Live data from Hacker News

Disney+ streaming uses draconian DRM

hansdegoede.livejournal.com

321–330 of 330 posts

Re: Disney+ streaming uses draconian DRM

#321

Earlier quoted context omitted.

Having the EME specification distributed by the W3C appears to be a very effective method of propaganda. > A standard we don't like isn't propaganda. A "standard" that doesn't even attempt to fulfil the purpose of a standard is not a standard.

What purpose is it failing to fulfill? It outlines how to indicate media is encrypted and how decryptors can be surfaced by the user-agent. It doesn't indicate how decryption must happen, but OAuth2 doesn't indicate what standard an authorization server should use to authorize that a client matches a resource owner either.

> What purpose is it failing to fulfill?

Here you are:

> The point of standards is to facilitate interoperability.

> but OAuth2

isn't the topic.

Re: Disney+ streaming uses draconian DRM

#322

Earlier quoted context omitted.

What purpose is it failing to fulfill? It outlines how to indicate media is encrypted and how decryptors can be surfaced by the user-agent. It doesn't indicate how decryption must happen, but OAuth2 doesn't indicate what standard an authorization server should use to authorize that a client matches a resource owner either.

> What purpose is it failing to fulfill? Here you are: > The point of standards is to facilitate interoperability. > but OAuth2 isn't the topic.

It facilitates interoperability between content providers and user agents to convey and display encrypted media (without the need for one company to own both sides if that pipe, like in the Flash era). Much as OAuth2 facilitates authorization handshakes between services owned by different companies.

Re: Disney+ streaming uses draconian DRM

#323

Earlier quoted context omitted.

Competition. You hire a different police force to protect your property. Of course, if one entity has a monopoly over the legitimate use of force in an area, you're in trouble.

That sounds a lot like warring oligarchical or dictatorial nation states with extra steps in practice.

If they manage to get monopolies over geographic areas then yes, you get exactly what we have today.

However, for a couple of years after 1990 we actually had quite a lot of security companies that were competing peacefully in the same areas (Romanian police being absolutely irrelevant at a local level, with the reorganization of the state that was taking place). Of course, once the state got re-established "properly" that was quickly ended.

Re: Disney+ streaming uses draconian DRM

#324

Earlier quoted context omitted.

> What purpose is it failing to fulfill? Here you are: > The point of standards is to facilitate interoperability. > but OAuth2 isn't the topic.

It facilitates interoperability between content providers and user agents to convey and display encrypted media (without the need for one company to own both sides if that pipe, like in the Flash era). Much as OAuth2 facilitates authorization handshakes between services owned by different companies.

Facilitating DRM, which runs counter to interoperability, is exactly why EME isn't a standard.

And please stop spamming your OAuth2 nonsense, it's off topic.

Re: Disney+ streaming uses draconian DRM

#325

Earlier quoted context omitted.

It facilitates interoperability between content providers and user agents to convey and display encrypted media (without the need for one company to own both sides if that pipe, like in the Flash era). Much as OAuth2 facilitates authorization handshakes between services owned by different companies.

Facilitating DRM, which runs counter to interoperability, is exactly why EME isn't a standard. And please stop spamming your OAuth2 nonsense, it's off topic.

I keep bringing up OAuth2 because it's in a similar domain to EME. Authorization restricts access to resources that users are not supposed to be accessing (for whatever reason, be it privacy or they simply haven't paid to access it).

Similarly, encryption restricts usage of resources in ways users are not supposed to use them (including having not paid for the privilege).

It's not "counter to interoperability" that Google Drive won't fork over your documents to anyone who requests them without the right token.

Your frustration isn't the technology, it's what it's used for. If you want to claim EME isn't a standard, clarify how it differs from OAuth2.

Re: Disney+ streaming uses draconian DRM

#326

Earlier quoted context omitted.

Why would the cost of supporting an additional platform ever be zero?

When the platform is the web browser, not an OS. If I write a website today, it works just as well on Linux, Windows, macOS, or any other modern platform. Other than DRM, there is nothing needed for Disney+ that isn’t common across all desktop OSes.

