25 ms·
Google Widevine Content Decryption Module DMCA
- resynth1943 6y agoOnly Level 3, sadly, which means it can decrypt Standard Definition (480p) videos. This has been out for a while. Some reputable people in the pirating industry have actually cracked Level 1, which means they can decrypt 4K! :-)
- kayson 6y agoAny resources on Level 1 decryption?
- m-p-3 6y agoIt's probably kept under wraps by large scene groups, they don't want to show their methods and have them patched out.
- gruez 6y agoOne method appears to be playing back on a legitimate player, then using HDCP strippers on hdmi/displayport outputs[1]. I've seen some 4k releases that clearly show the streaming site's playback controls, for instance. [1] search for "hdcp bypass" on ebay
- mmm_grayons 6y agoI remember cheap chinese hdmi splitters used to inadvertently strip hdcp; is that still current?
- dannyw 6y agoYes, but you could just explicitly search for a hdcp stripper and it'll work.
- bawolff 6y agoThere have been a bunch of papers recently about using undervolting to break secure enclaves. No idea about how applicable that is, but that might be a possible attack vector.
- snvzz 6y agoCapture HDMI. Strip DHCP. Refer to the perfectly legal NeTV2 + trivial modification if you understand the HDL.
- Thorrez 6y agoIs that considered decryption? Wouldn't that both decrypt and decompress? What if someone wants the original compressed stream so the video doesn't need to be re-compressed?
- bscphil 6y agoThat can't be done without hardware hacks, which can (often) be traced to isolated hardware which the manufacturers will then lock out or force a software upgrade for, making it impossible to use in the future. That's why most 4k pirate releases are re-encoded from HDMI, not lossless rips of the original stream as they are for 720p and 1080p.
- matheusmoreira 6y agoWill that reduce the quality of the audio/video?
- bawolff 6y agoLevel 1 means everything is done in a secure enclave from what i understand. I wonder if google does something similar to bluray AACS where if a level 1 device is compromised they can revoke just that device (or manufacturer's key). If not, i wonder why they don't. (To clarify my curiosity is in an abstract way, i am ideologically opposed to DRM)
- AlexCoventry 6y agoWhat kind of secure enclave? There have been a lot of catastrophic vulnerabilities in secure enclaves, over the past year or three.
- bawolff 6y agoWhichever one your device has. Its a technology that google licenses out. If you are making a device that has a secure enclave you can apply for a license for level 1 widevine. If indeed level 1 has been breached, presumably it happened via one of those weaker secure enclaves.
- gruez 6y ago>If not, i wonder why they don't. mainly because it's hard to trace back which device key got leaked, especially if all you have to go on are whatever the ripped videos. if you had the tools it'd be much easier, but that's probably kept under tight wraps by the piracy groups.
- Retr0spectrum 6y agoThis is just not true. It's up to individual content providers to decide what resolutions to supply via L3, and for Netflix and Amazon Prime, that resolution is 1080p.
- Thorrez 6y ago>and for Netflix [...], that resolution is 1080p. Do you have a source for that? This page[1] says Firefox and Chrome on Windows, Linux, and Mac only go up to 720p. Chrome on ChromeOs goes up to 1080p, is that still L3? [1] https://help.netflix.com/en/node/23742 https://help.netflix.com/en/node/23742
- Retr0spectrum 6y agohttps://i.imgur.com/uveeA6a.png https://i.imgur.com/uveeA6a.png https://addons.mozilla.org/en-GB/firefox/addon/netflix-1080p-firefox/ https://addons.mozilla.org/en-GB/firefox/addon/netflix-1080p... It seems that many streaming platforms disable 1080p by default, and I assume that this is only for performance reasons (some hardware struggles to run an obfuscated software video decoder...) - it's not a DRM limitation, and in netflix's case it can be re-enabled via trivial changes to the frontend JS.
- Aissen 6y agoOf course you can watch the test streams, but try watching a recent movie from a third party studio and see if it reports the same resolution.
- Retr0spectrum 6y agoThis is true, but if you care about quality you'd go directly to the third party source. All of the content I actually use Netflix for is available in 1080p on L3 (Which matters to me, since L3 is the highest supported level on desktop x86 Linux).
- 0xbkt 6y ago
- delroth 6y agoRepository mirror: https://archive.softwareheritage.org/browse/origin/directory/?origin_url=https://github.com/tomer8007/widevine-l3-decryptor https://archive.softwareheritage.org/browse/origin/directory...
