Earlier quoted context omitted.
No, that's all fine for mucking around and developing apps, but actual SGX needs attestation which the emulator can't fake. That's the whole point of SGX.
But how does that remain a secret when the browser can MitM everything between the CPU and the web?
Update on HTML5 Video for Netflix
501–510 of 524 posts
Re: Update on HTML5 Video for Netflix
#502Earlier quoted context omitted.
The CDM is just a plugin - on Firefox it's a Gecko Media Plugin, and it seems easier to implement the GMP API than the NPAPI for Silverlight, since it's a lot more restricted.
Please re-read my post. These steps are not technical but they are very significant. Consider how you would provide this plugin to your users as the author of a new browser? You have to ask the plugin authors for permission to use it. Then consider that you have to persuade Netflix to allow the users of your browser to use their site (without changing user agents). Neither of these steps were required with NPAPI
There is no reason why Netflix would need to do user-agent sniffing - the EME API is built around request access to specific "Key Systems" (eg. Widevine) by well-known-name. If they do user-agent sniffing that's an entirely separate issue, and is just as much as problem in the Silverlight case.
Re: Update on HTML5 Video for Netflix
#503Earlier quoted context omitted.
Because the studios are the ones demanding DRM. I was under the impression that netflix original content is actually far more relaxed on restrictions (I don't recall where I heard this). They don't want DRM necessarily, but if they say "DRM is not an option" then the change of getting major studios on board is 0. And even if you take netflix original content out of the picture, that applies. their "viable business" i…
> Because the studios are the ones demanding DRM. I was under the impression that netflix original content is actually far more relaxed on restrictions Where can you buy it DRM-free?
Re: Update on HTML5 Video for Netflix
#504Earlier quoted context omitted.
Because the studios are the ones demanding DRM. I was under the impression that netflix original content is actually far more relaxed on restrictions (I don't recall where I heard this). They don't want DRM necessarily, but if they say "DRM is not an option" then the change of getting major studios on board is 0. And even if you take netflix original content out of the picture, that applies. their "viable business" i…
Netflix probably also enjoys this, as it presents a barrier to entry. They also don't say anything negative about DRM[1], instead talking about "premium" content. They even go as far as to say: "This is a requirement for any premium subscription video service" -- this is blatantly false, unless you redefine premium to mean "requires DRM", in which case it's circular. Also note the use of "protect" as if it was a posi…
Premium = big name movies
Big name movies = big name studios
Big name studios = full of corporate bigwigs who dont understand that DRM doesn't stop piracy
Re: Update on HTML5 Video for Netflix
#505Earlier quoted context omitted.
We somehow got away from DRM on audio. I was wondering how to do this for video too. What worked for audio, was that you had one vendor (Apple) that had a large enough market share. In order to sell DRMd media that worked on Ipods, the media companies had to sell through Apple. Or they could sell non-DRMd files that would still work on Ipods. They did the calculation, and figured they would make more money going non-…
> For video, people don't download it and take it with them (typically) ...which is crazy, especially for HD video. Why use the bandwidth every time you want to watch something when storage is so much cheaper?
Re: Update on HTML5 Video for Netflix
#506Earlier quoted context omitted.
The CDM is just a plugin - on Firefox it's a Gecko Media Plugin, and it seems easier to implement the GMP API than the NPAPI for Silverlight, since it's a lot more restricted.
Please re-read my post. These steps are not technical but they are very significant. Consider how you would provide this plugin to your users as the author of a new browser? You have to ask the plugin authors for permission to use it. Then consider that you have to persuade Netflix to allow the users of your browser to use their site (without changing user agents). Neither of these steps were required with NPAPI
I don't believe that's true. The plugin is freely available. You just have to write the host.
I don't think Netflix or the rights owners would care since the stream is protected equally in any browser.
Re: Update on HTML5 Video for Netflix
#507Earlier quoted context omitted.
Someone can fork FF though and make it so that the DRM looks like it's there to the websites it visits, but it isn't really there. There's no way DRM can't be removed if I own the device that can play it.
You don't understand how this works. Firefox just provides some APIs that the DRM blob can use. All the decryption is done by the blob, not Firefox. You can reverse engineer the blob itself to an extent, but that will also become impossible with SGX (hence 4k on kabylake + edge only).
Re: Update on HTML5 Video for Netflix
#508Earlier quoted context omitted.
At the time that Firefox started really turning heads, it took an order of magnitude less money to build a better browser. JIT innovations that were once just good research ideas from the Smalltalk world had an open source implementation in Java which then got ported to open source dynamic languages like Python (see polymorphic inline caching & similar techniques). Then Adobe came along and donated a bunch of it's JI…
I encourage you to try out Firefox Nightly. https://wiki.mozilla.org/Electrolysis has made me switch from Chrome to FF as the experience has improved greatly.
Re: Update on HTML5 Video for Netflix
#509Earlier quoted context omitted.
There's a big different between breaking a door down to bypass a lock and pirating a movie via bittorrent though. It doesn't "keep honest people honest" when piracy is so damn easy regardless of what they do with DRM. The point of that phrase is to increase the effort and motivation necessary to commit a crime - in this case, DRM doesn't do that. With or without DRM any idiot can download the latest Popcorn Time fork…
People are pretty wary of using torrents because they're scared of being sued. What DRM on Netflix prevents is you ripping all of the seasons of your favorite shows, with almost no risk of getting caught, and then cancelling your Netflix subscription/sharing the rips with your friend, who is probably not inclined to use torrent sites.
None of these are exactly out-of-the-way high-effort options. There's no increased effort - you just don't bother trying to do so via Netflix. Any of these can be Googled in a few minutes. DRM does nothing to prevent them.
The legal risk you're talking about is just that though - nothing to do with DRM, everything to do with a legal threat. Note that it's more effective than DRM.
Even those who do go out of their way somewhat to improve the piracy experience don't go that far. I wouldn't compare configuring a typical Usenet+Sonarr+CouchPotato+Plex rig to breaking down a door, and that's pretty much the most advanced sort of setup you can get. It may require slightly specialized knowledge, but it doesn't require specialized intent usually. The intent is still the same as that of the casual pirate, it's just a tradeoff of upfront effort for later ease.
Re: Update on HTML5 Video for Netflix
#510Earlier quoted context omitted.
> Really? How would you do that, exactly? Wireless isn't very secure, you're mileage may vary on the encryption mechanism but here is a guide to hacking WPA networks (with WEP it takes seconds): http://www.hackingtutorials.org/wifi-hacking-tutorials/how-t... From there you can try a range of known exploits and gain admin access to a PC, after that it's game over, they can run what they want, when the want. There is n…
WPA2 is reasonably secure and has been the standard for home and business WiFi for years. In any case, merely compromising WiFi won't get you someone's Netflix account. The Netflix data itself, including the credentials, are all encrypted. As for taking over someone's PC, that's far beyond the average pirate, and you're talking about serious criminal offences on top of mere copyright infringement at that point. And e…
WPA2 is reasonably secure, but most home instances aren't set up well. They often have WPS enabled or a guessable password. Plus weaker set ups are still easy to find. Once you're on, redirect Netflix to a site to grab their info, record the stream from a computer outside their house. This is needlessly complex for what is needed, find a compromised Netflix(+email?), record.