Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Everyone who is ignorant towards the standard DRM in web browsers does not see the forest behind the trees.

It does not stop with movies or music.

If DRM is deeply integrated into the web then everything will get affected by it. Already today some publisher go to great lengths to try to disturb people from copying simple text and images. It will get only worse.

Currently the openness of the web has been very beneficial to the people willing to make an effort to learn the web technologies. I think that this has opened the field for many talented people. You can just inspect the page and try to learn how it is made by reverse engineering it. This will go away and you will get the inaccessible binary blob instead.



This is all true, but what has it got to do with the W3C approving the standard or not?

The content publishers and the browser makers are severely intermingled and often the same company. (Google, Apple, "Netflix HD only on Edge") We don't even need to pretend Firefox has any relevance in this particular space.

If Google wants to push SPDY or HTTP2 or a DRM technology through, they can just do so through combined browser and YouTube/Gmail/Google Play/Android/Google Docs marketshare. Similar things apply to the iOS and Windows ecosystems.

The W3C exists as place for these companies to work out interoperability standards. They have no other incentive to attend. If the W3C gets in the way of that, what does it matter? They can interoperate or not. There can be a standard or not.

DRM will be there anyway. Be it Flash, be it something else.


> DRM will be there anyway. Be it Flash, be it something else.

Then let it be Flash, so it can die with Flash. Let's not perpetuate it, or make it any easier. Let a hundred competing "standards" bloom so media companies have more work to do, and might decide that DRM seems like too much trouble and decreases their target audience. Let browsers prune away support for DRM with their outdated plugin interfaces.

Don't give any one "standard" the blessing of any standards organization. And don't accept something inherently non-standard as a standard. Don't accept as a standard something completely unimplementable in a fully Open Source browser. Don't accept a standard interface to custom binary DRM implementations.


There aren't going to be a hundred competing standards, because the production tool ecosystem has its own working groups who will settle on a small set of standards, with or without the input of the browser vendors. The browser vendors only have a say in DRM formats insofar as providing universal support for a format entices the production-tool ecosystem to provide export-compatibility for it. If the browser-vendors refuse to provide such a standard, they're really just refusing to sit at the table where the standard is decided.

In the end, there'll be a standard DRM multimedia format whether it's "endorsed" by Open Web people or not; if browsers don't build in support for it, then it'll just build support for itself, via the APIs that do exist: WebGL, WebRTC, ASM.js, etc. Consumers will get their media; they'll just be running an opaque blob of Javascript in the browser to get it, instead of the browser doing the job—cleanly—itself.


That opaque blob of JS wod be great compared to an opaque blob of binary code that has access to the GPU, which in turn has access to DMA...


I suggest you read on how modern display drivers are designed, you can't cross boundaries.


Designed. Many designs fail to achieve their goals. Has there been much research into 0-days in the GPU firmware itself? Or the closed blobs that get loaded into kernel space?


Yes, quite a bit actually, and you also need to understand that you aren't hitting the GPU directly by any means you are going through several layers of API's each with it's own security controls, then hitting a restricted end point in a usermode driver.

This is not to say that there aren't vulnerabilities in the drivers, that said the only 3 PE/CE vulnerabilities in the NVIDIA driver in the past 4+ years were not exploitable through any vectors you are suggesting since they involved NVAPI, AMD doesn't discloses vulnerabilities openly IIRC.

To exploit a vulnerability in the manner you suggest you need to break through the sandboxing and security model of the browser, break the sandboxing and security model of the web API you are using e.g. WebGL break through the security model and sandboxing of the actual API e.g. DirectX on Windows, break through the sandboxing and security model of the user mode driver, and then exploit a vulnerability in a kernel mode driver that might have actual access to something you might care about.

And even then it's not that simple in WDDM for example even in pure kernel mode you'll have issues accessing memory out of the bounds of your application due to how GPU resource are managed, pinned and translated.

To put it simply every process accesses a "virtual GPU" through it's own endpoint, there is a zero-out process which is invoked on both the GPU and system memory when any buffer is allocated or accessed, and there is an out-of-bounds behaviour control running on the GPU independent of the driver, basically once you access (read or write) out of bound memory the GPU would terminate the loaded kernel which would crash your application and the driver would be cycled (restarted).

The out of bound memory is a real annoyance anyone who's worked with GPGPU especially CUDA is pretty familiar with, it's the #1 app killer (as far as code errors go) and for good reasons, even a privileged kernel running natively on the GPU is protected from abusing it's own rights.


The CDM is sandboxed in Firefox and Chrome.


What does that mean in regards to parent's comment? If it renders, it went through both a graphics driver and GPU. Therefore they're in attack surface for malicious data designed to take over privileged code and/or DMA engines.


The CDM doesn't need to do any rendering, and interaction with the GPU can be limited to writing in a designated shared memory area.


