Mozilla bug 923590: Pledge never to implement HTML5 DRM
bugzilla.mozilla.org
bugzilla.mozilla.org
Users can vote with their wallets in order to reverse the sick trend of publishers who push DRM everywhere, but it's not as effective as distributors voting with their wallets. And Netflix clearly votes for DRM, not against it.
All this comes from some paranoid and unhealthy urge of publishers to restrict copying (even legal copying).
> Renting of digital data is a stupid idea to begin with.
I don't think it's stupid. I think it allows consumers flexibility; they can pay more and fully own digital content, or they can save money and pay less for temporary access.
May be you have ideas how to enable renting of digital goods without resorting to unethical preemptive policing? Until anybody comes up with such, renting of digital data will remain a bad idea.
To put this in perspective. When you rent physical goods, do you find it acceptable to be tracked while you use them with some hidden surveillance mechanisms?
But I honestly consider renting of digital data stupid anyway, since it's pointless. There is a valid reason to have renting for physical goods - it allows reusing of the same object and removes the need to make another one which is costly. So it lowers the price for the user of the object as well. Digital goods have none of these issues at all. They cost nothing to duplicate. So renting them simply has no point whatsoever, and is used to reduce usability and out of paranoid fear of piracy, not because it's making anything cheaper and reusable.
I already explained multiple times why DRM is unethical per se. In short - it's overreaching preemptive policing, that's why it's unethical. DRM in digital sphere is akin to making a police state to prevent crime. Sure, some desire such stuff, but I find it unethical. That's why massive surveillance and DRM issues always converge.
Massive? I don't see a major difference. You accept running some black box surveillance software which exists because of the mere reason of some publishers considering you a potential criminal (infringer) without any warrant and probable cause, based on them by default not trusting you. Now, why are you suddenly supposed to trust them in return that they aren't going to abuse that?
I just can't though. You're not paying for a copy, you are contributing towards it's creation.
Creation of content, digital or not, costs money. Sometimes it's an excessive amount (e.g. Blockbuster movies) and sometimes a sane amount (e.g. "regular" and indie moves).
Continuing with the movie examples... Most cameras these days record digitally. Do you expect that, since copying a digital file is free, that the movies should be free? It's entirely digital after all.
I'm hoping you don't, because otherwise you place zero value on the time and effort spent by the crew producing the film and that would be bordering(?) on unethical.
Ah, so you're also against most car rentals? They are often GPS tracked to enforce rules about leaving the country and such. I see no problem with this. It is their property, and they want to know where it is.
If you want to talk about the death of ownership and the rise of rental, and how that might be damaging, that's a fine an interesting topic, but I don't see how it's about ethics.
http://www.defectivebydesign.org/what_is_drm_digital_restric...
If we consider anything that works to prevent media from being copied in violation of copyright, then there is one solution that does not have a central service, and is not rent-based: watermarking.
Every purchase is watermarked for the specific customer. If they give someone else a copy, it is detectable from who they received it, so legal action is possible. But fair use is never prevented, as copying is always technically possible.
(Yes, it is possible to remove watermarks, but it is also possible to get around DRM - all of these schemes are continuously escalating arms races.)
Online games that require validating with a central server after being downloaded? Try not to get a virus downloading a crack after the company goes under.
I think that the millions of happy Netflix customers, including me, are going to respectfully disagree with you on that one. I don't illegally download media, but I don't want to have to commit to purchasing every single show or movie that I watch.
Netflix (as it is all streaming and not really "renting") isn't the greatest example. For some things that I can't stream on Netflix, I often rent from the iTunes store. The cost is much less than a purchase from the same store. The only difference is the understanding that the digital media I'm renting will no longer function after a well-understood period of time. I'm an adult, I can make informed consent to that arrangement.
I wouldn't be happy with this being the only media option, but I like having that as one of the many options in the media ecosystem.
All these reasons have completely no application to digital goods. So what's the point in renting them, or making the purchase price any higher? I see none, except someone's potential greed may be.
You can say, that renting an object more often produces more profit, in case when one time fee is charged for each renting, so that's the reason for the time limit. But then again, this is only valid when the resource is limited (physical object), and each user prevents others from renting it. In case of the digitial data which costs nothing to duplicate, the resource is unlimited, so this reason doesn't apply. And if we are talking about the same user renting it again and again, then what's the point? Purchase makes more sense again.
The bottom line, I think that renting of digital goods is a pointless idea. And since as we see it causes DRM in result - it's a bad idea too.
The price of something is instead based exclusively on willingness to pay for it. The market has proven that people are willing to pay more for digital goods that they own and can consume over and over over digital goods that they have a short-term access to.
Anyway, ask anyone if they prefer to buy and not to overpay, rather than rent. Just because someone devised an idea of renting digital goods for no reason except their own greed is not a reason to say that it's a good idea. It gives no benefits for the user and can be used as an excuse to drive prices up on purchases as you said yourself.
That's a fundamental misunderstanding of basic economics. The market always sets the price. If the price that is set by the market is lower than the cost to produce that item, then you just don't have a viable product to sell.
The basic real-world reason that renting of digital media exists is because some people are willing to pay more for the added value of being able to watch it over and over while some people aren't.
This is rather devoid of meaning. What is the market if not a label we use to reference the extremely complex interactions of individuals with varying degrees of information and rationality in an adversarial system? Of course the actual price to produce a product influences what people are willing to pay for it! This is why companies fight so hard to keep that information secret. This is why I refuse to buy a typical cell phone plan that charges absurd amounts for data and text and stick to prepaid. I influence the market because of my knowledge of how much it actually costs to send a text. The market absolutely reacts to the actual costs of products.
