Live data from Hacker News

Update on HTML5 Video for Netflix

techblog.netflix.com

501–510 of 524 posts

Re: Update on HTML5 Video for Netflix

#501
post #463

Earlier quoted context omitted.

No, that's all fine for mucking around and developing apps, but actual SGX needs attestation which the emulator can't fake. That's the whole point of SGX.

But how does that remain a secret when the browser can MitM everything between the CPU and the web?

There is a hardware-based secret which emulators cannot obtain or fake. That breaks the attestation chain. At the heart of it, there is some stuff that only your processor can do and not you the user even though you may have full control over the operating system. The OS is in SGX's threat model.

Re: Update on HTML5 Video for Netflix

#502
post #346

Earlier quoted context omitted.

The CDM is just a plugin - on Firefox it's a Gecko Media Plugin, and it seems easier to implement the GMP API than the NPAPI for Silverlight, since it's a lot more restricted.

Please re-read my post. These steps are not technical but they are very significant. Consider how you would provide this plugin to your users as the author of a new browser? You have to ask the plugin authors for permission to use it. Then consider that you have to persuade Netflix to allow the users of your browser to use their site (without changing user agents). Neither of these steps were required with NPAPI

Your browser can just download the plugin from Google the same way Firefox does. No permission required since you're not distributing it yourself. This is no different than the case of the Silverlight plugin.

There is no reason why Netflix would need to do user-agent sniffing - the EME API is built around request access to specific "Key Systems" (eg. Widevine) by well-known-name. If they do user-agent sniffing that's an entirely separate issue, and is just as much as problem in the Silverlight case.

Re: Update on HTML5 Video for Netflix

#503
post #95
post #46

Earlier quoted context omitted.

Because the studios are the ones demanding DRM. I was under the impression that netflix original content is actually far more relaxed on restrictions (I don't recall where I heard this). They don't want DRM necessarily, but if they say "DRM is not an option" then the change of getting major studios on board is 0. And even if you take netflix original content out of the picture, that applies. their "viable business" i…

> Because the studios are the ones demanding DRM. I was under the impression that netflix original content is actually far more relaxed on restrictions Where can you buy it DRM-free?

I honestly don't remember where I had seen/heard this. Which admittedly makes my claim far less credible. But it was something along the lines of being able to play some netflix content on some player without DRM being applied to it. DRM would be something they use because they want to, not because it's part of their contract with themselves.

Re: Update on HTML5 Video for Netflix

#504
post #46

Earlier quoted context omitted.

Because the studios are the ones demanding DRM. I was under the impression that netflix original content is actually far more relaxed on restrictions (I don't recall where I heard this). They don't want DRM necessarily, but if they say "DRM is not an option" then the change of getting major studios on board is 0. And even if you take netflix original content out of the picture, that applies. their "viable business" i…

Netflix probably also enjoys this, as it presents a barrier to entry. They also don't say anything negative about DRM[1], instead talking about "premium" content. They even go as far as to say: "This is a requirement for any premium subscription video service" -- this is blatantly false, unless you redefine premium to mean "requires DRM", in which case it's circular. Also note the use of "protect" as if it was a posi…

perhaps "This is a requirement for any premium subscription video service that wants to interact with popular studios because if you don't interact with popular studios people don't view your service as premium."

Premium = big name movies

Big name movies = big name studios

Big name studios = full of corporate bigwigs who dont understand that DRM doesn't stop piracy

Re: Update on HTML5 Video for Netflix

#505
post #396

Earlier quoted context omitted.

We somehow got away from DRM on audio. I was wondering how to do this for video too. What worked for audio, was that you had one vendor (Apple) that had a large enough market share. In order to sell DRMd media that worked on Ipods, the media companies had to sell through Apple. Or they could sell non-DRMd files that would still work on Ipods. They did the calculation, and figured they would make more money going non-…

> For video, people don't download it and take it with them (typically) ...which is crazy, especially for HD video. Why use the bandwidth every time you want to watch something when storage is so much cheaper?

People usually watch video once, but listen to songs multiple times.

Re: Update on HTML5 Video for Netflix

#506
post #346

Earlier quoted context omitted.

The CDM is just a plugin - on Firefox it's a Gecko Media Plugin, and it seems easier to implement the GMP API than the NPAPI for Silverlight, since it's a lot more restricted.

Please re-read my post. These steps are not technical but they are very significant. Consider how you would provide this plugin to your users as the author of a new browser? You have to ask the plugin authors for permission to use it. Then consider that you have to persuade Netflix to allow the users of your browser to use their site (without changing user agents). Neither of these steps were required with NPAPI

> You have to ask the plugin authors for permission to use it.