Because it's isolated and there is no DMA really.

There is a reason why the graphics driver is in user mode, and why the memory is virtualized.

The application doesn't have traditional DMA unless you load a privileged kernel which you can't do via a browser.

An application can't access the memory of another application via the display driver this is a solved issue.


>>there'll be a standard DRM multimedia format whether it's "endorsed" by Open Web people or not

Open web people can not endorse DRM, once a open web persons endorses DRM they cease to be a Open Web Person.


No true Scotsman, in other words.


No, a No True Scotsman fallacy exclude the specific cases or others like it by rhetoric, without reference to any specific objective rule.

Claiming to be a Open Web supported while also endorsing closed items like DRM, is an objective violation of the Philosophy of the open web

People over use and misappropriate the charge of No True Scots Man


Not quite, it's more like a vegan recommending their favorite brand of bacon. They lose their vegan superpowers.


Except that's not what's going to happen. This problem is not going away. And if you create more "work", they'll just do what they need to to capture the majority of the market and leave a lot of users in the cold.

The people this hurts aren't going to be the media companies or the normal users. The people it will hurt will be us crazies that do stuff like run Unix on the desktop or try and run unlocked Chinese Android phones, because they just won't be supported because there's no financial case for it.


> Except that's not what's going to happen. This problem is not going away. And if you create more "work", they'll just do what they need to to capture the majority of the market and leave a lot of users in the cold.

And then that'll leave a market for someone else to come along and serve.


That would be great if copyright didn't exist.

If the company that owns the distribution rights to a piece of content doesn't want to support the last few percent of the market then they just won't and there's nothing anyone else can (legally) do about it unless they start further up the food chain, making their own content. And if there were enough money in those outliers for that to be profitable, then the existing content creators would probably be serving them.

DRM is going to happen one way or another, and in my mind ensuring that at the very least the DRM itself has a defined interface for everyone to work against results in a more "open" ecosystem than leaving it up to backroom deals between content creators and DRM vendors who create hacky hodge-podge software.


It's not going to be Flash precisely because Flash is dying. It doesn't matter whether the W3C is involved or not, the companies that want this are going to make it happen. The idea that stopping a W3C standard is somehow going to stop the entire media industry getting its way on this is nothing but a fantasy.

Unfortunately, many people who could bring some moderation to the discussions about DRM are still stuck in fantasy land where none of this is happening.


We don't even need to pretend Firefox has any relevance

And this is a collective fault of many ignorant persons also in this forum who more than often have suggest people to use Chrome. I think that Chrome has gained much support thanks to the wide spread ignorance about the implications.


I wouldn't say those people were "ignorant". Things like YouTube, Google Docs, most Google properties work better in Chrome. This isn't always intentional, even.

Google can control both ends of the pipe, which means whenever they make big changes Chrome users will have a better experience. They pushed ahead there with MSE, codec support (VP9), SPDY, HTTP/2, etc and other browsers had to catch up. If other browsers were ahead in some areas, it didn't matter, because the content side didn't support it. Sites are designed and optimized in Chrome first and foremost, so Chrome never risks looking slow.

Similar things apply to Safari on iOS, or Edge on Windows.

The problem in my mind is that by having the same parties sit on both ends of this story, it's inevitable the middle man (that could be a leverage against DRM) gets pushed out. It's very, very hard to explain to the majority of users that they have to accept short term pain to avoid an outcome that is much worse for them. Ask any politician.

But we don't even need to kill the web to get there (pushing out any middlemen). We have native apps! Nobody is complaining their Android or iOS phone has DRM, do they?


> Things like [Google] YouTube, Google Docs, most Google [projects] work better in Chrome.

I wonder why that is.

> This isn't always intentional, even.

I don't think everyone at Google is evil. There are many passionate engineers and hackers like you and me. However, if a Youtube developer has an issue with something running extraordinarily slowly, it's a much shorter call to the Chrome department than it would be to Apple's Safari or Mozilla's Firefox. So while developers might not be actively hindering other browsers, they are developing for Chrome. That it technically works on other browsers is a requirement but optimizing for the competition's browsers is not something I imagine management allocates hours for.

The end result is that they are hindering competition in the browser market, and quite a few people saw that coming. Still, even more people (vastly more people) either did not care or know and recommended Chrome anyway.

> Nobody is complaining their Android or iOS phone has DRM, do they?

My Android phone does not have DRM beyond what it in the SIM and I am complaining about people whose phones do. Many friends and peers share my view on this, so it's at least not "nobody".


My Android phone does not have DRM beyond what it in the SIM

https://developer.android.com/reference/android/drm/package-...

"Added in API level 11". Maybe you have a custom build with this ripped out, but then we're stretching by calling it "Android".


