Gamely, I accepted the challenge. Browser dev mode to sniff things out was very difficult - they put a lot of work into jamming that up. Turns out it is trivially easy with Fiddler.
What I learned in the process was interesting, trying on a few video files. What these sites do is slice up their video files into thousands of chunks, and then rename the files as innocuous file extensions (like *.jpg, *.html, *.csv, etc.) and stick them on various hosting services where you can do a GET on the file for free with no authentication. They spread those thousands of files for each video file all over the internet. Usually across multiple accounts / repos on a service like GitHub but not just GitHub - any place they can manage. A lot I looked at while testing had files on GitHub though.
Then, once the thousands of files are distributed, they stitch them together via an *.m3u8 playlist file which the in-browser player can handle buffering to make it all seamless.