Live data from Hacker News

Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

defectivebydesign.org

201–210 of 222 posts

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#201
post #168
post #60

Earlier quoted context omitted.

Note that part of standard DRM schemes is also "Computer verification" - e.g. that they refuse to work if your PC doesn't have the correct kernel, drivers or software installed. If you need special drivers to fix compatibility, want to customize your Android or do anything but leave your system full untouched and bloated, might be that you'll be prevented from watching online videos.

To some extend perhaps... One of the key arguments when Mozilla decided to implement EME was that the crappy-proprietary-code could be sandboxed by firefox to ensure that it doesn't infect a system with malware, spy on users, etc. From a security perspective it's light years better than flash and other crappy plugins.

I wrote a bug asking Mozilla not to implement HTML5 DRM. It was closed as RESOLVED WONTFIX.

https://bugzilla.mozilla.org/show_bug.cgi?id=923590

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#202
post #154

Earlier quoted context omitted.

> We had Flash and Silverlight. and when apple decides to drop flash support, what happened? Did netflix or any other video content producer suddenly decide to stop supporting those devices? No, they went with html5 video (and at that time, free of DRM). That was a great step forward for DRM free content for the web. By making the web standard include a mechnism to include DRM natively, this means content producers o…

Maybe, just _maybe_ that would have been a viable pressure point to favour non-DRM content* if we were all running Firefox. As it is, too many people decided they are OK with a google browser. The answer to: "It's cumbersome to use DRM" is to tell your consumers to use Chrome. * I find this highly questionable. We have an abundance of examples of media companies favouring DRM over user experience. Clearly they think…

> abundance of examples of media companies favouring DRM over user experience.

I don't think media companies particularly care about user experience. They care about control.

Once you have a piece of content (which you didn't produce) in your hands, and an exclusive distribution contract to guarantee the content producer can't go elsewhere - you have a monopoly over the content in question. DRM is an abhorrent, if natural, extension of this control-freakery. After all, you don't want to provide consumers control over how they view YOUR[0] precious content.

The ingrateful bastards might find a way to enjoy the content without going through the hoops you've carefully put in place. What good would a monopoly be? As the sole content distributor, the last thing you want is competition.

0: Nope, you still didn't produce it. Someone else did. But now you own it.

EDIT: grammar fix in footnote

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#203
post #110

Earlier quoted context omitted.

I disagree. Technologically it is possible to build a content protection system without obscurity, using open source software and open source hardware (and suitable cryptographic bootstrapping). That no one chooses to do so is another matter.

How so? The effect of DRM is to prevent the user from doing things that would otherwise be technically possible, such as copying. Once the software has decrypted the media, it can do whatever it wants with it. It is just so designed that what it wants to do with it is not the same as whatever the user wants to do with it. Free or open-source software give the right and the ability to the user to modify what the softw…

I was thinking along the lines of Kerckhoffs' principle.

You seem to be conflating open source with key extraction or decryption ability. You seem to be saying that if a specification is known then that implies an ability to modify the system to a degree that allows those things.

You can have a system whose workings you know precisely, without obscurity, where the SW/HW specifications are open and the only secret is the key material. For instance, you could have keys be embedded in processor fuses. How would a user extract the keys in that scenario?

For DRM systems the user or consumer is the adversary, but the principles of secure system design still apply. You can still place an asset outside of adversary reach. For example, by ensuring that they need a super expensive FIB machine to read keys. Or, more traditionally, by tailoring cryptography to their computational power.

You seem to be conflating the malleability of software with its modifiability in a given system, but in reality those can be controlled. Yes, you can fork the software, but why are you assuming you can replace it on a given system?

Consider a black box with an LED. The box has an internal power supply and the LED emits light pulses in a given pattern pleasing to the user who purchased it. I could give you its physical properties and circuit diagrams. The box has data stored in internal memory. You can call parts of this data software if you like, as long as we agree that the output of the box is a function of this data and time.

The only contradiction inherent in DRM systems is that knowledge of the data/function needs to be given to the adversary and not given to the adversary at the same time. This has less to do with open or closed source, and more to do with whether the user can open the box.

I think that the "solution" to this contradiction has been reduction in fidelity, where the user/adversary is only given an approximation of the function (analog outputs that they have a hard time spreading to other would be users).

DRM sucks, but is not fundamentally at odds with open source.

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#204
post #165
post #152

Earlier quoted context omitted.

I think the parent's point is that it's absolutely feasible to build hardware and software that successfully enforces a DRM scheme, and also release the specs for the hardware and the source of the software. That doesn't mean that a content producer will verify any old (modified) version of the software and allow it to play (and possibly "leak") their content. Put another way: it's possible to build a secure DRM pipe…

but what part of the pipeline is responsible for the verification of the 'unmodified' trait? If it's a part that's open-sourced (hardware or software), then won't it simply be _modified_ to allow it to pass and allow extraction of decrypted content? If it's _not_ open-source, then you don't have a fully open-source DRM scheme.

open source does not imply modifiable

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#205
post #152

Earlier quoted context omitted.