I suppose you might be right. I actually realized after posting that there is probably something somewhere in my phone that still contains some kind of DRM. Assuming this is still in Cyanogenmod, you're probably right.

Then again, I'm not sure I have any apps that use this.


I use Firefox over any other browser precisely because I can "hack" it. I've changed so much under about:config that I have to document it for the next install. Firefox allows so many useful hacks that are truly in favor of the user. Chrome not so much. I don't use anything other than macOS or *nix, so I cannot speak to IE or other platforms.


Unfortunately, you are in a tiny minority in being able to do that, wanting to, and actualy getting round to it


Except that as of FF 48 you can't install unsigned addons, even if you allow it in the config.

It's like they're trying to give up every advantage.


> That it technically works on other browsers is a requirement but optimizing for the competition's browsers is not something I imagine management allocates hours for.

Youtube exists to sell ads, and a slow browsing experience on any device or browser does not serve that goal. So while Chrome may be their default testing environment, there's a very strong incentive to have it work well across the board.


Say in the YouTube app you perform a search for a song. The results come back very quickly and the first result is what you want so you tap it. An ad starts to play. Except its not an ad. Its a video from the advertised spot above your search results - wait a minute you didn't click that. So you go back and realize, it loads 1 second after your search results and pushes them downwards, so your tap ends up on the advertisement that wasn't even rendered yet. Hm.


That might drive short term revenue but would drive down their CPM/CPC rates and user engagement longer term. I don't think Google's culture is conducive to playing those sorts of tricks.


Maybe they don't do it on purpose, maybe they A/B test their way into a black hole of emergent anti-patterns.


> Things like YouTube, Google Docs, most Google properties work better in Chrome.

As someone who has never used Chrome, I'd love to understand what exactly "works better" means. I've never had problems with any of those sites using Firefox and Safari.


Google Docs is more responsive and faster in Chrome (it improves in Firefox if you fake the Chrome UA, hah). YouTube relied on Flash much longer in Firefox, while Mozilla was working to make their MSE implementation compatible with Chrome.

Google broke YouTube for Firefox users right before the last Christmas holidays. Mozilla pushed out Firefox updates over the holidays that faked the UA as a workaround.

Google Inbox didn't work on Firefox initially, because Google claimed Firefox was too slow. When reported to Mozilla, it was fixed in a few hours, and they found that Chrome's implementation of the "thing that was too slow" was actually broken and not spec compliant.

Hangouts (used to?) require a plugin in Firefox, and just uses WebRTC in Chrome.

And so on...(sigh)


For more backstory, here's the Firefox bug report with the fix for Google Inbox being "too slow" due to JS array slice being faster in Chrome than Firefox due to a V8 bug:

https://bugzilla.mozilla.org/show_bug.cgi?id=1087963

Here's the Firefox bug report about Google Docs being 3-9% faster, in a particular performance benchmark, when Firefox spoofs the Chrome UA:

https://bugzilla.mozilla.org/show_bug.cgi?id=1307024


When you change the user agent in Docs, the JS app tries to use a webkit-specific selection API and just crashes. The timing results for that test seem bogus.


Google deployed SPDY on Google sites when only Chrome supports it. YouTube deployed streaming with QUIC when only Chrome supports it. I'm not saying Google sites are sabotaging other browsers, just that these are examples of Google sites the work best in Chrome because Google teams can work closely together.

Google Hangouts uses WebRTC and NaCl without plugins in Chrome, but requires an NPAPI plugin or ActiveX Control (confusingly called the "Google Talk Plugin") in other browsers. Support for any browser other than Chrome is not listed on the Hangouts home page. You must search their KB to find the plugin installer.

https://hangouts.google.com/

https://support.google.com/plus/answer/1216376


Being aware of being in a prisoner dilemma doesn't change the optimal strategy.


Is this classical or quantum prisoner's dilemma? Which variation?

Because the knowledge of the prisoner is deeply intertwined with the optimal strategy in quantum prisoner's dilemmas. And quantum prisoner's dilemmas have at times been shown to more accurately match human behavior than classical ones.


No, but if you have principles it might change the strategy chosen.


Or it could be that FF is perceptibly slower and currently has very weak dev tools. I personally use Chromium, which IMO, is the best of both worlds and actually, the only one of the three browsers that doesn't have EME (so you could argue it's better than FF in this regard). You also get a clear picture of the sites that stream with DRM (looking at you Vimeo).


I don't think the person you're arguing with is even necessarily denying this. He is pointing out that the trade-off of using the "perceptibly" faster browser has very bad long term consequences.


The W3C standard is not about whether the DRM will exist - to some extent it will exist regardless of what decisions the W3C makes.

The W3C standard is not about making DRM supported by all browsers and other tools - even if included in the standard, many makers of web technology will be locked out of DRM support.

