Live data from Hacker News

Why Rosyna Can't Take a Movie Screenshot

alexrad.me

151–159 of 159 posts

Re: Why Rosyna Can't Take a Movie Screenshot

#151

Earlier quoted context omitted.

What do you think they mean when they say "Data should be free!" Even a cursory look at their position that places like pirate bay should be allowed to be openly run would lead to creators not getting compensated. Of course if pressed on it, they'll say, "oh, they can work on donations or whatever people feel like paying." But that's forcing content creators to act like street beggars. Like a movie theatre is going t…

You keep putting up a silly proposition just to argue against it. I know it's easier for you, but it's also intellectually dishonest. I've had a small bit of dealings with political "pirates", and I have yet to encounter the position you describe. "Information wants to be free" (which I guess you really mean) is really an old catch phrase more associated with the cyber liberty movement of the early 90s and the crypto…

"movie theaters should be free to license movies outside the distribution agreements."

I'm not sure I understand what that means. Any deal they make to license the movie is a distribution agreement, by definition.

Re: Why Rosyna Can't Take a Movie Screenshot

#152

Earlier quoted context omitted.

The goal of DRM is not to kill piracy 100% and anything else is abject failure, it's to raise the cost of engaging in piracy to the point where just buying the movie seems easier and cheaper.

You can say that, but the fact that they do things like HDCP (normal users aren't going to do multi gigabit/s raw captures) would speak otherwise. Engaging in piracy is as simple as a search and download. Unless this tech works 100%, piracy will always remain that easy.

The idea is if only a handful of professionals are uploading high quality rips, then it becomes feasible for law enforcement to investigate and take them down. Sort of like professional DVD pirates where they have actual pressing plants. If everyone is uploading stuff from home, it's harder.

Regardless, they didn't stop at HDCP. Check out Cinavia for an interesting approach to closing the analogue hole.

Re: Why Rosyna Can't Take a Movie Screenshot

#153
post #110

Earlier quoted context omitted.

DRM is absolutely to do with piracy, that's the whole point of the technology. Of course Hollywood knows that any given DRM scheme will be broken at some point . How much they care about this depends a lot on what exactly "at some point" really means. Almost all money from movie sales comes in a spike when the movie is first release, hardly any movies go on to become long-term cult classics that people are still buyi…

"DRM is absolutely to do with piracy, that's the whole point of the technology." DRM's stated goal was dealing with piracy, 20+ years ago. That does not mean that that is what it does now. Goals aren't results, to say nothing of the fact that goals 20 years ago aren't necessarily goals today. It is highly arguable that, given that it has failed to stop piracy comprehensively, that its primary utility to the people th…

Either we'd see a great deal more investment into DRM than we do now to the point where it could actually be relied upon [1], or it would get dropped to save money.

... or studios have found a sweet spot they're happy with (or at least, not totally unhappy with) where spending more on DRM wouldn't be justified by the incrementally smaller increase in sales.

i.e. if you double your spending on your copy protection and it lasts an extra week before getting cracked, how much that extra weeks worth of sales is worth depends a lot on how many previous weeks there were before the crack. At some point the ROI curve stops making sense.

I suspect it's not pure business though - people in the media live off their creativity and seeing people pirate your stuff can be emotionally difficult. I would not be surprised if some places over-invest in DRM because they feel a moral and emotional imperative to defend their work from piracy as much as they can.

BluRay DRM is probably as good as you can technically get for movies distributed on discs. For movies distributed via the internet it's easier. But the economics of DRM are tricky - the key thing that hurt BluRay DRM (and the designers were fully aware of this problem) is that movie producers have a strong financial incentive to push player prices low, and player manufacturers have a strong financial incentive to push movie prices low. Movies and players are "compliments" of each other in the economics jargon. Not surprisingly, player makers make the absolute minimal effort when it comes to DRM and that's one reason why cracks keep happening.

One of the most obvious tension points here is PC software players. They're much harder to defend. But they increase the size of the player market (and therefore the movie market) a lot. So movie studios ended up deciding to allow them, despite knowing it'd weaken the DRM.

BD+ was designed to try and resolve this problem by allowing movie producers to spend the money on copy protection rather than player manufacturers, and it was remarkably effective for a long time. BD+ ended the era of open source players for good, only full time reversing teams that are willing to keep up continual effort on a disk-by-disk basis can break it. But in the end it wasn't enough for a fully convincing solution.

