Live data from Hacker News

W3C green-lights adding DRM to the Web's standards

boingboing.net

171–180 of 314 posts

Re: W3C green-lights adding DRM to the Web's standards

#171
post #51

Earlier quoted context omitted.

In most DRM systems the information is distributed encrypted. The decryption keys are given to technology developers who have specifically promised to obey the DRM rules, as well as to make their technology hard for users to understand or modify so that the users can't easily undo the restrictions or extract the decryption keys. Hence a browser developer or OS developer or developer of whatever software is in questio…

I see no way how an open source system can implement any effective DRM standard while staying open source. If a proper open source system has a component that enforces DRM, and is functional when I download it, then it includes those keys; but gives me an unconditional right to use and modify it. And I am physically able to modify it, un-implementing those restrictions. If part of the system cannot be modified by me,…

I agree. In previous discussions about this, some people emphasized the idea of open source development, as opposed to giving an open source software to an end user. For example, you could run a binary through an obfuscator after compiling in a decryption key -- from source code that had been published and distributed under an open source license. If the license isn't a reciprocal/copyleft license, this is probably not a license violation, but it seems wrong to say that the user who receives the binary is being given open source software.

This issue reflects the way that people have had very different ideas about what the point or purpose of free and open source software is (in some ways, reflecting the split between people who preferred to say "free software" over "open source" and vice versa).

It's also a very concrete issue today in whether people call, say, the Chrome browser "open source". Most of their source code is downloadable, derived from the fully open-source Chromium project, but in Google's current practice, users never get the complete source code to the Chrome binaries that they run. If you're focused on the development process, it might almost make sense to call Chrome "open source" because almost all of its source code is distributed, licensed, and developed in an open source manner -- but if you're focused on what users can do with the software, it's obviously just a proprietary application (with a proprietary EULA, to boot).

Re: W3C green-lights adding DRM to the Web's standards

#172
post #112

Ok, it sounds to me like this is way, way, over blown. First, the DRM is NOT going to be built into the browser it self. It's basically a new name for a plug in system, nothing more. So, to everyone who thinks they can roll their own browser and avoid the DRM, no you will not be able to. It's not bad or good for consumers, at best, it's about the same. It's very simple, studios will not allow you to rent their movies…

Actually Netflix and Stream could both operate without DRM. If content providers don't want to provide their content to open systems, that is their concern, not that of the middle men. Adding a DRM standard just placates to corporate wishes to control content. This has the chilling effect to prevent fair use, or worse it can be used to lock up content that should otherwise be open and free.

Re: W3C green-lights adding DRM to the Web's standards

#173

Earlier quoted context omitted.

I see no way how an open source system can implement any effective DRM standard while staying open source. If a proper open source system has a component that enforces DRM, and is functional when I download it, then it includes those keys; but gives me an unconditional right to use and modify it. And I am physically able to modify it, un-implementing those restrictions. If part of the system cannot be modified by me,…

> If part of the system cannot be modified by me, then the whole is not open source "Open Source" definition does not include any clauses that require hardware manufacturers to provide you encryption and/or signing keys, so you could run your code. GPLv3 and "Free Software" are what you're looking for.

The Free Software Definition doesn't require free software to be copylefted or to include measures against TiVoization or against proprietary or restrictive downstream products. GPLv3 does this and the BSD license doesn't, and both are free software licenses.

As I said in another comment, people who usually say "free software" are more likely to think that preventing restrictive downstream products is an important goal than people who usually say "open source". But that doesn't mean it's part of the definition of what it means to be free software.

EDIT: I also think the comment the parent replied to was right to say "then the whole is not open source". BusyBox is both free and open source even though its license allows it to be included in the locked-down TiVo -- but the TiVo as a whole is not open source.

Re: W3C green-lights adding DRM to the Web's standards

#174
Just have a label in Firefox that says:

CLOSED SOURCE

icon

on top so that we know we are about to visit a site where we can't see the source of the javascript that is being run on our computer.

The idea is to develop a culture for people to prefer OPEN SOURCED site vs a CLOSED SOURCED one.

Re: W3C green-lights adding DRM to the Web's standards

#175
post #141

Earlier quoted context omitted.

It was your own suggestion that spawned this thread. You wrote: "I may be totally naive here, but I'm not really sure why this matters. That there is a WC3 standard does not imply that browsers have to adhere to it." - https://news.ycombinator.com/item?id=6491428 marcosdumay is responding to that by saying "It matters because ..."

Sorry, fair point. My point that you quoted was that anyone could roll a browser that did not include the DRM standard (or any standard for that matter). And many do already. I don't think this implies that the W3C is dead.

anyone could roll a browser that did not include the DRM standard

And how many people will use it, apart from outliers like people who post here? The vast majority of people use one of the Big Three: Firefox, Internet Exploder [no, that's not a typo ;)], and Chrome.