The W3C standard is simply about whether we (the "tech guys") ENDORSE the use of DRM. And it DOES make a difference: if approved, DRM will be more common than if not approved.


Given that there is no sensible way to implement DRM in open source, the W3C should not approve the standard.

Or the other way around, W3C should only approve feature complete standards that can be implemented using open source.

You cannot have an open web if an essential part is governed by binary blobs.

Nothing is lost if W3C does not approve an interface to secret technology.


EME can be implemented in open source (there's an implementation in Chromium and another one in Firefox).

The problem is the CDM, which the W3C isn't standardizing.


That's why I wrote 'feature complete standards'. Anybody can come up with half finished standards that are only there to serve some proprietary technology.

An interface to an unspecified DRM module is not a useful web standard. And due to the nature of DRM, a fully specified DRM standard is also completely useless. DRM is just not compatible with open.


Which means you can't actually ship any useful implementation, since it won't have a backend to talk to. And an Open Source implementation would inherently be non-functional.


You can implement EME in open source (the part that W3C standardized), and then throw a closed source CDM module on top of it. You don't even have to provide the CDM, third parties can provide multiple ones.

This is in fact how it works in Firefox. There's no part of Firefox that is closed source, including EME support or even the CDM sandbox. The CDM is loaded at runtime from an external server.

Focusing on the W3C and/or it's relation with open source is completely and utterly missing the point, but it's explained enough throughout this thread that I see no point in repeating it once again here.


> You can implement EME in open source (the part that W3C standardized), and then throw a closed source CDM module on top of it.

Which means the whole thing doesn't work in a fully Open Source browser. EME is non-functional without a proprietary CDM.

It's like standardizing the <object> or <applet> tags: yes, they're a standard, but they're a standard way to talk to completely non-standard bits. But worse, because you could use <object> or <applet> to talk to an Open Source plugin, but a CDM completely loses what little function it has if open.

(That includes hardware-backed CDMs, since signed software you can't replace isn't Open Source either.)


>>>The W3C exists as place for these companies to work out interoperability standards.

Web for All

The social value of the Web is that it enables human communication, commerce, and opportunities to share knowledge. One of W3C's primary goals is to make these benefits available to all people, whatever their hardware, software, network infrastructure, native language, culture, geographical location, or physical or mental ability.

Web on Everything

The number of different kinds of devices that can access the Web has grown immensely. Mobile phones, smart phones, personal digital assistants, interactive television systems, voice response systems, kiosks and even certain domestic appliances can all access the Web.

https://www.w3.org/Consortium/mission

EME and DRM violate the Stated mission of the W3C


> We don't even need to pretend Firefox has any relevance in this particular space.

Browser market share changes widely depending on which capabilities browsers have. Firefox went from 0 to web dominance in a few years because it had a more compelling offering than IE. Then Chrome beat it to its own game. Then IE was kept alive on Windows in parts because Netflix' use of Silverlight. If DRM is kept at the add-on level in some browsers, then those browsers will succeed as DRM restrictions invade the web slowly, and publishers will not be able to ignore those browsers.

Even if Firefox came on board and publishers really started cracking down, I could see a DRM-free fork take hold. It could be called Firefork, actually. :)


Mozilla themselves publish a DRM-free version. You have to go look for it, but it exists.


Openness is not something one actor decrees. It is something promoted by a whole ecosystem. If W3C is the only opponent to DRMs, yes, it won't amount to enough resistance. If Firefox alone refuses to implement W3C-approved DRM standards, yes, it won't amount to enough resistance.

But if Apple does a DRM tech in Safari, that it is not approved by W3C, that it is not implemented in Firefox, how do you think they will get it into Chrome and IE? Heh, they'll have to pay a lot of money to Google and MS, or to accept reciprocal agreements, segmenting their markets, complicating the development of their tech.

It will slow them down, like it has so far. And if it slows them enough that they move slower than the tech they want to regulate, we win.

So yes, the W3C is just a stone thrown in the middle of the stream, trying to slow it down. It won't make much by itself. But at least it knows it wants to be a part of the dam.


We should make DRM as expensive, difficult, and unwieldy to use as possible. We need not and should not standardize the use of things that are detrimental.

"Oh, hackers will always be able to break into systems. So instead of making them do it ad-hoc, let's just create a standardized backdoor on every system. It will be less work for everyone."


Then only big medias companies will be the only ones able to reach as many users as possible. You have no idea of how expensive it's right now to target just browsers. Small producers will be constrained to only publishing trough their channels/platforms.


You're talking about the very people who build the systems here, not hackers. Standards bodies facilitate the work of implementers, they are not regulatory agencies.


Why do you think the pro-DRM forces want it to be an inter-operable standard with W3C approval?

Those would be the same reasons the anti-DRM forces don't.


