Live data from Hacker News

The W3C's plan for DRM in HTML5 is a betrayal for all web users

freeculture.org

91–100 of 158 posts

Re: The W3C's plan for DRM in HTML5 is a betrayal for all web users

#91

Earlier quoted context omitted.

Consumers don't care about implementation, they only care about the content, and until they do, suppliers of content hold all the cards. In this case, forget consumers. Once in a while, something is more important than appeasing the masses. A DRM free HTML5 spec is not going to force Hollywood to allow you to play Games of Thrones on your open source Linux browser. Neither is a DRM-infested spec. Instead, you have un…

So if the vast majority of people end up using native apps, and more and more information gets siloed behind these native app clouds on DRM'ed mobile devices, because that's where the money is, and the Web becomes a ghost town, that would be better for everyone? The perfect is the enemy of the good.

>So if the vast majority of people end up using native apps, and more and more information gets siloed behind these native app clouds on DRM'ed mobile devices, because that's where the money is, and the Web becomes a ghost town, that would be better for everyone?

You're talking nonsense. The web is just the dominant way of accessing "app clouds" on today's internet. Users don't care whether the code running on their device is Java vs. Javascript if the end result is the same. All you're promoting with "put DRM in HTML" is for all the horrific things you dislike about native apps to be allowed to infect the web.

You're fighting the wrong battle. It's not "make sure the web wins over native apps" -- it's "make sure open wins over corporate oligarchy." DRM is the opposite of open. We should not allow DRM to be in HTML. We should not allow it to be in operating systems. We should not allow it to be anywhere -- content providers who claim they won't sell their content without DRM are just lying. Make their choice "no DRM or no distribution method" and they'll pick no DRM.

Re: The W3C's plan for DRM in HTML5 is a betrayal for all web users

#92
post #71

Earlier quoted context omitted.

See below: https://news.ycombinator.com/item?id=5599601 DRM by definition implies security and privacy risk. Focusing on minor issue (native plugin) while ignoring the major one (DRM) sounds strange. And in reality this whole EME thing won't even remove native DRM code. It just will hook it into JavaScript. The risk caused by DRM won't get any less than it is already.

>>Focusing on minor issue (native plugin) while ignoring the major one (DRM) sounds strange. I don't think it is a minor issue at all. My biggest complaint with flash has been the security vulnerabilities, and I trust Google/Mozilla with web encryption WAY more than I do Adobe. Can you explain why you consider it to be such a minor issue? >>And in reality this whole EME thing won't even remove native DRM code. It jus…

It's a minor issue comparing to the issue of DRM. You say - let's worry about plugins, while users will agree to use DRM anyway. I say - if user agrees to use DRM, user can as well use native plugins - such user doesn't care about security or privacy already and there is no point to drag that issue into HTML at all.

I don't think it is a minor issue at all. My biggest complaint with flash has been the security vulnerabilities, and I trust Google/Mozilla with web encryption WAY more than I do Adobe. Can you explain why you consider it to be such a minor issue?

I don't really understand why you at the same time ready to trust some balck box DRM code from Netflix or whoever. Which can do anything of this sort: https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootk...

Re: The W3C's plan for DRM in HTML5 is a betrayal for all web users

#93

Consumers don't care about implementation, they only care about the content, and until they do, suppliers of content hold all the cards. There is nothing to be won by resisting hooks for DRM in the browser however appealing it seems to take a principled stand. The content suppliers will gleefully go with native apps, flash, silverlight, even Emscripten-cross-compiled codecs. With content consumption going mobile, the…

Emscripten cross-compiled codecs are better than black-box, closed source DRM codecs built into partially or fully proprietary browsers like Chrome and Internet Explorer. Do you really think a DRM plugin would ever work in Firefox or Chromium? If they really want to ship DRM, they can do it using the same tools everyone else uses, without special monopoly-preserving treatment or 'protected media paths' or kernel hook…

The problem is that they know as well as we do that DRM doesn't work

Unfortunately, as much as some of us would like that to be true, it seems very unlikely. DRM isn't some binary thing where either it prevents copying 100% or it doesn't; it's a deterrent. It works as long as it stops/delays anyone from copying the product illegally so they get it through a legitimate channel instead. It works and is cost-effective if it does that to enough people that it saves more money than it costs in implementation expenses and any loss of good will. On the evidence to date, that loss of good will doesn't seem to translate into much actual loss of custom once the bitching dies down, presumably because most of the people doing the bitching were never going to pay for the material anyway, so it's a relatively low bar for DRM to be economically viable.