Very few people have the time and knowledge to do a supply chain or BOM analysis before they buy anything. Hence, there is little incentive for companies to price products based on cost. Cost is a factor only when analyzing profits.
Hence, cost is usually whatever the market is willing to pay. Saying it is unethical or wrong does not change reality.
There is a lot of misconception surrounding this principle.
To oversimplify, in the short term, price is determined by the interactions of supply and willingness to pay.
However, in the long term (in a competitive market), new suppliers will enter the market if existing suppliers are making supernormal profits, and existing suppliers will exit if they are making subnormal profits.
This means that, in the long run, price will converge to the average total cost of production, in a competitive market.
Of course, Netflix is not operating in a perfectly competitive market, but that distorts the price in a different way. It's not quite technically correct to say that price is based exclusively on willingness to pay for it; even in noncompetitive markets (true monopolies, as opposed to monopolistic competition), one can just as easily say that price is determined by the quantity that the monopolist wishes to sell.
I don't subscribe to Netflix, but in my opinion if Netflix allowed downloading, what many people would do is make a list of movies they wanted to see, subscribe to Netflix for a month, download all the movies they could and then cancel. Then spend the next year or so watching the movies at over the course of a year or so. You don't get Netflix's recommendation features and everything's dated, but you could download many more movies in a month than you would want to watch. If people who were currently Netflix subscribers switched to this method, then Netflix would see its subscription rates drop. Since their costs would remain the same, they'd have to raise prices significantly. One of the advantages of Netflix is the low price, so many people would cancel outright, but first they'd want to build up a store of all the movies. Maybe some people would be willing to pay for a continuing subscription based on convenience, but I think that for the most part Netflix's user base would turn into one-month bulk downloaders.
Most subscribers would still subscribe to a DRM-free Netflix, because it's considerably easier than maintaining a failure-prone array of hard drives to store everything you want to watch.
there are already copies with better quality than netflix available to everyone to download. and netflix is still in business.
i still have to download those better copies in less than 2 hours when i want to watch something not on netflix or hulu. and i now hate it. i used to love when there were no convenient way to pay for it.
so, quit the nonsense as it even goes against factual evidence
Now, a different and more interesting question is what would happen if Netflix maintained the legal requirement to only view movies through streaming and not to store them, but eliminated the DRM. This would make their model comparable to Amazon's MP3 store, except with for video rentals rather music purchases. Netflix certainly think that such a model wouldn't work for them, and I'm willing to give them the benefit of the doubt. You can point to MP3 stores such as Amazon's to say it would work, but it's interesting that even though MP3 purchases are widely DRM-free, music streaming is still DRM-protected (as near as I can tell: correct me if I am wrong).
so i cant create a content distribution company that allows you to download and convert the movie to some format you need tonwatch on some roadtrip because the middle man says i have to sell it to you via streaming.
Your whole arguments abut price and overpay don't make sense. I call your arguments closed-mind and invalid. From a consumer's standpoint, there is nothing cheaper than being able to choose any movie you want to watch, unlimited at a bargin price like $7.99.
That being said, I and millions of other users think Netflix should have more movies. More newer movies but that's really impossible because stupid Hollywood movie companies like WarnerBrother won't sell them to any streaming company simply because they want to sell the DVD.
So, the argument that it's "cheap" is invalid, and a separate question to ask is, how much do you value your privacy?
I am paying $7.99 and I am happy to tell Netflix my preference (my ratings) because doing so do help refine results show up in my dashboard and also gives netflix an idea what people like XYZ. There is an equal opportunity for both users and the service to improve.
I am paying $7.99 for unlimited service. I can watch at any time, resume at any point, re-view at any time. I can always watch - downtime is statistically low. The streaming / connection is usually very good even for poor internet access. I am not giving up a lot of personal data to be honest. If I don't want to watch the movie / tv show after 20 mins I am still paying $7.99. I am not charged per movie. I can actually stream with my girlfriend instead of paying another $3.99 on Amazon for us to watch a movie together.
Tell me if this is not a bargain.
This is a purely a decision people can make. On the other hand, I never said FB isn't exploiting users' privacy to gain more profit. But if the argument is free services comes with a cost, well, "no shxt Sherlock."
Let's look at it this way. Do you think free software are truly free? Some people release free software in order to provide a premium version later time. Some people provide free software to build their skills and reputation. Some people provide free software to benefit everyone, and that's cool!
Do you think docker.io being an open source project really is free? How much $$ can dotCloud save by open-sourcing it? How many more customers will they get after releasing docker? How many people will now trust dotCloud now? There is a price and a gain, even from a pure altruist view.
DRM by nature is little different to public key encryption - it's a method of proving you are who you say you are. Usually there is some component that makes it resistant to tamper, but that in itself doesn't have to increase risk of breach.
You may raise the Sony rootkit debacle, and I say so what? That says more about Sony's failures as a consumer friendly company than anything about DRM.
You make points about how DRM implies contempt for the consumer, but I don't see why that is the case at all. DRM can be a technology that enables more choices for consumers, and that implies respect for consumers, not contempt.
I'm no fan of DRM, but it seems to me you are overreaching in your arguments, which is making your point weaker.
I see no place for DRM in the open web, but at the same time I want the open web to be able to compete with other platforms. I don't know what that means the best choice is here.
Simple. Do you think placing surveillance cameras in everyone's home is an acceptable crime prevention practice? Or may be attaching a camera to each person right away? That's what DRM is. DRM is invasion of people's private digital space. And if you don't see it, it makes it even worse, since secret and massive surveillance is even more unethical, since people get "comfortable" with it. So all this "unobtrusive" DRM is actually even worse.
> DRM by nature is little different to public key encryption - it's a method of proving you are who you say you are.
