML5 Video for Netflix

#402

Earlier quoted context omitted.

The major EME providers are PlayReady, which is Microsoft, and Widevine, which is Google. You've already given those two companies pretty broad permission to run binaries on your computer (unless you use Firefox on Linux) so I'm not sure what the incremental security issue really is.

That's quite the invalid assumption. Additionally, if I let Google run binaries on my system in one spot, it does not mean I have given them full access to run binaries elsewhere.

I suppose but when you're already using Chrome using the Widevine CDM isn't a huge difference. When you're using Edge using the PlayReady CDM isn't a huge difference.

I see the general theory of the argument for Opera and especially Firefox but even so, why trust a CDM blob less than any other commercial binary?

Re: Update on HTML5 Video for Netflix

#403

Earlier quoted context omitted.

Of course, but typically quality suffers significantly, so what you get isn't as good as the original and that in itself is a deterrent for a lot of people. Also, some modern watermarking techniques can survive conversions like this, so if anyone is making a habit of recording content from a service using watermarking and redistributing it on a scale that justifies taking serious action, it'll be pretty easy to prove…

> it'll be pretty easy to prove who it was when the lawsuit comes up Perhaps. But this person can always claim that it was done by an external hacker. In fact, it can be done by an "external" hacker, and it will be if these guys are smart.

I'm sure that's an appealing argument if you don't like DRM, but the reality is that someone who ripped content marked to their personal account, which server logs show did access the content in question from their usual IP address etc., is going to have a tough time convincing any court on the balance of probabilities that some unidentified bogeyman actually did it.

Re: Update on HTML5 Video for Netflix

#404
post #378

Earlier quoted context omitted.

Of course, but typically quality suffers significantly, so what you get isn't as good as the original and that in itself is a deterrent for a lot of people. Also, some modern watermarking techniques can survive conversions like this, so if anyone is making a habit of recording content from a service using watermarking and redistributing it on a scale that justifies taking serious action, it'll be pretty easy to prove…

> Also, some modern watermarking techniques can survive conversions like this, so if anyone is making a habit of recording content from a service using watermarking and redistributing it on a scale that justifies taking serious action, it'll be pretty easy to prove who it was when the lawsuit comes up. How many compromised netflix accounts do you think are floating around? At some point the bits have to actually go t…

If a compromised account was used, presumably the server logs will show an unusual access pattern on that account, in particular involving the content that has leaked being accessed from an unusual location. And then presumably the person whose account was used will have to make a convincing case that they shouldn't be held responsible for access using their credentials anyway.

Re: Update on HTML5 Video for Netflix

#405
post #340

Earlier quoted context omitted.

You don't understand how this works. Firefox just provides some APIs that the DRM blob can use. All the decryption is done by the blob, not Firefox. You can reverse engineer the blob itself to an extent, but that will also become impossible with SGX (hence 4k on kabylake + edge only).

What's to stop someone reverse engineering the blob before it's loaded into an SGX enclave? I don't understand it very well so I could be missing something, but wouldn't that at least let someone document how the DRM works even if not running their own implementation?

It would be of no use (and the code can also be encrypted for additional obfuscation). There is no private data in the blob. The blob communicates to mothership once it's safe inside the enclave, and that's when sensitive data is transmitted over an encrypted channel which only the blob can decrypt inside the enclave.

Re: Update on HTML5 Video for Netflix

#406
post #338

Earlier quoted context omitted.

You don't understand how this works. Firefox just provides some APIs that the DRM blob can use. All the decryption is done by the blob, not Firefox. You can reverse engineer the blob itself to an extent, but that will also become impossible with SGX (hence 4k on kabylake + edge only).

Can't you just run in an emulator to get the blob? It looks like qemu was the first to support SGX: https://en.wikipedia.org/wiki/Software_Guard_Extensions

No, that's all fine for mucking around and developing apps, but actual SGX needs attestation which the emulator can't fake. That's the whole point of SGX.

Re: Update on HTML5 Video for Netflix

#407

Earlier quoted context omitted.

Sorry, but as someone who spent nearly a decade founding and building a premium content VOD service, and 6 of those years fighting fiercely against DRM and making great content available without DRM, I have both the knowledge and moral authority to say that you're living in a fantasy world. You might as well say that anyone who is not living an RMS-sanctioned ascetic technology lifestyle is hurting the cause of free…

People have been recording the things they watch since the invention of the VCR. DRM will not have any impact on that. Someone will come along, and make a video-grabbing utility that bypasses the DRM. Also, many of the content is already available via bittorrent. DRM is pointless. But perhaps you are right about "browser vendors refusing to cooperate" not being the best possible approach. However, do you know what is…

Do you lock the front door to your house when you leave?

Re: Update on HTML5 Video for Netflix

#408

Earlier quoted context omitted.

Browser makers have plenty leverage. A Firefox user watching Netflix will, and this is a tautology, be worse off if they cannot continue doing so. That may lead to people switching to other browsers more often than dropping Netflix subscriptions, but the costs for Netflix wouldn't be 0, and may even be substantial considering the population of people using Firefox is self-selected to those placing a high value on ope…

Not only is it not true that Netflix would cave if they didn't have native browser support, but we know it's not true, because Netflix for years relied on plugins to deliver over browsers. Meanwhile, every year that passes, browsers have less leverage as more Netflix subscribers get their content either on set-top boxes or mobile devices (where Netflix has total end-to-end control), and fewer are stuck with browsers.

So the response becomes "so what?". Oh no, proprietary videos will move to proprietary apps, and free videos would remain in the browser. People aren't going to stop using browsers for everything else just because they watch youtube vids on the youtube app. Browsers just aren't going to suffer if proprietary videos move elsewhere - it doesn't matter whether Netflix caves or not. It's not like the rest of the world-wide-web that doesn't rely on DRM'd electronic files is going to follow suit and leave the browser.

Re: Update on HTML5 Video for Netflix

#409

Earlier quoted context omitted.

We somehow got away from DRM on audio. I was wondering how to do this for video too. What worked for audio, was that you had one vendor (Apple) that had a large enough market share. In order to sell DRMd media that worked on Ipods, the media companies had to sell through Apple. Or they could sell non-DRMd files that would still work on Ipods. They did the calculation, and figured they would make more money going non-…

> We somehow got away from DRM on audio. Did we? Look at Apple Music, Spotify, and other subscription music services. They all have DRM.

But music you buy on iTunes is DRM-free. That's a significant step away from DRM.

Re: Update on HTML5 Video for Netflix

#410
post #2

Translation: Netflix successfully lobied DRM into what is supposed to be the OPEN web standard, to the point where even Firefox couldn't afford not to support it. Dark days for the free exchange of information enabled by the web.

Sorry, but as someone who spent nearly a decade founding and building a premium content VOD service, and 6 of those years fighting fiercely against DRM and making great content available without DRM, I have both the knowledge and moral authority to say that you're living in a fantasy world. You might as well say that anyone who is not living an RMS-sanctioned ascetic technology lifestyle is hurting the cause of free…

> all that would mean is that premium content would not be available in browsers

I doubt that. All browsers boycotting DRM freaks would cause more rational heads in the media industry to push against those who insist on DRM, and it could become the tipping point in ridding video of this disease.

They themselves admit, they don't mind it, but don't want to be first to disrupt the status quo. So cowardice of browser makers only advanced the problem. But I agree that Firefox alone couldn't change things. This had to be a combined effort. But others simply either have no guts to stand against DRM, or are themselves dirty with it.

Post reply on HN