How so? The effect of DRM is to prevent the user from doing things that would otherwise be technically possible, such as copying. Once the software has decrypted the media, it can do whatever it wants with it. It is just so designed that what it wants to do with it is not the same as whatever the user wants to do with it. Free or open-source software give the right and the ability to the user to modify what the softw…

I think the parent's point is that it's absolutely feasible to build hardware and software that successfully enforces a DRM scheme, and also release the specs for the hardware and the source of the software. That doesn't mean that a content producer will verify any old (modified) version of the software and allow it to play (and possibly "leak") their content. Put another way: it's possible to build a secure DRM pipe…

yes, that was my point

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#206

Earlier quoted context omitted.

> i want DRM to be a difficult and cumbersome stack to use. More specifically, i want the end user to go through hassle to obtain the proprietary plugins, so that the end user feels the hurt from DRM. so you want to make stuff like netflix as much of a PITA as possible? why? why be this vindictive?

> you want to make stuff like netflix as much of a PITA as possible? Not op but yes, using DRM in a browser should be hard. Netflix should just make a native app, like everyone else who needs drm do. This clearly scopes what is open and webby and what is closed and DRMy. Nobody has issues installing Spotify to stream music. What makes Netflix special?

> Netflix should just make a native app, like everyone else who needs drm do.

The native app security model on desktop (i.e. can do anything) doesn't make the notion of letting streaming services run native apps look so great.

Do you really prefer giving streaming services (not just Netflix but others too) fully-privileged code execution instead of having an operating system or browser vendors exercise some oversight?

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#207
post #96

Earlier quoted context omitted.

CDMs are sandboxed, which is an improvement over the NPAPI plugins. I don't think we have to worry much about Sony rootkit attacks at least.

> which is an improvement over the NPAPI plugins. why does that argument get thrown around so much? flash runs in sandboxed processes too these days.

It runs in a separate process. I don't think that process is sandboxed in Firefox. And you probably can't restrict it too much or most Flash apps wouldn't work.

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#208
post #25

Earlier quoted context omitted.

Chrome has been using EME with Netflix since early 2013. This fight was lost years ago.

The point of web standards isn't to stop browsers from implementing anything else. Such a viewpoint is naive, that's not what W3C is. Back when IExplorer had a 90% market share, you could have argued that ActiveX needs to be a web standard. But it wasn't considered a standard even if it was a de facto one and now ActiveX is gone. I must be getting old if I'm talking with people that don't remember the browser wars or…

The object element in HTML 4 had some attributes that were pretty ActiveX-specific in practice, so in large part Microsoft got the HTML integration bits for ActiveX into the standard.

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#209
post #115
post #46

W3C takes advantage of the ambiguity of what the EME spec and "standard" DRM is. People unfamiliar with the spec may think it's the end of plug-ins and a spec for a DRM that is somehow open, implementable and cross-browser. It's nothing like it. It's a small JS API that launches the same old, fully closed, proprietary DRM solutions. The NPAPI has been replaced with DMCA-protected interface, and previously separate DR…

I think that is a bit of an exaggeration. First, for some browsers, the DRM scheme is built in, not any kind of plugin architecture. Second, without EME, the state of the art for DRM video was to run the whole playback path through a plugin. Now, only the DRM bit is generally going to be hidden in binary blob (whether plugin or not.) This has some important advantages: * Web content authors can build video players us…

If you read the EME spec, unless they've changed you're not guaranteed to be able to overlay anything over the EME-provided video rectangle using HTML. The only cross-platform approach is to treat it as an opaque, untouchable area that does not interact with the HTML side of things in any way, like the bad old early days of plugins. Also, at least on Android the playback chain goes through TrustZone code that's effectively running at a higher privilege level than the kernel.

Re: Tim Berners-Lee approves Web DRM, but W3C members have two weeks to appeal

#210
post #179

Earlier quoted context omitted.

I feel like you may have forgotten Firefox's role in history. Firefox unambiguously saved the world from Microsoft taking control of the web. Not to mention that Chromium is a free sofware project. It doesn't matter that the largest contributor is Google (it does for the top-level discussion of why the hell did Chromium implement this), the project itself is free software and is thus part of the free software communi…

I feel like you may have forgotten Firefox's role in history. Firefox unambiguously saved the world from Microsoft taking control of the web. I don't necessarily disagree, but I don't see how that's relevant to "bigcorps piggybacking on the work by the free software community". I'm pretty sure media corps would be fine with an IE world. Not to mention that Chromium is a free sofware project. It doesn't matter that th…

> I'm pretty sure media corps would be fine with an IE world.

But that's not the world we live in. We live in a world where Firefox saved the web, Chrom{e,ium} has changed it as well (though they have done plenty of things I think are horrible). In _that world_, they are trying to piggyback off the current state of the web's open standards by adding extensions that will only work because the same browsers that made the web what it is today are now forced to implement EME.

> Chromium is developed by the work paid by bigcorps, not by the free software community. The code being open source doesn't change this.

By that logic, Linux is not developed by the free software community (80% of kernel development is done by developers paid by companies -- which I think is great).

Post reply on HN