W3C Proposal from MS, Google, Netflix for adding copy protection API to html5
dvcs.w3.org
dvcs.w3.org
The issue with this proposal is that it it creates a segmented web, whereby if a vendor does not ship a "CDM" for a particular platform, you will never see DRM'd web content for that platform.
To those of you who are thinking "Woo! Now there's any easy way to get my license keys!" you have missed the part where there's a media layer interacting with a DRM stack - this is essentially the same situation as today.
The only thing this does is give blessing to break principles of universal computing. I am opposed.
To support this a user agent will need to implement one or more CDM that may include communicating with a DRM chip. For devices without the chip the web page won't render properly. We agree that this is undesirable, but it doesn't seem any different to me than the Capture API[1] that only works on devices with a camera or microphone.
Convince me, I'm leaning towards your position here.
Enshrining technology that has no other purpose than to restrict access to one's own computer into an international "open" standard is unacceptable. At some level in hardware or software there will always be a closed blob to prevent capturing the stream, so there will never be an open software and hardware implementation.
Giving DRM the blessing of the international web community is, effectively, giving Hollywood unfettered permission to be just as obstinate, manipulative, and anti-consumerist as ever.
I don't understand this perspective.
As far as I can see, nothing here prevents regular, un-DRM'd content being sent as HTML5 video just as it can be today. This seems to be adding an extra option, which is to send protected content as well.
There is clearly a demand from suppliers for this facility. As a consumer, your options right now are to accept the extra content protected, or not at all. You do not have the third alternative of accepting it unprotected, whether you think you should or not. A content provider is under no obligation to give you their material on your terms just because you would like them to. Declining to give you content at all is not breaking the Web, it's just saying they don't want you as a customer, and if you want to enjoy their content, that's your problem more than theirs.
Ultimately, technology is neutral, and how it is applied is what counts. A standardised version of protected video potentially allows more people access to more content using more diverse business models. Sure, some people will always point at that and say it will be abused in dubious ways. However, the most effective way to defeat any such abuses is to vote with your wallet. If the information-wants-to-be-free crowd are right and there really is plenty of profit to be made on unrestricted content and a large market segment who won't put up with DRM, then the DRM will die.
On the other hand, reasonably effective copy protection also makes low-cost models such as pay-per-view/rental or all-you-can-eat subscription commercially viable. That could very much be in the interests of a lot of people who don't want to pay the full price for a permanent copy of something they'll probably only ever watch once anyway. Such deals are never going to fly in today's culture if the terms are trivially violated, and this has been a serious bottleneck in terms of getting the best content onto on-line providers and ultimately to consumers for them to enjoy.
EDIT:
I meant, show me a platform where users can't get Flash for free easily. AFAIR on Windows, Unix and MacOS (I used only the first two) you can just download a free player...
However - I don't think Apple would implement these extensions in Safari...
Admittedly powerpc isn't being sold as much as it was.
There's certainly a technical factor here, even if the media ecosystem is also to blame.
For an example of standards-compliant way to deliver video, turn on HTML5 support on YouTube (http://www.youtube.com/html5) and watch this awesome movie: http://www.youtube.com/watch?v=17jVlt-d8W8&feature=watch...
See, no technical issues.
You seem to want to demonize Netflix/MS/Google/Hulu for this but I'm having a hard time doing so when they seem to be trying to evolve standards to meet current market conditions.
Do you have a suggestion, or do you think such systems should simply sink? What should replace them?
Perhaps, but not in a way that is hard to distinguish from legitimate use technically and/or legally.
Presumably they are. Think about it: if you are Netflix, you recognize that DRM adds a lot of technical and business complexity to your product, for a "feature" that your users don't care about or even actively dislike. Why would Netflix sign up for that unless it was the only option?
Not only that, but prominent networks have pulled out of their licensing deals with Netflix recently, which should give you an idea as to the amount of leverage Netflix has with the studios.
By Universal Computing, are you referring to accessibility on the web? Platform accessibility?
I am opposed. Leaving out DRM helps establish new social norms that benefit the commons over individual players. We all end up richer in the end.