"some publisher go to great lengths to try to disturb people from copying simple text and images"

Genuine question: why is this a problem if the publisher doesn't want a third party to use their work without their permission, or at all? I ask as an amateur photographer who doesn't want people to use their images without permission, especially for commercial gain. I choose to license my work as CC BY-NC-ND 4.0, but that doesn't mean others will necessarily honour my wishes. How can this be policed on a network as vast as the Internet? I get why DRM is almost assuredly not be the answer, but what are the other options (excluding CC licensing)? My issue here is that we make a lot of noise as to why DRM is bad, but the other solutions that I've seen are as bad, or offer little real protection to the content creator.


One problem is the unreasonable level of control over "second party" use - ie, people viewing it on the web as intended, but in a way that the publisher doesn't like. Whether they're using Linux or screen readers or adblockers or "non-standard" browsers. Even if they're just trying to fix usability problems in the site.

Example: streaming video on the Raspberry Pi; the hardware is quite capable of it but if it requires an x86-only plugin to do so you're out of luck.

Example: "readability mode" in browsers relies on the fact that currently text is not wrapped in DRM and can just be presented how you like it.

Trivial, petty example: currently on Twitter there's no sensible way to view images full size or save them without going via the DOM explorer.


The answer is that it's technologically impossible to prevent third parties from using your work if you publish it. DRM doesn't solve this problem, but claims to do so. As a result, genuine users suffer from DRM.


There was a post on Reddit recently which is a great example of this. Somebody said that Netflix didn't support their monitor as it was too old (i.e. didn't support HDCP). One of the comments suggested to get a HDCP stripper, a simple device for $10, which will disable the DRM.

https://www.reddit.com/r/Anticonsumption/comments/55r7i4/you...


Yes, all DRM is easy to bypass right now, but it works as a way to get studios on board with digital distribution. This brings up an interesting point. The main argument against DRM is that it is a slippery slope which will lead to more violations of freedom. But the problem with slippery slope arugments is that they're often unsubstantiated. We often don't know what the long-term effects of something will be.

What if DRM is actually serving the opposite purpose? By appeasing studios with weak protections, it may be preventing stronger digital locks from being developed. It could be that if the FSF and other anti-DRM organizations are effective in removing current standards, the industry will respond by developing something even worse, leading to an ever-stronger DRM arms race.

I'm not saying that I know this will be the result either, just that we don't really know what the effects of defeating standard DRM interfaces will be. The only real solution I can imagine would be to get content distributers not to want DRM, which is a very hard proposition. They have the money and the power, and they won't stop until they get what they want.


> DRM is easy to bypass right now

That's because DRM isn't and never has been about preventing copying. The intent has always been to transfer power from consumers to the studios and tech manufacturers. It doesn't matter if the DRM can be defeated by some subset of consumers as long as the idea that you don't have the right to us your purchases as you see fit. As long as this erosion of property rights and the doctrine of first sale becomes normalized and you start believing in artificial scarcity, DRM will have served it's purpose.

This is why it's so important to never compromise and accept any form of DRM. Compromise only shifts the Overton window[1] making change harder in the future.

> it may be preventing stronger digital locks from being developed

Even if "stronger digital locks" was the goal, you don't prevent future locks by allowing them today.

> the industry will respond by developing something even worse

They already do that.

> They have the money and the power

So they can use some of that money to develop their own players if they want to push DRM. There isn't any reason browser authors and the public in general should subsidize selfish businesses.

[1] https://en.wikipedia.org/wiki/Overton_window


I'm not so sure that haivng a standard way to connect DRM to a browser is changing the Overton Window. It's a technical standard that no users are actually looking at. What percenage of the population would even know the difference between a NPAPI plugin and a HTML5 interface for DRM? If you went on the streets and asked people if they feel less in control of their media because the W3C approved a standard replacement for NPAPI in browsers, would anyone even understand what you're talking about?

There are historical examples where weak DRM became standard and never got replaced. Look at CSS for DVDs. It was broken early on, but nobody bothered to replace it because it was already standard and the hardware was out there for it. Yes, there's different copy protection on Blu-Ray, etc., but a lot of people still use DVDs, and they can easily back them up because of weak encryption.

There's definitely a lot of benefits to creating a culture that values personal control, but I'm just not sure this is working. I want a DRM-free world as much as anyone, but the message is muddled and people just want their Netflix. If Mozilla and the W3C both came out against it, Chrome, Safari, and Edge would still support it, and I think all it would do would make Firefox lose even more market share. I would love to see some evidence that it would come out another way.


Normal users aren't relevant players in the politics of DRM. It's everyone who's tech- and IP-literate who is involved in the politics of DRM.


The Overton window though is about what's acceptable in public discourse.


Yes. That was my point. The goal is to change public attitudes, not practical enforcement of copyright. This has always been about shifting public discourse.

