21 ms·
"Widevine Dump":Leaked Code Downloads HD Video from Disney+, Amazon, and Netflix
- bertman 5y agoThe repos: https://github.com/widevinedump?tab=repositories https://github.com/widevinedump?tab=repositories
- sovietmudkipz 5y agoI don’t know why but for some reason I was hopeful to see unit tests in any of the repos. Searching “test” for that user doesn’t reveal any tests. :( Even the digital property liberators/internet pirates don’t test their software. I feel like I’m on an island with a small population of test enthusiasts.
- charcircuit 5y ago>Even the digital property liberators/internet pirates don’t test their software. The lack of automated tests doesn't mean they don't test their software.
- sovietmudkipz 5y agoYou’re right I should be more clear. I was more interested in automated test rather than manual/exploratory testing. Thanks for the opportunity to clarify my comment.
- unbanned 5y ago>Even the digital property liberators/internet pirates don’t test their software. I feel like I’m on an island with a small population of test enthusiasts. Ultimately, what's the point. The tool either works, or it doesn't. Then you patch what doesn't work so it does work. Heck even the Linux kernel isn't tested. Unit tests are so management can have a good metric to sell code quality. I don't know any time unit testing has actually benefited shipping faster (which really is the only bottom line those above you care about)
- develop7 5y agobut linux kernel is covered by tests. Not 100%, not all the subsystems, but there are automated tests nevertheless (introduced by Greg K-H, AFAIR)
- gentleman11 5y agoWhy isn’t the kernel tested? Too close to the hardware to be practical?
- danuker 5y agoMy experience: running a unit test is much faster than a manual test. While developing a feature or fixing a bug, it speeds you up overall, in spite of the initial investment in writing the test. As a bonus, you can keep them running permanently, to prevent new bugs or regressions.
- horsawlarway 5y agoAnd the test covers much less surface area than most manual tests. For code that's expected to be stable for a LONG time - sure, write lots of good tests. For code that breaks at someone else's whim, which has a small shelf life, or which has a large surface area, think really, really hard about whether the test is actually going to be worth it.
- caillougris 5y ago> I don't know any time unit testing has actually benefited shipping faster It's of huge benefits to me when I have to make a small tweak (fix a bug, or add a new specific corner case) into an existing codebase that I didn't write and don't know very well. Being able to make a small change and being confident that it will not send everything burning in hell.
- datavirtue 5y agoThis, and any code base of significant size is unknowable and starts to produce bugs naturally. Requiring tests and verifying minimum coverage are a few things you can do to control the death spiral. I have worked on large systems devoid of tests. Not recommended. I literally witnessed multi-million dollar losses that would have been prevented by requiring tests.
- GekkePrutser 5y agoThere's no point I guess, this kind of thing does not work for very long anyway. Because it gets blocked server side once it's out. It's more like a proof of concept than production code.
- arsome 5y agoIn this case, not so much, they block individual CDMs as they get leaked, but if you dump your own or find/purchase a non-public one, you're off to the races. They don't change the basic software APIs or crypto occurring. However when it comes to something like this, it pretty much works or it doesn't and it'll be obvious one way or another when you run it. Writing unit tests for that is probably of limited value.
- boppo1 5y agoWhat's the best place to get started with testing? As a newbie brogrammer it's intimidating enough writing software that works, let alone suites to comprehensively test it. Is there a testing 'bible'?
- hatware 5y agoBuild systems that break, the tests come naturally after that.
- corndoge 5y agoYou'll fare much better in today's software industry climate if you don't use the word brogrammer
- Godel_unicode 5y agoThere are many deeply held beliefs that people have about testing, so I recommend reading many different takes on how to structure your testing approach. For the pragmatic python programmer, Brian's book is quite good as a starting place: https://pragprog.com/titles/bopytest/python-testing-with-pytest/ https://pragprog.com/titles/bopytest/python-testing-with-pyt...