No. DRM by nature is a way to restrict what user can do with the data, or if it goes further - reporting tool for those paranoid groups who deploy DRM. By its own nature, DRM implies surveillance and contempt to the user.
DRM (and abusive surveillance) does not enable any choices. All it does is taking away people's privacy and ability to exercise fair use to the data they bought.
And intentions of those who push for deploying DRM aren't even secret: http://boingboing.net/2013/05/26/us-entertainment-industry-t...
So, are you suddenly supposed to trust them blindly when they insult you by not trusting you?
Netflix runs custom clients to make sure I'm authenticated and authorized before streaming video to me and streams it in a format that only their software can decode. Sometimes these clients are built into my TV and other times they are written in Silverlight and are built into my browser, but that doesn't automatically mean they're a rootkit any more than Lotus Notes is a rootkit. The only reason it seems otherwise is that you have this weird manichean worldview where any DRM is morally equivalent to the Sony rootkit.
DRM is unethical not because it's always a rootkit. But because it's overreaching. The fact that it's prone to be malware just demonstrates the potential for abuse of overreaching preemptive policing.
The only people likely to rip video from Netflix are casual copiers, digital information hoarders, and people with legitimate compatibility/access issues.
It's kind of baffling that anyone making money off this business would want to drive these paying customers into the arms of Bittorrent, YouTube, etc.
It's not ideal by any means, however still circumvents any sort of protection.
Someone will do that, big media will be mad, we'll have more laws, browsers will be forced into having a binary blob in by default, avid Netflix watchers will be so happy.
Remember what happened to html5 video. Everyone but Firefox was pragmatic, and implemented h.264 -- primarily, but not only for hardware acceleration reasons. Years later, Webkit-based browsers are ubiquitous, and Mozilla is developing a phone OS nobody will care about, in a desperate effort to become relevant again.
Imo, Mozilla ought to spare itself another embarrassment by being the only guys in the room with the contrarian opinion. Take the issue to the W3C directly -- or for that matter vote for your local pirate party. HN and other tech news venues might be the correct places to recruit support, but you ultimately want to lobby your case directly.
Wonder if I've still got tabs saved from the last time I seriously used Firefox, years ago. Probably not...
BTW I switched to Firefox on my laptop since it seems to be much less resource-hungry than Chrome. Not painful.
Good luck trying to get a webfont to render the same (or look any good) in Chrome as it does in IE and FF on Winderps. The sheer fact that it isn't IE for once...
The font thing, while somewhat recent in usage, should have been in Chrome ages ago. Not going to bother getting into Chromes other more critical flaws as I feel like these threads devolve into this kind of shit too easily.
Just sucks that Chrome has gone from this cool browser that actually is progressive, to some kind of Ad-friendly extension of Google that just qualifies as "better than IE!".
Methinks you should jump on FF, it's better, and not because it may not support some arbitrary HTMl5 spec that we wont see for half a decade.
- Tools like YSlow and PageSpeed require Firebug.
- You can't disable the browser cache from FF devtools, which really sucks when you are trying to debug a broken redirect.
- When inspecting an element in FF devtools, :before and :after CSS properties will not be shown. I wasted many hours debugging a CSS refactor because of this (imagine going up the DOM, comparing computed CSS properties until you reach the root). Both Firebug and Chrome devtools will show :before and :after properties.
I think Firebug and the Chrome devtools are comparable in quality.
And on that, I was plesently surprised to see Chrome will now display :before and :after psuedo elements in the DOM structure
It was fixed recently. https://hacks.mozilla.org/2013/09/new-features-in-the-firefo...
-1 to the logic of switching "if they implement drm": If your drmized content isn't available in FF, you'll have all incentives to come back. Unfortunately.
No I won't. I'll either find an uncrippled version of the content -- for example on TPB -- or I simply won't look at it.
DRM is a perversion of the WWW, and Berners-Lee is wrong to allow his invention to be sullied in this way. The web has been successful because it consists of open standards which means anyone can build on it. Just as tcp/ip is an open standard and Berners-Lee didn't need anyone's permission to build http and html. Take away that openness, and you'll be destroying something very valuable.
If the MAFIAA don't like the open web and want a locked-down system, let them build their own. I'm sure it'll be every bit as successful as Windows RT or the Ford Edsel were.
I personally use Safari, but if Mozilla supports this pledge, I'll move back.
[1] https://code.google.com/p/chromium/issues/list?can=1&q=EME&c...
"Part 2 will incorporate the EME API with the Widevine CDM and is slated for a later release (M31)"
https://tools.google.com/dlpage/widevine
Seems only Window and Mac for desktop, maybe it's only in Chrome for Linux on ia32 and ia64?
Then Firefox became faster and now i got the best of both worlds though Chrome did grow over that time and now they have everything I would need but I have no reason to switch.
I really hope Firefox puts its foot down and refuses to implement DRM I mean it's an open source browser this should be unacceptable.
So what if MPAA goes to Mozilla next and tells them to adopt whatever auto-DMCA/censorship schemes they come up with next. Is Mozilla supposed to just accept it because "all the others are doing it"? I sure hope they wouldn't.
Publishing a standard that says "the user agent MUST support Ogg/Theora/Vorbis" doesn't change anything until you motivate the company that implementing that standard is more important than anything else. And as long as IE, Safari, and Chrome all supported H.264 (etc.) anyway, most web developers would just use H.264 thus giving MS, Apple, and Google no (external) motivation in terms of site-compatibility to support Ogg/Theora/Vorbis, and if the market (i.e., browser users) don't care about it — they won't add support.
For now, there isn't even any standard for how the decryption algorithms should be implemented as plugins, so it's hard to see how Mozilla could implement it in the first place, let alone be pressured into implementing it.
