Live data from Hacker News

Yt-dlp: External JavaScript runtime now required for full YouTube support

github.com

601–610 of 646 posts

Re: Yt-dlp: External JavaScript runtime now required for full YouTube support

#601

Seems its already in Arch's repositories, and seems to work, just add another flag to the invocation: yt-dlp --cookies-from-browser firefox --remote-components ejs:github -f "bestvideo[ext=mp4]+bestaudio[ext=m4a]/best[ext=mp4]/best" 'https://www.youtube.com/watch?v=XXX' It is downloading a solver at runtime, took maybe half a second in total, downloads are starting way faster than before it seems to me. [youtube] [js…

What environment are you using that: - Has access to Youtube - Can run Python code - Can’t run JS code If the concern is security, it sounds like the team went to great lengths to ensure the JS was sandboxed (as long as you’re using Deno). If you’re using some sort of weird OS or architecture that Deno/Node doesn’t support, you might consider QuickJS, which is written in pure C and should work on anything. (Although…

Can QuickJS be compiled to WASM and executed in WASM sandbox?

Re: Yt-dlp: External JavaScript runtime now required for full YouTube support

#602
post #400

I remember when QuickTime came out in 1991 and it was obvious to everyone that video should be copied, pasted and saved like any arbitrary data. It's absolutely insane to me how bad the user experience is with video nowadays, even video that's not encumbered by DRM or complex JavaScript clients.

Experience with video is excellent for most people. All the complexity is hidden from the end user, unless you are trying to hack something. In the 1990s, streaming effectively didn't exist because people didn't have enough bandwidth (it was mostly dial-up), and there was very little legal offering, and the little that existed was terrible. Home video was limited too, as few people knew how to make video files suitab…

It took quite far into the 90's before things like truecolour displays and hardware accelerated video scaling appeared as well. Computers would struggle to view anything bigger than a postage stamp. Hard drive space was also really expensive. It started to change fast towards the end of the decade, though.

Re: Yt-dlp: External JavaScript runtime now required for full YouTube support

#603
post #467

Earlier quoted context omitted.

It is likely you use Chrome or a browser that uses Blink for its engine and the OP uses a non-blink browser like Firefox. I use Firefox and I can cofirm since the last few months Youtube usability borders on usable

They've also started to be really aggressive against VPNs. I've tried Private Internet Access, Mulvad and AirVPN and often I have to cycle through 5-15(!) servers before YouTube stops saying "sign in to confirm you're not a bot". Discord has started to become absurdly aggressive with it too, to the point that they don't even let you load messages whilst logged in if you're on a VPN. It really makes me feel like there…

What's so clean about YouTube, Discord, X etc? It's full of low quality content, scams, malware, influencers, advertisers and other scum and villainy.

Re: Yt-dlp: External JavaScript runtime now required for full YouTube support

#604

Earlier quoted context omitted.

Quick, everyone start sending unwanted junk mail to this guy's house, he'll pay you to stop!

Heaven forbid someone pay for an online service they use and enjoy.

Their point is that it's not "paying for" but it's "paying off".

Re: Yt-dlp: External JavaScript runtime now required for full YouTube support

#605
post #467

Earlier quoted context omitted.

They've also started to be really aggressive against VPNs. I've tried Private Internet Access, Mulvad and AirVPN and often I have to cycle through 5-15(!) servers before YouTube stops saying "sign in to confirm you're not a bot". Discord has started to become absurdly aggressive with it too, to the point that they don't even let you load messages whilst logged in if you're on a VPN. It really makes me feel like there…

What's so clean about YouTube, Discord, X etc? It's full of low quality content, scams, malware, influencers, advertisers and other scum and villainy.

I think it refers to the fact they can deperson you from their platforms if they want to. It's only "dirty" and "clean" if you emphasize the quote marks, but it's definitely "heavily censored" and "free".

There are allegations going around that e.g. some platforms are lax on child protection because some high up executives are pedophiles. But I'd still place those platforms in the "heavily sanitised" bucket if they're heavily restricting everything else. Those platforms just have a slightly different definition of "clean" than most of us.

Re: Yt-dlp: External JavaScript runtime now required for full YouTube support

#606
post #102

Earlier quoted context omitted.

It's fine for this project since google is probably not in the business of triggering exploits in yt-dlp users but please do not use deno sandboxing as a your main security measure to execute untrusted code . Runtime-level sandboxing is always very weak. Relying on OS-level sandboxing or VMs (firecracker & co) is the right way for this.

> It's fine for this project since google is probably not in the business of triggering exploits in yt-dlp yt-dlp supports a huge list of websites other than youtube

But YouTube is the only one that yt-dlp uses Deno for. No other website on yt-dlp's list has put up enough of a fight to merit an external JS runtime; only YouTube.

From the September announcement:

> The JavaScript runtime requirement will only apply to downloading from YouTube. yt-dlp can still be used without it on the other ~thousand sites it supports

Re: Yt-dlp: External JavaScript runtime now required for full YouTube support

#607
post #102

Earlier quoted context omitted.

It's fine for this project since google is probably not in the business of triggering exploits in yt-dlp users but please do not use deno sandboxing as a your main security measure to execute untrusted code . Runtime-level sandboxing is always very weak. Relying on OS-level sandboxing or VMs (firecracker & co) is the right way for this.

> Runtime-level sandboxing is always very weak. Relying on OS-level sandboxing or VMs (firecracker & co) is the right way for this. ... Isn't the web browser's sandboxing runtime-level?

Yes, but browser sandboxing is an absolute marvel of software design that also cost millions and millions of dollars in developers salaries and CVE bounties to develop. Neither Deno nor yt-dlp have anywhere close to millions of dollars to spend on implementing secure JS sandboxing.

Re: Yt-dlp: External JavaScript runtime now required for full YouTube support

#608
post #557

Earlier quoted context omitted.

From the preservation point of view yes. But realistically, it's been the norm throughout human history that irrelevant culture simply gets removed.

So is much of relevant culture, it's not like there is a magic preservation wand that sorts by relevance before removal

There is. If something is relevant, it'll organically be kept somewhere.

Re: Yt-dlp: External JavaScript runtime now required for full YouTube support

#609
post #570

Earlier quoted context omitted.

100%. Web Credentials + Digital ID + age verification will all be handled with Secure Attestation backing it. Cloudflare will have a checkbox for site admins... [X] Require Age Verification... and that's it. Boom. Your site is "safe" from accidentally allowing kids in. ...of course, free speech and anonymity die with this, but why would that be a problem? You don't want to say anything the current or potential future…

Free speech doesn't die with this. Host your own site.

The year is 2041. Google announces that only a negligible fraction of users acceses websites outside of the clean pool. These users are at risk, they claim, due to "all the bad stuff on the free web". They refuse to clarify if this refers to malware or to content not aligned with The Party doctrine. However, they draw the consequence that "free web" sites will no longer be supported by Chrome, to protect the users. Less than an hour later, Mozilla releases a new version of Firefox that also disables access to websites that were not whitelistet by The Party, using the same reasoning.

Re: Yt-dlp: External JavaScript runtime now required for full YouTube support

#610
post #519

Earlier quoted context omitted.

Damn that's crazy, nothing a simple static redirector in a single js line can't fix. Overall cost to implement this shit : likely thousands hundred k Bypass cost : literally 0 It really is just a way for them to say "we can fuck with you as much as we want and you won't do shit cause what you gonna do ? go somewhere else ?"

In killing the cable company, YouTube has become the cable company themselves.

Exactly like cable companies did when they killed whatever was before. Every corporation always acts to maximize revenue.
Post reply on HN