Live data from Hacker News

Web DRM moves to next phase, Defective by Design to continue opposition

defectivebydesign.org

41–50 of 53 posts

Re: Web DRM moves to next phase, Defective by Design to continue opposition

#41
post #28

There must be people who find this style of writing persuasive, but for me it has the opposite effect. The tone is so aggressive and slanderous that even though I should nominally be on the side of the author, I find myself thinking "surely there is another side to this story" and come away with the feeling that I should step back and consider that maybe the other side is in fact in the right. It's like reading angry…

I agree, and from the (admittedly few) opinions I've read on the topic it seems both sides at a lower level (i.e. mailing list as opposed to blogs) have quite well articulated and reasoned contents. From reading those, I feel I have a better understanding of both sides. I also feel there's little consensus, yet a choice was made anyway . The (grossly simplified) argument being that vendors implement DRM anyway so may…

The sad-hilarious thing is that I would pay Netflix exactly as much money if the content weren't DRM'd, in fact I might pay more since they currently limit to 720p on Widevine (which is disappointing for my 1440p displays).

The reason I'd still pay Netflix, is that I can already pirate all of the shows they license. I pay for their reliable adaptive-rate streaming technology, the content I can get from almost anyone. In trade for the convenience, I lose quality because the widevine streams only go up to 720p. Even sadder, I could torrent good quality screencaps of the 1080p Netflix streams if I wanted to.

The publishers are just being ridiculous, so the DRM is enabled for everything. Though I wish they would put their money where their mouth is and disable the DRM for Netflix originals.

Re: Web DRM moves to next phase, Defective by Design to continue opposition

#42

There must be people who find this style of writing persuasive, but for me it has the opposite effect. The tone is so aggressive and slanderous that even though I should nominally be on the side of the author, I find myself thinking "surely there is another side to this story" and come away with the feeling that I should step back and consider that maybe the other side is in fact in the right. It's like reading angry…

I wrote this statement and want to respond to your criticism.

Firstly, I think you make a very good point. I experience a similar feeling when I read things that appear one-sided, and I try in my writing to communicate the fact that both sides of the issue have been considered, even if I think one is completely absurd. I'll take your criticism into account with future writing about EME.

FWIW, here's the other side of the argument as I understand it:

"DRM is already happening on the Web, so we might as well do it at the W3C, with the vague hope that we will win some kind of concession from the DRM companies. Also, maybe if we don't, they will take their content off the Web and into some other system (subtext -- we care more about Netflix being on the Web as defined by W3C than we do about the Web as defined by W3C being free and open.

Re: Web DRM moves to next phase, Defective by Design to continue opposition

#43

There must be people who find this style of writing persuasive, but for me it has the opposite effect. The tone is so aggressive and slanderous that even though I should nominally be on the side of the author, I find myself thinking "surely there is another side to this story" and come away with the feeling that I should step back and consider that maybe the other side is in fact in the right. It's like reading angry…

I wrote this statement and want to respond to your criticism. Firstly, I think you make a very good point. I experience a similar feeling when I read things that appear one-sided, and I try in my writing to communicate the fact that both sides of the issue have been considered, even if I think one is completely absurd. I'll take your criticism into account with future writing about EME. FWIW, here's the other side of…

I think the other side of the argument is primarily the following:

a) The Membership of the W3C have decided they want to work on DRM.

b) Like most industry consortiums, the W3C is ultimately beholden to its (industrial) Membership. (And it's not clear they can refuse an organisation from joining as a Member without opening themselves up to allegations of being a cartel and the legal complications that would involve.)

A lot of this comes down to the relationship between the W3C and its Member organisations, and whether the W3C can refuse to work on something its Members want to.

There's also some of what you alluded to, which I will call c) A number of Member organisations have made it clear that they will work on this in some public forum regardless of what that forum is.

Now, from a purely pragmatic point-of-view, what is gained by the W3C refusing to work on it? Apple, Google, and Microsoft will still ship DRM modules; the web will still start relying on DRM modules existing within browsers. The outcome is entirely unchanged, as ultimately because of c we've ended up with an interoperable API from JS one can use to deal with DRM modules.