- codedokode 5y agoI cannot recommend a book or an article, but just wanted to give an idea: automated testing is when you make a script do what a human tester would do. So maybe you should read about testing software in general. How test planning is done, how do you choose test cases. You start with listing requirements (what a program/a class/a function is expected to do or not to do) and then write tests that verify that it is indeed so. The easiest thing is writing unit tests. Pick a function, define requiremens and write a test for every requirement. If your code is not very modular and it is difficult to isolate a class or a function in order to test it, then maybe you should refactor the code first.
- sydthrowaway 5y agoI've often wondered how easy it would be for people in the scene to rip Netflix or others streaming content. Isn't it as simple as getting the URL of the video player element in the browser and using cURL or wget?
- alt227 5y agoIt is, but the resulting files are encrypted. Hence this post being about exposing CDMs (Content Decryption Modules). These use decryption keys obtained through hacking or paying internal staff. Once the decryption keys are exposed like this then the content providers 'burn'; them and generate new ones meaning the process has to start over again.
- ordx 5y agoI assume at some point Widevine plugin decrypts these files to display the actual video stream in the browser, correct? Why don't they capture already decrypted stream?
- e3bc54b2 5y agoThat's why they now embed displays with verification modules. Basically whole stack from server to your display is a giant chain verifying you are not doing what they don't want you to do.
- Scoundreller 5y agoThough often they get it wrong, like when I bought a movie off Apple and it errored when I screen mirrored to my dumb TV and it’s back to piracy first for me.
- ArchOversight 5y agoYour dumb TV doesn't have the appropriate HDCP chips, which is why it errored. Your computer didn't know whether it was a dumb TV or if it was an HDMI capture card ready to rip the movie... Not that I agree with the practice.
- 2Gkashmiri 5y agothe videos look interesting but i am on linux and this looks windows only. also, i need some background knowledge to get this working so i could not retry. a good attempt imo. if i had the time and the necessary technical competency, i would've loved to jump into it. for many years piratebay was my default homepage. now, lookmovie or vumoo gets my occasional streaming fix
- tyingq 5y agoI imagine it's windows only because widevine on Linux is crippled for many services, like HBO Max.
- 2Gkashmiri 5y agowell if the utility is merely breaking encryption on the url, it shouldn't matter what the host is? right?
- peanut_worm 5y agoCan’t you just record the screen or is there something preventing it?
- ocdtrekkie 5y agoThat's what Widevine prevents: It ensures the decrypted video is only available to proprietary devices and software which agree not to help you rip the video.
- lapinot 5y agoAt the end of the day you can always record the video buffer in some way or another (hdmi capture device, etc). The problem is that screen recording isn't what you want: it's lossy because you'll re-encode the output of a lossy encoding (at comparable level). You always want an ultra high quality source for encoding (in comparison with your target quality), else you'll amplify artifacts. To not deteriorate the perceptual quality you'll have to do little lossy compression (ie big file size, much bigger than the original encode).
- ocdtrekkie 5y ago> At the end of the day you can always record the video buffer in some way or another (hdmi capture device, etc). You actually cannot without an HDCP decryptor, which tends not to be sold in a lot of countries since it's primarily used illegally. The idea with encrypted video such as Widevine, is that any time it passes over an unapproved device (such as an HDMI cable), it is encrypted on it's way to a device authorized to decrypt the signal. Also, HDMI is a digital format, and you lose nothing in transfer over it.
- sdflhasjd 5y ago> You actually cannot without an HDCP decryptor, which tends not to be sold in a lot of countries since it's primarily used illegally. They are trivially easy to buy online though
- 5y ago
- vmception 5y agoThis is one of those github repositories that you just clone and move on. Don't fork, just clone to your local system. When it gets taken down the forks will disappear, whereas the clones will not. You can also just download a zip file. https://github.com/widevinedump?tab=repositories https://github.com/widevinedump?tab=repositories
- jrm4 5y ago"Making an imaginary-ish copy that stays on the big Microsoft-owned system is mostly unnecessary and probably not enough to keep it around, make sure you save a copy on your own computer that they can't get to." Don't want to be (too) condescending, but, as an old-timer it's kind of wild to me that people who work with tech a lot do actually sometimes need to be reminded of this.