- justinclift 6y agoExcellent, thanks. Hadn't heard of this decryptor project before, now I can take a look through it to see how it works. :) Pity they don't seem to have `git clone` support, and only allow downloading a tarball. Anyway, that's still a lot better than nothing. :)
- captn3m0 6y agoThe private key mentioned in the notice is here: https://archive.softwareheritage.org/browse/origin/content/?origin_url=https://github.com/tomer8007/widevine-l3-decryptor&path=content_key_decryption.js#L22-L36 https://archive.softwareheritage.org/browse/origin/content/?...
- agilob 6y agoHow do I clone it to get .git directory? downloaded tar doesnt contain it.
- cryptonek 6y agoI thought it might be nice to create another mirror, just in case: https://github.com/cryptonek/widevine-l3-decryptor https://github.com/cryptonek/widevine-l3-decryptor Hopefully, it will hang at least till monday, so some of you will be able to clone. It is based on commit ed8a97745c69b8cc0fc7f59cec9474b216b49e16 which is latest archived by Web Archive (and signed by Github!). By the way, it is still possible to fetch original repo, provided you know the commit id above :)
- tim-- 6y agoIt was one thing when it was the RIAA that was coming for our repositories. Now that it is Google, I'm extremely sad and disappointed. I think the time has come for there to be a repository hosting service that is based somewhere in Switzerland :)
- Scoundreller 6y agoI think space is becoming a reasonable frontier. Until then, something IPFS based.
- dannyw 6y agoThis is maybe one of the few use cases where a cryptocurrency can help; in a similar vein to the effectiveness of BitTorrent. Specifically, Filecoin (built by the IPFS folks) could be used as a datastore for git. You can send DMCAs to pseudonymous Filecoin operators all you want; but the content will still be up if one operator keeps hosting it. Hopefully it will also encourage all commits and repositories to be PGP signed (and not through a centralized FVEY platform), strengthening security, authenticity, and trust.
- Scoundreller 6y agoSpace-based crypto-funded storage for guaranteeing that one operator. The best part about non-GEO satellites is that, although you can't see them 24/7 from one location, that also makes it incredibly difficult to jam their uplinks continuously.
- StavrosK 6y agoFilecoin isn't a datastore, it's a coin. IPFS is the datastore. However, I'd probably use something that works better, maybe Dat or Zeronet.
- Shared404 6y agoSourcehut may be a good option as well. Drew seems like the type to fight illegitimate DMCA's. Edit: I'm curious, why the downvotes? I am legitimately trying to be helpful. I recognize if you have personal differences with ddevault, but he puts his code where his mouth is. If I'm misunderstanding said downvotes, please enlighten me. Edit 2: Many thanks to those who have responded. It appears I misunderstood about this specific instance, where the DMCA does have some legitimacy.
- notRobot 6y agoIsn't DRM... Completely fucking pointless? I can go on The Pirate Bay and find 4K rips of all movies and shows I want. If DRM can't prevent that, what's the point? All it does is infringe on our rights to be able to do what we want on our own devices. It's crazy.
- deleted 6y ago[deleted]
- deleted 6y ago[deleted]
- Scramblejams 6y agoIsn’t the point to generate license revenue for the DRM IP holders?
- Polylactic_acid 6y agoYes movie DRM does seem completely pointless. Game DRM on the other hand does seem to hold up for the first few months which is where most of the sales happen. It would be nice if devs dropped the DRM once it is cracked though.
- zeusk 6y agoThere is a subreddit which tracks this https://www.reddit.com/r/CrackWatch/comments/ieo7u4/crack_watch_games/ https://www.reddit.com/r/CrackWatch/comments/ieo7u4/crack_wa...
- jaspergilley 6y agoSuper interesting, thanks for posting
- hnick 6y agoThanks for that. I found this interesting old discussion on Denuvo too (skim/skip the OP, seems to be BS, but the top comment is interesting). https://www.reddit.com/r/CrackStatus/comments/43dgej/how_denuvo_works_and_why_its_so_hard_to_crack/ https://www.reddit.com/r/CrackStatus/comments/43dgej/how_den...