Refusing the venue is purely making a political point, it doesn't change the outcome. Now maybe that political point is a goal in and of itself, but given most of the arguments people make against DRM I'd suggest the goal here isn't a political point but rather reduction of reliance of DRM on the web.

By refusing to work on it, you upset the Membership (because you're going against them), jeopardising your own future (because a industrial consortium is nothing without Members), and not changing the outcome.

Re: Web DRM moves to next phase, Defective by Design to continue opposition

#44
post #8

W3C did this move because its biggest sponsors are the DRM makers (Google, Microsoft). To make it acceptable they made it optional. But in practice all major browsers implemented it. The right answer is now to standardized the W3C CDM black box by standardizing DRMs as ETSI has started ( https://lists.w3.org/Archives/Public/public-html-media/2014F... ). W3C should contribute to this effort. Useful link on EME: https:…

The ETSI thing doesn't solve problems. It creates a layer of abstraction that in theory makes the key acquisition protocol defined by whatever runs on the ETSI layer, but now you have the problem of remotely attesting the tamper-resistance of the ETSI layer itself. It would make more sense to standardize the protocol than to define an execution environment for arbitrary protocol engines.

Agreed. That's one of the reason why this initiative stalls. However the back idea is to standardize a DRM protocol that would be accepted by the copyright owners and that's a step in the right direction.

Re: Web DRM moves to next phase, Defective by Design to continue opposition

#45
post #23

Earlier quoted context omitted.

> the organizations that develop the most influential browsers do The problem here is that 3/4 browser makers are also DRMs makers (Apple, Microsoft, Google) and are also the biggest W3C donators.

> are also the biggest W3C donators I'd be surprised if that were true. (Do they donate anything? I'd be surprised if they did, I suspect they merely pay their membership dues.) The membership fees come at five levels, mostly dependent upon annual revenue; Apple, Microsoft, Google all pay the same as Adobe, Boeing, Dell, Facebook, HP, LG, Netflix, Siemens, Sony, Disney…

You're right, I meant "contributors". It is not only a question of money: these companies can dedicate people to lead the standardization tasks and push their own interests. That's mostly visible at MPEG with patents (yet another hot subject).

Standards are very important. But the way we make them is still highly improvable.

Re: Web DRM moves to next phase, Defective by Design to continue opposition

#46
post #39
post #18

Earlier quoted context omitted.

> it was better to allow the w3c to specify a "black box" with well defined inputs and outputs. But they didn't! EME is a spec for only for inputs, and no outputs. EME entirely depends on CDMs, and their interface is deliberately left completely undefined (W3C uses that as an excuse to say they didn't—strictly speaking— define a DRM). Plug-ins at least had an open NPAPI interface that anybody could integrate with. CD…

> The spec allows them to be anything, including kernel modules or hardware (and in practice they're… plug-ins). On mobile platforms, they generally are system-integrated (and hardware-supported) components, often running at privilege levels exceeding the running Android/Linux kernel. See the recent Qualcomm case where a DRM component (Widevine) running in TrustZone context[0] was used to attack Android's full disk e…

Agreed. Some opponents of DRMs say this is the beginning of the end of open computers. We've heard recently about the Intel Management Engine.

On the other hand, almost all DRMs were broken because the content is available in clear: http://betanews.com/2016/06/26/chrome-drm-streaming-video-fl... https://iseclab.org/media/uploads/zotero/Steal_This_Movie_-_...

Re: Web DRM moves to next phase, Defective by Design to continue opposition

#47

Earlier quoted context omitted.

I wrote this statement and want to respond to your criticism. Firstly, I think you make a very good point. I experience a similar feeling when I read things that appear one-sided, and I try in my writing to communicate the fact that both sides of the issue have been considered, even if I think one is completely absurd. I'll take your criticism into account with future writing about EME. FWIW, here's the other side of…

I think the other side of the argument is primarily the following: a) The Membership of the W3C have decided they want to work on DRM. b) Like most industry consortiums, the W3C is ultimately beholden to its (industrial) Membership. (And it's not clear they can refuse an organisation from joining as a Member without opening themselves up to allegations of being a cartel and the legal complications that would involve.…

The W3C is not like most other industry consortium and it is not beholden to its industrial membership.

