Is it really true that CDMs are actually browser-specific or are able to enforce a browser whitelist? If so, that is horrific.
The EME standard only covers the DOM APIs and the interactions between the video player JavaScript and the CDM. There is no standard browser API or ABI for CDMs like there is for NPAPI.
For Firefox, Mozilla has a plugin ABI called GMP (Gecko Media Plugin) similar to NPAPI. Unlike NPAPI, GMPs are not directly instantiated by web content and, AFAIK, the list of supported GMPs is hardcoded in Firefox. Cisco's OpenH264 codec and Adobe's Primetime CDM are GMPs. Google's Widevine CDM has its own API, so Firefox uses a Mozilla-written GMP that wraps Google's Widevine DLL or .so binary.
As far as CDMs being blackboxes in the standard - you can verify that yourself: https://w3c.github.io/encrypted-media/
It would be good to have an EFF expert explain some of the nuance here though.
A standard way to allow anyone to run one of those CDMs and removing the publishers as the gatekeepers.
IE, firefox cannot use google sandvine, even if you have chrome installed, because it is not a standard interface from the browser's perspective.
CDMs are absolutely not browser agnostic like NPAPI.
> Beginning in version 47, Firefox desktop also supports the Google Widevine CDM.
CDMs could technically only work for one browser via fingerprinting, but that could already happen without EME (or DRM entorely) using browser fingerprinting to only serve content to UAs the publishers "trust".