- surround 6y agoSome self hosting options: Gitea: https://gitea.io/ https://gitea.io/ sourcehut: https://sourcehut.org/ https://sourcehut.org/ Gogs: https://gogs.io/ https://gogs.io/ Gitlab: https://gitlab.com/ https://gitlab.com/
- judge2020 6y agoThis has been brought up before in the other threads, but just because you self host doesn't mean you can ignore DMCA takedown requests. You can choose to ignore such DMCA requests if they decide to send one to your self-hosted website, but not honoring it means you think you're not infringing on their copyright and are willing to go to court over it. If they don't want to go this far, or you try to not include contact info, they'll probably first send a DMCA to your web host/registrar who will suspend your hosting/website unless you counter-notice, which still means you've got to be ready to fight a lawsuit (note that Cloudflare forwards DMCA requests to your web host company, so you can't hide behind CF).
- snvzz 6y ago>DMCA Is a very US specific request.
- formerly_proven 6y agoDMCA itself is obviously an US law, but many Western countries have similar laws.
- pmlnr 6y agoPoint me at them, please.
- zinekeller 6y agoWell, since youtube-dl was the news, they have cited a German decision on the takedown request, which solely references German law. I don't know German enough to find this specific law, but I do know that by default copyright associations have a presumption to copyrights over certain media (like GEMA's case in music, which is used on YouTube around 2010, and Google was found guilty of that and therefore Google pays royalties to GEMA).
- userbinator 6y agoIn addition to this request, we have filed a separate Sensitive Data takedown request of this file: /widevine-l3-decryptor as it contains the secret Widevine RSA private key, which was extracted from the Widevine CDM and can be used in other circumvention technologies They are practically asking for Streisand Effect... if you distribute your key with the software, then whatever form it is in, I would not consider it "private" at all!
- R0b0t1 6y agoThis is DeCSS all over again. Was that ever resolved? It seems to me the original DeCSS complaints were more or less dropped because technology moved on and they couldn't mount a defense in a real court, and had to rely on bluffing.
- freeone3000 6y agoCase was dropped by the DVD CCA in Norway because the number was no longer secret. That isn't relevant for section 1201 of the DMCA. It cares only if the program's intent was to bypass copy protection. DeCSS, and even libdvdcss, are absolutely infringing on this, and can't be hosted in USA repositories.
- akersten 6y agoHow is one supposed to exercise their right to Fair Use without "bypassing" technological measures via tools like these? I think there is solid legal DMCA ground for them to remain hosted in the US, without even needing to reach for the whole "freedom of speech" thing. I won't even get into how I think GitHub is being overly courteous to media companies by extending takedown ability for alleged Section 1201 violations. I'm firmly convinced the only remedy the DMCA offers for that is via the courts, and that the takedown process explicitly requires the identification of infringing material, not circumvention tools.
- roywiggins 6y agoFair use is about copyright. The DMCAs anti-circumvention section means you can't distribute software designed to circumvent DRM, even if that software isn't itself infringing. So I don't see how fair use could apply.
- JohnTHaller 6y agoDoes this mean I have to update the MAFIAA.org website to add Google now?
- BlueTemplar 6y agoSure. But you seem to be specifically missing Github's owner Microsoft : https://web.archive.org/web/20201025014127/https://www.riaa.com/about-riaa/riaa-members/ https://web.archive.org/web/20201025014127/https://www.riaa....
- deleted 6y ago[deleted]
- young_unixer 6y agoToday, Apple and Google have been exposed in anti-user shenanigans. The future looks bleak.
- echelon 6y agoThey've both been anti-user for a long time.
- echelon 6y agoGoogle, you're disappointing. You're not cool, and you definitely not good. I hope the future moves on without you.
- kortilla 6y agoIt will take a long time. They are well on their way to becoming the next IBM but that means at least a good 30 years of being relevant. Brain drain takes a long time because most of the people still at Google now are ok with this kind of thing.
- izacus 6y agoNot as disappointing as Americans who enacted abusive DMCA law which makes hosting such keys illegal. Blaming a company to follow law you've passed is lopsided.
- rvdmei 6y agoThis might be a good explanation why my Philips 55POS9002 oled tv can no longer stream 4K with Netflix/Prime/YouTube. A Widevine certificate was revoked for some Philips TVs. Maybe the RSA key was leaked in the Philips firmware.
- nitrogen 6y agoHave you tried to get a refund? This kind of remotely downgrading a physical purchase is an outrage.