My attitude towards DRM changed somewhat when I saw what happened with the online music stores. DRM was absolutely required for Apple to get major labels to the table. Then, over time, DRM was chipped away, to the point where the iTunes Music Store is DRM-free, Amazon's MP3 store is DRM-free, etc.
If we can skip the DRM phase entirely, sure, I'd be on board. But is that realistic?
In the case of other content, for the most part it is either streaming only (most of the movie content, Netflix etc), or there are multiple players in the device market -- Amazon, B&N, Sony, etc. for ebooks.
I would hope that DRM goes away for all other media, but I don't see the other industry players giving in anytime soon.
I think the real intention here is MS, Netflix, etc, wanting to distribute & sell video to iOS users without paying Apple a cut, and they need DRM outside of apps.
Competition is the easiest way to combat DRM.
The presence of DRM legitimizes a social norms of restriction. The lack thereof legitimizes social norms of sharing.
DRM is a tangible embodiment of the the tragedy of the commons. DRM is analogous to a series of electric fences partitioning off the commons so that only some cows from some individuals can graze in certain places, but no other cows can graze there. People will invent electric fences for use in chipping away at the commons, but it would be a disaster for society to standardize the electric fences so that anyone can chip away at the commons effortlessly.
I'm of the opinion that if some entity wants to cripple their content with DRM, that is their prerogative, but they shouldn't get help from W3C and other bodies creating open standards.
On top of all that, as a developer, DRM is one more layer of bullish*t to deal with. I'm perfectly happy paying for APIs based on usage. I connect, you measure, you charge. Last thing I want to encounter are APIs which require me to implement a cumbersome layer of DRM to use content.
Lastly, I can only see the presence of DRM reducing accessibility of content for special needs users, such as the blind, because any form of DRM is likely to reduce how you can manipulate content. What if the DRM prevents close-captioning? text-to-speech? Addition of semantic data? etc.
DRM is wrong. It doesn't not produce a better environment for the consumer because it reduces competition.
DRM introduces friction. Friction reduces "liquidity". Lower liquidity results in a smaller market with fewer options.
REST vs SOAP is a perfect example of unnecessary friction in a "technological market". A market with DRM would have the same impact on innovation as a SOAP-based market.
If this were true, surely we would already see copyleft and creative commons content replacing TV programs and movies, since we've been in the DRM world for so long already. Yet we don't see those things. Why?
* People who really really care and don't mind spending the money have cable or go to the movies or buy Bluray disks
* Many others use Netflix, Amazon and iTunes, which all use DRM for their video content
* For other cases not covered, people either bootleg or just wait till the disc comes out
Free content wonks have been making this same argument for years, and it has yet to come true, so I fail to see why you'd expect it now.
The fundamental flaw in your argument is that you assume we would still have the same content available to consume without DRM.
However, the whole reason to allow copyright in the first place is to create an economic incentive for those who can to create and share works. And the whole point of DRM is that people weren't honouring copyrights, so the incentive wasn't working. Clearly there is not sufficient incentive for the major content producers to share their movies via on-line systems without DRM right now, because they have almost unanimously refused to work with such systems, and no-one has been able to force them to do so through commercial pressure.
> A market with DRM would have the same impact on innovation as a SOAP-based market.
The market already has DRM, and there are more (legal) ways to get access to the latest video content today than at any time in human history. But right now, implementing adequate DRM takes more effort than it should, and that has an impact on innovation by at best reducing the efficiency of services working with DRM'd content and at worst rendering services that would otherwise have been successful and beneficial to consumers commercially unviable.
Hixie's response: "I believe this proposal is unethical and that we should not pursue it."
It's safe to say I'm very happy with Hixie being the editor of the html5 spec.
https://www.w3.org/Bugs/Public/show_bug.cgi?id=10902
There's some vitriol from various parties in there as well, and all the points you would expect from people trying to create an open, accessible, and compatible presentation standard. Standards at its finest!
My thoughts exactly once you view the first diagram on the proposal.