Also, H.264 was already dominant on the web when the video tag was introduced, it was far better than Theora, it's slightly better than V8, and as you mention, it has hardware acceleration - all strong reasons for people to use it regardless of their opinion on patents. EME's support is mostly limited to a small number of companies that want to use it and doesn't seem inevitable at all. The situations are very different.
That's what you're backing. It may sound odd, but I imagine a large number of folks on HN disagree with you.
And if your talking about mobile browsers, smartphones are dominated by two platforms, each owned by the corporate parents of two webkit-based browsers, one of whom doesn't allow you to install other browsers at all.
Nitpick, you can install other browsers on iOS. Don't think you can make them the default handler for URLs from other apps however, but most apps still ship their own web view inside the app making that a mostly moot point in my experience.
What did happen exactly? The desktop is still not playing Html5 video, Flash is still used. I still can't go fully with Html5 on YouTube.
On Android mobile phones, Firefox had a rough time not because of Html5 video, but because they were slow to develop a usable version. The first versions I tried were very unstable and ate too much memory compared to the stock browser. But you know, it's evolving and on Android right now I think it's better than Chrome, minus one or two annoyances. Plus, they took the pragmatic approach, as they fall-back on the operating system's support for H.264 - remember open-source projects cannot bundle H.264 by themselves. Chrome is not open-source, while Chromium is and Chromium does not come with H.264 (although you can make it work on Ubuntu at least by installing the necessary code packages).
How is Html5 video related in any way with Firefox's marketshare?
> Years later, Webkit-based browsers are ubiquitous, and Mozilla is developing a phone OS nobody will care about
You're probably speaking about mobile web browsers. People here forget how big the desktop is and it's not going anywhere. And the WebKit browsers you're talking about are incompatible with each other. As for Firefox OS - personally I care about it, because it's tackling a market that has been ignored by both iOS and Android and because it leads the way to new Web APIs. So there you have it - you can't say that nobody cares about it, when clearly I do.
> Mozilla ought to spare itself another embarrassment by being the only guys in the room with the contrarian opinion
Maybe you should spare yourself the embarrassment of not recognizing that Mozilla made the web better precisely because of its contrarian opinion.
Firefox makes money (through the search engine integration at least), VLC et al do not.
It might also help that VLC is a french project. Laws and patents are sufficiently different that it takes effort to build a case, while for US cases the MPEG-LA + members have probably a template on file where they only have to fill in the victim.
Firefox can't afford to play fast-and-loose with patent liability.
Webkit-based browsers are ubiquitous
Are they? All the corporate guys I know that jumped on Chrome jumped to (..) IE10 now.Everyone else still uses Firefox around me and wonders why someone would ever install a browser from an advertisement company.
Have you used Firefox on Android? I've to admit that running Aurora is kind of hardcore (daily updates..?), but - wow. It's not just a really good browser, it's beautiful on top of that.
I'm really looking forward to see devices with that OS nobody will care about - because all alternatives suck or died (WebOS was promising, so was Maemo/Meego. I'm also interested in sailfishOS).
Your whole comment is weird. Your claims make no sense from this point and I have to disagree with literally every single line you wrote here.
My hope is that FF/Mozilla _will_ pledge not to implement any of these idiotic ideas.
Everyone else still uses Firefox around me and wonders why someone would ever install a browser from an advertisement company.
I have no idea who you have around you, but that is a very minority opinion. Chrome's usage keeps going up and Firefox usage goes down.
I've used Firefox on Android (including Aurora) and it's fine. I don't see what makes it better than Chrome.
Though I don't think your whole comment is "weird", I think that we both have different experiences.
Firefox around me: From technical people to guys that use mostly Excel, everyone here uses FF (apart from the IE10+ guys at work). Heck, I learned about some of these strange 'take FF, compile it for amd64 and call it "optimized"' FF derived browsers through people that .. are average not-into-computers-really joes.
The only people that DO install Chrome around here (I know, I know, nothing but anecdotes to back this) are elderly family members that click that annoying huge 'You should really download our browser, it's teh best thing ever' button on Google - and get back to launch IE again the next day, because they didn't understand the whole thing, really.
I don't want to take Chrome away from anyone, I just dislike the 'Meh, FF OS is useless anyway, their browser is becoming obsolete and they just meddle with politics' dismissal in the original comment. A 'desperate effort to become relevant again'? Why (and in what world) would they be irrelevant in the first place?
Everyone uses Chrome here, and we're not a fancy new tech company or anything, we're a pretty conservative shop that's been around twice as long as many HNers have been alive.
WebKit powers the highest percentage of browsers, more than any other rendering engine. Not saying these stats are authoritative, but they are typical and similar to my own sites: http://www.w3counter.com/globalstats.php
DRM-enabled Firefox would be effectively non-free software: you could not modify it and rebuild it from source while retaining the DRM functionality.
An open source browser can conform to the W3C DRM standard ("Encrypted Media Extensions") and remain open source.
Frankly, this system would only work if you standardise in a DRM system. The W3C may claim "only the simple clear key system is required to be implemented as a common baseline" [1], but that's highly misleading IMO.
1. https://dvcs.w3.org/hg/html-media/raw-file/tip/encrypted-med...
This is really only about replacing a huge proprietary blob with a much smaller one.
The video element already exists and is implemented in all major browsers. Have a good look over http://en.wikipedia.org/wiki/HTML5_video
This has exactly nothing to do with reducing the attack surface of a browser.
What this is about is letting people like Audible and Netflix encrypt their content in a special way that means that only browsers that support the DRM api can decrypt it; by including the closed source binary blobs provided by those vendors.
Don't want to do that? Sorry, our website doesn't work on your browser.
