This—on the other hand—provides a replacement for use cases which used poorly-supported, insecure, and battery-hungry proprietary plugins. I run Safari with no extensions and having this for Netflix and Amazon is fantastic. I trust Apple to patch security vulnerabilities and the browser is auto-updated along with the rest of my system. Not having to worry about Flash zero-days is more important to me than some purity argument about what the W3C should be doing.
If you seriously think VoD services were going to operate using standards without DRM in place I'm not sure you'll find many productive conversations on this topic. The web has been dead for some time and Netflix had very little to do with that.
Movies aren't important. Netflix isn't important. The open web, the ideology (or as you put it pejoratively, "purity") behind it, is important.
The amount of heat this change has generated is disproportionate to its actual role as a threat to the open web
From the beginning or near the beginning it was possible and not uncommon to put things on the web with restricted access. The HTTP protocol itself supports a couple of login mechanisms which were intended to be used to restrict access to content, and these have been there since at least as early as 1996.
I understand that you don't want to run code Netflix approves of and that you're not permitted to read in its original source form. And that's fine, a good reason not to subscribe to Netflix. But how is that any more an offense to "the open web" than a subscription-only website?
It works the same regardless of what browser or OS you are using.
Your argument is that EME covers most of the code responsible implementing DRM. This is false. EME is a small part. The large majority of the implementation is not standardized. For example, there is no equivalent of NPAPI in the post-EME world; the CDM/browser interface is browser-specific.
Is there another interpretation of 'everything' in this context? You're making EME far more comprehensive than it is. CDMs do way more than derive a key, so your statement is false on its face.
That is what people oppose. The fact that you do not directly address this point and try to equivocate it to <input type=password> makes me question your good faith here.
For a browser to run a blob, there needs to be an interface between the browser and the blob. Flash and Silverlight blobs used a standard interface: NPAPI. Any browser implementing NPAPI could run the blobs (assuming the blob was compatible with the host OS).
CDMs have no such standard browser/blob interface (note that EME relates only to the Javascript environment not the actual browser code). In fact, the only browsers able to run these blobs are the ones that the CDM provider 'trusts' and is willing to provide proprietary information to in order for browser developers to get their blob working. Your independent Firefox fork will almost certainly never be able to support any major CDM; the CDM provider doesn't trust, nor care about your browser.
Therefore, CDM providers arbitrarily _select_ which browsers can have access to their Web content. This is unprecedented. Content on the Web, in whatever form, has always been accessible by _any_ browser; it was merely a matter of that browser implementing the necessary standards. This is the idea of the open Web. CDMs are literally the opposite idea.
You are free not to run those blobs, and not to use Netflix's services. Where you lose me is the militant demand that Netflix not offer services to those willing to run the blob.
> This is the idea of the open Web. CDMs are literally the opposite idea.
Yes, both a CDM and passworded accounts limit access to content. The difference is that CDM providers are only letting certain Web browsers view the content. Passworded accounts have no such limitation.
The open Web is dependent on any conceivable browser being interoperable with ALL Web content. Any barriers to interoperability are only technical. Third-parties, like a CDM provider, cannot setup arbitrary barriers. Otherwise, it is no longer "open". THIS is the definition of 'open Web'; it has nothing to do with authorization as in subscription only websites.
> This is the idea of the open Web. CDMs are literally the opposite idea.
I, as an open web proponent, want to make it difficult for any business to add DRM to their media offering. by making DRM a difficult system to implement due to proprietary plugins, it increases the perceived value of just offering it without DRM.
but by having EME a standard, it makes it a no brainer to use DRM, because their customers will automatically have it as part of a browser. the cost of DRM is then externalised, and even legitimised such that it's the norm.
Where you lose me is the notion that there's an intrinsic ethical imperative not to provide attachment points in standards for DRM. That doesn't ring true.
I know you are completely right. But I'm still not happy about it and I will still complain about it.
The technical ineffectiveness of DRM isn't something that needs to be explained on HN, this is absolutely about business people and lawyers getting too much power without having the necessary technical understanding.
While I'm waiting for the solution on that, I'll continue watching torrented shows that are obviously Netflix screencaps.
DRM = control. See Apple and iTunes DRM for the first decade of its existence. Same with Amazon and the Kindle.
And now see how Microsoft is already abusing that power to say that its Edge browser can deliver higher resolution Netflix shows - not because it's any better at rendering videos than Chrome and Firefox, but because it's uses its Windows DRM to only allow Edge to play higher-quality Netflix videos. Hashtag #NewMicrosoft
Uber wouldn't be a viable business model if it didn't exploit drivers and dodge laws that apply to taxis.
Airbnb wouldn't be a viable business model if it didn't sidestep hotel laws.
If your business depends on having unjust power over your customers then you ought to go out of business.
Also, many people seem to have a real hard-on for the same legal system that outlaws marijuana and created the DMCA.
Uh, why not? All Netflix series are already getting pirated even with DRM.
Digital IP is different - you can make infinite copies of it. A copy I make does not diminish your copy, nor does it deprive you of possession of your copy, or usage of that copy.
What it does deny you is the amount of money which you might have made on the sale of that copy (if you are the rights-holder and are selling the digital IP "thing" to others). I haven't, however, stopped you from continuing to sell your digital IP "thing" - you still have it. You just don't have the money.
Surely you can see this difference? If it could be called anything, it would be considered theft of opportunity, rather than theft of an object. You have been deprived of making a portion of money.
Now - that's very close to - if not almost identical, to me going up to your digital IP (via website, a kiosk, you at a table burning copies onto disc - whatever), looking at it, then saying to you "I would love to have a copy of this, but you know, I just won't, because you are charging money for it".