- Apple decides (wrong or right) to not support Flash on a wildly popular mobile platform
- Flash begins its demise in general (again inevitable but IMO a little too soon)
- Adobe cedes further development on Mobile Flash
- secure video content deliverers are immediately faced with loosing the only existing "secure" video "standard" on the web and having to develop platform specific solutions
- a proposal is put forward to put DRM into HTML5 video (which it is going to have to get eventually for ubiquitous adoption, like it or not)
That's the chain I see.. which may have pushed this HTML5 DRM thing to the forefront before it has been properly hashed out. Not placing fault on any of the parties there, just a chain of events to me.
I disagree completely. It's now much easier to create and distribute your own content than it ever was, in great part exactly because of the new interactive websites.
Youtube alone is a great example. Sure, it has plenty of old media content (and plenty of abusive takedowns), but how many hours of amateur stuff is being viewed every single day? Probably orders of magnitude more than there ever was on the web ten years ago.
Then there's Flickr, Tumblr, Wordpress, Blogger, deviantART (140k submission/day) and so many more.
Sure, Netflix, Hulu, etc are major players, but I don't think user generated content is being replaced - TV is.
Previously, normal users were unable to interact with each other at all. Do you really think grandma/your uncle/etc would have learned to write HTML, found a place to get hosting, and put it online, if only Facebook hadn't come along?
Oh, and by the way, it turns out you have even more options for putting your HTML content online now [Heroku, AWS, Linode, Wordpress, Jekyll, etc], thanks in large part to the financial and social capital influx that came to the Web during the "Web 2.0" boom.
My whole point is that this philosophy of server-knows-best is causing the 'web' to revert to the standard creator -> middleman -> passive consumer chain. Of course many different "ways" of publishing are flourishing - those are the middlemen!
When you want to stream gigabytes of data for each client, for millions of clients at a time, you are going to start caring about the overheads you create elsewhere in the pipeline.
The initiation of an HTTPS session is expensive because it consumes a large chunk of CPU for a real-world-measurable chunk of time, all at once, in most libraries.
Everything beyond that point you're dealing with <use algorithm of choice> over <max of 32kb> of data. It does indeed consume CPU. It does indeed consume perhaps 8x MORE memory than a typical http connection - but the memory side here is completely dominated by the fact that we're trying to cache multiple gigabytes of data.
You can serve HTTP faster than you can serve HTTPS with less CPU - this is objective fact. But if we're talking about CPU utilization? I can't speak to whether this argument has traction right now, for large connections, relative to the claimed 'non-problem' position of several companies who serve small sessions dominated by that connection time, but as time passes it's going to be even less coherent a position than it is right now.
This proposed extension appears to provide a means for distributing keys between DRM chips/implementations (BD+/AACS/etc) and a remote license server. The reason this is a HTML specification extension is that Netflix and Google want to use <video> within HTML -- thus the browser environment must become responsible for interfacing between the DRM implementation and license providers.
Knowing the "keys" being transmitted is not useful because they'll be encrypted using public key cryptography. A heavily protected/tamperproof[1] DRM chip will have access to the actual keys required to decrypt the content. This could take the form of a Trusted Platform Module (TPM) as part of the widely criticised "Trusted Computing" initiative (is this one of the reasons why Microsoft is involved with the proposal?).
Some of the motivations of pushing towards this heavily restricted and inaccessible method of delivering content could include:
1) Ability to lock content to particular devices (iPhone users can access a TV show 2 weeks before anyone else).
2) Taking control over the purchasing cycle of consumers by forcing constant hardware upgrades.
3) Renting content for short durations of time under very specific conditions and limitations.
4) Pricing content on a per-user basis (some users pay more than others for the same content)
[1] Security Engineering, Edition 1, Chapter 14 by Ross Anderson - https://www.cl.cam.ac.uk/~rja14/Papers/SE-14.pdf
Always a scary sentence.
All user agents are untrusted, and for that matter, are often not the UA they claim to be. C’est la vie.
The goal here is to break the end-user's ability to access the material at will.