...but to the main point:
This will in fact catastrophically increase the attack surface of browsers, as they are forced to bundle unmoderated, unreviewed binary code blocks (Content Decryption Module, from the spec) that can do whatever they like into the browser code.
What was said was that it is there, and services are choosing not to use it, even accepting that using it would be suicide for their business. It's not the responsibility of http to preserve the business models of those companies rather than a free and open internet, though it's understandable that those businesses are fighting for it.
Even half of the ad-supported content on YouTube isn't available.
As an implementor, until mozilla finished shipping native h.264 support I have to either use Flash as a fallback for IE8 and Firefox (mediaobject.js is great!) or encode all of my video twice and double my storage bill. Guess which one is more appealing?
That's no different from the current situation with Flash and Silverlight. You're not forced to use them, but some content is only accessible if you do. If we can replace Flash with a CDM, the attack surface is decreased, because a CDM is less complex.
Without the EME standard, it seems highly unlikely that media companies would decide to distribute videos DRM-free. They would simply continue to build and use non-standard solutions. EME is just a standard API for what they'd be bound to do anyway.
The browser must invoke the closed source, vendor provided CDM by pass a binary stream from the server.
Certainly, it's no worse than what we currently have, but current plugins have, shall we say, a rocky security history wouldn't you say? (>_> java)
Worse, every content provider is going to have their home written CDM, because they certainly aren't going to share. Once a CDM is compromised thats it, it's useless.
It's going to be a nightmare of install-all-the-plugins. Most likely major browsers will bundle the most popular one to reduce the burden on the user.
That's why this is such a big improvement.
It also does not define a common API to load such a module in a browser. In fact the module can also be built into the browser. Which is exactly what Microsoft will be doing with their PlayReady for the Internet Explorer.
An open source browser would have to rely on the DRM module to do all the video decoding and rendering. If the module handles the unencrypted stream back to the browser then one could simply change the browser to dump the stream. A browser would also have to make sure that other JavaScript can't access the unencrypted content. So no more funny graphic effects with videos rendered onto canvas or WebGL textures.
This proposal will destroy the open web and make it rely on closed source binary blobs. A free software browser will end up being useless because it will be excluded from most of the content. Who would want to use Firefox or Chromium if they can't access YouTube? When we start to add DRM for media elements then how long can it be until publishers demand DRM for text and image content? And what argumentative position would the W3C have to refuse it?
With Firefox market share decreasing and proprietary browsers like Chrome, IE, Safari increasing we are in a really bad position. Microsoft can simply push their PlayReady in IE and provide plugins for Chrome and Safari. Netflix is already using PlayReady. So no change for them. And then Firefox is fucked. Linux is fucked.
And how long until Google moves YouTube to DRM? Google is involved in the design of the DRM proposal. If DRM is in HTML5 then it's just a simple step for them.
That's why we have to oppose DRM in HTML5 and keep the web open. It is sad that Tim Berners-Lee has given up on the open web. But I won't and I hope Mozilla won't and I hope you and others won't either.
Fully agree. I think the focus of the effort should be to lobby the 2 browser vendors that are driving this DRM effort, Google and Microsoft (see 'Editors' section on https://dvcs.w3.org/hg/html-media/raw-file/tip/encrypted-med... ).
The only way to stop this DRM proposal is to have it not be implemented in browsers. The only way to stop that is to convince Google and Microsoft to stop pushing it.
Opposing EME will simply keep Microsoft and Adobe uncharged of the web video market and keep that market smaller thB the Apple, Google, Amazon, etc. stores.
The last time someone took a “principled” stance like this and blocked H.264 in Firefox, remember what happened? Flash got many extra years of life and Firefox lost marketshare.
I'd prefer we stop pretending this is anything other than a minor shift in the status quo and focus on the larger anti-DRM campaign. The right place to focus is the bottom-line: educating consumers about the restrictions and supporting alternatives. As long as people are paying billions of dollars through native apps, you're fooling yourself to believe that this EME opposition is doing anything but supporting competitors to the open web.
http://en.wikipedia.org/wiki/Mozilla_Corporation_software_re...
It's not really a big deal, but the trademark restriction does mean you can't just redistribute Firefox as-is. Whether you count that as non-free is subjective.
Here it is right in the list of APPROVED Free Software licenses: https://www.gnu.org/licenses/license-list.html#MPL-2.0
* Firefox is the only browser that can't play certain content
* Firefox is the only browser that plays all content
?I would assume the first, because it should be easy for a content provider to just block a certain browser entirely (and that block could be circumvented, but the majority of people won't do that). People will blame Firefox, not the content provider.
Since FF is still popular enough in certain regions, that it (plus legacy IE versions) could kill EME before it gets popular, except for certain special use cases like Netflix on Chromebooks (where, honestly, a fully custom plugin solution would work just as well).
Surely the website will detect FF and instead of serving an encrypted stream, display some informative message laying the blame with Mozilla and link to a DRM-enabled browser download.
So instead of installing a plugin, the user is now expected to install a new browser (with different UI and everything) _and_ a plugin for the DRM implementation. That surely helped the DRM vendors' cause.
1) Firefox won't play DRM'ed content by default
2) Firefox could be the browser that allows you to go around all DRM'ed content through 3rd party plugins (they probably won't be able to condone the activity themselves).
The sad thing is the content guys will start yelling from the rooftops afterwards that "Mozilla is facilitating piracy and content theft" or something like that, even though they would keep the browser just like before - the "open web" we all wanted.
But because everyone else will have sold their soul to the content corporations, that sort of censorship will become the status quo, and now Mozilla will be the enemy.
Instead of "open web" being the status quo, I fear that "DRM'ed web" will become the status quo.
[1] http://www.afterdawn.com/news/article.cfm/2013/06/27/netflix...
