Live data from Hacker News

EFF Makes Formal Objection to DRM in HTML5

eff.org

211–220 of 280 posts

Re: EFF Makes Formal Objection to DRM in HTML5

#211
post #69

Earlier quoted context omitted.

It's not correct for W3C to enforce policies that are worth billions of dollars to big companies at the average user's expense.

That's the thing, though. It's not at the average user's expense. It's only at the technological idealist's expense. The average user is in fact benefited greatly by having an open, standardized approach, because it increases the likelihood that things will Just Work™.

I disagree. At the moment, companies have a point of competition on their licensing agreement with customers - exactly what license they allow, and how exactly they choose to enforce it.

That there is competition (and that the market cares) is evident in the fact that iTunes have removed FairPlay DRM from music tracks.

To have an open standard for DRM removes some of this competition point: a win for big incumbents and a loss for consumers.

Re: EFF Makes Formal Objection to DRM in HTML5

#212

Earlier quoted context omitted.

It seems that those making the most noise over this haven't spent the requisite 2 minutes reading the actual proposal. https://dvcs.w3.org/hg/html-media/raw-file/tip/encrypted-med... From the abstract: "This specification does not define a content protection or Digital Rights Management system. Rather, it defines a common API that may be used to discover, select and interact with such systems as well as with simpler…

The fact that you can build a browser which doesn't support DRM doesn't alter that fact that if we allow this in, W3C has officially sanctioned that the web, one bit and one platform at a time, can and shall be DRMed. So sure. You can build a browser which only supports clear key. And that browser will not be a fully supported browser on this new encrypted and DRMed web. No FOSS-based platform will be a viable option…

Hollywood doesn't need nor care about the web or the w3c apart from as a marketing avenue. They would be just as happy delivering all content through a standalone application, as they are doing currently.

Most likely the new generation of games consoles provides a more compelling platform for them to send content to you than a web browser.

There are no "CDMs in HTML5" , this is a nonesense statement.

There is no part of the proposal that advocates for any website to integrate any DRM solution, it is entirely a matter for individual site owners, the majority of whom do not want to put up hurdles for people to view their sites. The web will continue to work as it always has.

Re: EFF Makes Formal Objection to DRM in HTML5

#213

Earlier quoted context omitted.

Yes, you can. You are free to support whichever content protection systems you want to support. The only DRM mechanism which is part of the standard is clearkey which is DRM in the same way that SSL is DRM, i.e not at all. https://news.ycombinator.com/item?id=5791579

You mean you are free to implement a second class citizen on this new, closed down and Hollywood-driven web. Yeah. That sounds really sexy. That sounds like the pinnacle of achievements for open standards.

Hollywood does not have jurisdiction over the majority of web. They cannot force you to use DRM.

Re: EFF Makes Formal Objection to DRM in HTML5

#214
post #204

Earlier quoted context omitted.

Not at all, your browser does not need to be sanctioned. Anybody can build a browser that speaks HTTP and can send HTML pages around. There is no mandate that you integrate DRM to be standards compliant, it's perfectly valid to write a browser that simply says "no" to any requests to perform DRM functions. https://dvcs.w3.org/hg/html-media/raw-file/tip/encrypted-med... You can simply implement a "clear key" system wh…

That misses the point. While anybody can built partial web-browsers, they can't build competitive alternatives to those sanctioned by DRM-vendors. Just speaking HTTP and partially parsing HTML pages does not a web-browser make.

> While anybody can built partial web-browsers, they can't build competitive alternatives to those sanctioned by DRM-vendors.

That's true, but it's not connected to the w3c inclusion in the spec.

People hosing DRM encrypted video could stop your third-party browser from consuming their video with or without the w3c spec provision.

Re: EFF Makes Formal Objection to DRM in HTML5

#215
post #208

Earlier quoted context omitted.

It seems that those making the most noise over this haven't spent the requisite 2 minutes reading the actual proposal. https://dvcs.w3.org/hg/html-media/raw-file/tip/encrypted-med... From the abstract: "This specification does not define a content protection or Digital Rights Management system. Rather, it defines a common API that may be used to discover, select and interact with such systems as well as with simpler…

Such API will encourage more DRM to be access through the browser, which in turn lets malware exploit such vectors in similar way that Java applets, active X and flash has been plagued by remote code exploits. The amount of money and greif caused by such malware is very high, and was a major incentive for moving to HTML 5. The draft in question would rather move so we had 10-20 more such lovely (in)secure plugins all…

Just disable the plugins or don't install them in the first place.

Re: EFF Makes Formal Objection to DRM in HTML5

#216
post #133

Earlier quoted context omitted.

People hate DRM because it gives the content producers too much power, and then they treat consumers like muppets: http://neosting.net/wp-content/uploads/2012/05/pirated_vs_le... The Internet has shifted a huge amount of that power back to consumers (especially technically savvy ones), so it's understandable that something needs to change. It's also obvious that producers can't create decent content if they don't get…

I see people often saying to vote with your wallet and then go illegally download whatever movie, TV show, videogame or piece of software—which I find kind of funny. Why don't people vote with their time? Don't watch something, for example. I suppose the main thing I find funny is how outrageous people become when something isn't provided which seems trivial to life. I live in Australia where it seems we are one of t…

>People here, and elsewhere, act as if having a TV show is a basic human right and necessity. Who cares if you can't watch a TV show?