- rvdmei 6y agoNot yet. Apparently Philips (TP Vision actually) is working on resolving the issue. If they can’t fix it I will definitely go back to the store (Dutch law makes them responsible for any defects) and try to get some kind of refund.
- Ayesh 6y agoFrom what I read, the decryption is done in software. It might be interesting if they send an over the air update to fix this.
- lucb1e 6y agoBe sure to report the defect. Even if you already know they're working on a solution, which you can acknowledge (or ask them to confirm) in your message, you need to make it clear that you observed a defect with the bought product without undue delay for warranty to apply to you. (More info at Consuwijzer.nl, the website from the autoriteit consument & markt .) Since I had some trouble with a certain model airplane store in den bosch, I know a thing or two about Dutch warranty law (and a bit about how it relates to European law; the Dutch one is more broad). Was a huge pain and cost me a ton of time and I didn't really have anyone who already knew the law or was willing to dive into it to double check my work (juridisch loket was also fairly unhelpful). Feel free, you or anyone, to shoot me an email if you have further or other questions on the topic.
- jaspergilley 6y agoThis inspired me to research and download Brave Browser. Thanks Streisand Effect! So nice to have a browser that doesn't feel like bloatware
- danielsamuels 6y agoWhat on earth does that have to do with this topic?
- webmaven 6y ago> What on earth does that have to do with this topic? Presumably, Brave doesn't include the Widevine DRM components from Chrome?
- dep_b 6y agoTrying to get Widevine going on iOS / macOS has been a royal pain in the ass so far (crashes when you touch the lib while having a debugger attached, so you can't even debug your own code unless you swap in a severely castrated development version that only works on the simulator) and Google guards access to the official libs and docs like it's the precioussss. To me this is just one of the many developer hostile steps I've seen. I understand they don't want you to access illegal content too easily but honestly the only thing that could drive me back to Torrenting is the declining quality of content on Netflix & co.
- git1234566789 6y agoat least thanks to git a lot of people have a full local repo copies and can restore them online fast, maybe not in github, but anywhere else btw, if would be nice if git would allow a salt be configured per repo for their hashes, and if needed to resalt whole repo; this would make commit bashed censor like github does impossible and expensive and unreliable if they need to hash all files
- MauranKilom 6y agoYou could just rebase on top of a new initial commit, no? Might lose some metadata but this otherwise does exactly what you asked for...
- hyperman1 6y agoI am missing a party in this discussion: The role of the github monoculture. Because all these repos are hosted by the same party, one lawyer writing one letter can cause global disruption. Github did nothing wrong here. They got an important, maybe controlling share of the market by creating a great product. While they might have a monopoly, I see no abuse of it. But that's irrelevant for the rest of the world. The simple existance of the monoculture makes all of us vulnerable to attacks.
- gspr 6y agoThe GH monoculture isn't great, but it's less of a problem than other monoculture threats we've faced, due to git's distributed nature. Thus far GH has not changed git itself, and since every repository is canonical, it's easy to change what the "main" repository is at the snap of a finger. Self host, move to sr.ht, whatever. I try to think of GH as a convenient mirror service that happens to provide a lot of discoverability. Nice, but in no way essential.
- kortilla 6y agoThis is only true if you don’t use GitHub for reviews/issue tracking/etc. You’re correct that it’s trivial to move the code, but that’s only a fraction of the critical history and tooling for a large collaborative project.
- Macha 6y agoMany of the projects that are on github were once on Google Code and migrated over issues.
- acoard 6y agoTrue, but I've seen many projects that use both GitHub and JIRA (i.e. not BitBucket). Those work totally fine for issue tracking, project management, etc. It's the same amount of friction for what you're proposing. The main thing you are missing out on is a UI for merging and PRs, which is nontrivial but not a moat that can keep a monopoly afloat. Of course if JIRA shut down that'd be annoying too, but I could re-create my project in another project manager. To me, the bigger impact is things like GitHub Actions and your CI/CD pipeline. Issue tracking and PRs don't seem like big issues to me.
- Tepix 6y agoThe keys they are trying to suppres can be found at many locations now, one of them is https://pastebin.com/QxhukwBR https://pastebin.com/QxhukwBR
- mjevans 6y agoAlready removed
- jeffrallen 6y agoNo problem, now it's here: https://pastebin.com/0U14ahpm https://pastebin.com/0U14ahpm
- faxanxiety 6y agoAnd in rot13 in case anyone gets it in their heads to auto-remove copies based on content (upload filter style) https://pastebin.com/bGNq9ahn https://pastebin.com/bGNq9ahn
- Tepix 6y agoWhat countries are there that do not honor the DMCA? That would be a good place to host these types of software.