> It's a technical standard that no users are actually looking at.

Of course users aren't looking at the standard. The shift happened with the technically-minded people that eventually make recommendations to their friends and family. Just look at this very thread where people like you already accept the premise that DRM is anything other than malware that gives control over your hardware to some other party. The fact that you are making arguments that use language such as calling DRM a "digital lock" demonstrates how far the Overton window has already moved.

> If you went on the streets and asked people if they feel less in control of their media because the W3C approved a standard replacement for NPAPI in browsers, would anyone even understand what you're talking about?

You're trying to frame that question to get the answer you want. Of course most people are not familiar with NPAPI. However, if skip the technical jargon and actually ask people about their experiences, you will get very clear answers. I've literally never met anybody that wasn't directly profiting from DRM that thinks crippled video players are fine. Many have mentioned the things they would like to do but can't because of DRM.

> standard replacement for NPAPI

EME is not a replacement for NPAPI. At best it's a replacement for the DRM in Flash.

> weak DRM became standard and never got replaced. Look at CSS for DVDs.

Except it did get replaced - which you admit - in the next version of the hardware (Blu-Ray). The only reason DVD wasn't affected is the large amount of existing hardware. It's simply not possible to update all of the existing hardware players.

However, web browsers are software that updates regularly.


I'm not a good representative of public discourse. I've read Richard Stallman's blog for over fifteen years.

What you're talking about with hardware is exactly my point. We're talking about encryption, which I'm sure you support for individuals. Public Key Encryption is great for when you want to send a secret message to someone you trust to keep it secret. But what if you don't trust them? You have to convince them to trust you to have some control over their system, even if in a jail or a restricted VM. DRM is sender-controlled encryption employed by software.

So what happens if you tell the sender you refuse to run software you don't control and they still don't trust you? Their only other option is to convince you to use hardware they control. So rejecting broadcaster-controlled software might just lead to a demand for more broadcaster-controlled hardware. It's been done for years, but now we're moving from a full hardware solution to a more software-based solution, something you can contain and easily run with whatever restrictions you want.

I'm not saying it's good, but I'm not saying it's definitely not progress either.


I work on the video streaming sector and we get the shivers when a client wants a web application. And if anyone thinks media producers will allow their content to be streamed over a DRM free channel they're either naïve or stupid. What Google, Netflix and others want is to stop the mess this is currently on browsers.


Exactly that. I have issues watching copy protected dvds on my playstation where if I pause the film for a short while the copy protection kicks in and I can't watch the film, instead have to restart and fast forward to when I'd paused.

That's content protection preventing me - a purchaser - using it properly.


So, I have to ask! What makes you sure this is copy protection? It sounds more like a bug or fault rather than DRM.


True, it's likely a bug from either the disc or the player but if they weren't attempting DRM I wouldn't have the issue. Inconveniencing legitimate users because you can't implement the protections without it breaking isn't the way to go.

I know I can download a copy of a film, push play/pause and it will just work. I know if I buy a dvd I'll have to sit through unskippable piracy messages and ads and not be sure the film will play after pausing.


How do you know that without a doubt it isn't just a bug in the software unrelated to whether or not DRM was implemented?


because when I do the same on a non DRM disc it doesn't happen


> It sounds more like a bug or fault rather than DRM.

Even if it isn't the DRM, it still is. Because the player could be open and someone could fix the bug if it weren't for the DRM.


Even if it's not the DRM fault here there are plenty of other examples. E.g. You can't copy/backup a DVD on your computer/stick/cloud so once the DVD format is deprecated(i.e. Macs no longer have a DVD-drive) or the DVD is lost you can't play it anymore. Not to mention the convenience. The latest wonder from the DRM promoters is the HDCP: People with 4K TVs can't play 4K TV content anymore because of this new "feature"[0]. Apparently the only sane solution is to hack the HDMI cable.

[0] http://www.howtogeek.com/208917/htg-explains-how-hdcp-breaks...


> DRM doesn't solve this problem, but claims to do so.

If you actually listen to any of the arguments being made on the W3C mailing lists, none of the pro-DRM sides have actually argued such an absolute stance, because they're not stupid and can see DRM regularly getting broken. The argument primarily centres on "casual piracy"—some technically illiterate user sending a copy of "something fun" to their friends—and not on eliminating piracy or preventing third parties from using your work.


Is fixing "casual piracy" even going to make a dent in their spreadsheet? I doubt it.


Such "casual piracy" is legal in my country, at least when it comes to music (and we pay for the priviledge, unfortunately). Publishers shouldn't mess with my rights.


It sounds like they believe there are more potential sales there than there are from other forms of pirates. (Whether that's true or not is anyone's guess!)


"DRM doesn't solve this problem"

Again, no wish to goad, but why?