- alias_neo 5y agoIt continues to amaze me that so many people in my profession (software) don't know that Git is "decentralized". GitHub et al have taken over so ubiquitously that many developers I know have no idea that a bunch of what they do isn't even Git, and a bunch of what they don't do, is.
- jrm4 5y agoWonder if they pay any attention to who wrote it as well. :)
- vmception 5y agoIts wild to me too, but I've seen people actually debate fork perseverance and I'm always confused what the issue is when you can just have a local copy but somehow that often never gets brought up in those conversations. Its not even about something used in a package manager, they just really had no backup when the default behavior of the git protocol is to have a backup. I'm like "wait did they actually lose something?" so since that seems to be the case, yeah, gotta remind people.
- jrm4 5y ago
- marcodiego 5y agoI don't care about downloading anything. Does it allow me to watch netflix without the need of proprietary software?
- charcircuit 5y agosource available software can still be proprietary
- marcodiego 5y agoCan't ffmpeg/gstreamer/whatever just use the keys?
- m3nu 5y agoIt seems to use ffmpeg and aria2. :-) So the repo is a bit like youtube-dl in that it puts the pieces together and finds the right links. https://github.com/widevinedump/WV-AMZN-4K-RIPPER/tree/main/helpers/Utils https://github.com/widevinedump/WV-AMZN-4K-RIPPER/tree/main/...
- thrwn_frthr_awy 5y agoI don't care about downloading anything either. Does it allow me to watch Netflix at the resolution I pay them for?
- garblegarble 5y agoThe repo readme is pretty telling - this is being leaked to force this particular key to be blacklisted, I guess one group annoyed with others and wanting to cut off their access (and presumably the leaking group already has other L1 keys so doesn't fear this key being burned...)
- charcircuit 5y agoor they had the skills to just dump it again Edit: nvm I understood which key you were talking about. I would have replied, but I'm rate limited.
- garblegarble 5y agoAh, I thought L1 keys were burned into hardware, so blacklisting this key was effectively blacklisting a bunch of Lenovo tablets from accessing 4K HDR streaming? Edit: looks like I'm wrong about this, and the Widevine L1 keys can be changed with a firmware update. There's an interesting breakdown of how it works on Qualcomm chips here: http://bits-please.blogspot.com/2016/04/exploring-qualcomms-secure-execution.html http://bits-please.blogspot.com/2016/04/exploring-qualcomms-...
- londons_explore 5y agoDoes this mean if I have a lenovo tablet that currently streams 4K, that it will lose 4K video support? Could I ask Lenovo for a refund?
- nikanj 5y agoYes and yes. Lenovo probably doesn’t give a shit, though. But you can ask!
- Scoundreller 5y agoDepends on the country. Some do have some liability on manufacturers and/or vendors for defects. Unsure if an asterisk in their click through contract about key revocation would even matter.
- unbanned 5y agoDunno who the person linked by that miimoji thing, but I hope they have a good lawyer
- deleted 5y ago[deleted]
- 0xdeadb00f 5y agoThe person who leaked either: used their repo as a basis for their readme, just found some random character and decided to use it, or it's one of the discord people they were talking about.
- deleted 5y ago[deleted]
- natdempk 5y agoDoes anyone know what CDM stands for or refers to? Saw the acronym mentioned in a lot of the repos.
- deleted 5y ago[deleted]
- Tobu 5y agoContent decryption module: https://en.wikipedia.org/wiki/Encrypted_Media_Extensions https://en.wikipedia.org/wiki/Encrypted_Media_Extensions A component that decrypts streams locally, which DRM makers intend will be restricted enough to not leak the keys it uses.
- natdempk 5y agoThanks for the explanation. So it seems like these repos are just scripts to download content and decode it once you have a CDM then? Seems like the actual CDMs here are ripped from devices and not actually included in this leak from a cursory glance. Edit: Yep this is what is happening, but there is an L1 CDM in the Lenovo repo. I should read the article before jumping in to the comments/code. :)
- deleted 5y ago[deleted]
- cute_boi 5y agoHaha, I chuckled when I saw that bandicam logo.