- captn3m0 6y agoIt comes as part of WIPO usually. I checked the list and could find the following countries that don't seem to be a signatory: - Palau - Micronesia - Palestine The first 2 are under "Free association" with the US, but have their own copyright laws. All three have their own TLD (.pw, .fm, and .ps)
- hda2 6y ago> It comes as part of WIPO usually. No, it does not. DMCA is a US-specific implementation of WIPO treaties. Parties residing in other countries are under no obligation to honer it (beyond complying with local laws) and will not benefit from its safe-harbor provisions even if they did.
- lucb1e 6y agoOther comments, replying to people suggesting to host in Switzerland or so, say that similar protections apply there. Now GP is downvoted with as sole response that other countries don't have DMCA. Can't have it both ways: yes, DMCA is a USA law but that doesn't mean that other WIPO signatories don't have similar laws that lawyers will be sure to find if people move stuff there.
- deleted 6y ago[deleted]
- BlueTemplar 6y agoFrance, in practice ? https://news.ycombinator.com/item?id=25081583 https://news.ycombinator.com/item?id=25081583 https://news.ycombinator.com/item?id=25083782 https://news.ycombinator.com/item?id=25083782
- torbentorsten 6y agoJust to quickly help the Streisand effect, this is the private key, extracted from [1]: -----BEGIN PRIVATE KEY----- MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQC10dxEGINZbF0nIoMtM8705Nqm6ZWdb72DqTdFJ+UzQIRIUS59lQkYLvdQp71767vz0dVlPTikHmiv dYHRc7Fo6JsmSUsGR3th+fU6d1Wt6cwpMTUXj/qODmubDK/ioVDW7wz9OFlSsCBvylOYp9v2+u/VXwACnBXNxCDezjx4RKcqMFT31WTxqU9OM9J86ChMOW4bFA41aLAJ ozB+02xis7OV175XdQ5vkVXM9ys6ZoRF/K6NXeHiwcZFtMKyphXAxqU7uGY2a16bC3TEG5/km6Jru3Wxy4nKlDyUjWISwH4llWjdSi99r2c1fSCXlMCrW0CHoznn+22l YCKtYe8JAgMBAAECggEAGOPDJvFCHd43PFG9qlTyylR/2CSWzigLRfhGsClfd24oDaxLVHav+YcIZRqpVkr1flGlyEeittjQ1OAdptoTGbzp7EpRQmlLqyRoHRpT+MxO Hf91+KVFk+fGdEG+3CPgKKQt34Y0uByTPCpy2i10b7F3Xnq0Sicq1vG33DhYT9A/DRIjYr8Y0AVovq0VDjWqA1FW5OO9p7vky6e+PDMjSHucQ+uaLzVZSc7vWOh0tH5M 0GVk17YpBiB/iTpw4zBUIcaneQX3eaIfSCDHK0SCD6IRF7kl+uORzvWqiWlGzpdG2B96uyP4hd3WoPcZntM79PKm4dAotdgmalbueFJfpwKBgQDUy0EyA9Fq0aPF4LID HqDPduIm4hEAZf6sQLd8Fe6ywM4p9KOEVx7YPaFxQHFSgIiWXswildPJl8Cg5cM2EyMU1tdn5xaR4VIDk8e2JEDfhPtaWskpJp2rU2wHvAXOeAES7UFMrkhKVqqVOdbo IhlLdcYp5KxiJ3mwINSSO94ShwKBgQDavJvF+c8AINfCaMocUX0knXz+xCwdP430GoPQCHa1rUj5bZ3qn3XMwSWa57J4x3pVhYmgJv4jpEK+LBULFezNLV5N4C7vH63a Zo4OF7IUedFBS5B508yAq7RiPhN2VOC8LRdDh5oqnFufjafF82y9d+/czCrVIG43D+KO2j4F7wKBgDg/HZWF0tYEYeDNGuCeOO19xBt5B/tt+lo3pQhkl7qiIhyO8KXr jVilOcZAvXOMTA5LMnQ13ExeE2m0MdxaRJyeiUOKnrmisFYHuvNXM9qhQPtKIgABmA2QOG728SX5LHd/RRJqwur7a42UQ00Krlr235F1Q2eSfaTjmKyqrHGDAoGAOTrd 2ueoZFUzfnciYlRj1L+r45B6JlDpmDOTx0tfm9sx26j1h1yfWqoyZ5w1kupGNLgSsSdimPqyR8WK3/KlmW1EXkXIoeH8/8aTZlaGzlqtCFN4ApgKyqOiN44cU3qTrkhx 7MY+7OUqB83tVpqBGfWWeYOltUud6qQqV8v8LFsCgYEAnOq+Ls83CaHIWCjpVfiWC+R7mqW+ql1OGtoaajtA4AzhXzX8HIXpYjupPBlXlQ1FFfPem6jwa1UTZf8CpIb8 pPULAN9ZRrxG8V+bvkZWVREPTZj7xPCwPaZHNKoAmi3Dbv7S5SEYDbBX/NyPCLE4sj/AgTPbUsUtaiw5TvrPsFE= -----END PRIVATE KEY----- [1] https://archive.softwareheritage.org/browse/origin/content/?origin_url=https://github.com/tomer8007/widevine-l3-decryptor&path=content_key_decryption.js https://archive.softwareheritage.org/browse/origin/content/?...
