Identifying HTTPS-Protected Netflix Videos in Real Time [pdf]
mjkranch.com
mjkranch.com
Stepping back a bit, although this paper is definitely valuable, it isn't that startling, because we already know that encrypted communications are vulnerable to passive attacks when the contents are predictable. It's a good reminder that "vanilla" encryption isn't necessarily the best way to protect privacy when the attacker can simply guess what we're transmitting because the search space is so small; in this case, it's easy to compare the length of what is being transmitted against a corpus -- and bam. There's only ~42k entries...
Entropy entropy entropy. It is your friend. Just so happens that VBR and DASH weren't designed to increase entropy when transmitting segments.
http://www.cs.unc.edu/~fabian/papers/foniks-oak11.pdf
edit: this paper is referenced in fact by the paper submitted here.
From a bandwidth perspective, such CBR encodings are either wasteful or low quality for high motion scenes—or both. So it makes sense that Netflix has chosen a VBR system, but does have this privacy caveat.
To avoid that issue you just artificially make multiple movies have the same length, meaning do some padding to round up to the next e.g. 10 minutes (so if the movie is 1:48:23 it becomes 1:50:00), to do so the movie keeps buffering in the background (some random audiovisual noise).
Maybe netflix should have a "Fully safe" mode where it uses CBR instead of VBR so the user knows the trade off (slower/heavier buffering)
Different bit rates on the random audiovisual noise (white noise would be uncompress-able, thus weight more, pure black would be too compress-able, etc).
Some possible counter-measures are discussed in the conclusion:
"To that end, we believe that Netflix could defend against passive traffic analysis by ensuring that the byte-range portion of the HTTP GETs sent by the browser do not perfectly align with individual video segment boundaries. For instance, the browser could average the size of several consecutive segments and send HTTP GETs for this average size. As an alternative approach, the browser could randomly combine consecutive segments and send HTTP GETs for the combined video data. Designing obfuscation techniques for VBR DASH streams that do not degrade video quality remains a potential area for future research."
edit: clarity
> In order to generate these fingerprints, we first mapped every available video on Netflix. We took advantage of Netflix’s search feature to do this mapping by conducting iterative search queries to enumerate all of Netflix’s videos. This enumeration was done by visiting https://www.netflix.com/search/<value> where <value> was ‘a’, then ‘b’, etc. and then parsing the returned HTML into a list of videos with matching URLs.
This is not the same as but still in the same class of "unauthorized" use that Weev was charged with carrying out on AT&T endpoints. No privacy concern here, and in theory you are authorized to view this Netflix content but not to "use any robot, spider, scraper or other automated means to access the Netflix service; decompile, reverse engineer or disassemble any software or other products or processes accessible through the Netflix service; insert any code or product or manipulate the content of the Netflix service in any way; or use any data mining, data gathering or extraction method." Though Weev's conviction was vacated on appeal, that was only based on a venue problem so the prosecution's legal theory about violating terms of use still seems to be in play.
Not concern trolling here, I do this sort of scraping all the time and there's no reason to believe the authors are at any risk. It's just an interesting juxtaposition that illustrates how overly broad the DOJ's interpretation of CFAA is, and how selectively it can be pursued. As the EFF notes, one of the major impacts is that is puts security researchers in a legal gray area (https://www.eff.org/issues/cfaa).
They mention they used Silverlight. I wonder if this also works for videos when viewed with HTML5, and if the same fingerprints can be used.
I am very curious why this matters to you.
I would think Netflix would be protective of their content and would likely have monitoring to detect mass downloading. The adversarial nature of one person trying to do something and other people trying to detect and stop them is interesting to me. I find JSOR's account of their monitoring, detection, and attempted blocking of Aaron Swartz's downloading of academic papers (not just metadata like this post), and the cat and mouse game that followed to be very interesting. https://docs.jstor.org/summary.html
And the perspective from the other side: the authors of this paper, whether they were concerned with being detected by Netflix and possibly blocked or even banned from Netflix for life, and maybe took action to avoid that such as using multiple accounts or VPNs.
Paypal does do checks to ensure that blocked accounts are not easily resurrected.
Netflix has less incentive to perform such a costly operation but it's more than possible, this is what every credit and background check agency can do.
Sure if you want to get a completely new identity, credit history and address you can probably fool most of these but you are going to be violating a few laws in the process and it would be probably be cheaper to purchase the entire Netflix library on DVD/BR at that point.
Billing address sort of, but address verification is usually only on the numbers, not the names of the street. Very few credit card systems pass the name on to the bank when requesting authorization. If you're only using streaming, it doesn't really matter if the street address isn't correct.
Credit and background checks usually request a lot more information than netflix does; nobody would give netflix their social security number, or recent addresses.
The FBI was involved before it was even discovered who it was or what was the purpose of the device.
When an institution discovers such an incident when an unauthorized device is plugged to a secure network and in a covert manner their hands are tied.
For the rest, I am not sure how many people should be afraid to let people know what they are watching on Netflix.
Blogpost (includes demo vid): http://blog.ioactive.com/2012/02/ssl-traffic-analysis-on-goo...
Note: not defending Netflix's position on VPNs, just pointing out that the user still has free will.