4 ms·
I don't have expertise in video codecs or file formats, but couldn't you hash the first N bytes of a stream? Stream those N bytes to the client and if it matche
by skipants 5y ago
I don't have expertise in video codecs or file formats, but couldn't you hash the first N bytes of a stream? Stream those N bytes to the client and if it matches start the video, else stop the download and not start the video.
- jodrellblank 5y agoPresumably for SHA256 you only need to hash ~256 bits; what's anyone gonna do, try all possible combinations to find a collision?
- mkl 5y ago256 bits is only 32 bytes, and most file formats have standard stuff right at the start. Collisions would be very common.
- tomjakubowski 5y agoIf you only hash/check the first N bytes of the video stream, the remainder of the video could be anything.
- kazinator 5y agoThey will keep the first few seconds or minutes of the original video, bit-exact, and then switch to porn. The player needs to validate every section.
- giantrobot 5y agoThis has a number of problems. The most egregious is if I'm an attacker and I have the file you request I can hash the appropriate portion you'd use to verify it but fill the rest with junk or exploits. You'd receive the file, it would emit the correct hash, yet be not what you were expecting. For video especially what you receive isn't necessarily predictable by the client. With HLS or MPEG DASH streaming the video you receive could be one of a number of different encoding e.g. lower or higher bitrates to deal with changing network conditions. The actual m3u8/mpd file you might receive could change arbitrarily as the video provider adds or drops different encodings. The hash of such a file today isn't guaranteed to match the hash tomorrow for entirely banal non-malicious reasons. Fun fact: the UUHash algorithm used by the FastTrack network (Kazaa, Morpheus, etc) only hashed the first bit of a file. Hashing a large file took forever on hardware of the day. Even hashing small files was non-trivial. The RIAA through various fronts would insert spoofed files where the first portion of the file was legitimate but the content of the file would be junk or annoying sounds. The files would be named like any other MP3 someone was searching for and even have seemingly good IDv3 tags.
- dragonwriter 5y ago> Fun fact: the UUHash algorithm used by the FastTrack network (Kazaa, Morpheus, etc) only hashed the first bit of a file. The first 300KiB plus a series of 300KiB chunks at exponentially-increasing offsets, per Wikipedia. But still a small fraction of thw file.
- skipants 5y agoWell explained. Thank you!
- AgentME 5y agoMerkle trees basically accomplish this with separate hashes over every N bytes, so that the content can be verified continuously as it's downloaded.