Live data from Hacker News

Microsoft PlayReady – Complete Client Identity Compromise

seclists.org

51–60 of 175 posts

Re: Microsoft PlayReady – Complete Client Identity Compromise

#51

Is there any video DRM scheme which successfully protects video content appearing on the pirate bay within 24 hours? I really don't see why so many millions (billions?) of dollars have been spent on technologies which so far have never kept the bad guys out.

> I really don't see why so many millions (billions?) of dollars have been spent on technologies which so far have never kept the bad guys out.

Because the goal isn't actually to "keep the bad guys out" - it's to strip user freedom and privacy, and make a shit load of money at the same time

Re: Microsoft PlayReady – Complete Client Identity Compromise

#52
post #33

Earlier quoted context omitted.

DRM schemes never worked, and it has been speculated that the people building them always knew it, but had other goals. Backn in the days it was: Of course you can break DVD copyprotection schemes. But you cannot build a legal opensource DVD player software. Today it's: Of course every Netflix series can be found on the pirate bay. But you're not legally allowed to build an alternative netflix player frontend.

From the executive’s perspectives, DRM is working just fine. People can’t just go get a random browser extension to save videos. Alternative and unlicensed clients are illegal. Sure, there’s some piracy - but even at the end of the day, pirates would watch a smartphone recording to save a buck. To them, DRM does not have to be perfect to be a good investment; any more than copyright needing to be perfect or Speed Lim…

> Sure, there’s some piracy - but even at the end of the day, pirates would watch a smartphone recording to save a buck.

I spend a lot of money on hard drives and Usenet to have quality rips. It's a service problem, not about the money

Re: Microsoft PlayReady – Complete Client Identity Compromise

#54
post #21
post #19

Earlier quoted context omitted.

> so everything is immediately available in at least 1080p. Aren't the lower tiers only 720p? At least all the streaming services give Linux users only 720p. (There is a workaround for one particular service to still get 1080p - I'm paying for it so I better can watch it in 1080p! The moment this stops working I cancel my subscription.)

There's three Winevine tiers, L1, L2 and L3, which generally correspond to 4K, 1080p and 720p respectively though it depends on the service. L3 is what you get on Linux. L2 is supposed to be more secure than L3 but AFAICT it makes little difference to piracy groups, L1 is the only actual roadblock for them.

Why are Linux users limited to L3?

Re: Microsoft PlayReady – Complete Client Identity Compromise

#55
post #20
post #19

Earlier quoted context omitted.

> so everything is immediately available in at least 1080p. Aren't the lower tiers only 720p? At least all the streaming services give Linux users only 720p. (There is a workaround for one particular service to still get 1080p - I'm paying for it so I better can watch it in 1080p! The moment this stops working I cancel my subscription.)

L3 can do FHD on Linux but it's the services config that prevents that.

Why do they do that?

Re: Microsoft PlayReady – Complete Client Identity Compromise

#56

Earlier quoted context omitted.

As long as it stops even 100,000 people from not downloading videos off of Netflix, from an executive’s perspective, it pays for itself. To them, it’s like saying Speed Limit signs are useless, because cars can go faster than the number posted by literally pressing a button. That’s not the point.

Yes if a particular group gets to externalise / socialise the costs of maintaining a protection then obviously from the perspective of the protected group then it's worth it. The question is, is it good for society overall. Who or what is being protected and what impact does that have on everyone else? Speed limit / stop signs represent a decent point of discussion I think.

Speed limit signals danger, right?

Does DRM signal an ethical dilemma?

And if yes, what does it mean considering that each year we lose millions of people on the roads. (To fatalities and horrific injuries resulting in permanent disabilities.) Yet the majority doesn't care?

Re: Microsoft PlayReady – Complete Client Identity Compromise

#57

Earlier quoted context omitted.

From the executive’s perspectives, DRM is working just fine. People can’t just go get a random browser extension to save videos. Alternative and unlicensed clients are illegal. Sure, there’s some piracy - but even at the end of the day, pirates would watch a smartphone recording to save a buck. To them, DRM does not have to be perfect to be a good investment; any more than copyright needing to be perfect or Speed Lim…

> Sure, there’s some piracy - but even at the end of the day, pirates would watch a smartphone recording to save a buck. I spend a lot of money on hard drives and Usenet to have quality rips. It's a service problem, not about the money

Yes, yes, the Gabe Newell quote - even though that quote was only an explanation for why piracy happened. Commonly lost in translation, that quote never once said piracy was justified or acceptable, nor did he encourage piracy under any circumstances.

Re: Microsoft PlayReady – Complete Client Identity Compromise

#58
post #54
post #21

Earlier quoted context omitted.

There's three Winevine tiers, L1, L2 and L3, which generally correspond to 4K, 1080p and 720p respectively though it depends on the service. L3 is what you get on Linux. L2 is supposed to be more secure than L3 but AFAICT it makes little difference to piracy groups, L1 is the only actual roadblock for them.

Why are Linux users limited to L3?

Because it doesn't meet the requirements for L2. I think L2 implementations are required to block software screen recording, for example, and there isn't really any practical way to enforce that on an open platform. Windows/Android/iOS have special support for compositing protected content so if you try to read the framebuffer back the content just shows up as a black rectangle.

Re: Microsoft PlayReady – Complete Client Identity Compromise

#59
post #53

At some point this silly game of cat-and-mouse is going to escalate, and streaming players won't work unless your entire computer is locked down and "verified" by Microsoft or Apple.

And yet content will still be torrented within hours. It’s always the honest consumers that lose.

Re: Microsoft PlayReady – Complete Client Identity Compromise

#60
post #46

Earlier quoted context omitted.

As long as it stops even 100,000 people from not downloading videos off of Netflix, from an executive’s perspective, it pays for itself. To them, it’s like saying Speed Limit signs are useless, because cars can go faster than the number posted by literally pressing a button. That’s not the point.

If you take the capitalistic lust of the corporate executive to its logical extreme, given the massive costs of the DRM tech you'd think that at least one of them would realize that they could make more money if they didn't have to pay for something that doesn't work. The economics of distributing the copies are such that it doesn't actually matter if it's easy or hard for 1 or 100,000 people to break the protection.

I agree, DRM has significant costs.

Consider you've encoded and packaged your mezzanine into ABR (dash, HLS) and it's working on phones, browsers, smart TVs, STBs etc. Now you add common encryption: repackage and get double the number of tracks (CENC as well as CBCS). You buy your licenses from Apple (Fairplay), Google (Widevine), Microsoft (Playready) and Marlin (old crap). What used to "just work" now has all kinds of subtle interop problems.

Audio sync issues on iPad? Ah, Apple pushed a bad firmware update, thank you. Tomorrow it's users complaining about Widevine in Firefox. Only Netflix, maybe Disney+ — the biggest of the biggest can do streaming with DRM and make a profit.

Post reply on HN