Is it because someone will somehow get a copy and upload to torrents/streaming sites which of course won't have DRM. Thus only potentially annoying legitimate (eg. Netflix) users? Or are there other concerns?
Is it because someone will somehow get a copy and upload to torrents/streaming sites which of course won't have DRM. Thus only potentially annoying legitimate (eg. Netflix) users? Or are there other concerns?
People ideologically opposed to DRM tend to have two blind spots about the DRM service model.
First, they assume that DRM users demand that DRM prevent any copies being made. But that's not true: obviously, any video you show a user in the privacy of their home can be cam-copied. It has even been the case (though it will be less and less the case moving forward) that you could obtain a high-fidelity digital copy. DRM users have always understood that to be the case; what's important is not that copies be impossible, but that they be difficult for ordinary users and, ideally, incur a quality hit. If copies are inconvenient and/or of lower-quality, most of the market will pay for legitimate copies.
Second, and more importantly, DRM opponents assume that the restriction DRM users are seeking is indefinite. But for the most part, content owners are much less concerned about long-term restrictions than they are about the new-release window when their content is most in demand. A DRM scheme only has to survive for a couple weeks to generate immense value for content owners.
From a security and cryptography perspective, a scheme that can be resilient against expert adversaries for a few weeks, or even a framework for minting such schemes on demand, is a commercially reasonable proposition.
This is what video DRM will need. For games, where each game has a somewhat customized version of DRM, taking a few weeks to break is good enough. For video, this will give you a few episodes; but once it is broken it is broken for everything until you roll out a new scheme. Overtime, I would expect the breakers to get more efficient and automated at breaking schemes, while the DRM makers get increasingly lazy and complacent.
That doesn't change the technological harm of DRM. Putting a DRM-shaped hole in web standards makes browsers less secure, less stable, and less maintainable.
iTunes copy protection used to be broken in a few hours, Blu Ray is long since cracked. DRM is neither secure nor cryptographically sound ( http://craphound.com/msftdrm.txt ). The business models that work online keep on being built without DRM.
But DRM remains an irresistible fantasy for corporations who haven't worked out the economics of getting Apple, Amazon or Netflix to add locks to their content.
That's similar to saying words don't communicate well.
It makes no sense to say that DRM is cryptographically unsound - for the very reason you state, DRM is not a technology.
There have been non-optimal algorithmic choices and weak key-management, but those are entirely separate from saying DRM is cryptographically unsound.
This goes (if I'm not mistaken) for the Screen, HDMI cable, GPU and OS. It's a hard balance between keeping consumer happy with their choice and only accepting compliant and capable producers.
The downfall of the DRM is either going to be stripping the legal protections, or competitors without DRM being able to offer a better experience. Sadly, whilst cutting DRM gives a massively better experience, it comes at the cost of control over the customer. I think Netflix really doesn't mind that I can't watch Netflix on Plex. Heck, they might even prefer that.
This is what really scares me about DRM, it enables the building of walled gardens for much more than just media content.
Honestly, this might be why people aren't on the same wavelength. They're not cryptographically speaking.
In DRM, Alice and Carol are the same person.
I thought most pushback against easier access to content was from publishers / curators / distributers. They are being made obsolete by digital distribution and are using 'but the poor artists' as an smoke-screen to delay their obsolescence.
And yet, most content creators I know recognize that the "old ways" are dying, and community involvement and other value adds are the way of the future.
Look at youtube (pre ad-pocolypse), twitch, and patreon. DRM isn't where the money is at with content-creation. Spotify, apple-music, et. al. don't pay their artists nearly enough. The future of content is in direct distribution - not billionaire funded recording companies.
Even Denuvo, the darling of the major games publishers, is broken on a regular basis. The company acknowledges that their software doesn't last forever (they tout '300 days' on their website as the longest any of their DRM schemes has held up, it usually is broken in a couple of weeks) and that the value is protecting the profits during that period.
You can also think of DRM as branching into online services. DRM commonly required some form of interaction with an online service to validate a key or whatever else. As a result, some DRM is in fact built into the foundation of the software and this is the most successful. Think of World of Warcraft or Everquest. To essentially crack that DRM, you have to recreate the server backend which is a serious undertaking. This has been done, but it took a long time, only applies to older versions and doesn't connect you to the legitimate service.
Steam is an online service and games which use SteamWorks are coupling at least some of their features with the online service, but this is not as complicated as something like World of Warcraft so it is easily cracked. Denuvo attempts to fill that gap by more strongly coupling the software with Steam. As a result, Steam is technically the DRM while Denuvo is helping to enforce it and thus is not labeled as "3rd party DRM" on the Steam Store pages.
There is a balance between the popularity of your software and the difficulty of breaking the DRM. If your software isn't extremely popular, then a crack is not in high demand. If the software is easy to crack, then even if it isn't in high demand it may get drive-by cracked. If it's difficult enough, many people will decide that their time is better spent elsewhere even if it is possible to crack.
As we enter the age of encrypted processing where both the code and data are encrypted during execution on the processor, cracking will be time consuming enough and have enough prerequisites that it simply won't be able to keep up with even the most popular software. It will be a while before this can become mainstream, because unless governments start requiring it, there will always be devices without encrypted processing that companies can't ignore in order to maximize profit. It won't surprise me if we see both governments that require encrypted processing and governments that ban encrypted processing.
