17 ms·
Firefox Users Can Now Watch Netflix HTML5 Video on Windows
- omarforgotpwd 11y agoTranslated headline: content owners can now deliver DRM'd video without using browser plugins.
- splike 11y agoWhat else can be sent to a browser without the user being able to inspect it?
- kuschku 11y agoIn Firefox? Not much. In Chrome? Full native binaries that are executed natively.
- wmf 11y agoThere's definitely a plugin here; it's just auto-downloaded.
- mtgx 11y agoGreat, so they told us to "embrace DRM on the web if you want plugin-free Netflix!", and then we got both the DRM and a Netflix plugin. Such a deal.
- Someone1234 11y agoBut why did you want plugin free Netflix to begin with? Because Flash (and Java) are massive ongoing security concerns. Flash is too complex and has too much surface area, this new plugin even aside from being sandboxed, is simpler and with less surface area. I am not saying that exploits won't be found here. I am just saying it may not be as bad as the continuously dripping tap that is Flash.
- admax88q 11y agoThey could easily have implemented a better more secure plugin without having to corrupt W3C standards with DRM.
- cpeterso 11y agoThe EME DRM specification was authored by Microsoft, Google, and Netflix. Now that the other major browsers like Chrome, Edge, IE, and Safari implement EME and it is used by major content providers like Netflix, Amazon, HBO, and Canal+, Mozilla is backed into a corner. Not that long ago, Mozilla tried to challenge H.264 on the Web. The Chrome team agreed to drop H.264 too, but they didn't keep their word and, without a public explanation, kept supporting H.264. When cat videos encoded in H.264 don't work in Firefox but work in Chrome, users switch to Chrome and may never come back. And now when video services people pay money for work in Chrome but not Firefox, users switch to Chrome and, again, may never come back. http://blog.chromium.org/2011/01/html-video-codec-support-in-chrome.html http://blog.chromium.org/2011/01/html-video-codec-support-in... https://news.ycombinator.com/item?id=2093219 https://news.ycombinator.com/item?id=2093219
- pdkl95 11y ago> Not that long ago, Mozilla tried to challenge H.264 on the Web. Ahh, hubris. They thought they could force the industry's hand with their market share... which was already starting to decline. By focusing on H.264 (and promoting Theora!), they succeeded in keeping Flash around as websites decided letting Firefox users stay with flash was easier and cheaper than listening to Mozilla's demands regarding <video>. Sometimes I hate bring right[1]... What they should have done is dodge the problem by leaving the question of codec to the OS. Instead, Mozilla decided to drive users away. Which was also the obvious end result[2]. I understand (and support) making ideological decisions, but it's also important to pick you battles. [1] http://yro.slashdot.org/comments.pl?sid=1597850&cid=31643970 http://yro.slashdot.org/comments.pl?sid=1597850&cid=31643970 ("Endymion"/UID=12815 on /. is me) [2] http://yro.slashdot.org/comments.pl?sid=1597850&cid=31644218 http://yro.slashdot.org/comments.pl?sid=1597850&cid=31644218
- nnethercote 11y agoThere are two different meanings of "plugin" being used here. The CDM plugin does just one thing (the DRM stuff) compared to, say, Flash, which is a gigantic thing. DRM still sucks, but it's a clear improvement from a security/attack surface point of view.
- mmastrac 11y agoGiven that the CDM is sandboxed, does this mean that it should be significantly easier to recover encryption keys from it given that you could effectively run the CDM inside of a tracing emulator?
- adrusi 11y agoPerhaps. I don't think anyone who can think of that attack vector would really care because they'd also understand that their DRM will be broken as soon as anyone really wants the data it "protects" because it's a futile endeavor.
- nekitamo 11y agoThe encryption keys would probably be whiteboxed (http://www.whiteboxcrypto.com/ http://www.whiteboxcrypto.com/) and thus you would have to break the whitebox scheme in order to recover the unprotected keys.
- Nursie 11y agoThat is kinda interesting but.... "This means that an attacker can easily ... use any kind of attack tool such as IDA Pro, debuggers, emulators, etc." Attack tools?!
- Aissen 11y agoI like calling those "Debug tools".
- dmm 11y ago""" Dan had had a classmate in software, Frank Martucci, who had obtained an illicit debugging tool, and used it to skip over the copyright monitor code when reading books. But he had told too many friends about it, and one of them turned him in to the SPA for a reward (students deep in debt were easily tempted into betrayal). In 2047, Frank was in prison, not for pirate reading, but for possessing a debugger. """" -Richard Stallman in The Right to Read http://www.gnu.org/philosophy/right-to-read.en.html http://www.gnu.org/philosophy/right-to-read.en.html
- kozukumi 11y agoIt has been working since Firefox 42 for me. Maybe even before then I am not sure. I guess this is just Netflix making it official now that both 32 and 64-bit versions of Firefox are officially supported on Windows?