I don't believe that's true. The plugin is freely available. You just have to write the host.

I don't think Netflix or the rights owners would care since the stream is protected equally in any browser.

Re: Update on HTML5 Video for Netflix

#507

Earlier quoted context omitted.

Someone can fork FF though and make it so that the DRM looks like it's there to the websites it visits, but it isn't really there. There's no way DRM can't be removed if I own the device that can play it.

You don't understand how this works. Firefox just provides some APIs that the DRM blob can use. All the decryption is done by the blob, not Firefox. You can reverse engineer the blob itself to an extent, but that will also become impossible with SGX (hence 4k on kabylake + edge only).

Oh, apparently I don't. Still though, it should be 100% possible to circumvent it given that it's playing on the device.

Re: Update on HTML5 Video for Netflix

#508
post #423

Earlier quoted context omitted.

At the time that Firefox started really turning heads, it took an order of magnitude less money to build a better browser. JIT innovations that were once just good research ideas from the Smalltalk world had an open source implementation in Java which then got ported to open source dynamic languages like Python (see polymorphic inline caching & similar techniques). Then Adobe came along and donated a bunch of it's JI…

I encourage you to try out Firefox Nightly. https://wiki.mozilla.org/Electrolysis has made me switch from Chrome to FF as the experience has improved greatly.

Will do. I only reluctantly admitted that Chrome was better than FF about a year and a half ago. Would be thrilled to switch back.

Re: Update on HTML5 Video for Netflix

#509

Earlier quoted context omitted.

There's a big different between breaking a door down to bypass a lock and pirating a movie via bittorrent though. It doesn't "keep honest people honest" when piracy is so damn easy regardless of what they do with DRM. The point of that phrase is to increase the effort and motivation necessary to commit a crime - in this case, DRM doesn't do that. With or without DRM any idiot can download the latest Popcorn Time fork…

People are pretty wary of using torrents because they're scared of being sued. What DRM on Netflix prevents is you ripping all of the seasons of your favorite shows, with almost no risk of getting caught, and then cancelling your Netflix subscription/sharing the rips with your friend, who is probably not inclined to use torrent sites.

Most people I know who casually pirate things don't even use torrents, they use streaming websites, file lockers, Kodi plugins, etc. Which offer similarly no risk of getting caught. I was simply using Popcorn Time as the extreme example of the level of ease it can be at.

None of these are exactly out-of-the-way high-effort options. There's no increased effort - you just don't bother trying to do so via Netflix. Any of these can be Googled in a few minutes. DRM does nothing to prevent them.

The legal risk you're talking about is just that though - nothing to do with DRM, everything to do with a legal threat. Note that it's more effective than DRM.

Even those who do go out of their way somewhat to improve the piracy experience don't go that far. I wouldn't compare configuring a typical Usenet+Sonarr+CouchPotato+Plex rig to breaking down a door, and that's pretty much the most advanced sort of setup you can get. It may require slightly specialized knowledge, but it doesn't require specialized intent usually. The intent is still the same as that of the casual pirate, it's just a tradeoff of upfront effort for later ease.

Re: Update on HTML5 Video for Netflix

#510
post #445

Earlier quoted context omitted.

> Really? How would you do that, exactly? Wireless isn't very secure, you're mileage may vary on the encryption mechanism but here is a guide to hacking WPA networks (with WEP it takes seconds): http://www.hackingtutorials.org/wifi-hacking-tutorials/how-t... From there you can try a range of known exploits and gain admin access to a PC, after that it's game over, they can run what they want, when the want. There is n…

WPA2 is reasonably secure and has been the standard for home and business WiFi for years. In any case, merely compromising WiFi won't get you someone's Netflix account. The Netflix data itself, including the credentials, are all encrypted. As for taking over someone's PC, that's far beyond the average pirate, and you're talking about serious criminal offences on top of mere copyright infringement at that point. And e…

I can't figure out why you've added this ridiculous "need to use their computer" part, that would be necessary for a successful lawsuit but suing random Netflix users will look terrible even if the court clears them in the end. But OK...

WPA2 is reasonably secure, but most home instances aren't set up well. They often have WPS enabled or a guessable password. Plus weaker set ups are still easy to find. Once you're on, redirect Netflix to a site to grab their info, record the stream from a computer outside their house. This is needlessly complex for what is needed, find a compromised Netflix(+email?), record.

Post reply on HN