Obviously for static media like audio or video this is harder to deal with, but there have been a number of novel solutions to this that just haven't been widely adopted. There are also still a lot of consumers with older hardware that publishers want to target, because not targeting them is worse than the concern of piracy. These are more about mitigation rather than outright making it impossible for a time period.
Unfortunately, a lot of people mistakenly believe the purpose of DRM is to prevent copying. That is the justification, not the goal, which has always been about maintaining control over playback device.
They've been trying to accomplish this for many years now, to no avail. This is a nontrivial problem.
> They've been trying to accomplish this for many years now, to no avail.
Any evidence that they haven't had any success whatsoever in making it harder to save/distribute?
For the casual law-abiding user, it succeeds in making it harder to save/distribute. For everyone else, it's only a matter of time before the DRM is broken.
But even if some content is popular, DRM certainly prevents people like me from saving a copy, since I'm not one to go on piracy sites and the only reason I want a copy is so I don't have to get authorization from someone every time I want to play something I already paid for. It might be a dumb business decision since I'd already pay for it before getting a copy anyway, but maybe they think that still makes business sense even if I'd pay for it. Regardless of that it still seems to be working as intended.
And casual users might be law-abiding in the USA, but not everywhere :)
There's no way around that. You can't magically change the universe so that content that's viewed can't be captured. It HAS to be converted to analog somewhere. That signal can always be captured and converted back to a digital form that's no longer embedded with DRM.
Best case: you make it marginally more difficult for a mom&pop computer user to copy your content. Anyone with a lick of understanding and 100 dollars to buy some hardware will be able to get it without any problem.
Worst case: you introduce all sorts of unnecessary security holes with poorly written software, that can't be audited (legally speaking), and does absolutely nothing to slow the availability of the content online and for free.
> Not really. If it's available to view, it's available. Full stop. Best case: you make it marginally more difficult for a mom&pop computer user to copy your content. Anyone with a lick of understanding and 100 dollars to buy some hardware will be able to get it without any problem.
You literally just agreed with my point though.
The proof in the pudding is that every TV show and film is instantly available online to anyone who can work a BitTorrent client.
Your second point, Denouvo is for video games and is a very different ballpark - it turns out storing code to lock things down is a lot easier in an executable vs in a video. DRM is certainly more effective in games (although the evidence is it causes way more problems for legitimate users, and Humble Bundle et al have proven that users prefer legitimate options when they are easy and affordable).
My point was that DRM doesn't stop anyone torrenting the content - it only takes one person to break it, which will happen. It does mean some people won't be able to watch the content legally, which will push them away from the legal option.
The only thing DRM really stops is the "let me give you a copy" friend-to-friend copying, which is the equivalent of sharing a VHS copy back in the day. Is stopping that really worth pushing people away from your legal option?
Fundamentally, I can read or write to any byte in my computer's memory. That includes whatever is coming out of the piece of code that reads in the protected file and then passes it to the video decoder or the display.
Until we have computers that can read and write bytes in such a way that not even a user with full privileges on their own machine can access them (keeping in mind, this user can control the kernel and even the hypervisor), this can't be made to work.
The people pushing for DRM, in my experience, really do have no idea what they are talking about. They tend to be industry lawyer types. People who do understand DRM are usually aware that what they are implementing can be broken, but their VP told them to do it anyway so they can make a deal with content distributors.
Also, the DMCA forbids circumventing copyright measures, so they like to have that as a legal tool as well. As long as they tried something, they can go after anyone disabling it, using the legal system.
Apparently ME is somehow used on the DRM path but really it's kinda irrelevant — the whole point of modern movie DRM is that the video frames get decrypted on your display.
If it did work, that would be a legitimate reason to include these potentially dangerous, un-inspectable DRM features. But it fundamentally can't, so foisting this security risk on everyone seems misguided.
But I also disagree that DRM should be baked into "the web" as a standard, especially when most users seem to disagree, the EFF disagrees, and almost half of the committee disagrees.
And consider the number of hands a piece of media goes through during the various stages of content production. Movies get stolen from anywhere from postproduction studios to the factories that produce the discs.
Adding a layer of DRM on top of the consumer-facing product does almost nothing to prevent the content from reaching pirate sites. And once they're there, the rest of the distribution problem is easy.
It is just that you can not have a video for watching it, and not having the video for distributing it. Computers don't work that way, you either have the video or don't.
That said, things are more insidious than what is on the above paragraph. It's computers that don't work that way, so the solution that many people thought about was making computers illegal, and replacing them with closed controlled machines that resemble them in many ways but aren't as powerful.
Meanwhile, user-hostile DRM can and will (and already does) push users to simply pirate the media in question instead of putting up with the DRM. Users lose, publishers lose, browser vendors lose, and pirates are entirely unaffected.
First DRM proponents have gone very far to protect their content. It costs them a lot of money and from a economical point of view it is difficult to see how DRM help them making more money.
Second: The guys who use pirated stuff would anyway not pay if DRM was working, so why the media industry would bother to struggle with them?