While technically true, it's certainly stretching the truth a wee bit.
Saying "Internet Explorer 11 can play netflix videos using EME without using additional plug-ins because it ships with specific DRM-implementations built-in" would be the more correct version.
I mean... Chrome can play Flash-content without any plug-ins, because the Flash plug-in is built in. When you put it that way, it doesn't sound so impressive any more, now does it? Further extending the browser will require plug-ins.
The special about this thing, is that it's a plug-in architecture deliberately created to enable DRM, to take control away from the user. That's legitimizing DRM as a concept in a supposedly open standard.
That's as just madness and 100% self-contradicting.
But don't forget that implementing something like this will have negative consequences as well. By dodging these consequences Mozilla could - at leas in theory - gain an upper hand.
In the longer term, Silverlight is abandoned and Flash is on its way out. I think it's unlikely that Firefox holds out against EME in the long term, but it could be that it slowly gains a reputation for being bad for many streaming sites. The Flash fallback is buggier and less featureful than the streaming in other browsers, maybe slower as well. At some point, people upgrade their computers and find it hard to get a Flash plugin that works and so they eventually give up and switch browsers.
I'm not sure how technically possible it is, but another option is that Netflix and similar companies will write their own plugin for Firefox which supports DRM. Presumably they will try to make a plugin which is not a platform like Flash, but only serves the purpose of doing the DRM. An equivalent, but probably techincally superior, option is to put the DRM into an asm.js blob.
Some people in this thread believe that the lack of support for EME will put pressure on media companies non-DRM streaming options. This strikes me as wishful thinking. In the short-term, the existence of Flash and Silverlight fallbacks mitigates the pressure on Hollywood and streaming providers. Again, see the H.264 story. In the long-term, Hollywood's smart enough to realize that if there exists a DRM solution for Firefox today, then it will be technically possible in the future as well.
That's why I don't see the point of boycotting EME. If it could plausibly lead to DRM-free streaming options, that would be an improvement, but I don't believe it will happen. On the other hand, from a binary blob perspective, EME plugins are strictly better than NPAPI plugins, and second, users who don't want DRM can always not use it. All boycotting does is reduce the options for users who are willing to accept DRM.
DRM can't be implemented in a simple binary plugin since the user will still be able to copy the protected content by e.g. modifying the video driver. All system layers from EME module in a browser to hardware will need to be restricted from modification. Do you believe that Secure Boot was created just for malware protection?
Even if the OS starts becoming as locked down, you're still technically inaccurate: a CDM could just be a shim which pass data through to an OS media API which handles the actual playback.
Flash and Silverlight do not provide any real protection and they are certainly not enough for content cartels. That's why DRM solutions are being developed. As soon as the major software vendors will provide complete DRM implementation restricting all levels from user agents to drivers and bootloader, content providers will start to require it.
> Even if the OS starts becoming as locked down, you're still technically inaccurate: a CDM could just be a shim which pass data through to an OS media API which handles the actual playback.
But that shim will not provide any real content protection if the OS is open for modification. For example, someone could make a version of the OS's media API implementation that will allow users to save any media stream decoded by CDM. Thus, the OS will have to be locked down to support DRM, that's what I am trying to say.
I see the corruption of W3C (because that's what it is) by corporations almost as bad as the corruption of NIST and the security standards by the NSA.
And for what exactly? The apparent "convenience" of not having a 3rd party plugin, but instead a "native" plugin in the operating system, that will only work on certain operating systems and browsers? HTML and DRM are incompatible in principle, and will be incompatible in practice, too. It won't give you any convenience, and will potentially make things worse in many other ways.
And all of this because we're starting to buy into the idea that the content companies are right and piracy is hurting their sales? I guess repeating a lie long enough, does make it true in the end - even though it probably isn't [2].
So once again, why are you letting our Internet freedom slip away without even a fight?
[1] - http://www.freedomhouse.org/report/freedom-net/freedom-net-2...
[2] - http://torrentfreak.com/piracy-isnt-hurting-the-entertainmen...
That is the future we can very well face unless we oppose this DRM evil now, at its root, before it enters our HTML standard.
Don't attempt to be "pragmatic" about this one; be principled. Stop using any browser supporting the EME initiative.
Perhaps the fragmentation it will cause will destroy closed media on the internet as a whole.
Nothing bad can come of it.
It almost certainly won't. The majority of consumers won't care (or even notice) so long as good products are being made with the technology.
The basic argument is that those who want restrictions to content have been attempting to chip away at what is essentially an open platform. While the W3C's argument is that it is an "extension" to the HTMLMediaElement, and while the draft goes to great pains to state that it is not a DRM system, in actual fact it goes a great way towards allowing for a DRM system.
If you review the diagram in the draft [1], you will see that it covers playback of certain content. Currently, it is restricted to media files. But you can see that once this is adopted, it would then lower the barriers for media companies and other interested actors to push for encryption mechanisms for individual elements.
Even worse, note that the Content Decryption Module (CDM) is a "part of or add-on to the user agent that provides functionality for one or more Key Systems". In other words, these will probably need to be implemented as binary blobs which are add-ons for browsers. They may need to use specific technologies that are part of particular operating systems.
What does this leave us all with? Well, it leaves us with the promogulation of a bad idea (restrictive DRM) implemented using a variety of browser specific extensions that may need to utilise the specific technologies of a particular operating system.
As an example, you could be forced to use an add-on for Internet Explorer that can only be used on Windows 8.
So in other words, the plan is a bad one for technical reasons, and for political reasons it lowers the barriers to campaigning for more restrictive measures leaking nto the rest of the standard.
1. https://dvcs.w3.org/hg/html-media/raw-file/tip/encrypted-med...