Re: Why Rosyna Can't Take a Movie Screenshot

#154

Earlier quoted context omitted.

You keep putting up a silly proposition just to argue against it. I know it's easier for you, but it's also intellectually dishonest. I've had a small bit of dealings with political "pirates", and I have yet to encounter the position you describe. "Information wants to be free" (which I guess you really mean) is really an old catch phrase more associated with the cyber liberty movement of the early 90s and the crypto…

"movie theaters should be free to license movies outside the distribution agreements." I'm not sure I understand what that means. Any deal they make to license the movie is a distribution agreement, by definition.

The deals underlying movie distributions are cut once or twice a year, mostly at trade conferences. It's not something the theaters are privy to. You are normally not allowed to license elsewhere unless you care to lose your distributor. It's something that plagues many independent theaters, at least in Europe.

It's all a bit of a power play over their heads and it's one of the reasons why you can't start an online streaming service in today's environment, which was one of the questions that was relevant to the political pirates last I've heard from them.

I don't know much more because I'm out of touch with the whole piratism thing, I just wanted to correct the "why u no pay" attitude earlier. It's a bit silly to think they could have reached parliamentary representation on that party line, and slightly condescending to everyone involved.

Re: Why Rosyna Can't Take a Movie Screenshot

#155

Earlier quoted context omitted.

Exactly, this is the main problem I have with the people who claim in comment sections across the internet that since I'm only paying for a license to play the content, I can't complain about owning it. Nowhere on the iTunes store does it say, "Click here to purchase license to play video". Not on Amazon or Google Play either. This is just a case of false advertising by content producers and distributors. If they can…

While that is a reasonable question, a even more reasonable question would be why are they allowed to cheat you and why do you have to cheat them back in the first place?

Sorry for the late reply, but I was simply framing my response in the context of the current situation, where if I want the right to play content that I purchased, then I basically have to resort to 'cheating'. Since I was misleadingly led to believe that I was purchasing the content itself, and not merely a right to play it within some closed box, I was cheated. I then have to resolve to cheating to regain what I believe I lost.

If politicians took a stronger stand against the tactics of media companies, then I most likely wouldn't need to cheat.

Re: Why Rosyna Can't Take a Movie Screenshot

#156
post #110

Earlier quoted context omitted.

"DRM is absolutely to do with piracy, that's the whole point of the technology." DRM's stated goal was dealing with piracy, 20+ years ago. That does not mean that that is what it does now. Goals aren't results, to say nothing of the fact that goals 20 years ago aren't necessarily goals today. It is highly arguable that, given that it has failed to stop piracy comprehensively, that its primary utility to the people th…

I think you attribute your own goals to the DRM. I, for one, don't believe DRM is there to prevent all and any copyright infringement through technical means. It works very well against casual copying. Even Macrovision for VHS did, despite being cracked. It has no means to prevent e.g. unlicensed public performance though. Neither it's aiming at preventing unlicensed distribution on non-DRM platforms, which you seem…

"I think you attribute your own goals to the DRM."

Impossible. I have no goals for DRM, except maybe to see it die. While I do not believe that DRM is currently related to piracy, it is hardly a bizarre idea that it is intended to restrict piracy... that is the stated goal.

Re: Why Rosyna Can't Take a Movie Screenshot

#157
post #98

Earlier quoted context omitted.

As far as I know the DRM on DCPs (Digital Cinema Package) isn't broken. Yet. Maybe because relatively few people have access to the encrypted content. I guess the most important thing for the movie industry is to have the cinema window free from pirated copies.

Where/how is this used? I ask because screeners are definitely a thing.

DCP is the format in which movies are distributed to theaters, usually on hard drives but sometimes over satellite or wired networks.

Re: Why Rosyna Can't Take a Movie Screenshot

#158
post #145
post #136

Earlier quoted context omitted.

Please take the conspiracist nattering somewhere else. As explained in the second paragraph of the article, the features of IME were requested by large corporate IT departments and pushed mainstream by marketing pressure, with the addition of DRM bits as requested by the large tech vendors who need them to negotiate licenses with members of the copyright cartel. You look at this and see a secure rootkit. A corporate…

Anyone who requested the feature of "able to send and receive packets which are not seen by the OS" is either not really asking, or should be told no. I mean, even if I have a pfSense or whatever box running in between, if I'm reading this correctly, there could be packets traversing the network I can't see? And all of this has a "zero-touch" configuration capability. You know what that means, right? The two together…

You're misunderstanding is what's going on here: if you need something like lights-out management, which is a requirement in any decent large IT shop, you by definition have a separate processor running its own operating system. That's the whole point: you can use this to power on the machine and initiate something like a software install when it has no existing OS install or a severely broken one.