The reality is though, adding DRM to browsers produces no value for anyone other than the lazy big media companies that can't adapt to the modern world.

Of course they can't. The law in most places is set up so the content producer's side of the bargain is clear, but that law is not enforced to make sure that everyone else keeps up their side of the bargain too.

Lots of people post on forums about how these companies need to "adapt their business models". Approximately 100% of those people also enjoy content made by the "lazy big media companies" in question under their current business model, which is becoming less effective. Wanting cheap/free access to that content by making sure that the legal/economic framework under which is was produced continues to be circumvented is a Faustian bargain. It's not sustainable. But no-one seems to be having much success with ideas for alternative business models so far.

Of course there will probably always be mass market films or pop music or sports games that will reliably make a profit even under these conditions. However, the same conditions are toxic to smaller, independent content producers who might have done something innovative or catered to a niche market. Next week the same consumers who object to DRM and dying business models will be complaining that modern AAA games are all derivative titles in long-running series, the SyFy channel doesn't show much good sci-fi any more, the latest Hollywood blockbusters are mostly SFX, action scenes, and attractive young stars whose acting abilities are debatable, and it's getting harder and harder to buy a general purpose computer and run your own software on it instead of buying a device that is already locked-up to some degree the moment you take it out of the box.

Re: The W3C's plan for DRM in HTML5 is a betrayal for all web users

#94
I don't see the big deal.

Right now DRM depends on proprietary plug-ins. If this is allowed in HTML5, DRM will still depend on proprietary plug-ins.

What is different?

edit: also, browser vendors don't have to implement it if they don't want to. Really, I don't like this DRM thing that much, but I am kind of indifferent to this.

Re: The W3C's plan for DRM in HTML5 is a betrayal for all web users

#95
post #6

DRM is based on obfuscation at the core. How would this ever work with open source browsers?

It wouldn't. The explicitly stated plan from the people who originated this proposal involves proprietary browser plugins.

Then it would only be a matter of hacking one browser to claim to support drm scheme x and then not to get it to work. Since we have to distribute the run time in at least one browser, this shouldn't be a problem.

Re: The W3C's plan for DRM in HTML5 is a betrayal for all web users

#96
post #71

Earlier quoted context omitted.

See below: https://news.ycombinator.com/item?id=5599601 DRM by definition implies security and privacy risk. Focusing on minor issue (native plugin) while ignoring the major one (DRM) sounds strange. And in reality this whole EME thing won't even remove native DRM code. It just will hook it into JavaScript. The risk caused by DRM won't get any less than it is already.

>>Focusing on minor issue (native plugin) while ignoring the major one (DRM) sounds strange. I don't think it is a minor issue at all. My biggest complaint with flash has been the security vulnerabilities, and I trust Google/Mozilla with web encryption WAY more than I do Adobe. Can you explain why you consider it to be such a minor issue? >>And in reality this whole EME thing won't even remove native DRM code. It jus…

>I don't think it is a minor issue at all. My biggest complaint with flash has been the security vulnerabilities, and I trust Google/Mozilla with web encryption WAY more than I do Adobe.

Why do you think Google or Mozilla would be the ones to implement the black box in the DRM? Firefox is developed by a community. The process is public and anyone can identify or patch vulnerabilities -- that's why the security is good. You expect Mozilla to devise and implement some DRM scheme? The actual DRM would end up being created by someone like Adobe again and have all the same security vulnerabilities, because the wider developer community couldn't be allowed to be privy to how it does what it does or it wouldn't be DRM anymore.

One of the problems with DRM is that pretty much anyone who understands security will laugh at you for thinking you can implement effective DRM, so it ends up being built by snake oil salesmen who don't know what they're doing. I don't see how putting it into HTML would change any of that -- all it would do is pollute HTML and encourage the proliferation of more bad code.

Re: The W3C's plan for DRM in HTML5 is a betrayal for all web users

#97
post #63

Earlier quoted context omitted.