- specialist 5y agoI just want to control the viewing experience, not hoard warez. Effortless rewind, skip filler (car chases, sex), play at x1.25 speed, etc. aka the "Blu-Ray experience". If that means I gotta bypass the DRM and download, so be it. -- Some shows have my complete rapt attention. I'll keenly watch (and rewatch) every single frame. Like Netflix's Maniac. OMG. So frikkin good. (So many other examples.) Other shows, especially rewatching a series, I just want to focus on the character development, dialog, and plot points.
- searine 5y agoFYI There is a great chrome extension that allows you to control playback speed, and it works on just about every video site.
- mtsr 5y agoSimilar extensions exist for Firefox as well.
- specialist 5y agoI'm interested. Link? I'll mosdef try it. For whatever I reason, I have to use Firefox to watch Disney+. (Mac Safari will always eventually ABEND. Shouldn't Apple regression test Safari on the Top X most popular sites?!) As for spotty rewind, like with Netflix, another comment might have the explanation (root cause); streams are broken into individually encrypted chunks. So of course there's lag (latency) when jumping around the timeline.
- rishimaharaj 5y agoThis is the one that I use to control video speed pretty much anywhere (works on any Chromium based browsers): [Video Speed Controller](https://chrome.google.com/webstore/detail/video-speed-controller/nffaoalbilbmmfgbnbgppjihopabppdk https://chrome.google.com/webstore/detail/video-speed-contro...)
- JZL003 5y agoOn my phone so can't respond fully but if you select the <video> element in chrome and Firefox, you can control the .playbackRate attribute. Extensions can be useful but also abused, this is simple enough to do with a bookmarklet or manually
- londons_explore 5y agoSo this repo contains keys that are soon to be blacklisted, but for $150 you can subscribe to the leakers API which presumably has other keys and will decrypt one movie at a time for you.
- orliesaurus 5y agoSurely some people just use screen recording software for the "Download" illegally part?
- tomc1985 5y agoI don't think that works with HDCP, usually you get a big green box or something
- snailmailman 5y agoThe DRM technologies in place prevent screen recording from working, as far as I know. Or at least prevent it from working at high resolutions.
- agilob 5y agoI found this interesting, so I tried: I recorded a HD movie on Netflix in Firefox, recorded using simplescreenrecorder on KDE5 in Xorg. I remember it was impossible to record shared screen in old (Ebay owned Skype).
- nly 5y agoHD != 4K
- Mindwipe 5y agoThis is why Netflix only serves Firefox low resolution video.
- shbooms 5y agoIt's not just Firefox though, if you're running Chrome on Windows or Mac, you get the same 720p as Firefox. The only way to get Netflix in high def (1080p and 4k) from a web browser is to use a browser that is made by the same company as the OS it's running on. e.g.: - Microsoft Edge running on Windows 10 or 11 (if running Edge on some other OS, output will cap at 720p) - Chrome running on Chrome OS (if running Chrome on some other OS, output will cap at 720p) - Safari running on MacOS In any scenario not listed above, Netflix serves a max of 720p. https://help.netflix.com/en/node/23931 https://help.netflix.com/en/node/23931 https://help.netflix.com/en/node/55764 https://help.netflix.com/en/node/55764
- wcarss 5y agoA pile of .exes and compiled python code like this, especially with such a targeted audience, seems like a great vector to potentially own a lot of people's boxes.
- mehdix 5y agoThis was my first though as well, but not everything is in compiled form. For example see `bad34.py` in the Paramount-Plus-4k-Downloader repository.
- bogwog 5y ago> Hi! My name is WVDUMP. I am Leaking the CDM to burn it & punish few idiots that think themselves as dicord lords :smile: Why do so many people doing illegal/shady shit online use Discord? You might as well be using Facebook at the point.
- agilob 5y agoBefore Discord they were using IRC which was printing your IP address (or reverse DNS) when joining a channel.