Because there is always a way to extract the "protected" work. See: https://en.wikipedia.org/wiki/Analog_hole.

If you're a photographer, I can always make a screenshot, or record the video from my HDMI/DVI cable to the monitor or take a very precise photo of my screen, and I WILL get the photo from your website or app.

There is plenty of evidence that DRM doesn't stop copying: millions of torrents ripped from crunchyroll/hulu/netflix/Blu-Rays, all of those have some sort of DRM, all of them were circumvented. There are people who think that DRM is not designed to stop copying, but it's designed to control how legitimate users consume your product (see: DVD ads).

Edit: Please don't assume that this is the only argument I have, it's just the most obvious argument from the top of my head. There are plenty of people who explain the negative sides of DRM and reasons it doesn't solve the problem you described. They do it in a very eloquent way with rigorous arguments, and I don't believe that I need to repeat those arguments. I'd like you to listen to Cory Doctorow: https://www.youtube.com/watch?v=HUEvRyemKSg


Thanks. It's an iteresting discussion that needs to be had. As I said, I often see things along the lines of 'It's just bad, m'kay' without any reason. Your explanation is reasoned and cogent. Again, Thanks!


Producers don't watch BitTorrent statistics. They send a document asking stuff like: will my product be DRM protected? If you answer no, then farewell pal, they won't allow their content to be on your platform.


Because it's literally impossible. If you want someone to be able to read your text or view your image, in the end the light has to reach the viewer's eyes, and that means it can be recorded. At best, DRM can be an annoyance. It can never stop unauthorized redistribution of material.


Don't Copy that Floppy.

Perfect example from the 80's, an arms race to prevent copying of software, which ended up doing what ?

Software still got copied while increasing the publishers cost.

Now 30 years later, efforts to preserve are stymied by copy protection on failing hardware. In an ironic twist, the protection broken by the pirates is salvageable.


How can you expect anyone without a time machine to explain what it ended up doing?

For example, we live in a world where companies like Adobe or Autodesk can sell software licenses for thousands of dollars. Would that be true if software piracy became the norm decades ago? Would we be better off one way or the other? Who can say?


What if piracy was never invented and we all just paid our dues. What a happy little libertarian utopia.

>Would that be true if software piracy became the norm decades ago?

How many decades ago? I built my first computer and installed pirate Windows and Photoshop versions back in 97. Warcraft had questions you had to answer during installation that were answers from the lore in the manual. Do you think people in the 80s with the first personal computers would see their friend use a new software and then wait 4-6 weeks for their own floppy disk to arrive in the mail?


Not to detract from your argument, but most libertarians support either substantially scaling back or entirely eliminating IP law, including copyright law.

Internet piracy in general seems to be culturally quite left-libertarian.


They didn't anyway. But all of that is irrelevant. The point is that questions like the one I originally responded to are fundamentally unanswerable. Don't get too caught up in the specific example. It could just as easily be "maybe walking across the street on a different day causes RMS to be hit by a bus". Or Microsoft taking a different path delays the Gates foundation from eradicating polio by 30 years.


Because it works in a similar way to general security - it's reactive to the state of the art of those looking to get around it. Once someone has dedicated time to getting around it, those wanting to get around it have a free pass with that content to use it in the ways they want, whereas those who have no intention to are restricted in their use (which is usually more locked down than it needs to be for genuine users, thus more inconvenient).


Yep. For example there is a image with power lines here https://backchannel.com/the-internet-really-has-changed-ever...

I liked to see the image as the whole. Had it been made not directly viewable by the publisher I would have had great pain to make it happen. Now I just opened it on another tab.


SnapChat became popular because it restricts what people can do with a post. Its users don't seem to be suffering. So it seems that there is demand for this sort of thing from many users.


> why is this a problem if the publisher doesn't want a third party to use their work without their permission, or at all?

Because whether they are allowed to do that is a determination that has to be made by the law, not the company.

Imagine someone is using your work for commercial gain and you want to sue them. If DRM is a thing and breaking it is illegal, you can't -- you need to make a copy of what's on their website to use as evidence against them, they put DRM on it that says you can't. (In practice this rarely happens because all the DRM is broken anyway, but what does that tell you?)

And the same situation plays out in a hundred different ways. Imagine politicians owned all the clips of them speaking and could throw anything that discredits them down the memory hole. Or evil companies could prevent the press from publishing incriminating documents.

It isn't a matter of whether there is some alternative. That is a thing that cannot be allowed to happen.


> but the other solutions that I've seen are as bad, or offer little real protection to the content creator.

Frankly, "then don't put your content on the Internet" would have been the response 20 years ago. But that conflicted with making money over an ultra-low-cost, global, distribution medium so something had to give-way.

The early days of the Web had a real new-frontier feel, as if the common man had finally found a platform for communicating with the World. It was heady and thrilling.

