Live data from Hacker News

Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

defectivebydesign.org

161–170 of 222 posts

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#161

Earlier quoted context omitted.

No, but maybe we need to look at it from relative numbers. Example: DRM music hasn't stopped music piracy, but better models for the content distribution (i.e. DRM music platforms like spotify, etc.) have demotivated more people from bothering to pirate music.

The fact that spotify has DRM is inconsequential to it, and those like it stomping out a ton of music piracy. It's all about the distribution model, and the DRM is just to make the rights holders happy.

But Spotify is a native app.

It can have all the drm it wants. It's not part of the open web.

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#162

Earlier quoted context omitted.

> The fact that this standard is coming to be is just plain silly, but it does no harm in and of itself. I disagree that it does no harm. I agree with this quote from the article: "If EME is ratified by the W3C, the FSF expects it to cause a long-term increase in the amount of DRM on the Web, by simplifying the DRM implementation process for streaming services." Standardization is explicit support and encouragement.

Forgive me for having a differing opinion, but just to clarify. I would agree with the FSF statement that there will be more DRM on the web. Where I differ is that I believe it would happen regardless. If it's not standard DRM, then it's Apple DRM and Windows DRM... like we already have. > Standardization is explicit support and encouragement. Standardization shouldn't be about good or bad. If enough people want to d…

> If it's not standard DRM, then it's Apple DRM and Windows DRM... like we already have.

which is fragmentation, and bad for businesses that want DRM, but don't want to _pay_ the cost of fragmentation. By adding it to an open standard, they no longer need to deal with end fragmentation (which causes end user a bad experience). But the solution was never to standardize on DRM, but to standardize on _non-DRM_ formats! The pirates can obtain content regardless - DRM only hurts consumers in the long run.

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#163

Earlier quoted context omitted.

What if it was legally bound that a securing tech (enforcing users not to abuse content) HAS to be opened in case of future demise of the author company ? If Apple and iTunes suddenly crash, they have to make a tiny effort into releasing a conversion/stripping tool and/or open source the system so that ex-customers can at least attempt to help themselves.

If a business is failing THAT BADLY, they're not likely to have resources to implement the safeties. And if they don't, who's going to get in trouble?

It's not about businesses failing - content disappears from Netflix and other services all the time. Shows people were watching previous month regularly disappear even though people pay for service. And DRM prevents them from exercising the legal right (in most juristictions, even US) to make private copies and watch them later. Remember VCRs and DVR devices? We changed laws to explicitly allow that.

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#164
post #16

Earlier quoted context omitted.

Well this doesn't actually change much in practice. Web browsers have allowed black-box extensions for DRM'd content since the dawn of flash. Personally I am disgusted that this standard is being promoted by the W3C and Tim Berners-Fucking-Lee. The browser vendors are perfectly capable of building (and even standardizing) this tech by themselves. The open web is as available today as it ever was, and even more so wit…

> Personally I am disgusted that this standard is being promoted by the W3C and Tim Berners-Fucking-Lee. The browser vendors are perfectly capable of building (and even standardizing) this tech by themselves. I don't understand these two sentences in conjunction, which is most of why I don't understand all the complaining about this issue. If, as almost everyone admits, the browser vendors are going to ship DRM-enabl…

> whether or not the DRM is in the spec changes nothing on the ground.

no, having a sanctioned DRM mechanism in an open standard means DRM is being normalized (and by extension, acceptable). The fact that DRM already exists as plugins isn't the point - but making DRM part of the web standard gives free reign for the pro-DRM camp that it's acceptable, or even desirable!

The only acceptable standard is one where the user benefits. I don't see how a user can benefit from DRM, except that this standard makes DRM less difficult to swallow for an end user (who, let's face it, don't give a shit about DRM). The added convenience of standardization means we can never get to a place where DRM-free content is the majority/norm.

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#165
post #152

Earlier quoted context omitted.

How so? The effect of DRM is to prevent the user from doing things that would otherwise be technically possible, such as copying. Once the software has decrypted the media, it can do whatever it wants with it. It is just so designed that what it wants to do with it is not the same as whatever the user wants to do with it. Free or open-source software give the right and the ability to the user to modify what the softw…

I think the parent's point is that it's absolutely feasible to build hardware and software that successfully enforces a DRM scheme, and also release the specs for the hardware and the source of the software. That doesn't mean that a content producer will verify any old (modified) version of the software and allow it to play (and possibly "leak") their content. Put another way: it's possible to build a secure DRM pipe…

but what part of the pipeline is responsible for the verification of the 'unmodified' trait?

If it's a part that's open-sourced (hardware or software), then won't it simply be _modified_ to allow it to pass and allow extraction of decrypted content?

If it's _not_ open-source, then you don't have a fully open-source DRM scheme.

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#166
post #143
post #127

Earlier quoted context omitted.