Furthermore, if the Big Three implement a DRM standard, then web pages that want to "protect their content" will simply use the DRM standard, and it won't matter that Joe's Really Cool Browser doesn't implement it; that browser simply won't be able to view the pages. A few outliers like us will rant and rave; anyone else who tries it will say "Joe's Really Cool Browser Sucks" and go back to using one of the Big Three.

Re: W3C green-lights adding DRM to the Web's standards

#176
post #25

Earlier quoted context omitted.

If it's just going to end-up plug-ins, I don't understand why DRM is being treated specifically at all instead of tweaks to the existing general-purpose plug-in architecture. If you want DRM, deal with Microsoft Silverlight or Adobe Flash or roll your own.

You can, of course folks have, but then you can't use the video/audio tags. (or you need a pretty significant js shim)

But this still effectively limits the rendering of content to blessed implementations. Why introduce a standard that isn't open when there are already other options.

Re: W3C green-lights adding DRM to the Web's standards

#177
post #65

Earlier quoted context omitted.

> The issue is that some big name content providers don't want to sell you content unless they can also install things on your computer. This fact remains regardless of the technological implementation details. Sure, but we don't have to aid them in their quest > The overwhelming majority of content on the web is DRM free. These proposals do not mandate nor give any incentive for that content to be protected if it is…

"As it is now, businesses have to balance the cost of losing customers against the cost of not being able to DRM their content. Take that dilemma away and I think you certainly have a new incentive." And the businesses (Hollywood) with the content that Web users want have done that math and decided that DRM through plug-ins and native apps is an EXCELLENT system and they're happy to keep mandating it forever. If Plug…

If the Web cannot give them the content they want, they'll get it elsewhere, probably from silo'd App Stores where things "just work."

And in this scenario (i.e., the way things are now), someone like me, who doesn't give a shit about "content" but does care about the Web itself, can still avoid DRM by not installing the plugins, not using the silo'd App Stores, etc. But if my browser is the silo'd plugin/App Store, I'm SOL. That is why all this matters: it makes DRM and all of the closed source nastiness that goes with it the default, instead of something people have to choose. I think that's a very, very bad idea.

Re: W3C green-lights adding DRM to the Web's standards

#178
post #36

Earlier quoted context omitted.

What is the WHATWG's position on this? They represent the browser makers. If they support DRM then it's game over. Another break-away standards group won't be able to do anything to sway the browser makers. What could they do?

Consider that three of the largest browser makers -- Microsoft, Apple, and Google -- all have arms that deal heavily with media companies. I dislike DRM as much as the next person, but if it's implemented reasonably (think Steam or Netflix), then many consumers are willing to deal with it. EME was what enabled Netflix on ARM-based Chromebooks, for example; and I prefer EME to not being able to legally access media at…

I prefer EME to not being able to legally access media at all.

In other words, you are willing to give up freedom to get--what, exactly? Movies? Music? Eye candy?

I confess I simply can't understand this point of view. People are willing to hand over the Internet to DRM and the media corporations because they can't live without the "entertainment" that Hollywood provides? People are willing to have their computers pwned just so they can watch Netflix? That appalls me.

Re: W3C green-lights adding DRM to the Web's standards

#179
post #129

Earlier quoted context omitted.

Browser vendors don't have to implement any DRM scheme, but they will and sites will use them. What this means in practice is that there will be 100% standards compliant, pure HTML5 websites that can only legally be rendered in specific, proprietary browsers. The stated purpose of HTML5 EME is to make it a criminal offence under the DMCA anti-circumvention clause to develop an unauthorised browser or extension that d…

If anything it's the opposite. Defining a standard interface for content decryption allows such a system to be browser agnostic. You install a module and it works in any browser which implements the spec, whether proprietary or open source.

Unless they've changed it since I looked, the only interface the HTML5 EME specification defines is the one between the website and the browser. There is no standardized interface between browsers and DRM modules, nor is there any requirement browsers support external content decryption modules. For example, last I heard IE was only going to support a built-in implementation of Microsoft's PlayReady which isn't available to anyone else.

In fact it's not clear that anyone can use a standardized, open API for decryption modules and meet content providers' security demands. While some of them were historically willing to use Flash which did use standard browser APIs, they've taken this as an opportunity to demand more.

Re: W3C green-lights adding DRM to the Web's standards

#180
post #64

I don't understand why everyone is up in arms about this. Some content cannot go anywhere without DRM. That's not going to change. Do you think the Universal is just 6 months away from streaming the latest blockbuster with VP8 in a video tag? Right now we have Flash and Silverlight everywhere and it's a PITA. How open are those two? This adds the option of moving this stuff out of plugins. If you want to live in some…

> Do you think the Universal is just 6 months away from streaming the latest blockbuster with VP8 in a video tag?

They should be. Because I'm going to continue getting my DRM free video from the Pirate Bay until they do. They might have a chance at revenue if they'd just get over themselves. Dinosaurs.

Post reply on HN