- intricatedetail 6y agoAfter RIAA stunt corporations see that Github is weak. They are coming for your repos! I wish Microsoft would have stood up for the community, but for them it is all about profit.
- BlueTemplar 6y agoAnd Microsoft is also part of the RIAA : https://web.archive.org/web/20201025014127/https://www.riaa.com/about-riaa/riaa-members/ https://web.archive.org/web/20201025014127/https://www.riaa....
- spullara 6y agoWherein, Google asserts a copyright on the API for their license system, the protobuf file. Maybe this file is more creative than the Java APIs? Additionally, the Git repo contains several files that violate Google’s copyrights: Google license_protcol.proto (see Google copyright at the top of the file): /widevine-l3-decryptor/blob/main/license_protocol.proto
- koreanguy 6y agoit is very clear what github is becoming if value open source as a developer find alternatives github.com could not any longer be trusted. self host
- zoobab 6y agoGit over uncensorable storage.
- deleted 6y ago[deleted]
- lol123456789 6y agohttps://github.com/github/dmca/pull/8283 https://github.com/github/dmca/pull/8283 added widevine decryptor to dmca idk if theyll take it down
- Liskni_si 6y agoThe proper way to add stuff into the dmca repository is to fetch the entire git history from the repo, git merge --allow-unrelated-histories, and then make a pull request from that. This way, we could just git fetch https://github.com/github/dmca 225ce7ac70aec3002599ba4cc8cee7197e0f1cee to update our existing clones of widevine-l3-decryptor from the dmca repo. So... can someone push that please? I don't have the recent commits. :-(
- agilob 6y agoYoutube on DRM next year then?
- bergstromm466 6y agoI honestly believe this is just a small component, which is a part of the long term strategy of the RIAA and others: a periodical check to test the waters to see where public opinion is at, to be able to guage if they can implement more dramatic and restrictive DRM mechanisms yet [1]. They are either 1) waiting for us to be too exhausted to notice/care/fight back, or 2) seeing whether they have to go further to 'protect content creators' by lobbying for more draconian laws that allow for the use of new DRM strategies. It reminds me of reading about how Corporate personhood was invented to protect freed slaves [2], yet is now used as a way for business owners to avoid personal liability/responsibility. One could even argue that Corporate personhoood is one of the most destructive forces that exists today; causing some of the worst crimes in modern history [3]. It's important we continue to fight back and set a precedent for protecting users over corporations or governments. [1] https://en.wikipedia.org/wiki/The_Right_to_Read https://en.wikipedia.org/wiki/The_Right_to_Read [2] https://www.history.com/news/14th-amendment-corporate-personhood-made-corporations-into-people https://www.history.com/news/14th-amendment-corporate-person... [3] https://www.counterpunch.org/2013/02/05/corporate-personhood-and-the-culture-of-pathology/ https://www.counterpunch.org/2013/02/05/corporate-personhood...
- BlueTemplar 6y ago> It reminds me of reading about how Corporate personhood was invented to protect freed slaves [2] Why not Magna Carta while you're at it ?
- marcodiego 6y agoIs this a leak? Was it previously publicly known? Will this allow me to watch netflix on my arm linux box like DeCSS allowed me to watch DVD's in early 2000's?
