Live data from Hacker News

Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

defectivebydesign.org

11–20 of 222 posts

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#11
post #7
post #4

I can't wait until this gets used by malware!

Can you explain how malware could benefit from EME? Note that EME only applies to video.

The reasoning goes that EME is a standard that specifically allows for attaching a closed-source black-box to the browser in a standardized way. This code is not auditable by outside sources, and therefore could be a breeding ground for malware and exploits (standard open-source philosophy that "sunlight is the best disinfectant"---many eyes on open source software minimizes the opportunities for exploitable bugs to hide). We've seen codec software---even open-source codec implementations---used as an attack vector in the past.

This reasoning, IMHO, ignores the fact that the user-agent still asks for consent, so the user may choose not to allow anything they can't audit. It's just the "Do you want to allow Flash to play this cool video?" story all over again.

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#13
post #7

Earlier quoted context omitted.

Can you explain how malware could benefit from EME? Note that EME only applies to video.

The reasoning goes that EME is a standard that specifically allows for attaching a closed-source black-box to the browser in a standardized way. This code is not auditable by outside sources, and therefore could be a breeding ground for malware and exploits (standard open-source philosophy that "sunlight is the best disinfectant"---many eyes on open source software minimizes the opportunities for exploitable bugs to…

The user often does not have a choice because websites that they must use for one reason or another will require these extensions, just like some required Flash. And that's assuming that the extension even works on their system. The extensions are native code IIRC. Ever get a "sorry, your OS isn't supported!" message on a website that you really need to use to get something done? It sucks, a lot. I don't know why the W3C would want to steer themselves in such a direction, it's the antithesis of what the web was supposed to be. The web is supposed to have a well defined set of standards that anyone can implement and use to view the web. This was never true in practice because of things like Flash, but the W3C never endorsed such a thing. Now they are, and that is sad.

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#14
post #7

Earlier quoted context omitted.

Can you explain how malware could benefit from EME? Note that EME only applies to video.

The reasoning goes that EME is a standard that specifically allows for attaching a closed-source black-box to the browser in a standardized way. This code is not auditable by outside sources, and therefore could be a breeding ground for malware and exploits (standard open-source philosophy that "sunlight is the best disinfectant"---many eyes on open source software minimizes the opportunities for exploitable bugs to…

"It's just the "Do you want to allow Flash to play this cool video?" story all over again."

Another comparison to existing tech is Javascript. A lot of sites break if you disable Javascript in your browser, but if you enable it you open yourself to Javascript vulnerabilities.

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#15
post #7

Earlier quoted context omitted.

Can you explain how malware could benefit from EME? Note that EME only applies to video.

The reasoning goes that EME is a standard that specifically allows for attaching a closed-source black-box to the browser in a standardized way. This code is not auditable by outside sources, and therefore could be a breeding ground for malware and exploits (standard open-source philosophy that "sunlight is the best disinfectant"---many eyes on open source software minimizes the opportunities for exploitable bugs to…

Presumably they feel the same way about all closed-source browsers?

Also, the comparison to Flash is not quite right. For example, Flash was an entire black-box, top to bottom, with a runtime, codecs, UI, a JS engine, etc., which downloaded code from the internet to run it.

Web DRM, on the other hand, is a standard that allows for an encrypted video stream to be decrypted. The only differences that I can see between this and the current state of web video are that now the stream can be encrypted. Everything else is still using Javascript, HTML, CSS, HTTP, h.264/265, etc.

The thing that gets me is that open-source browsers are free not to implement this extension if they're not comfortable with (or opposed to) it. The theory is that if companies start encrypting their content then open-source browsers will have to follow suit, but we already have that kind of junk; the difference is that now, with EME, we can keep 99% of the stack open standards, open-source, and auditable, rather than having to rely on Flash or Silverlight to do our decoding.

EME isn't the death of the open web, it's the death of the closed web. It's the death of awful, insecure, and obsolete technologies like Flash and Silverlight by taking the one single thing they're still good for and moving it to the browser. If EME failed and no one implemented it, Netflix wouldn't just stream their content unencrypted; they'd keep using Flash or Silverlight, or maybe implement something themselves so they didn't have to.

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#16

This truly is the death of the open web. I hope the appeal is successful. Freedom seems to be losing on all fronts these days.

Well this doesn't actually change much in practice. Web browsers have allowed black-box extensions for DRM'd content since the dawn of flash.

Personally I am disgusted that this standard is being promoted by the W3C and Tim Berners-Fucking-Lee. The browser vendors are perfectly capable of building (and even standardizing) this tech by themselves.

The open web is as available today as it ever was, and even more so with blockchain and "dark web" technologies like tor and i2p.

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#17
Everything that I have read suggests that this is standardizing what has already happened with video, which is a great deal better than the bad old days when companies relied upon Macromedia/Adobe for video streaming. (Or worse, a plug-in from an obscure company with an unknown track record).

As much as I would like to avoid DRM, relatively few producers are going to budge on the issue. The only options are standardized DRM, non-standardized extensions to provide DRM, or simply doing without. None of the options are particularly desirable. This one is likely the best of the three.

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#18
post #16

This truly is the death of the open web. I hope the appeal is successful. Freedom seems to be losing on all fronts these days.

Well this doesn't actually change much in practice. Web browsers have allowed black-box extensions for DRM'd content since the dawn of flash. Personally I am disgusted that this standard is being promoted by the W3C and Tim Berners-Fucking-Lee. The browser vendors are perfectly capable of building (and even standardizing) this tech by themselves. The open web is as available today as it ever was, and even more so wit…

> Personally I am disgusted that this standard is being promoted by the W3C and Tim Berners-Fucking-Lee.

Yes, that's the disgusting part. But so it goes. The flesh is weak.

Overlay darknets are indeed the only hope for freedom.

Post reply on HN