Firefox’s adoption of closed-source DRM breaks my heart (2014)
theguardian.com
theguardian.com
The reason Firefox is allowing this is that browsers and operating systems produced by nonprofits acting in the public interest don't have enough market share to resist being dictated to by for-profit corporations. Imagine FirefoxOS had the market share of Android and Debian had the market share of Windows. Would we still be having this conversation?
The free software people have been preaching this for decades. It turns out they're right.
So don't install Chrome, use Firefox. Then next time it will be easier for Mozilla to do the right thing.
Try setting up an alias in your bashrc? If you really want to point-and-click just add the appropriate entries to your launcher/menu?
Sandbox = CPU sandbox, not just cookie isolation.
To achieve that in Firefox will require massive re-writing of lots of code to basically do all the stuff Chrome was built to do. Chrome doesn't allow the CPU process running the webpage to access any OS services or hardware. All access to those are in other processes that do tons of validation that what the page is asking for it should be allowed to access. That way, even if there's a code execution bug it's unlikely to be able do any damage.
Shouldn't be so surprising in retrospect (like many things), but I never fully got that before.
Power comes from being chosen by end users. Firefox needs power to be able to resist this kind of crap. In this case, they didn't quite have enough power (probably because they let memory bloat get away from them a few years back, giving Chrome the upper hand which is has done a decent job of holding on to).
Google is trying to do the same with EME over HTTPS. Google wants Mozilla to stand together with Firefox and Chrome resisting EME over unprotected HTTP. But they want Firefox to go first (again), even though Chrome is already shipping EME.
Besides chrome didn't get its market share on technical merit alone, but mostly by paying for its installation and targeted PR.
And don't underestimate all the bundleware installs, too. Even today, when upgrading your version of Java in Windows, it still tries to trick you into installing Chrome.
Does caving in to commercial pressure and adding unpopular (for its core audience) features like DRM advance it in that direction, or in the opposite direction? I believe "more of the same" isn't going to help it pull ahead, it needs distinctive features such as more privacy, fewer ads, or even a strong anti-DRM stance.
As a (former) large-ish website owner I have to disagree with your assessment. Even browsers with 5% market share (Firefox has 15-20%) have the power to influence design decisions and thus counter browser-based DRM adoption, except strong de facto monopolies (like Google, youtube) that can make or break browsers by supporting or excluding them (youtube has even more influence than Google search currently because of its unique content). It's true that Firefox was simply too bad to use for a couple of years (cue conspiracy theories about Google being their main source of income and desperately trying to push Chrome), but it still had power due to its large user base.
We don't need counterfactuals to imagine a world without EME; we've lived it.
Also, Flash did not die, just because Apple said so although that certainly had an impact. It also died, because the web was getting better and better; because it was a proprietary tool not available to everyone; because it integrates poorly with the whole architecture of the web - e.g. dynamic generation on the server; because it had a bad reputation due to security and performance issues; and because a plugin, even if widespread, is still a dependency that you want to avoid.
It is a tautology that DRM-based video streaming is going to use some kind of DRM. The point is that if several major platforms provide no support for any form of DRM then DRM will be removed from video streaming. The idea that video providers are going to give up a majority of their customers because their devices support no DRM is not reasonable.
> Also, Flash did not die, just because Apple said so although that certainly had an impact. It also died, because the web was getting better and better; because it was a proprietary tool not available to everyone; because it integrates poorly with the whole architecture of the web - e.g. dynamic generation on the server; because it had a bad reputation due to security and performance issues; and because a plugin, even if widespread, is still a dependency that you want to avoid.
I'm not sure what point you're making... that Flash sucks and died for multiple reasons? Granted. But it was still dying before EME existed and DRM wasn't enough to save it.
Browser makers don't have some crippling monopoly power over how computers work that they can use to force submission on an entire industry (thank god).
The idea that the movie industry will give up on something they view as a fundamental requirement for them to earn money, just because browser makers throw a hissy fit, is not reasonable. The movie industry will find a way because they believe their industry must, or else it will wither and die.
Video on the web was a reality before flash came to be.
At which point they'll be losing customers. And if the operating system doesn't support apps with DRM, what then? Ask the user to buy a new device?
> Or use Apple TV/Xbox/PlayStation to watch things rather than their browsers.
At which point they'll be losing more customers. And if the dominant console is also something that doesn't support DRM, what then?
> Browser makers don't have some crippling monopoly power over how computers work that they can use to force submission on an entire industry (thank god).
No, but customers do. Which is why customers should choose browsers and operating systems that do what customers want.