The option I'd like, where video is watermarked or otherwise not encumbered, isn't on the table and much as I'd like that to change, the security realist in me would like a web without Flash even more.
That said, I was not previously aware of watermarking as a viable alternative with meaningful industry support, and it has consequently replaced the (relatively clean) DRM interface under discussion here as the value bound to 'least-harmful-option.
Like this: http://www.w3.org/community/webappscp/
> copy-paste of text demanding micropayments to complete
There was some discussion about restricting copy-paste of text at http://www.w3.org/2012/08/electronic-books/ for example.
So the way we get there is that there are existing constituencies pushing for those things. And now they would be able to point to EME and say "Hey, video gets this, why don't we?", strengthening their bargaining position.
http://www.w3.org/blog/2013/05/perspectives-on-encrypted-med... is an example, for your delectation.
"The W3Cs (and Tim Baner Lees) support of EME shows clearly that once again, the W3C has gone down a blind alley (like with XHTML) and is not interested to serve the real needs of the web. The WhatWG was the result of W3Cs stagnation on addressing real world needs. And once again the W3C is more interested in stagnation than real world needs with EME. It has to be expected that the relevancy of any W3C standard will substantially diminish in the future."
I wrote pretty much the same thing in the comments on the blog post yesterday when people were freaking out about this then. EME is a plugin spec for implementing DRM, not something that would get baked into browsers.
Everyone put their logic pants on and stop freaking out for a second. This is might be a silly spec for implementing a stupid premise (DRM), but it's not the end of the open web.
So has syphilis.
Your argument (here) is not better than the STD comparison: Apples, oranges, no relevant content.
Isn't most of the (digital!) music market DRM free by now? How does that EVEN WORK?
What was that about getting paid again?
I guess they mustn't consider the international market worth the trouble of solving whatever legal issue is stopping them from selling them to other countries.
Plus, it was funny. Absurdity often highlights problems in arguments.
That will make Firefox on Haiku less functional than Firefox on Windows. (and if the plugin were able to run everywhere, it would be trivial to work around: Just run on a system without a protected AV path)
If you can't use HTML5 DRM with Netflix your other options are either Silver light or a native app and Haiku has neither.
I'd say HTML5 DRM is the far lesser evil in this case.
IMHO If anything EME is more evil than the other options in that it standardizes (and this way implicitely mandates) a special plugin interface for DRM purposes only.
Users still have to install plugins, and now browser vendors get the blame if things fail (since the user will be hard pressed to identify plugin issues in "that website doesn't work").
I fail to see where it's the W3C's, browser vendors' or web users' responsibility to make the DRM vendors' lifes easier. And that's all EME does.
For one, because they'll fail in the most hilarious ways (and each one separately), so there will be backdoors, or at least a good laugh or two. But also because it drives up the cost of DRM, hopefully making it less attractive.
Should DRM manage to get hold even despite such problems and Amazon notices that they can reduce the price of their media package by 1$/month if they drop the DRM, the resulting massacre will be great to watch.
Completely disagree. HTML5 DRM is non-interoptable but disguised as interoptable through its HTML form. That makes it much, much worse.
And in the future I expect more pain with proprietary, closed-source, non-interoperable (and, almost certainly, non-linux-supporting) CDMs, which are where the meat of the DRM will be implemented under the W3C EME proposal but which themselves are not being proposed for standardization.
Is this just a crusade agains DRM as a whole (good luck with that) from the free software movement, or do they have problems with this exact proposal from the w3c?
This proposal simply trades one insecure, binary blob for another. It doesn't really solve the problem.
> rather than getting and updating 2-3 different insecure plugins all the time for doing the same thing?
IIRC each site can provide its own module, so it'll be many more than 2-3 plugins
> Is this just a crusade agains DRM as a whole (good luck with that) from the free software movement, or do they have problems with this exact proposal from the w3c?
Why good luck with that? DRM simply makes honest users jump through hoops and allow themselves to be controlled. Also, the proposal itself doesn't really solve any of the problems that flash and silverlight do. And those binary blobs will still probably not run in linux...
No, the problem is that they think they reserve the right to control what your hardware displays.
Like the crusade against DRM in mp3s? Which succeeded.
Or the crusade against DRM in ebooks? Which is making progress.
Or the crusade against DRM in broadcast TV (the broadcast flag)? Which succeeded.
The history of crusades against DRM is that they succeed. It's baffling why some people are giving up on fighting web DRM so easily.
The point of DRM is precisely to make sure that it does take time and effort to capture and redistribute video. So live events are actually a perfect example of where DRM is useful.
And we're both assuming that the people running those mirrors won't work out a way to disable the watermarks in real time. I've not read up on digital watermarking technology, but it's hard to imagine that it's bulletproof.
And yes, I'm assuming that robust-enough watermarking methodology is possible. I don't think it has to be bulletproof, I just think it has to be good enough to enable cancelling enough stream consumer accounts to deter casual mirror-ers. DRM isn't bulletproof either; watermarking is preferable for users because it doesn't require that the stream producer take control over your machine.
Even if its not true (I have half a dozen current gen devices and end up using them all regardless of my beliefs), you definitely opened yourself up to a 'Do as I say, not as I do' attack.
Just ignore the trolls.
"A Web where you cannot cut and paste text; where your browser can't "Save As..." an image; where the "allowed" uses of saved files are monitored beyond the browser; where JavaScript is sealed away in opaque tombs; and maybe even where we can no longer effectively "View Source" on some sites, is a very different Web from the one we have today. It's a Web where user agents—browsers—must navigate a nest of enforced duties every time they visit a page. It's a place where the next Tim Berners-Lee or Mozilla, if they were building a new browser from scratch, couldn't just look up the details of all the "Web" technologies. They'd have to negotiate and sign compliance agreements with a raft of DRM providers just to be fully standards-compliant and interoperable."