Oh sweet summer child...

Re: Disney+ streaming uses draconian DRM

#327

Earlier quoted context omitted.

Facilitating DRM, which runs counter to interoperability, is exactly why EME isn't a standard. And please stop spamming your OAuth2 nonsense, it's off topic.

I keep bringing up OAuth2 because it's in a similar domain to EME. Authorization restricts access to resources that users are not supposed to be accessing (for whatever reason, be it privacy or they simply haven't paid to access it). Similarly, encryption restricts usage of resources in ways users are not supposed to use them (including having not paid for the privilege). It's not "counter to interoperability" that G…

> Authorization restricts access to resources that users are not supposed to be accessing (for whatever reason, be it privacy or they simply haven't paid to access it).

Oh, sorry. I thought you actually knew what DRM is.

https://www.defectivebydesign.org/what_is_drm_digital_restri...

> Your frustration isn't the technology, it's what it's used for.

Stop trying to read my mind, it's a violation of privacy and physics.

> If you want to claim EME isn't a standard, clarify how it differs from OAuth2.

If there is no relevant difference, then OAuth2 isn't a standard either. Happy now?

Re: Disney+ streaming uses draconian DRM

#328

Earlier quoted context omitted.

I keep bringing up OAuth2 because it's in a similar domain to EME. Authorization restricts access to resources that users are not supposed to be accessing (for whatever reason, be it privacy or they simply haven't paid to access it). Similarly, encryption restricts usage of resources in ways users are not supposed to use them (including having not paid for the privilege). It's not "counter to interoperability" that G…

> Authorization restricts access to resources that users are not supposed to be accessing (for whatever reason, be it privacy or they simply haven't paid to access it). Oh, sorry. I thought you actually knew what DRM is. https://www.defectivebydesign.org/what_is_drm_digital_restri... > Your frustration isn't the technology, it's what it's used for. Stop trying to read my mind, it's a violation of privacy and physics.…

> If there is no relevant difference, then OAuth2 isn't a standard either. Happy now?

In the sense that you've reached the conclusion that your definition of "standard" isn't sufficiently universal to discuss the topic because you've excluded what is generally accepted to be a widely-accepted authorization standard that lacked the controversy over socioeconomic control that the EME standard does, yes.

Trying to short-circuit debate by bullying the field of definitions and declaring the other viewpoint "propaganda" isn't constructive.

Re: Disney+ streaming uses draconian DRM

#329
post #297
post #291

Earlier quoted context omitted.

What's the argument here, that average people are too dumb to know that their computer needs to be on to access something running on it? That they're too dumb and poor to find and buy another device to run their Plex server if they don't want to use their PC? I think you underestimate people a bit too much.

"Too dumb" feels overly emotive. But yes, I'm saying there is a significant gulf between the average user's current setup (a Roku, Apple TV, whatever) and a server that costs several hundred dollars (if you want anything approaching plug and play) and has to be on all the time, both financial and tech knowledge wise. It's not that users are "too dumb" to do it, it's that it is an inconvenience people are more than wi…

My experience around average income non-tech-enthusiast parents is they have a binder stuffed with $2 pirated DVDs and a USB drive full of stuff they've torrented / exchanged with friends.

Running Plex with whatever computer they've got isn't a stretch.

Re: Disney+ streaming uses draconian DRM

#330

Earlier quoted context omitted.

> Authorization restricts access to resources that users are not supposed to be accessing (for whatever reason, be it privacy or they simply haven't paid to access it). Oh, sorry. I thought you actually knew what DRM is. https://www.defectivebydesign.org/what_is_drm_digital_restri... > Your frustration isn't the technology, it's what it's used for. Stop trying to read my mind, it's a violation of privacy and physics.…

> If there is no relevant difference, then OAuth2 isn't a standard either. Happy now? In the sense that you've reached the conclusion that your definition of "standard" isn't sufficiently universal to discuss the topic because you've excluded what is generally accepted to be a widely-accepted authorization standard that lacked the controversy over socioeconomic control that the EME standard does, yes. Trying to short…

Stop twisting my words. Thanks.
Post reply on HN