(reply to below). Only if you consider DRM unethical. I don't consider non-free software, or DRM software unethical. I consider it shitty, and I am free to ignore it if I want. You don't have any "right" to non-DRMed content. I say this as a person who hates DRM and who spent most of my youth cracking copyright disk protection on 8 and 16-bit software. I don't have a single atom of love for it, but software producers…

I consider DRM unethical, but even besides that, it by definition implies privacy and security risk. You can't have safe DRM. I'd say producers aren't within their moral rights to push preemptive policing on people. That's where the unethical aspect comes in.

You can't have safe DRM. I'd say producers aren't within their moral rights to push preemptive policing on people.

It's hardly preemptive. People have been illegally ripping off content since forever, and they've been doing it on a potentially business-destroying scale since the Internet became popular. The official law enforcement bodies conveniently sidestep the whole issue by making copyright infringement a civil rather than criminal offence in most places, which also transfers the burden of enforcement onto the copyright holder in most cases, and then the costs of actually bringing a case to court over someone ripping off a $10 movie are prohibitive. The normal mechanisms that are supposed to protect someone who has been wronged under the law have failed.

The content producers are now saying that if you want their content, you have to let them include technical measures to protect their rights because the legal system mostly doesn't. What other choice has society left them? You are still free not to consume their content and the accompanying DRM by buying something else... assuming, of course, that there is a viable business model to produce that "something else" instead.

Re: The W3C's plan for DRM in HTML5 is a betrayal for all web users

#98
post #72

Earlier quoted context omitted.

How can the "lazy big media companies" adapt? What's the DRM-free business model that would allow them to produce the blockbuster movies that are apparently still quite popular with the public?

This. While I don't like DRM, I feel like this boxing out of DRM-using media companies is pointless. Consumers continue to subscribe to media sources they find convenient and many use DRM. This may not last forever, but I'm inclined to vote bring all these people into the fold on the modern web so it's a place for everyone. Nobody's forcing anybody to use DRM.

I think the point is more nuanced than that. It's not that DRM doesn't belong on the web, but it doesn't belong as an integral part of the web and web components. There are already well-specified mechanisms like and NPAPI/ActiveX plugins that you can use right now to ship encrypted video if you want.

The cost of every single feature added to the Standard Web is tremendous and we pay that cost forever. By that standard alone, adding a feature like DRM video to serve the demands of an enormous, incredibly powerful, incredibly rich lobby is ridiculous. There are simply much better problems to be solved with less downsides.

So, to try and rephrase it: The question here isn't whether these people should be 'brought into the fold' on the modern web; DRM is intrinsically at odds with the modern web (and the web we've had before), both in concrete purpose and in the more nebulous philosophical ways. A major strength of the web has always been its ability to open doors and put powerful tools in the hands of everyone, and encrypted/protected video limited to certain platforms/devices just fundamentally runs counter to all of that.

Re: The W3C's plan for DRM in HTML5 is a betrayal for all web users

#99
This is because all you dummies were too busy lauding Google's services and nobody notices how "evil" they are.

This came as a proposal from Google. It was tested in Chromium first. The DRM is essential for their "World-saving" ChromeOS that nobody really cares about.

Re: The W3C's plan for DRM in HTML5 is a betrayal for all web users

#100
post #94

I don't see the big deal. Right now DRM depends on proprietary plug-ins. If this is allowed in HTML5, DRM will still depend on proprietary plug-ins. What is different? edit: also, browser vendors don't have to implement it if they don't want to. Really, I don't like this DRM thing that much, but I am kind of indifferent to this.

>What is different?

That's kind of the point. The people promoting this seem to be misunderstanding what the result would be. It would in no way reduce the amount of poorly written proprietary code full of security vulnerabilities. It would just move it around a little.

But in the meantime it breaks the web. Even if you support the new HTML5 spec, you can't actually support it without having the proprietary black box necessary to make it work. You break the ability of the web to be platform agnostic. For the web to work at all you'll soon end up needing the black box, because once it's there sites will use it. So if the black box doesn't exist for your platform or you want to create a new platform then you'll be locked out of most of the web. How can that be acceptable?

Post reply on HN