This means that the heavy lifting of distributing video can be done by CDNs, with the high-value keys/licenses going over secure links.
And there's more to this than just the transport encryption: it provides a standard API for decryption modules in the client, so a browser doesn't have to understand the details of every technology.
No "DRM" is added to the HTML5 specification, and only simple clear key decryption is required as a common baseline.
Why did they feel the need to use the word "license" and not just "key"?
http://dvcs.w3.org/hg/html-media/raw-file/tip/encrypted-medi...
It's daft.
IMHO, it's against of those principles.
I've been commenting against various forms of anti-web proposals such as this for more than a decade. Every 3-4 years somebody proposes to accept RAND (non-free) licensing terms. This time around it's non-free content distribution. Let's hope the W3C remembers who they are, and what they're for, once again.
I believe the two main advantages of Flash over the Video tag are that Flash can encrypt, and flash can do adaptive rate streaming - and adaptive rate streaming is also going through the standards process at the moment.
http://www.streamingmedia.com/Articles/ReadArticle.aspx?Arti... http://dashpg.com/?page_id=25
Firefox and Chrome both seem to be working on implementing it:
https://bugzilla.mozilla.org/show_bug.cgi?id=702122 https://code.google.com/p/chromium/issues/detail?id=109652
My experience recently is with Lovefilm, where they switched to silverlight delivery of content citing "anti-piracy measures" [1]. If we want to move to a www with HTML5 only video, an addition to the standard is required.
Whilst there will no doubt be people opposing any copy protection, I'm sure many can cite examples where it's exclusion is hampering the web.
[1] - http://blog.lovefilm.com/uncategorized/why-were-switching-fr...
This proposal _is_ DRM in the sense that it makes it much harder for paying legitimate users to access and control what they've purchased. It continues to provide incentive for users to pirate content using far simpler and more accessible channels.
The point is that if you are authenticated to view streaming content, you may not also be authenticated to copy and distribute it. This is flawed thinking on the content providers part, and has always been the case (recording the radio, using a VCR, etc.)
I'm not stating that I agree with the concept of this kind of protection, I'm merely suggesting that it exists, and needs to be accommodated. Clearly there will always be a way to circumvent whatever protection is in place, but there is no reason for a reliance on third-party plug-ins to do the job.
This is about copy protection. You can argue that that is practically impossible to do, but this isn't about about client authorization.
the question is whether you care more about the adoption of the standard or the purity of that standard. if html5 doesn't include methods for DRM, then hulu and netflix will continue to use proprietary extensions. how much do you care about adoption? if only 50% of sites use it, is it still meaningfully a standard?
I assume this will be something that is available in Chrome and Safari but not Chromium and WebKit, etc.
Looking at the companies that control media today and trying to mold the environment of the web so that they survive is exactly backwards. Instead, I think the W3C should focus on creating the best environment for an open web possible, and let the companies that exist now adapt to it or be replaced by those who can.
For DRM to be "effective" you have to control the client and not allow arbitrary implementations. Or what am I missing here?
All it does is giving credibility to DRM ("but the W3C has a standard for that!")
Requiring DRM for the web is ridiculous as long as the content is being broadcast in the clear over-the-air.
Now it's up to us, the tech community, to push back against this attempt at control. The broadcast situation shows definitively that DRM isn't an absolute requirement for the content industry.
So, effectively, by putting up DRM and copy protected content, they make up themselves the whatever value "piracy" has.
It would of course be much easier if the content owners some day understood that DRM solves absolutely nothing, only makes the UX worse, and the content is still being copied freely out there, despite all the protection.
Poppycock.
If I were unwilling to come to work unless I was to get €1,000,000 per day and the system wasn't set up to do that, then I would have to stay at home all day. I would have no right to insist that just because I find the current system unsuitable that it should be changed.
And if you were unwilling to consume content unless you were to get it without any technical measures to enforce the terms on which it is offered and the system wasn't set up to do that, then you would just have to do without the content. You would have no right to insist that just because you find their current business model unsuitable that it should be changed.