- DarkmSparks 6y agoI'm generally of the opinion that if a creator doesn't want you to watch or listen to something, you shouldn't watch or listen to it. The solution to DRM is not to work around it, it is that everyone refuses to use or pay for it.
- danlugo92 6y agoAgreed. I don't watch movies or TV shows anymore except for the occasional trip to the big screen (last movie was Avengers, next movie I'll go will be Tenet). Not to mention I don't have a credit card and can't pay for stuff even if I wanted (last tv show I watched was HBO's Westworld will probably skip next season though). Only thing I pay for is Spotify through a family plan, relative has a credit card of course.
- Ayesh 6y agoDo you not use a credit card by choice? Because you can probably just use a debit card.
- autoexec 6y ago"voting with your dollar" does less than most boycotts which are basically worthless. I mean, you could cut yourself off from nearly every form of entertainment created in the last 150 years going forward to stick it to the man I guess... Personally, I'll stick with paying for stuff when I want and can afford to and if a company charges too much or places too many restrictions on the works they've bought the rights to from a creator I'll consider seeking out alternative means to get what I want or work around those restrictions. It's a nice balance that lets me reward companies that acquire great works that are priced well and not overly encumbered by DRM while still letting me participate in our culture.
- dingaling 6y ago> I'll consider seeking out alternative means to get what I want or work around those restrictions. But consider the time-value you're expending in doing so, versus just not engaging. Invert the scenario: say that you sent Big Media Corp a bagful of poker chips in payment for watching something. Do you think they'd expend their time going down to the casino to cash them in? Of course not. So why waste your time playing around their rules? Just walk away.
- user5994461 6y agoThey should host the software in France, like VideoLan. https://www.videolan.org/legal.html https://www.videolan.org/legal.html >>> Are libdvdcss and libaacs legal? libdvdcss is a library that can find and guess keys from a DVD in order to decrypt it. This method is authorized by a French law decision CE 10e et 9e soussect., 16 juillet 2008, n° 301843 on interoperability. >>> Patents and codec licenses. Neither French law nor European conventions recognize software as patentable (see French section below). Therefore, software patents licenses do not apply on VideoLAN software.
- zoobab 6y ago"Neither French law nor European conventions recognize software as patentable" Wait for the Unitary Patent to come to reality: https://ffii.org/donate-now-to-save-europe-from-software-patents-says-ffii/ https://ffii.org/donate-now-to-save-europe-from-software-pat... French courts won't have a say anymore.
- user5994461 6y agoThere is very little explanation in this article, don't understand what this is about. Seems to be hinting toward something coming up in German law, that would not be applicable in other EU countries. The EU is very fragmented, every country mostly applies its own laws.
- zoobab 6y agoThe software patent directive has been replaced by another attempt to achieve the same, via a central patent court for Europe: https://ffii.org/ffii-oppose-the-third-attempt-to-impose-software-patents-in-europe-via-the-upc/ https://ffii.org/ffii-oppose-the-third-attempt-to-impose-sof...
- Mindwipe 6y agoFrance has an anti-circumvention law.
- 6y ago
- deleted 6y ago[deleted]
- Fumtumi 6y agoFunny how people think anyone cares to hide this key after it is out now. Leaked = known Do they need to take action? Obvious but not because the key is out but because it would look bad if Google wouldn't do anything. Content providers might hesitate to do deals like this again.
- worldmerge 6y agoAt least in the past it seems like China doesn't care about copyright or the DMCA. Why not host a repository there? There are a lot of ethical issues but if your goal is to avoid the DMCA, why not?
- gowld 6y agoIf you don't like DRM, just stop downloading DRM-encumbered content.
