An excerpt:
> ...the challenge algorithm is served in a mini-language within the minified player JS and therefore the specific algorithm could be extracted and executed by interpreting the mini-language without actually running the JS itself.
An excerpt:
> ...the challenge algorithm is served in a mini-language within the minified player JS and therefore the specific algorithm could be extracted and executed by interpreting the mini-language without actually running the JS itself.
This is linked from the description of PR 30184 of youtube-dl but @varenc linked to a specific comment (talking about patching Windows builds, AFAICT) which might confuse some people.
I'll even save you the click:
> YouTube's strategy to restrict downloading videos is to send a ciphered version of the signature to the client, along with the decryption algorithm obfuscated in JavaScript. For the clients to play the videos, JavaScript must take the ciphered version, cycle it through a series of "transform functions," and then signs the media URL with the output.
There are still a lot of things I don't understand here but gotta give Youtube a slow-clap moment for their devious ingenuity.
Well, sorta. They have basically come up with a DRM scheme by another name. They're always just speed bumps.
It reminded me ofthe old joke about two people entering an area infested by lion's, and one of them sits down on a log, and takes 5 minutes to replace his robust hiking shoes by a very expensive pair of running shows. The other says "why are you doing that - you can't our run a lion." The reply is "I don't have to be faster than the lion - just faster than you".
It makes prefect sense of course, when the lion has a choice. But in this case there is no choice. There is only one youtube. No matter how much time and expense youtube putting into their running shoes, youtube-dl / yt-dlp is always going to chase after them.
They are always going to win that race. While Google may be paying 5 or 10 of the cream of worlds programmers, those two open source projects ultimately how pools of 100's of equally talented people who occasionally want to download a video, and will happily contribute back a few hours of their time to do it. Which is probably how yt-dlp came about - youtube-dl slowed down, and someone said "fuck it - I'll do it myself". Worse from google's point of view, unlike splitinering a commercial endeavours, once those two projects are already contributing code to each other and may well merge again.