Re: Web DRM moves to next phase, Defective by Design to continue opposition

#48
post #47

Earlier quoted context omitted.

I think the other side of the argument is primarily the following: a) The Membership of the W3C have decided they want to work on DRM. b) Like most industry consortiums, the W3C is ultimately beholden to its (industrial) Membership. (And it's not clear they can refuse an organisation from joining as a Member without opening themselves up to allegations of being a cartel and the legal complications that would involve.…

The W3C is not like most other industry consortium and it is not beholden to its industrial membership.

How is it not? Its very existence relies upon its membership continuing to choose to pay membership fees, after all.

Re: Web DRM moves to next phase, Defective by Design to continue opposition

#49

I thought the general consensus amongst people, including the general HN crowd was that it was better to allow the w3c to specify a "black box" with well defined inputs and outputs. Allowing vendors to slot in their own (probably closed source) implementation than it was to slam the door in their faces whilst screaming "SCREW YOU, USE SILVERLIGHT OR FLASH". Defective by design seems to be misinterpreting the "build t…

I wouldn't say there's concensus. > because the alternative to this proposal is not "no DRM", the alternative is a worse UX from a plethora of more hostile, wider reaching proprietary DRM implementations. Good. Everything which makes DRM easier to implement, more reliable/stable/cross-platform/interoperable/etc., more streamlined and simpler to use, just skews the cost/benefit in the wrong direction. Everyone should…

Genuine question: how should streaming companies protect against their content being stolen/ripped/etc without DRM? What's the alternative? I'm sure it's in the contract of every streaming service that they have to protect the licensed content to the best of their ability. Saying "fuck the greedy media companies" doesn't help the streaming services that need to license content to survive. Considering almost half of all bandwidth (in the US at least) is used for streaming, I'd say it's pretty important to have a well-defined solution to enable streaming companies to do what they need to do.

Re: Web DRM moves to next phase, Defective by Design to continue opposition

#50

Earlier quoted context omitted.

I wouldn't say there's concensus. > because the alternative to this proposal is not "no DRM", the alternative is a worse UX from a plethora of more hostile, wider reaching proprietary DRM implementations. Good. Everything which makes DRM easier to implement, more reliable/stable/cross-platform/interoperable/etc., more streamlined and simpler to use, just skews the cost/benefit in the wrong direction. Everyone should…

Genuine question: how should streaming companies protect against their content being stolen/ripped/etc without DRM? What's the alternative? I'm sure it's in the contract of every streaming service that they have to protect the licensed content to the best of their ability. Saying "fuck the greedy media companies" doesn't help the streaming services that need to license content to survive. Considering almost half of a…

> content being stolen

It's duplication, not transfer, so "sharing" is a more appropriate word than "stealing".

> I'm sure it's in the contract of every streaming service that they have to protect the licensed content to the best of their ability.

I've also read many EULAs which contain onerous terms; contracts don't need to be agreed to, and negotiations are a two way street. We need more of http://news.bbc.co.uk/1/hi/entertainment/2843069.stm and less of https://www.theguardian.com/technology/2011/nov/14/bbc-hd-dr...

> need to license content to survive

> Considering almost half of all bandwidth (in the US at least) is used for streaming, I'd say it's pretty important to have a well-defined solution to enable streaming companies to do what they need to do.

Streaming companies don't "need" to do anything. If they truly "need" DRM to exist, then they should shoulder that burden themselves rather than coercing others into doing the work for them; especially organisations and structures governing the Web, which was created specifically to disseminate human knowledge.

If that's too much of a burden for media companies to handle, then they should bow to market forces and close down. Humanity has survived perfectly well for millenia without them. Perhaps that will help divert some of the entertainment industry's billions towards causes of some actual importance.

Post reply on HN