- bogwog 5y agoAt least with IRC you can use a VPN and self host a server. Discord can, and is highly incentivized to, identify and track you across the internet. Idk if they do this, but it shouldn’t be that hard in this day and age to build a profile on users based on messages and activity. That can be cross referenced with other sources of data to identify you, especially if it’s done manually by like an FBI agent or whatever.
- kuroguro 5y agoIIRC quite a few botnets used to use public IRC channels as C2 servers (also a pretty bad idea).
- LinuxBender 5y agoThe IRC networks I used did not block VM's and rented servers from proxying my connection or using an IRC client from a tmux/screen session. Back then I could use visa gift cards to rent machines. That is harder to do now. Discord in most cases will prevent people from doing this. Most people should be ready to click all the crosswalks, buses, traffic lights forever in a loop.
- ronsor 5y agoThey use Discord for illegal stuff because they already use it for tons of other things. Sure it's a bad idea, but they don't care (and with all honesty, Discord support doesn't seem to either).
- alufers 5y agoCan we just stop the shitshow with DRM? I have NEVER encountered a TV show/movie that I could't rip using a torrent either on public p2p sites or a private tracker. But I have seen a lot of my non-technical friends and family having a degraded experience, who pay for their streaming services every month. It was either because they were using a browser or device which was deemed unworthy of full quality streaming by the mighty DRM authors. And now the poor users of the TB-X505X will also have a degraded experience.
- antihero 5y agoIt's such a chain - even if a distributer didn't want to use DRM, the buck will stop with a lawyer for the content owners who's job it is to do everything in their power to make sure their clients get paid for the content. Why would one of those make it easier to pirate? Corporate drone logic man.
- tgsovlerkhgsel 5y agoBecause they can sell more views if paying customers are happy. I refuse to pay for Netflix because even if paid I wouldn't be able to watch the content (including Netflix originals where the "rightsholders don't allow it" argument doesn't make much sense) in reasonable quality. Meanwhile, people can watch it from an unlicensed source without paying (legality varies by country but generally low risk for users), and as long as adblock works, the experience really isn't much worse than with Netflix.
- darkwater 5y agoI'm all against DRMs but the friction nowadays is, if you stick to one platform, almost zero, way less than your average pirated experience. Now, if we talk about platforms balkanization and how you have to shell out 50€-$/month if you want to enjoy just the best content from major platforms, that's another topic.
- midasuni 5y ago
- widevinedump 5y agoAn IPFS Mirror of all the repos of the GitHub account. https://cloudflare-ipfs.com/ipfs/QmWPo4VqWwrdU3A7fm9Ze3Qm31DHBz4bZPNeFPojS8huSg/widevinedump https://cloudflare-ipfs.com/ipfs/QmWPo4VqWwrdU3A7fm9Ze3Qm31D... For example: ``` git clone http://cloudflare-ipfs.com/ipfs/QmWPo4VqWwrdU3A7fm9Ze3Qm31DHBz4bZPNeFPojS8huSg/widevinedump/Paramount-Plus-4k-Downloader.git http://cloudflare-ipfs.com/ipfs/QmWPo4VqWwrdU3A7fm9Ze3Qm31DH... ``` To pin and help seed on your local IPFS node ``` ipfs pin add /ipfs/QmWPo4VqWwrdU3A7fm9Ze3Qm31DHBz4bZPNeFPojS8huSg ``` Cloudflare IPFS can be replaced with other ipfs nodes like dweb.link or your local one.
- 323 5y agoAm I correct that homomorphic encryption will solve the DRM problem, in the sense that it will be mathematically proven (in the cryptographic sense) to be impossible to bypass? Of course, you'll still be able to cam-record the actual output, or steal the image from the TFT/OLED electronics, but no easy bypass.
- unnouinceput 5y agoYou are wrong. An encryption, any encryption, needs a key for decryption process. If the client is given that key then it can decrypt and rip the content. If the client is not given the key then how will they legally watch it since they paid for the content anyway? As a rule of thumb, anything that was made by humans can be unmade by humans. All you can do is make the pirate life harder, but never impossible.
