84 karma · joined July 9, 2022
You're a fish swimming in fragile water you fail to appreciate.
> Still, though, privacy-wise: why should I trust this guy? I like what he says on the website, but I've never heard of him, and don't really know anything about him.
Do you prefer to use tech presented by opaque committees with institutional funding, but only if they also consist of people you're acquainted with?
MP4 encryption, specifically Common Encryption addition to ISO BMFF has two levels of partial encryption.
- Each frame's media bytes are encrypted independently of other frames. MP4 boxes themselves are not encrypted. This is done so that applications can parse container metadata such as codec params and timestamps without depending on the secure decrypt and decode layer.
- Each frame consists of codec protocol messages such as NAL Units for H.264 and HEVC, OBUs for AV1, and uncompressed and compressed headers and tile headers for VP9. Subsample encryption leaves message headers unencrypted, but encrypts their contents. This is done for efficiency of the secure decode hardware. Clear and encrypted byte ranges are stored in MP4 boxes.
MP4 encryption of course fully supports HEVC using both mechanisms.
Widevine in general supports HEVC. The Widevine module in Chrome has to include a decoder for each supported codec. They probably skipped HEVC to avoid increasing download size for users.
2FA is a vaccine that mitigates or prevents spread of this disease. It is unconscionably selfish to refuse to harden your accounts just because it's a little inconvenient to you.