I still haven't deprived you of your IP - you still have it, you still have your copy, etc. What I have done is deprived you of the opportunity of making money. Should I go to jail, or be fined, or be forced to pay you the money in some manner because I didn't buy it?
The only real difference between the two? Well - in the first scenario, I have a copy of the digital IP; in very real terms, I have the knowledge of a particular number (because that is what any digital work can be reduced to - just a very large number) - in the second case - I don't.
But - what if on the off chance I somehow guess that large number? What if I am able to do that? Since it is a real number, there is that possibility (granted, the probability of being able to do so is vanishingly small). I know have the knowledge of that number, and can use it as I see fit - including decoding it to watch it as a movie, or play it as a piece of music, or whatever. But I didn't copy it from you; in fact, you might not even know that I now know your number!
Have I committed a crime?
DRM (and the laws which surround it) - in a very real sense - is a system put in place to criminalize and prosecute people for knowledge of particular numbers - nothing more, nothing less. In other words, knowledge of such numbers is considered a crime, unless you have paid money for that knowledge - even possibly if you independently arrive at that knowledge.
Agree or disagree - but it's the truth.
The manufacturing (copying) cost for digital content being 0 doesn't really matter; it just means that the net cost of production is front-loaded. I can invest $30,000,000 in a housing complex with a tangible amount of units, or a Hollywood movie with infinite "units". I still deserve to get a return on my investment.
And even if you take netflix original content out of the picture, that applies. their "viable business" is "stream other people's content" and "other people" have to agree to that, and won't without DRM.
"This is a requirement for any premium subscription video service" -- this is blatantly false, unless you redefine premium to mean "requires DRM", in which case it's circular.
Also note the use of "protect" as if it was a positive or good thing.
1: http://techblog.netflix.com/2013/04/html5-video-at-netflix.h...
Premium = big name movies
Big name movies = big name studios
Big name studios = full of corporate bigwigs who dont understand that DRM doesn't stop piracy
Where can you buy it DRM-free?
"We didn't bother protecting our content, and yes, sales are down 25% year over year, but..."
Fired.
Are you suggesting that there are many shows on Netflix that someone wants to pirate, but the DRM is preventing them?
If one day the industry recognizes that DRM is useless and it's no longer demanded by content holders, then as CEO of Netflix you can abandon it.
Steve Jobs told the music industry to suck it up and deal, and they did. He was unable to convince the movie/TV industry to do the same.
I hope you realize the movies people 'pirate' have been stripped of the DRM. Even if the original file had DRM, that does not inconvenience downloaders at all.
Because Netflix is freeloading on our open technology to deliver closed content, and putting the cost to support their DRM on us. It's not right. It's not fair.
They are fragmenting the web by making "web sites" which are browser and OS-specific.
If they want to make closed, OS-dependent stuff anyway, they should have to pay the cost, not us. They should just make a native app. Like they already do for at least 10 other platforms.
Basically keep your closed and non-free poison out of my browser and open web-standards. That's a no-DRM zone.
I'll use your app though, if you just go make it.
Netflix came in and screwed over everyone, in a way that is just as bad as Flash.
Sure, use the TCP/IP stack. Send your data over the internet. Make your own software based on that, it's just a transport layer and it screws no one else. Except they seem to be pretty damn awful at it, considering how comically bad all their desktop apps are.
By forcing their way into the standard with EME, yes, they did. You cannot implement the full standard without getting their blessing.
They profited from the entire work done by hundreds of persons on an open standard, and implemented a proprietary solution on top of it. And made it part of the standard.
See https://www.gog.com/forum/general/introducing_gogcom_drmfree...
It was obviously never going to be my contention that there were no DRM-free video content producers. Just the major ones.
And I meant major ones. They admit that DRM isn't needed. See the report in the link above. Their usage of DRM isn't caused by business enabling requirements, but has completely crooked unrelated reasons.
From the recently released, Shadow Warrior 2 is also pretty big. I wouldn't call the above mentioned TToN a small game either.
Besides, they said that the Apple Music Store couldn't survive without DRM. And then one day they removed it and nobody even noticed. Now nobody uses DRM when they sell music. Even Spotify don't bother encrypting cached mp3s on your hard drive.
If Netflix switched to unencrypted streams tomorrow, it would have no effect. There is no content that is exclusive to Netflix. As soon as Netflix makes something available, it is immediately ripped losslessly and put on The Pirate Bay.
The conventional way to do so would require recipients to download an encrypted video file, then run a separate program to decrypt the file. Then they could play the file. Then they have to remember to delete the decrypted file if it is something sensitive that should not be lying about unencrypted on their system.
It should be possible to design a system that plugs into EME that greatly simplifies this.
If you mean that the recipients of the video are restricted in what they can do with it, that's a DRM use case.
I don't see anything that requires that the key be delivered over the net. I just did a test with Clear Key where the page with the video playback has a text field that the viewer pastes the key into, and that worked [1].
The scenarios I'm envisioning involve sharing videos between people that have good non-web methods of communicating, so can distribute a video's encryption key via some non-web means. End user encryption applications tend to by usability train wrecks for non-tech people (heck, they are often terrible for tech people, too...), so what I'm going for here is trying to get rid of the video viewer having to go outside their browser to deal with viewing an encrypted video.
Maybe this can be done with MSE without EME, by handling the decryption in JavaScript?
[1] Based on the Clear Key sample here: https://www.html5rocks.com/en/tutorials/eme/basics/