> The idea that the movie industry will give up on something they view as a fundamental requirement for them to earn money, just because browser makers throw a hissy fit, is not reasonable. The movie industry will find a way because they believe their industry must, or else it will wither and die.
This is just meaningless rhetoric. It is possible to make money without DRM as proven by the fact that many people are doing it. Piracy does not exclude profitability as proven by the fact that there are more Disney movies on The Pirate Bay than there are in the Disney store and Disney is still making tons of money.
The people who think the movie industry would disappear without DRM are idiots. The harder we make it for those idiots, the more share they'll lose to people who know better and the fewer idiots will remain.
It's not even like this is a fight. It's just widespread misunderstanding. DRM is bad for the movie industry. It locks customers into closed platforms which put the companies that control those platforms between the studios and their customers. It causes viewers to derive less value from DRM-encumbered content, which causes them to consume it less often and not be willing to pay as much for it. It causes piracy to increase because it has zero effect on the experience of downloading from The Pirate Bay and a negative effect on the experience of paying customers. The studios have been sold a bill of goods.
You might as well say, if the developer community got its act together and stood on principle, no company could caputure 'market share' without their consent.
The problem is not the Mozilla non-profit knuckling under -- it is developers failing to have an institution similar to other professions, such as the Bar or AMA, giving them principles.
A professional organization would have no control over that whatsoever. People have principles. Principles don't come from bureaucracies. Professional organizations are full of politics and politics and ethics are entirely orthogonal.
If anything professional organizations are used to undermine an individual's principles: Economic interests pressure the professional organization to approve some unethical behavior and then anyone who objects to it is pointed to the professional organization's approval and told to shut up and do it.
The whole idea behind the no flash movement was to move services that relied on a plugin, away from the web and onto the app store.
Apple wasn't fighting for free technology, they were pushing users onto Apple's own version of EME.
Let's imagine all web browsers drop flash, silverlight, EME and all the other common technologies used for DRM. What do you think netflix will do on the desktop? Will they move to pure HTML video or will they start building desktop apps?
That's the trouble. They practically did it by accident. Imagine they actually were fighting for free technology. Then they wouldn't allow DRM in any apps either and what you're worried about goes away.
You get to the same place with licensing instead of restrictive app stores for actually free systems. For example put some language in the license (call it LGPLv4) for all the libraries for putting video on the screen that requires any application implementing DRM to be distributed under the GPL. You can have all the DRM you like as long as the source code is provided and anyone is allowed to make and distribute changes. :)
http://www.cvedetails.com/product/15031/Google-Chrome.html?v...
http://www.cvedetails.com/product/3264/Mozilla-Firefox.html?...
Until that number changes I'm not switching to back to Firefox.
Firefox sucks a lot (no usable UI integration, missing many basic modern features, changes stripping user of choice, and more) but chrome sucks to infinity and is automatically disqualified, I would consider Iron but not chrome. Now my hopes are for vivaldi, I'm waiting for it to get out of tech preview.
Also Chrome doesn't bundle itself with anything other than a special more secure version of flash which you can turn off. If you got a version bundled with something else that was a fake install by a 3rd party. The same thing happens to firefox
Here's a search for chrome. First 3 links are fake installers made by a 3rd party that likely installs a virus/trojan/rootkit
http://i.imgur.com/RpXy3bz.png
Here's a search for firefox. first link is also a fake installers made by a 3rd party that likely installs a virus/trojan/rootkit
Maybe you should switch then, why?
A lot of this information is subject to interpretation.
# of Vulnerabilities in 2014: Chrome: 127 Firefox: 108
The code exploit stats show how many exploits were found and patched, which is completely different from the number of exploits that a browser has.
Only 4 exploits were found and fixed in Chrome whilst 55 were found and fixed in Firefox... in my opinion that makes Firefox the leader as they found and fixed more vulnerabilities.
Mozilla is made of google money and advertising money.
Doing the right thing means doing it regardless of market share and piles of money.
These are only a few examples off the top of my head, but one does not have to look very deep to find a trail of not doing the right thing at mozilla along its history. Sorry if pointing this out infuriates the fanboï in you, but mozilla has done its share of wrong along the otherwise good stuff.
Why is supporting EME and limiting closed source crapware to a minimum so bad, while supporting huge closed source, bug ridden application runtimes sort of okay?
However, on the other hand:
1. EME is an actual W3C standard. It feels - and is - wrong for an organization like the W3C to promote an API that is not about openness, but rather about the opposite.