> same technology stack (HTML5 video+JS) for DRM-ful video as for DRM-free video this isn't a pro in my books - i want DRM to be a difficult and cumbersome stack to use. More specifically, i want the end user to go through hassle to obtain the proprietary plugins, so that the end user feels the hurt from DRM. This makes a non-DRM version much more simple to view (just click and play), so that users would vote with th…

Unfortunately, "Get the browser that makes it harder to watch Netflix! On purpose!" is not a winning marketing message.

or, if DRM-free streaming is there, "get netflix on all your devices with a browser, no plugin or installation needed! Netflix everywhere, on your fridge, on your car's video player etc"

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#167
post #79

Earlier quoted context omitted.

The server can send an encrypted blob to your browser which hands it off to the DRM module which can hand it off to the system's ring -2 PAVP/Trustzone/etc. stuff that only runs signed firmware which passes it encrypted over the PCIe bus to the gfx hardware which passes it encrypted via HDCP2 to the monitor. So in principle fully encrypted paths that can'e be screengrabbed exist. Not all DRM makes use of those compon…

You can screengrab at the interface between the decoder in the monitor and the panel itself, using an LVDS capture card. Not cheap at the moment, and you still have to process the gigabits per second of uncompressed video, but you can expect the Chinese to come up with some inventive and low-cost solutions if they start locking down the other routes... in fact a lot of DRM-stripping hardware already exists for sale,…

But what about literally recording your screen with a hand-camera? That would be quite tech-proof right? It's been done in cinemas for decades.

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#168
post #60
post #46

W3C takes advantage of the ambiguity of what the EME spec and "standard" DRM is. People unfamiliar with the spec may think it's the end of plug-ins and a spec for a DRM that is somehow open, implementable and cross-browser. It's nothing like it. It's a small JS API that launches the same old, fully closed, proprietary DRM solutions. The NPAPI has been replaced with DMCA-protected interface, and previously separate DR…

Note that part of standard DRM schemes is also "Computer verification" - e.g. that they refuse to work if your PC doesn't have the correct kernel, drivers or software installed. If you need special drivers to fix compatibility, want to customize your Android or do anything but leave your system full untouched and bloated, might be that you'll be prevented from watching online videos.

To some extend perhaps...

One of the key arguments when Mozilla decided to implement EME was that the crappy-proprietary-code could be sandboxed by firefox to ensure that it doesn't infect a system with malware, spy on users, etc.

From a security perspective it's light years better than flash and other crappy plugins.

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#169
post #154
post #139

Earlier quoted context omitted.

This already happened. We had Flash and Silverlight. This didn't make the Netflixes of the world drop DRM, and it didn't make customers flee for DRM-free solutions. All it did was decrease security for all of us. But yes, you do have a point that making DRM easier will likely make more content producers consider and implement DRM than before. I'm not sure there is a good solution to this right now, and yours is just…

> We had Flash and Silverlight. and when apple decides to drop flash support, what happened? Did netflix or any other video content producer suddenly decide to stop supporting those devices? No, they went with html5 video (and at that time, free of DRM). That was a great step forward for DRM free content for the web. By making the web standard include a mechnism to include DRM natively, this means content producers o…

> and when apple decides to drop flash support, what happened? Did netflix or any other video content producer suddenly decide to stop supporting those devices? No, they went with html5 video (and at that time, free of DRM). That was a great step forward for DRM free content for the web.

That's a figment of your imagination. They used DRM in an app store app.

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#170
post #44

Earlier quoted context omitted.

> This one is likely the best of the three. I don't agree. Ignoring the massive injustice of ramming proprietary extensions into an open standard, standardising DRM has several secondary detriments to the free culture movement. In fact, standardising EME might actually be the worst of the three choices (the best being no DRM of course). Non-standard extensions are better to the movement (though still disastrous) than…

It's a bit tough to argue we should keep computers insecure and hope people get annoyed and change their minds. Keeping people's computers safe is a primary goal of browser vendors, and this improves that state of affairs. Sure, DRM sucks, but at least the vendors can't root your machine and install keyloggers now.

I completely agree that it's tough to argue for user freedom in a world where widestream education about software freedom is non-existent. But we don't live in a world where users are aware of the importance of software freedom, so it's necessary to use secondary inconveniences to alert them to the primary injustices.

Maybe this comes from a lack of technical literacy. Maybe it comes from the fact that Microsoft and other large corporations indoctrinate children into thinking that proprietary software is acceptable. I don't know, and that is another front that needs to be fought.

However this is only one of the detriments that I listed of standardising EME.

> Keeping people's computers safe is a primary goal of browser vendors, and this improves that state of affairs.

It's unfortunate that this is the case. Don't get me wrong, security is very important, but security should not be the primary goal. The primary goal should be user freedom, with all other goals secondary.

To butcher a quote, "Those who would give up freedom, to purchase a little temporary security, deserve neither freedom nor security."

> Sure, DRM sucks, but at least the vendors can't root your machine and install keyloggers now.

Why are we as a community saying that corporations are allowed to piggyback on the hard work of the free software community to entrap users? Just because they might not be able to repeat their previous unethical and illegal actions such as installing rootkits (which I'm not sure I agree is accurate).

Post reply on HN