- deleted 5y ago[deleted]
- smoldesu 5y agoThe issue is that the image will always exist in a decrypted state if you're presenting it to the user. You can push that decoder further and further down the pipeline, but there's always a clean framebuffer to rip, no matter how you frame it. Yes, they could make it harder, but I could also design an Arduino that dumps the serial output of your decoder before it reaches the display controller. It would take some borderline space-age technology to design an IC resistant to that sort of vuln.
- Unklejoe 5y agoFor a while, there were HDMI splitters for sale on Amazon that would effectively strip out HDCP 2.2. I haven't checked in a while, but I bet that's still the case. It seems like these DRM efforts are futile, but then I remember that it's really just about keeping piracy outside of the grasp of "common folks". They will never be able to stop piracy if someone is determined enough.
- cheeze 5y agoReally? HDCP 2.2? I'm not aware of any of those except for the HDFury products with a custom firmware. Any links to examples? Are you sure you're thinking 2.2 and not 1.4?
- Unklejoe 5y agoYep, I'm positive that it's HDCP 2.2, but I don't think I should post a link here for obvious reasons. I also don't remember which one it was, but it was a switch capable of 4k60 (HDMI 2.0). There was a forum where a guy had some sort HDMI analyzer on both ends and confirmed it.
- BTCOG 5y agoWe really need real, ownable media. While I understand that even "owning" a disc 20 years ago was considered a license and not ownership, let's call it what it is for these intents and purposes here. I want to own my music, I want to own my movies and I do NOT want to essentially rent them and have them revokable. Same goes with games. I'll continue to pirate the videos and music as I see fit and continue to play emulated N64, PSX, etc games that are full copies of unchanging code. I don't want my collections to need an internet connection. The cloud is a fad that needs to die. I know many here like cloud, but it's a trap. Anyway, just my thoughts. I'll check out these tools if they're still up on the 'hub.
- solidr53 5y agoSounds like an NFT project
- _fn2y 5y agoI did one of these for Hulu (https://github.com/chris124567/hulu https://github.com/chris124567/hulu) a while back. It didn't take very long to write. Most of these programs are just using the pywidevine library along with some key that's been leaked (if you know how to navigate Github search you can find one in a couple of minutes) and then integrating the streaming site's API. I wrote mine in Go because I got sick of the pywidevine hegemony and I felt it was unnecessarily complicated. The annoying thing is that key revocations are happening pretty frequently now. It's another one of those pointless cat and mouse games.
- dontreact 5y ago
- acomjean 5y agoI'm not exactly sure how this works, it seems you need to have to have a hulu subscriptions, which means you are paying for the content. From the instructions "Note: Ensure you are signed in before following these steps." You are just able to download the video/ You'll at that point likely watch it once and then not watch it again. But sometimes when your traveling and you don't have internet and you want to watch something, this is useful. I mean if you got the video files through someother DRM free site, you wouldn't have these restrictions at all and you wouldn't be paying at all. Then you could argue you are consuming without compensating the creators, which I think wouldn't be right.
- extra88 5y ago> when your traveling and you don't have internet and you want to watch something Hulu and a number of other streaming services have a download feature for exactly this situation.
- arsome 5y agoIn my experience the download services have weird time limits and are pretty crappy, I'd rather just have the content on my Plex server.
- brutal_chaos_ 5y agohttps://github.com/widevinedump/NETFLIX-DL-6.0 https://github.com/widevinedump/NETFLIX-DL-6.0 seems to have just been replaced with https://github.com/widevinedump/NETFLIX-DL-6.1.0 https://github.com/widevinedump/NETFLIX-DL-6.1.0 Due to a bad connection the 6.0 clone didn't finish. So, naturally, I tried again and was receiving a login prompt....so I go to the URI in a browser and ... 404. But the 6.1 repo was available...
- swills 5y agoIs it possible to use widevine if you don't run binaries from others and build everything from source yourself yet? This doesn't look to be that as far as I can tell.
- proctoration 5y ago
- proctoration 5y ago