2. While EME proponents - and DRM proponents in general - argue "content makers will never accept delivery without DRM", that is far from clear. First, and most importantly, just a few months ago The Interview was sold online, without DRM whatsoever, and it made lots of money. The sky didn't fall. Second, the argument that "DRM is necessary" was also said about digital music, which eventually dropped DRM. Finally, there are also alternatives like watermarking (with their own downsides, to be sure) which over time could be explored.
Overall, I think it is sad that Google, Microsoft and Netflix have won and EME is unavoidable at this point. But, given the power of those entities, only a miracle could have stopped it.
I fully agree with point 2. Even if all browser vendors assumed this point to be true however, I think Netflix and other video content providers would have 'happily' run Flash and Silverlight for years and years. There hasn't been a shortage of browser DRM options for a very long time now. EME is an improvement over the Flash/Silverlight situation, and a realistic option at this point for improving the situation right now.
It's a shame Firefox is being derided for being pragmatic or not being perfectly virtuous here. With implementing EME they are still working on improving the openness of the web.
At some point Google proposed standardizing PPAPI, a new plugin API (and a very large and complex one), but it met with no interest.
Historically, plugin use was much more widespread, and there were plugins for all kinds of things. You had to have a separate plugin for each of Video for Windows, RealAudio, Quicktime, Shockwave, Java, etc., and there were others for playing different media types like .mod, .xm, .it, displaying image formats, ...
The NPAPI interface was also standard enough that every browser supported it. So yes, it's "more wrong" to add a new interface to new proprietary plugins than it is to continue supporting a dying legacy interface to proprietary plugins. The NPAPI trajectory was downward, while EME's intended trajectory is upward.
I think this needs data. From my foot in the enterprise world, this doesn't seem even close to true; random SSL VPNs and the like require Java. If anything, most people are running an out-of-date version of Java because corporate IT hasn't approved the one that fixes ten exploits yet.
> and Flash was only required for some video and animation sites.
Due, largely, to (EME-free) HTML5 video and other HTML5 features. EME is not replacing HTML5 video, nor is anyone talking about using EME to replace Flash-played videos that weren't using DRM inside Flash.
There's a lot of implication running around that Flash is being replaced with EME video. It isn't. The vast majority of Flash is being replaced with non-EME HTML5 features. A fraction that was previously implementing DRM in Flash is now implementing DRM in EME.
NPAPI plugin usage, specifically Flash video, was going to continue to be a thing for Flash videos that were using DRM. (You could make the argument that these things would just drop DRM if it were too hard, but given how long Flash stuck around until there was a high-quality replacement that was objectively better than Flash from the content-publisher's side, it's a hard argument to make.)
Maybe someone with in-depth knowledge of the sandbox could weigh in about its actual security, I'd be interested in hearing about it.
Because if it's not secure enough to allow arbitrary code from random websites to execute safely, it's sure as hell not secure enough to run that DRM crap. What happens instead is Firefox becomes a vector for Trojan horses and root kits installable on my computer on behalf of any interest group imaginable.
I switched from Chrome to Firefox specifically for things like these.
I don't know if that has changed or not, I don't pay close attention. I only mentioned it because of the "Docker for the client" line, that it already exists is a pretty emphatic yes.
You're right. I corrected the original comment to make it clearer I'm talking about Firefox. The point was to call out the sandbox argument a bit, since I'm not so sure it's actually safe to run malware in it.
I want to be able to rent any movie for streaming. For better or worse, that means some kind of DRM is inevitable. I'd rather Mozilla and the standards advocates have a seat at the table, where they can be a moderating influence, than pretend the table doesn't exist.
Besides, spotify uses flash for their webplayer, probably for DRM as well. Yet there exists an open source spotify client, despotify, that probably would make it very easy to download the music as MP3.
In the end, DRM just means making your client's life a pain.
There are a lot of ways to engineer DRM in a system, I think you just don't see that you're actually using a DRMed system to play your music.
Although this is relevant again since they also decided to put DRM in Firefox OS for the Matchstick (curiously, the plan is Adobe DRM for desktop Firefox and Microsoft DRM for Matchstick; corrections/clarifications are welcome).
So I think the "they" in your statement there might be confusing, as it seems to imply Mozilla is doing something here.
(btw, I hadn't heard about this latest development with matchstick regarding Microsoft DRM, link?)
Update 16. It went out on Friday.
This is kind of surprising to me, that Microsoft would license PlayReady for a non-Microsoft platform, in this case Matchstick. I wonder if their policy was always that way, but it just didn't happen, or if it changed?
But meh, drivers.
Hopefully their efforts on MSE and EME will help expedite development in Firefox so that Youtube doesn't suck as much.