Well, so essentially like the situation with native apps then. My guess is most consumers wouldn't notice at this point.
Oh, they can't monetize it then? That's the price for security.
The internet dorks who frequent HN and Reddit who know how to easily circumvent said DRM are the minority.
That any normal people would torrent anything says a lot. Normally convenience wins. Maybe torrenting actually is the easiest way to get some content? For me, it's a no-brainer[1], but it's more surprising if this is the case for normal people as well. That should open the eyes of some content providers, but of course it won't.
[1] - Meaning that for me as a technical user, torrenting is really easy. Some things have just started to compete, like spotify, netflix and hbo online, but they are often crippled in other ways.
"Their point" to reiterate was "Realistically, DRM keeps the majority of users from pirating content".
Yet then right here you say "I don't believe that anyone thinks DRM effectively protects content, even the companies employing it."
Which is the exact opposite of the point they are making....
The majority of users would not be capable of getting the URL of the actual movie out of the HTML source, saving it to disk and sharing it with friends.
The majority of users is, however, capable of going to thepiratebay and downloading the same movie through bittorrent.
It takes one 'internet dork who frequents HN and reddit' to circumvent the DRM and upload it somewhere where the average user can easily get to it.
DRM doesn't work because it only takes 1 internet dork to provide a DRM free copy for everyone else.
That's almost double the unique hits on Reddit, and those are just two P2P applications; there are plenty more that are extremely popular among other populations.
otherwise I'll venture to guess that BigBadCo would have found via their research it was a losing proposition
Only if you assume that controlling the paying users is not the real purpose. It's much easier to get suckers to pay three or four times for the same content if you lock'em up with platform-specific DRM.
[1] http://torrentfreak.com/bittorrent-surges-to-150-million-mon...
When has charging $15-25 for a DVD/BluRay become a suckers bet? Sure most of us here like all digital platforms, but many don't, and happily shell out that amount of money. Also because it is easy to pirate a digital copy of a BluRay (if you are technically inclined), doesn't mean that somehow all digital copies of BluRay releases should somehow approach $0.
When Apple dropped DRM from music their revenue didn't go down. It increased instead.
Providing content is easier to access than to pirate and of a reasonable price the majority of people (bar kids that don't have a credit card) will just cough up and pay.
The way to fight piracy isn't to lock down something. Security through obscurity isn't security at all. Sure I won't be able to right click > save, but what stops someone from using a screen recorder?
Protected AV Path. Which is why I'd expect this feature to quickly extend to plugins that only work with certain graphics drivers on certain platforms.
If a company wants to hassle their users with DRM then they can use Silverlight/Flash or write their own crap plugin. But keep it out of HTML5 and other supposedly open standards.
In the end Silverlight/Flash are dying and it is up to them to come up with something new. We don't have to bend over to please them by perverting the open web.
Why do they even want to copy restrict their content? You can download it from Pirate Bay anyway. When Apple stopped DRM in music their revenues increased. Because the average user doesn't care about copying. It is all about being available, affordable, and easy to use. But the content industry is not understanding that and rather interested in making the content unavailable, unaffordable, and hard to use and they sue their customers on top of that. So no keep that crap out of HTML5.
Leaving Firefox stranded. If Firefox bends over and adds support for PlayReady and the other crap then this will effectively mean that Firefox will depend on proprietary binary blobs to do the video rendering. In other words it will be exactly like Flash but unlike Flash it won't work on Linux at all.
We have to oppose DRM in HTML5 and we shouldn't give up on the open web. It is sad that Tim Berners-Lee has given up on it and is destroying this own legacy. But we should fight it!
My point is that adding DRM to Flash won't make DRM content (e.g., Netflix) available on Linux and in fact will make it harder for Linux to access web content.
So you have completely misunderstood me.
So I wonder if FireFox CAN even implement it ?
Imagine the new world that would be open to the malware/spyware if DRM is enabled they will easily use this to hide their shitty stuff and not allowing anybody to see whats going on, how does w3c is going to let that happen :S
Hopefully Firefox wont be open to implemment this shit on their browser.
You think the DRM blob would be less slow, less buggy, less closed and less resource-hungry than flash is and has been? Think again.
In that case, a browser implementation could just write the unencrypted video to disk or re-stream it over http to other clients, without even having to do a new transcoding/compression (which costs cpu power and reduces quality).
The whole point of effective software video DRM is that the plugin must render the video to screen itself, and ideally in a way that doesn't let the attacker find the unencrypted stream in memory. Silverlight does this via PlayReady for example.
- Media purchase was inconvenient and overly expensive.
- People pirated because it was convenient and cheap.
- Streaming services offered convenient, low cost
solutions.
- People 'stopped' pirating because streaming is a decent,
convenient legal alternative.
At least that's how I've (and everybody I've asked about) gone through it. So in that perspective, it seems to be a useless attempt at defending from a fading threat.The answer is that such proposals get laughed out of the room. They would break the Web, which is far more valuable than anyone's JavaScript source code. Has innovation in JavaScript suffered for lack of source code protection in Web standards? That's also a laughable idea.
So, why not the same answer for passive content?
And even if they implement DRM, I could probably just grab the source and comment out a few ifs, and would be fine (assuming its not just a wrapper for Windows' DRM).
here is the reason: if there was such kind of mechanism in browser, we probably already had snapchat years ago on browser instead of Apple's safe guarded garden.
there is no evil technology. it just depends on how to use it. i'm surprised so many are blindly naive.
as we all know drm is folly. if the data can be decrypted to use then it can be stolen /always/.