- cpeterso 11y agoGood eye! :) Netflix has been A/B testing the Adobe CDM in the Firefox 42 release channel for a couple weeks (and in the Firefox pre-release channels for months). This is just the official launch announcement.
- kozukumi 11y agoYeah I figured it was such. Thanks for all the great work on Firefox, a lot of people love to hate on it these days but it is still my favourite browser. Have a great Christmas :)
- daguava 11y agoThe part I find scary is it uses Adobe's new Content Decryption Module. So you mean to tell me the alternative to the buggy insanely insecure Adobe Flash is... more software by Adobe?
- TD-Linux 11y agoIt's still a security win, because the CDM sandbox is allowed to do substantially less than the Flash sandbox. Flash can access your webcam, filesystem, make any network connection, etc. The CDM only decrypts and decodes frames.
- cpeterso 11y agoFlash is a general-purpose virtual machine with a large attack surface, including a JIT and access to the GPU. The Adobe CDM has a tightly-controlled API. Unless Adobe's Flash updater, Firefox manages CDM updates so any CDM security fixes can be deployed to users within 24–48 hours.
- JustSomeNobody 11y agoBut is it guaranteed to be buggy and insecure just because it is by Adobe?
- daguava 11y agoI desperately hope not, my original comment sure appears to come off as rooting against Adobe, but I'll absolutely hope this means success and is the start of secured content playback on HTML5
- pasbesoin 11y agoHaving spent 7.5 hours on multiple customer support calls to Adobe just to get a feature enabled (compatibility with a 32 bit system) that was stated ON THE PRODUCT BOX as being present and working... YES! (Yes, this is a bit OT, but still, "Adobe".) I also fear the CDM support being used to "lock down" ever more aspects of web content. And I fear attempts on the part of Adobe as well as others (perhaps in concert with a State or corporate power) to escape sandboxing and do "whatever" on client systems for their own purposes. In other words, here is another binary blob from Adobe (et al.?) that we are supposed to trust. Sorry, Adobe, but -- through dint of extended experience -- I simply don't trust you.
- shmerl 11y agoNo, thanks. Not using Windows and not using DRM either.
- i80and 11y agoPSA for those stuck on Windows: Mozilla makes an EME-free build for Firefox available here: http://download.cdn.mozilla.net/pub/firefox/releases/43.0/win64-EME-free/ http://download.cdn.mozilla.net/pub/firefox/releases/43.0/wi...
- skrebbel 11y agoI really wonder what kind of filter bubble one must live in to write "those stuck on Windows" on a place like HN.
- scrollaway 11y agoGP didn't imply that "those stuck on Windows" make up 90% of the population or anything. But seeing how inconvenient Windows, compared to alternatives, is for the tech crowd which makes up a large portion of HN... then yes, it's fair to say "for those stuck on Windows".
- skrebbel 11y agoWow, you simply can't imagine people might have other preferences than you!
- scrollaway 11y agoI can. I'm very sorry you can't.
- shmerl 11y ago> I really wonder what kind of filter bubble one must live in to write "those stuck on Windows" on a place like HN. Aren't most users still stuck there? There is no reason to use privacy abusing, proprietary OS, unless one is really pressured by circumstances, or in more valid cases like when working on cross platform projects. That's what's called stuck.
- lolyololol 11y agoFree computing dies one circus show at a time.
- jokoon 11y agoOh, nice, I recently tried netflix something like 1 month ago, and changed my mind instantly when I saw this weird message about some silverlight key DRM agreement.
- distantsounds 11y agoUnless this is open enough to the point where I can natively browse and watch Netflix on XBMC / Kodi, this really isn't making any strides towards anything really usable. They're just shifting the tech around from one format to another without much benefit to the end user.
- z3t4 11y agoThis is amusing ... HTML5 video have been available for years! Even in royalty-free formats. As for DRM, if you can play it on a monitor, even hardware decoded, you can still capture it! Doesn't Netflix allow you to watch the same movie over and over again without paying extra!? So there is no incentive to copy it in the first place!
- izacus 11y agoIt's not Netflix (and other providers) that want the DRM, it's the actual movie studios. The deal is "either you use DRM from our approved whitelist or you will not be allowed to offer our shows for streaming".
- nomel 11y agoIn the future, all recording devices will be stream their feeds through a content approval system before being accessible for replay. Any unapproved reproductions of sounds or video captured will be replaced by approved promotional videos or ads featuring the starving children of burnt out artists, ruined by the lack of DRM. Owning a tripod, any analog media player, and any non approved recording device, will be considered a felony, punishable by a full screen video add sent to your mandatory content approved augmented reality headset every 30 seconds to slowly pay off the lawyer fees and damages. At 0.1 cents per ad, the strongest will only survive a few hundred thousand before going completely insane.