Maybe your friendships and interests are such that you don't feel you need to. Good for you. But that's not true for everyone, and flippant solutions like "get better friends" aren't always practical or desirable.

>They say they would buy everything if it was available in a way that jives with them and postulate that the masses will run out and buy everything.. and maybe they will, but as one of the 'computer guys' when most people ask about how to use torrents and you ask them why they want to know usually they just want to get something without paying for it.

So your anecdote disagrees with other people's anecdotes. That happens. Is there any actual evidence in either direction?

Re: EFF Makes Formal Objection to DRM in HTML5

#217
post #43

I've made this point already on the W3C CEO's blog, but it bears repeating here: DRM removes control of certain aspects of a device that I own, and places it in the hands of another. It does so in a manner that could not be less trustworthy: most DRM solutions are proprietary, closed-source applications. This means that I can't rely on others to audit it for me (as with FOSS) and I can't audit it myself. Some DRM imp…

DRM allows you to volontarily give up whatever control of your machine you're talking about. As painful as it is, one part of living in a capitalist society is to exercise your right/power as a consumer. Don't like it? Don't use it. To me, DRM is not something that infringes on your freedom, though I'm very glad we have the EFF when they spend their time combatting things like surveillance, that are not opt-in.

>> DRM allows you to volontarily give up whatever control of your machine you're talking about.

Sometimes excluding an option creates better outcomes.

Example: you cannot become someone's lifelong slave in America, even if you voluntarily agree to it; The agreement is not legal. Not allowing you this option also protects you: if you could do it voluntarily, you could be coerced into volunteering ("well, I see you can't pay your bank loan...").

Here's a possible scenario with DRM: If media companies can easily DRM video on the web, they will. Soon nearly all video on the web will have it. Goodbye, video options.

Also, new browsers who can't make the business agreements to use the DRM will effectively not support video on the web. Which means nobody will use them. Goodbye, browser options.

Cutting off the DRM option preserves video and browser options. I say we voluntarily give up the possibility of DRM to preserve other possibilities.

>> Don't like it? Don't use it.

Exactly the message I'd give to media companies concerning the open web.

Re: EFF Makes Formal Objection to DRM in HTML5

#218
post #204

Earlier quoted context omitted.

That misses the point. While anybody can built partial web-browsers, they can't build competitive alternatives to those sanctioned by DRM-vendors. Just speaking HTTP and partially parsing HTML pages does not a web-browser make.

Yes, you can. You are free to support whichever content protection systems you want to support. The only DRM mechanism which is part of the standard is clearkey which is DRM in the same way that SSL is DRM, i.e not at all. https://news.ycombinator.com/item?id=5791579

You are free to implement whatever content protection systems the developers of the content protection systems allow you to implement, so long as it doesn't conflict with their contracts with content providers (which it probably will in many cases).

The HTML5 ECE spec is intended to make sure it's a criminal offence to implement any "content protection" scheme without permission. In the eyes of both W3C and its proponents, that's a non-negotiable feature.

Re: EFF Makes Formal Objection to DRM in HTML5

#219

Earlier quoted context omitted.

But this standard - EME - isn't for CDMs, it's for the interface between CDMs and Javascript. So yes, your Linux-based browser might well have EME support. But if the company who makes the DRM CDM doesn't support Linux, you're out of luck. The existence of the EME standard does not in any way increase the likelihood of DRM vendors supporting any more platforms than they do now.

It does make it easier to add support to new platforms, though. If Linux support is just a recompile with a different compiler away (supposing the browser/plugin interface is a simple C API with no GUI), it's more likely to happen.

The point of HTML5 ECE is to tie into OS-level and hardware-level DRM facilities, so in practice it's going to be far harder to port than existing solutions.

In fact we can see this happening already. Netflix supports multiple DRM schemes, one of which is based on the draft HTML5 ECE standard and is used on ChromeOS. Apparently, both the Silverlight-based player and the Android-based player can be used to watch Netflix on ordinary desktop Linux. The ChromeOS one, on the other hand, only runs on authorised Google-provided hardware and only if you don't enable developer mode; no-one's managed to bypass this yet.

Re: EFF Makes Formal Objection to DRM in HTML5

#220
post #218

Earlier quoted context omitted.

Yes, you can. You are free to support whichever content protection systems you want to support. The only DRM mechanism which is part of the standard is clearkey which is DRM in the same way that SSL is DRM, i.e not at all. https://news.ycombinator.com/item?id=5791579

You are free to implement whatever content protection systems the developers of the content protection systems allow you to implement, so long as it doesn't conflict with their contracts with content providers (which it probably will in many cases). The HTML5 ECE spec is intended to make sure it's a criminal offence to implement any "content protection" scheme without permission. In the eyes of both W3C and its propo…

How is it a criminal offence to implement a content protection scheme? Who's permission does one need?

If I write a content protection scheme that runs everything through ROT13 I don't understand why anyone would care.

Post reply on HN