- zeusflight 6y agoThe proliferation of DRM technology may look like the result of bad consumer choices, but the reality is more nuanced. What percentage of consumers know that their content is DRM encumbered, or what DRM is even? This is a result of subtle consumer behaviour manipulation. Let's take the case of widevine itself. It wouldn't have proliferated if Encrypted Media Encryptions (EME) standard wasn't shoehorned into web standards by Google. EME allowed companies like Netlify and Spotify to demand proprietary plugins like Widevine in an otherwise completely open standard. Independent browser implementations became impossible at that point. EFF and Mozilla protested. EFF withdrew from W3C and Mozilla was arm twisted into agreeing. Now look at this from consumer perspective. Vast majority of users simply wouldn't have noticed these moves that would ruin the web in some way for them later. Most of them wouldn't have noticed DRM being rolled out. Everything seems to be normal - for a while. With this and a few other moves, it's clear that DRM based content will be unviable on independent browsers and open operating systems. At that point, most consumers will negligently decide that these browsers and OSs can't play DRM content because of software quality issues, and will switch over to locked down systems. That wouldn't have happened if DRM was presented as is to consumers from the beginning itself. A few people who hate DRM holding out is not a solution for this. At this point, consumers have funded DRM based streaming companies to grow into megacorps and they have killed their competition. For consumers, it will be a choice between freedom of platform choice and availability of media. This is why EME should never have been allowed in the first place. Another example of the futility of 'Don't use what you don't like' argument is Chrome. Chrome gained market share over Firefox using similar tactics. Now we don't have a viable alternative for blink web engine. This is an ambush on consumer rights - sneaking in silently and then killing it.
- exabrial 6y agoGithub is an abusive Lawyer's dream. One DMCA notice and they can DDOS thousands of volunteers work. While Git itself is fairly decentralized, we need a user-friendly GUI and project management system.
- grayhatter 6y agoIs that what happened here? I doubt thousands had worked on this repo. They exist, they're just not as popular as github.
- exabrial 6y agoI'm happy to see bi-partisan support for breaking the FAANG companies up. Enough is enough.
- hedora 6y agoGoogle says API’s can be copyrighted now. I thought the oracle case was ongoing: > Additionally, the Git repo contains several files that violate Google’s copyrights: Google license_protcol.proto (see Google copyright at the top of the file): /widevine-l3-
- devrand 6y agoThis doesn't claim that they're infringing on the copyright of their API, rather that they infringed on their copyrighted code (even if the code is just declaring the API). It's fairly unlikely that someone would reimplement the API and then add in a Google copyright header. It's pretty clear that it was directly copied.
- timdorr 6y agoLooks like someone missed the most recent forks. There are still a number of repos not listed in the DMCA complaint that have the extension content: https://github.com/tomer8007/widevine-l3-decryptor/network/members https://github.com/tomer8007/widevine-l3-decryptor/network/m...
- RachelF 6y agoIt's still available in other places: https://anonfiles.com/x7I0p8m5p4/widevine-l3-decryptor-main_zip https://anonfiles.com/x7I0p8m5p4/widevine-l3-decryptor-main_...
- tbirdz 6y agoSay what you want about fossil[0], but having the issues be part of the repo would come in real handy in times like this. 0: https://fossil-scm.org https://fossil-scm.org
- 2Gkashmiri 6y agoso......... can any one here in clear terms explain how to use this.... that chrome only extension thing is hot right now but i read somewhere its windows only..
- salawat 6y agoHaven't looked at the code, but the above is a private key that is likely embedded in a non-obvious way in the Widevine level 3 binary used to decrypt content. Users of Widevine industry wide would use the public key derived from this previously unknown private key generally to encrypt or derive a secondary symmetric encryption key that is then used to performantly decrypt the symmetrically encrypted stream. Asym crypto is slow. Symmetric is fast. The fact this key is leaked means it is quite likely a new version of the program will be pushed with a different key, but for any data still using this version of Widevine, this is the key piece of information to unraveling the entire cryptosystem by masquerading as an intended stream endpoint. You'd have to trawl the source for any other relevant goodies like parameters and algo names, but all of those tend to be unprotected in the clear, with only the key material being subject to overt secrecy. Again, haven't trawled the code myself, but that would be the gist of it if I have any intuition whatsoever on applied cryptosystems for media streaming.
- lootsauce 6y agojust gonna put this right here https://docs.ipfs.io/how-to/host-git-style-repo/ https://docs.ipfs.io/how-to/host-git-style-repo/
- 533474 6y agoRMS was right...youtube-dl, now this...and apple computer apps not working fiasco...etc...was the crazy communist guy not so crazy after all?
- dkdk8283 6y agoThe youtube-dl fiasco has given a bunch of lawyers the precedent (or perhaps idea) they needed to fight open source software. It’s a shame.
- TechBro8615 6y agoReally Google? Shame on you. We can't trust our industry peers anymore than the RIAA and MPAA? Seriously? Whatever happened to the Google that started "chilling effects" as an act of civil disobedience?