Live data from Hacker News

The Quest for Netflix on Asahi Linux

da.vidbuchanan.co.uk

251–260 of 293 posts

Re: The Quest for Netflix on Asahi Linux

#251

Anyone who knows some technical detail about Widevine, please could you explain what is the difference between L1 and L3 (other than resolution/quality)? How does each interoperate with EME? And what sort of process would one need to do, to be able to view an L1 stream on a bespoke Linux distribution, rather than the L3 stream that this person received? How difficult is it to do, and what are the specific challenges?

EME is just an API to access the native code.

Levels are primarily about various kinds of hardware protection, I think. The lowest level just uses ordinary software obfuscation in the widevine library that this article is about, and regular updates to change the media keys.

Higher levels integrate more with special hardware "APIs" of various kinds. I think you generally cannot play the highest levels on PC hardware at all, it's more meant for Apple TVs and other such devices. Other levels may require things like the Windows protected media path, which lets you upload encrypted video data to the GPU and then it's up to the GPU firmware to decrypt it. So then it becomes a question of understanding how the GPU is decrypting the data and defeating that.

Re: The Quest for Netflix on Asahi Linux

#252

Earlier quoted context omitted.

But the loss happens during re-encoding, not during capture.

In practice, that difference doesn’t really matter because almost no one is going to store their captured, already-lossy material in a lossless format.

If you know you have to recompress and want to reduce unneccessary artifacts, you do. But beware that uncompressed video in 8 bpc (not HDR) 1080p @ 30 fps is 1,5 Gbps so you'll need 1,3 TB to store your 2-hour capture :)

Re: The Quest for Netflix on Asahi Linux

#253

Earlier quoted context omitted.

But I doubt the harmed people will feel materially less harmed if some tiny fraction of content isn't in harm's way while the rest still is.

It's in their interest to get rid of all the DRM, so it's a matter of setting an example. If they try to get Hollywood to stop demanding it while they're still doing it themselves, they look like hypocrites and fools. If they stop they can demonstrate the worthlessness of it and the success of their content without it and try to get others to follow.

> It's in their interest to get rid of all the DRM, so it's a matter of setting an example.

Is it?

I doubt it's a significant cost center. Plus, right management is viewed favourably by the rest of the entertainment industry. Actively going against the grain would impair their image with their commercial partners.

I honestly think they don't care at this point.

Re: The Quest for Netflix on Asahi Linux

#254
post #243

Earlier quoted context omitted.

Again, what prevents you from ALSO having all those? You just need to point to them and run some programs that require them with those...

There can be only one ld.so in each process. Widevine is a plugin-like .so meant to be loaded into Chrome/Chromium. Because it uses glibc, the entire process hosting it must use glibc. So, what prevents me from ALSO HAVING GLIBC CHROMIUM instead of musl Chromium? Nothing, but I hope you get that it propagates further and it's a horrible idea to just glibc everything on Alpine.

>There can be only one ld.so in each process.

Sure, but you need it for Chromium alone iirc, no?

>Because it uses glibc, the entire process hosting it must use glibc. So, what prevents me from ALSO HAVING GLIBC CHROMIUM instead of musl Chromium? Nothing, but I hope you get that it propagates further and it's a horrible idea to just glibc everything on Alpine.

Well, don't glibc everything. Just Chromium and its dependencies. How does it "propagate further"? It's not like libraries leak outside where they're told to load!

Re: The Quest for Netflix on Asahi Linux

#255
post #51

Earlier quoted context omitted.

L1 has been bypassed by piracy groups for years (through social engineering). They just don't share the keys publicly because it would give their opponents an advantage. See [1]. [1] https://news.ycombinator.com/item?id=29702110

True, I didn't realize those were l1 keys. I'll have to read up on the revocation mechanism, if there is any. I'm also wondering how those keys usually leak. Is it through vulns, or just exploiting unsecure key handling?

The Nexus 6's L1 keys were dumped through a vulnerability in Qualcomm's trusted code execution environment.

http://bits-please.blogspot.com/2016/05/qsee-privilege-escal...

https://googleprojectzero.blogspot.com/2017/07/trust-issues-...

Re: The Quest for Netflix on Asahi Linux

#256

> The only officially supported way to use Widevine on Linux is using Chrome on an x86_64 CPU. To be precise it is "The only officially supported way to use Widevine on Linux is using Chrome on an x86_64 CPU using glibc." In other words, even though I have x86_64 cpu, since I'm on alpine, I'm fucked anyway.

wasn't Firefox including widevine for DRM stuff ? I don't have any issues playing Netflix and Amazon Video from Firefox in Kubuntu

Per the article,

> In the instance of Chrome, the browser doesn't implement the DRM itself, but delegates it to a native library referred to as a CDM (Content Decryption Module).

> This library is an opaque proprietary blob that we are forbidden to look inside of (at least, that's how they'd prefer it to be).

> Graciously, as part of the Chromium project, Google provides the C++ headers required to interface with The Blob. This interface allows other projects like Firefox to implement support for Widevine, via the EME API, using the exact same libwidevinecdm.so blob as Chrome does.

Re: The Quest for Netflix on Asahi Linux

#257
post #17

Earlier quoted context omitted.

True for Widevine L3, which is what the article is talking about. Not true in general, and not true for L2 or L1.

I believe that L2 would be weaker than L3 in practice, which likely explains why I've also never seen it implemented (If you know about an L2 instance I would be genuinely interested in taking a look)

> I believe that L2 would be weaker than L3 in practice

How come?

Re: The Quest for Netflix on Asahi Linux

#258
post #215

Earlier quoted context omitted.

> What happened? Isn't that obvious? Circumventing the copy protection of your own property is a crime.

Yeah but so is speeding on the freeway. People do that all day long and never gets ticket. Other times, people actually get arrested they were speeding so fast. So I ask again, did something actually happen? Did the FBI/whomever show up at your door and someone went to prison? Or is it just that format shifting got deemed illegal and now we're all running around scared?

This is different, because we don't have lasting evidence (yet). If circumvent a B-Ray's copy protection some person knowing I ripped them could still report me years after.

Re: The Quest for Netflix on Asahi Linux

#259

Earlier quoted context omitted.

Why would a capture card look any worse? Isn't it capturing lossless video output? Just because of the re-encode?

I think it's both things. Netflix, and other platforms, don't send lossless streams to you. Even at 4k. Plus, you are re-encoding it. Its like doing a VHS copy from another VHS, or creating a new JPEG image from another. Always there is a loss of quality.

It's closer to VHS to DVD.

Re: The Quest for Netflix on Asahi Linux

#260

Earlier quoted context omitted.

You're not understanding how lossy compression encoders work. Try recompressing a JPEG a few dozen times. Or take an MP3 and export it from Audacity, open the export, export as MP3 again a dozen times and see what it sounds like. All those artifacts keep getting amplified every time you re-encode until it's practically just the artifacts. Every time you render and recompress you're losing information, it's lossy comp…

But JPEG purposely discards information to save space. A digital stream is copied directly, only a codec would subject it losing information

Like the codec used to get the stream from Netflix to you, to be decompressed for the capture card (so lossless capture of a lossy source) and then back through x264/265 so lossy compression on a lossy compression. Just because there is a capture card in the middle doesn't stop it going through multiple lossy steps.
Post reply on HN