Since that needs network access you either have the expense of needing separate NICs and ports – common in the server space – or having some way for it to share the NIC with the primary OS, which is popular because it costs significantly less and doesn't require wiring two ports for every computer. It's the latter capability which gives it the ability to send packets without the knowledge of the main OS since the traffic isn't processed by it in any way.

Again: this certainly could be abused but the capability originated for quite benign reasons – every large organization with an even marginally competent IT department wants the ability to do things like reinstall a system without having to pay to send a tech on-site to hit a couple of keys.

Re: Why Rosyna Can't Take a Movie Screenshot

#159
post #158
post #145

Earlier quoted context omitted.

Anyone who requested the feature of "able to send and receive packets which are not seen by the OS" is either not really asking, or should be told no. I mean, even if I have a pfSense or whatever box running in between, if I'm reading this correctly, there could be packets traversing the network I can't see? And all of this has a "zero-touch" configuration capability. You know what that means, right? The two together…

You're misunderstanding is what's going on here: if you need something like lights-out management, which is a requirement in any decent large IT shop, you by definition have a separate processor running its own operating system. That's the whole point: you can use this to power on the machine and initiate something like a software install when it has no existing OS install or a severely broken one. Since that needs n…

I understand perfectly well the IT requirements. However, capabilities which originate for quite benign reasons but which allow complete, persistent, and undetectable system compromise are typically called "bugs".

For example, I don't have any issue with remote power control. A secure form of Wake-on-LAN is wonderful, as long as the public keys are fully enumerable and totally under operator control, and the feature can be decisively disabled if desired.

To your point about packet processing, to keep with the Wake-on-LAN example, it's perfectly easy to share a physical port and keep the traffic fully visible to the OS as well as a separate processor.

If a remote party has permission to completely own my system, I want to see their name (public key) listed every time the machine boots, like the warning you get any time you access a government system;

  You are accessing a [Company Name] information system, which includes (1) this
  computer, (2) this computer network, (3) all computers connected to this network, and
  (4) all devices and storage media attached to this network or to a computer on this
  network. This information system is provided for [Company]-authorized use only. 

  Unauthorized or improper use or access of this system may result in disciplinary 
  action, as well as civil and criminal penalties. 

  By using this information system, you understand and consent to the following:
  
  You have no reasonable expectation of privacy when you use this information system;
  this includes any communications or data transiting or stored on this information
  system. At any time, and for any lawful government purpose, the government may,
  without notice, monitor, intercept, search and seize any communication or data
  transiting or stored on this information system. 

  The government may disclose or use any communications or data transiting or stored on
  this information system for any lawful government purpose, including but not limited
  to law enforcement purposes. 
Such a warning, requiring an 'I Agree' click at each boot, would adequately explain the risks to end-users of having such a component active on their system. But apparently, the more common practice is to hide the prompt at startup (typically Ctrl-P) to enter the MEBx Configuration screens behind another BIOS setting.

I'm not an expert at vPro or Intel AMT by any stretch, but upon cursory investigation, it appears the trust model (a.k.a all you need to completely own a system) is an easily obtainable certificate, and control over the DNS and DHCP server. It looks like the only thing that protects a system beyond this is a vendor-specific "remote configuration timeout" which would have to be reset by a local agent after it has expired. [2, 3] However, some Intel documentation claims that TLS-PKI "...allows a client system to be provisioned with zero physical interaction. Remote configuration is ideal for systems that have already been deployed into an environment..." which implies some way to overcome the remote configuration timeout... (See 'Alternate Path #2' on footnote #5)

[1] - https://software.intel.com/en-us/blogs/2009/10/07/intel-amt-...

[2] - http://h10032.www1.hp.com/ctg/Manual/c03455054.pdf

[3] - https://communities.intel.com/docs/DOC-1989#SECFAQ8

[4] - http://downloadmirror.intel.com/21729/eng/RemoteConfiguratio...

[5] - https://software.intel.com/en-us/articles/intel-amt-use-case...

Post reply on HN