Live data from Hacker News

Yt-dlp: External JavaScript runtime now required for full YouTube support

github.com

71–80 of 646 posts

Re: Yt-dlp: External JavaScript runtime now required for full YouTube support

#71
post #36

I use yt-dlp (and back then youtube-dl) all the time to archive my liked videos. Started back in around 2010, now I have tens of thousands of videos saved. Storage is cheap and a huge percent of them are not available anymore on the site. I also save temporary videos removed after a time for example NHK honbasho sumo highlights which are only available for a month or so then they permanently remove them.

Do you ever go back and actually watch those videos? Whenever I start to journal, track, or just document something, after some time I notice again and again that most of the value has already been created the moment I finish working on a specific entry. Even with something seemingly very important like medical records. Maybe one exception I can think of are recordings of memories involving people close to you

I would be interested in knowing as well. I've been watching YouTube since it first came out and can't remember any times where I saw something I thought I needed to actually download and save in case I wanted it in 10 years. 10,000+ videos is a lot of videos to just seemingly save.

Re: Yt-dlp: External JavaScript runtime now required for full YouTube support

#72
post #13

Earlier quoted context omitted.

They’d need dedicated hardware to enforce any kind of effective DRM. Encrypted bitstream generated on the fly watchable only on L2 attested device.

Can you explain in simple terms what would prevent one from running the decryption programmatically posing as the end client?

Let's say the only devices you can get that will run YouTube are running i/pad/visionOS or Android and that those will only run on controlled hardware and that the hardware will only run signed code. Now let's say the only way to get the YouTube client is though the controlled app stores on those platforms. You can build a chain of trust tied to something like a TPM in the device at one end and signing keys held by Apple or Google at the other that makes it very difficult to get access to the client implementation and the key material and run something like the client in an environment that would allow it to provide convincing evidence that it is a trusted client. As long as you have the hardware and software in your hands, it's probably not impossible, but it can be made just a few steps shy.

Re: Yt-dlp: External JavaScript runtime now required for full YouTube support

#73

It's quite worrying. A sizeable chunk of cultural and educational material produced in the last decade is in control of greedy bastards who will never have enough. Unfortunately, downloading the video data is only part of it. Even if we shared it all on BitTorrent it's nowhere near as useful without the index and metadata.

What are you talking about? It's in control of the creators. YT doesn't get exclusive copyright on user's content. Those creators can upload wherever they want. And YT isn't "greedy bastards". They provide a valuable service, for free, that is extremely expensive to run. Do you think YT ought to be government-funded or a charity or something?

> Do you think YT ought to be government-funded

Benn Jordan made a pretty compelling video on this topic, arguing that the existing copyright system and artifacts of it are actually not that great and a potential government system might actually be better: https://www.youtube.com/watch?v=PJSTFzhs1O4

I will say that is something I would not have considered reasonable prior to watching his video.

Re: Yt-dlp: External JavaScript runtime now required for full YouTube support

#74
post #4
post #3

In ten years time YouTube will be entirely inaccessible from the browser as the iPad kids generation are used to doomscrolling the tablet app and Google feels confident enough to cut off the aging demographic.

The YouTube web app is so full of bugs it's almost unusable on a phone. Comments also disappear regularly on all platforms...

> Comments also disappear regularly on all platforms...

I don't believe that that's a bug. The disappearance depends a lot on the topic of those comments. It's very much deliberate censorship.

Re: Yt-dlp: External JavaScript runtime now required for full YouTube support

#75
post #36

I use yt-dlp (and back then youtube-dl) all the time to archive my liked videos. Started back in around 2010, now I have tens of thousands of videos saved. Storage is cheap and a huge percent of them are not available anymore on the site. I also save temporary videos removed after a time for example NHK honbasho sumo highlights which are only available for a month or so then they permanently remove them.

Do you ever go back and actually watch those videos? Whenever I start to journal, track, or just document something, after some time I notice again and again that most of the value has already been created the moment I finish working on a specific entry. Even with something seemingly very important like medical records. Maybe one exception I can think of are recordings of memories involving people close to you

I have the same with journals, but the video archiving has actually come up a few times, still fairly rare though. I think the difference is that you control the journal (and so rarely feel like you need it's content) while the videos you're archiving are by default outside of your control and can be more easily lost.

Re: Yt-dlp: External JavaScript runtime now required for full YouTube support

#76
post #13

Earlier quoted context omitted.

They’d need dedicated hardware to enforce any kind of effective DRM. Encrypted bitstream generated on the fly watchable only on L2 attested device.

Can you explain in simple terms what would prevent one from running the decryption programmatically posing as the end client?

Attestation requiring a hardware TPM 2.0 (or higher), and not being able to extract the private key from the TPM on your system.

TPM is Mathematically Secure and you can't extract what's put in. See, Fritz-Chip.

Re: Yt-dlp: External JavaScript runtime now required for full YouTube support

#77
post #68

Earlier quoted context omitted.

Can you explain in simple terms what would prevent one from running the decryption programmatically posing as the end client?

Here are a couple ideas: The decryption code could verify that it's only providing decrypted content to an attested-legitimate monitor, using DRM over HDMI (HDCP). You might try to modify the decryption code to disable the part where it reencrypts the data for the monitor, but it might be heavily obfuscated. Maybe the decryption key is only provided to a TPM that can attest its legitimacy. Then you would need a hardw…

[deleted]

Re: Yt-dlp: External JavaScript runtime now required for full YouTube support

#78
post #36

I use yt-dlp (and back then youtube-dl) all the time to archive my liked videos. Started back in around 2010, now I have tens of thousands of videos saved. Storage is cheap and a huge percent of them are not available anymore on the site. I also save temporary videos removed after a time for example NHK honbasho sumo highlights which are only available for a month or so then they permanently remove them.

do you have a cron job or something? i know it is probably trivial but eh

Re: Yt-dlp: External JavaScript runtime now required for full YouTube support

#79
post #74
post #4

Earlier quoted context omitted.

The YouTube web app is so full of bugs it's almost unusable on a phone. Comments also disappear regularly on all platforms...

> Comments also disappear regularly on all platforms... I don't believe that that's a bug. The disappearance depends a lot on the topic of those comments. It's very much deliberate censorship.

> It's very much deliberate censorship.

Also known as "moderation"

Re: Yt-dlp: External JavaScript runtime now required for full YouTube support

#80
post #13

Earlier quoted context omitted.

They’d need dedicated hardware to enforce any kind of effective DRM. Encrypted bitstream generated on the fly watchable only on L2 attested device.

Can you explain in simple terms what would prevent one from running the decryption programmatically posing as the end client?

Yes, it's called: Web Environment Integrity + hardware attestation of some kind

> "the technical means through which WEI will accomplish its ends is relatively simple. Before serving a web page, a server can ask a third-party "verification" service to make sure that the user's browsing environment has not been "tampered" with. A translation of the policy's terminology will help us here: this Google-owned server will be asked to make sure that the browser does not deviate in any way from Google's accepted browser configuration" [1]

https://www.fsf.org/blogs/community/web-environment-integrit...

Post reply on HN