Reverse-engineering the security model behind Netflix's 'Watch Instantly' service
blog.pomelollc.com
blog.pomelollc.com
Still, they need to make sure that, for example: - you don't give your credentials to all your friends (so that they too can watch movies, without having to get their own Netflix subscription) - their content doesn't get streamed outside of the US, because that would be a violation of the license agreements that they have signed.
We studied their system to understand how they implement those security constraints, and how they manage to do it without affecting performance and user experience too much. The incentive was to learn, not to break their security.
No security is perfect though, and if you lock something down so tight that people can't get what they want from it, they'll find a way to break it. I think Netflix largely succeeds because it makes legitimate uses easy (sitting down and watching a movie) and only impedes the illegitimate uses (burning it to a DVD and selling it on the street).
Music DRM failed largely because its security impeded legitimate uses, e.g. copying your files to a new computer or a new MP3 player.