Live data from Hacker News

Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

defectivebydesign.org

101–110 of 222 posts

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#101

A younger version of myself would be against Web DRM, but these days I wonder if there's a potential for it to help in democratizing distribution among indie content producers. Ideally I'd have some time to piece together an essay, but the major points are: 1) Ted Nelson's vision on how Project Xanadu would have some form of copyright protection / micropayments for authors. 2) Independent content creators that have c…

>democratizing distribution among indie content producers So I have this idea for a video/audio streaming website that operates like an open market. Website operator makes a cut for infrastructure costs. Other than that, the site runs pretty much on its own. No content deals, no drm, no geo restrictions, no ads. Some safeguards to limit abuse. A producer puts up content. Consumers consume content. Revenues are split…

https://www.collide.com

Not sure if it fulfills everything and I like your model better.

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#102
DRM is a non-starter and is in reality defective by design.

Pirates have created markets where there were none and are an important part of every entertainment eco-system. It's been that way since the beginning.

This is just another in a long string of bad decisions that attempts to give major distribution channels far more control than they deserve or could ever manage responsibly.

If you want to make money in entertainment, the business plan is simple. 1. Get people to like you. 2. Find a way for those people to get you money. You don't need Google, Netflix, Apple, NBC, CBS, ABC, RKO, ClearChannel, or anybody else that inserts themselves between you and your customers. None of them provides enough real value to anybody who didn't already have a market before leveraging them.

The fact that this standard is coming to be is just plain silly, but it does no harm in and of itself. All of the potential problems are today's reality. A rubber stamp by W3C implementing a tag in the HTML spec and blessing a workflow change nothing.

The FSF is stirring up noise without providing links to what it's talking about. I presume it's this: https://www.w3.org/TR/encrypted-media/

The workflow isn't particularly well thought out - it's not significantly different than what RealMedia or Adobe have had put together for a generation.

The real downside is the fact that browsers will be further plagued with vague integrations. Those integrations will all carry security ramifications that nobody cares to consider until a major exploit is publicized. The fact that so many people are willing to sacrifice their security for access to a 12 year old lionsgate video is beyond me, but such is the nature of the world we live in. Like I said before though... that is a problem that browsers face today. The new "standard" doesn't change much in reality.

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#103
post #78

Earlier quoted context omitted.

Has DRM ever actually stopped piracy?

No, but maybe we need to look at it from relative numbers. Example: DRM music hasn't stopped music piracy, but better models for the content distribution (i.e. DRM music platforms like spotify, etc.) have demotivated more people from bothering to pirate music.

The fact that spotify has DRM is inconsequential to it, and those like it stomping out a ton of music piracy. It's all about the distribution model, and the DRM is just to make the rights holders happy.

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#104
post #26

Earlier quoted context omitted.

I disagree. "Doing without" seems the most sensible to me. There is no rule that industries whose business is built on copyright need to be able to live in the browser. Netflix demonstrated that quite nicely. Just because the want it doesn't mean they should get it. I personally cripple EME on my browsers, and if your content won't display for me, I'll happily go elsewhere. (Haven't had the problem yet, but fully exp…

For doing without to work, all browsers must agree to do without. As soon as one browser ships it and people prefer browsers that can stream Netflix, everyone else must follow suit or wallow in obscurity. Microsoft and Google make CDMs; no one else had a chance in this fight.

If I follow, you're implying browsers that hypothetically refused to work with Netflix's DRM would wallow in obscurity.

While probably correct since the majority of users do seem to like Netflix, others ignore Netflix and get their media through, shall we say more "obscure" sources. Such an obscure browser would seem to suit their needs just fine. Tor Browser doesn't need to be popular among the masses for those who use it to find lots of value in using it, for example.

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#105
post #75

Earlier quoted context omitted.

> Option 1 is the best because playing DRM content should be Netflix's problem. By not making it a standard we'll make sure that Neflix never, ever comes to Linux. That guarantees that proprietary operating systems, browsers and hardware will always be prevalent. > By making it a standard it means that we'll never, ever get rid of it. and were standards. NPAPI was a quasi-standard. Black-and-white worldviews are ofte…

> By not making it a standard we'll make sure that Neflix never, ever comes to Linux. Isn't the EME a system binary that would be specific to each platform? There's no guarantee tat they'll be a linux one for each provider.

Agreed. However, Widevine is Google's thing and it's plausible that they'd ship it with some non-free build of Chrome. Unless they're worried about trusting the OS, in which case my original argument is void.

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#106
post #75

Earlier quoted context omitted.

Option 1 is the best because playing DRM content should be Netflix's problem. Why in the world would you want to subsidize Netflix's development? So what if Netflix's DRM plugin would be proprietary and buggy? Heck, that's a window of opportunity for DRM-free competition. By making it a standard it means that we'll never, ever get rid of it. Even if DRM is fundamentally flawed. #2 is in fact the worst solution.

> Option 1 is the best because playing DRM content should be Netflix's problem. By not making it a standard we'll make sure that Neflix never, ever comes to Linux. That guarantees that proprietary operating systems, browsers and hardware will always be prevalent. > By making it a standard it means that we'll never, ever get rid of it. and were standards. NPAPI was a quasi-standard. Black-and-white worldviews are ofte…

> By not making it a standard we'll make sure that Neflix never, ever comes to Linux.

Netflix already works on Linux, with Chrome and Firefox: https://help.netflix.com/en/node/23742

It uses EME with closed-source CDMs bundled with the browser (Chrome) or downloaded by the browser (Firefox).

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#107
post #79

Can EME prevent people from doing 30fps screengrabs of their screen and dump all into an mp4 file using FFmpeg or such? As someone else pointed here: > You can't simultaneously give us the content and not give us the content.

The server can send an encrypted blob to your browser which hands it off to the DRM module which can hand it off to the system's ring -2 PAVP/Trustzone/etc. stuff that only runs signed firmware which passes it encrypted over the PCIe bus to the gfx hardware which passes it encrypted via HDCP2 to the monitor. So in principle fully encrypted paths that can'e be screengrabbed exist. Not all DRM makes use of those compon…

>So in principle fully encrypted paths that can'e be screengrabbed exist

This is the worrying part. While DRM has always existed, it has always been possible to defeat it largely because any software can be reverse engineered. Once you get down to the processor, it's close to impossible. And it's not like we have a lot of processor companies.

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#108

Earlier quoted context omitted.

> By not making it a standard we'll make sure that Neflix never, ever comes to Linux. Isn't the EME a system binary that would be specific to each platform? There's no guarantee tat they'll be a linux one for each provider.

Agreed. However, Widevine is Google's thing and it's plausible that they'd ship it with some non-free build of Chrome. Unless they're worried about trusting the OS, in which case my original argument is void.

Plausible sure. anyone using any other plugin is also plausible, though much less likely.

The point is since it's not standard Linux and BSD will get the shaft.

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#109
If the W3C does this, it will be time -- regrettably -- to turn away from that organisation and make a completely new one that exists to serve users of the Web rather than those seeking to monetise it. That Tim Berners-Lee has lent his name to this hijacking is shameful.

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#110
post #20

What's the reason DRM can't be implemented as an open-source solution? Is the closed source just to prevent people from easily accessing the secret key or are there other reasons it needs to be closed source?

DRM is fundamentally security by obscurity. Being closed source is the only way to maintain obscurity, and thus the illusion of security.

I disagree. Technologically it is possible to build a content protection system without obscurity, using open source software and open source hardware (and suitable cryptographic bootstrapping). That no one chooses to do so is another matter.
Post reply on HN