But DRM, and content restrictions in general[0], is a rude reminder that the Web nowadays is primarily commercial and centralised and is run for profit, not enlightenment or sharing, and that creates an emotional response in many people. Perhaps that response is irrational, but it's widespread and deeply-set.

A closing question: why do you want to put photographs on the Internet but also want to control what people do with them? Why not just keep them on your NAS, nice and safe?

[0] I consider anything like -NC-ND to be content restrictions.


"Perhaps that response is irational..."

No argument to your points, but the quoted sentence deserves a response: It is not irrational to expect a product/service that is, and has always been, advertised as open & shared to be open & shared. False advertising, data sequestration and shady patterns are antonymous to the claims.


> why is this a problem if the publisher doesn't want a third party to use their work without their permission, or at all?

Because they do some really stupid and awful things with js and css. For example, some websites try to hijack the clipboard so that if you highlight a piece of text, no matter how small (and small is allowed by fair use), it'll replace your clipboard contents with an attribution to the website or completely forbid you from copying the text.

Some websites try to disable highlighting text via css or js. This one tries to hide its HTML source code, try looking at it without the DOM inspector:

http://etimologias.dechile.net/

Fuck off, the data is on my computer, my home, my personal affairs. Don't try to hijack control away from my computer. Your perceived and exaggerated sense of author's rights or copyrights do not trump my right to use my clipboard or browser the way it was meant to be used.

If we have a problem with how data is being handled, we take it to court. Letting people take data enforcement into their own hands by letting them subvert laws via technical means is vigilantism and a breach of rule of law.


> why is this a problem if the publisher doesn't want a third party to use their work without their permission, or at all?

Because it often breaks accessibility tools used by the blind, for instance.

It also has a potential to break the social contract that copyright is based on. Copyright doesn't last forever, but most DRM schemes that I know of don't suddenly go away when the copyright term ends.


I use right click -> back to navigate, it drives me nutty when sites try to disable right click or put transparent gifs on top of everything.


> Genuine question: why is this a problem if the publisher doesn't want a third party to use their work without their permission, or at all?

Suppose the publisher's content consists of slander or government propaganda. They use DRM to prevent copying or archiving or citing it properly, and revise it as they wish, denying that older versions were ever published.

In the print days, you'd still have the old copy. Today, you can point to the internet archive. What if the text was DRM'd?

What the publisher wants to permit is one consideration. What the reader has a right to do with what they're reading is another.


"why is this a problem if the publisher doesn't want a third party to use their work without their permission, or at all?"

This misses the point. People when given a choice about something they don't fully understand will generally be conservative and protective. It would be very easy for the default to become locked-down for resources that haven't really had this fully considered for them. Which, if we're being honest, will be most of the web.

It's also not so much about using a third party's work - the more valuable thing is being able to see how something works.


Right, but this is a moral argument. I'm uneasy with this because as much as I like the idea of sharing, I also respect peoples desires not to share.


If you want to share something, then share it. If you don't want to, then don't. Nothing is forcing people to share their content.

DRM is saying you want to have your cake and eat it too. It's sort of like they're sharing content with you, but not really. You have to consume it the way they want to you to consume it. That's trying to control the experience, not the content, and I don't see any reason content creators have that right.

If they don't want to let the content loose on the world, then they don't have to.


There are perfectly legal things one can do with your work under "fair use" that involve being able to reproduce your content that your technological lock can never discriminate.


I think it's a crass mistake to bet on restricting content, there are so many nascent ways for people to go p2p today (images, videos, audio, files), unless rare cases, if they lock data, people will share information their way. Lots of news fed from twitter users photos, vine and periscope streams. Publishers have a pandora box in hands.


https://np.reddit.com/r/Anticonsumption/comments/55r7i4/your... should be a wakeup call.. why couldn't Popcorn time work with cryptocurrency?


Exactly. Even -- and especially -- your precious ad-blocking.

About which I, as many, feel conflicted. But if it's going to infect my computer, or distract me to the point where I can't use the actual content, then hey.

And DRM isn't going to fix any of that.

P.S. My primary concern is for open protocols and data, I should add.

But even for the average user/consumer, it bodes ill.


> If DRM is deeply integrated into the web then everything will get affected by it. Already today some publisher go to great lengths to try to disturb people from copying simple text and images. It will get only worse.

The question is whether a paywall is actually worse that 4MB of malware ridden ads (which is how content is payed for currently).


Anecdotally, I often think "just let me pay you directly!" for content that is shrouded in ads. I also actively avoid apps that use ads for revenue. I suppose that the infrastructure to do that is hard vs serving ads, and I suppose targeted ads generate more revenue...


You don't need DRM to enable your users to pay you for content.


It doesn't have to be a binary thing though. We can (and do) have a system where you can just share things quickly and easily.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: