23 ms·
The Quest for Netflix on Asahi Linux
- shaunsingh0207 4y agoI was looking into this very problem yesterday! Terribly scared by widewine, I ended up building webkit with eme support enabled, then enabled the relevent setting in the nyxt browser. Seems to be working fine so far.
- Retr0id 4y agoSo are you using Widevine?
- deleted 4y ago[deleted]
- shaunsingh0207 4y agoIn the end yes, although it was much easier to get working than the authors adventures with firefox
- trollied 4y agoJust goes to show that the DRM is just security through obscurity.
- klodolph 4y agoTrue for Widevine L3, which is what the article is talking about. Not true in general, and not true for L2 or L1.
- babypuncher 4y agoAt the end of the day, the user's hardware/software has to be given a decryption key for the content, and the DRM scheme is all about obfuscating that encryption key so that users can't find it.
- klodolph 4y agoI’d say that a key stored on hardware is not merely obfuscated, when that hardware is designed to prevent you from recovering the key.
- Nextgrid 4y agoThe hardware ultimately has to decrypt and play the content, so you can use it as a decryption oracle even if you can't extract the key itself.
- klodolph 4y agoSort of, within constraints. L1 both decrypts and decodes, so you can’t really use it as a pure decryption oracle, but it doesn’t matter if you’re going to re-encode it anyway. Not that it really matters, since HDCP has been cracked. There are a lot of holes here and a lot of problems with DRM.
- mardifoufs 4y agoEehhh at the end of the day, L1 is still almost impossible to bypass and hasn't been broken in years. So it still works, meaning it doesn't really matter even if it's security by obscurity (I dont think it qualifies for the term but anyways).
- grishka 4y agoIf it hasn't been broken, then where do all those 4K HDR torrents come from?
- judge2020 4y agoNvidia Shield[0] 0: https://forum.xda-developers.com/t/nvidia-shield-pro-widevine-keys-extraction-and-re-flashing.4203089/ https://forum.xda-developers.com/t/nvidia-shield-pro-widevin...
- DeathArrow 4y ago
- no_time 4y agoI'd argue the same goes for L1 and L2. But the obscurity is provided by the silicon packaging process. Would be nice to crowdfund a lab to break these hardware backed treachery schemes.
- klodolph 4y agoWhen you say “security through obscurity” there’s a certain understanding that we’re drawing a line between implementation secrecy (obscurity / obfuscation) and key secrecy. If we extend the word “obscurity” to include the notion of physical security, I think we’ve gone too far—even if physical security is just the physical security of a secret embedded in silicon that you have physical access to (because it is super difficult to recover secrets from silicon).
- the8472 4y agoWith DRM the user who owns the machine is the "attacker". The keys have already been handed to the user, he only needs to get them out. This is like hiding an API key in a public website's javascript with rot13. Very much security by obscurity. Proper security means that the attacker should never be in possession of the key.
- klodolph 4y agoYou’re saying that a hardware security module is like rot13? When you say the attacker “only” needs to get them out, the “only” is doing a lot of work, there.
- yipbub 4y agoYes, but it only has to be done once.
- the8472 4y agoThe standard for cryptographic security is that the attacker can do no better than brute force. And the complexity for that is usually set high enough that it is out of range for the entire computational capacity of our civilization for years to come. I'd say handing the key to the attacker in a package that requires somewhere between a skilled reverse-engineer and a semiconductor lab to untangle falls far short of that standard.
- Retr0id 4y agoI believe that L2 would be weaker than L3 in practice, which likely explains why I've also never seen it implemented (If you know about an L2 instance I would be genuinely interested in taking a look)
- calgarymicro 4y ago> I believe that L2 would be weaker than L3 in practice How come?
- Retr0id 4y agoAccording to the descriptions I can find, L2 does cryptography in secure hardware, but video decoding in software. (as opposed to L3 that does both in software, and L1 that does both in hardware). In L3, you can obfuscate the cryptography and the video codecs together as a unit, blurring any defined border between them. A determined reverse-engineer can inevitably unravel that obfuscation, but it's non-trivial. In L2, there must be some interface between the hardware and software components. That interface presents itself as a very obvious weak point. As an attacker, all you'd have to do is watch the data flowing out of the cryptography hardware, and into the video decoder software, and you'd be able to siphon out the plaintext video data. (To be clear, this is entirely "in theory" because I've never seen an L2 implementation)
- socRate35 4y agoThe “security through obscurity” chant needs to die. It’s such a generalized concept it applies too broadly. Encryption is “security through obscurity”. Having few admins is security through obscurity; a guessing game of who is the admin?
- deleted 4y ago[deleted]
- compsciphd 4y agosecurity through obscurity is generally not about keeping a well known encryption scheme's keys "private". It's generally about not knowing how a system works at all. In this case (and the same for blurays actually), we know exactly how the system works, given the keys we could decrypt the content, but the keys are kept "well" protected (depending on widevine level, different levels of protection). In BluRay land enough player keys have leaked to make it basically irrelevant. It's also harder to determine whose keys are being used to decrypt, making it harder to revoke. In an online widevine world where one has to use one's baked in device keys to get the content key, its much easier to determine if a single device's key is being used an abnormal amount of time and then revoke it. while one can view the efforts to protect a widevine l3 key as security through obscurity, its mostly there to make the effort hard enough that most people are interested in doing it, than to keep it perfectly secure.
- rvz 4y ago> This should be alarming to anyone with a stake in content "protection". Look how many hoops I had to jump through just to legally watch Netflix as a paying customer! This tells me I should just stay on macOS or Windows rather than go on a Safari hunt for getting Netflix working on a ARM Linux machine.
- jraph 4y agoYou wouldn't have to anymore thanks to this work. You can just install the necessary package now.
- krono 4y ago”Hacker”news in 2023 ;-)
- Rebelgecko 4y agoThe browser compatability is still a bit of a mess on those OSes. The only way to get the full resolution on MacOS is to use some specific combinations of Safari and MacOS versions. If youre using OSX or using Chrome/FF you're limited to 720p https://help.netflix.com/en/node/23742 https://help.netflix.com/en/node/23742
- Retr0id 4y agoYou can get 1080p with a browser extension that forces it.
- chpatrick 4y agoPirates meanwhile have no issues...
- monetus 4y agoResolution: Google Chrome Up to 720p on Windows, Mac, and Linux Up to 1080p on Chrome OS Microsoft Edge up to 4K* Mozilla Firefox up to 720p Opera up to 720p Safari Up to 4K on macOS 11.0 or later Up to 1080p on macOS 10.11 through 10.15 *Streaming in 4K requires an HDCP 2.2 compliant connection to a 4K capable display, Intel's 7th generation Core CPU, and the latest Windows updates. Check with the manufacturer of your system to verify specifications. ^ is this the lawyers or the programmers' doing?
- samstave 4y agoCan one use "Kigo Netflix Downloader" in a WINE or native install for linux if they have one - and then play with VLC? https://kigo-video-converter.com/netflix-tips/play-netflix-on-vlc-media-player.html https://kigo-video-converter.com/netflix-tips/play-netflix-o... (not associated with them)
- musicale 4y agoThat company doesn't look dodgy at all.
- jasoneckert 4y agoExcellent writeup. Asahi is my daily driver, but I've never had the need for either Spotify or Netflix. I guess the gospel of RMS and the FSF over the past few decades has steered me away from anything DRM-related.
- aidenn0 4y agoIn terms of freedom of using compute devices, RMS has a point. In terms of freedom of using media, I'm less annoyed by Spotify or Netflix than I am by "purchases" of media that have DRM. It's clear that one is renting with the streaming services, but Amazon can revoke permission for me to read books I have purchased or Valve can revoke permission for me to play games I have purchased, we are truly living in a dystopia.
- lotsofpulp 4y agoInstead of “buy”, they should be labeled “rentals - as long as provider exists or chooses to give you access”.
- judge2020 4y agoThe terminology should be either "License", "Buy a License", or "Purchase<br><small>Indefinite License</small>", but it's distinctively "not renting" since it's a one-time cost to obtain that indefinite license. Renting anything implies and requires some form of ongoing cost.
- arsome 4y agoDoes this actually get 1080p? I thought L3 was limited to 720? L3 is weak enough that you can dump it by just hooking the decoders.
- winterqt 4y ago> Most streaming platforms will limit you to only "HD" content on L3 (as opposed to 4K on L1). On Netflix, this upper limit is 1080p (although it might depend on the specific content you're trying to watch?), but you are further limited to a mere 720p by default. For some reason, you can only get 1080p if your client asks nicely for it (at the protocol level), and there are browser extensions that do this for you automatically.
- judge2020 4y agoEntirely depends on what the streaming service feeds you. IIRC Disney+ drops you to 480p.
- tarotuser 4y agoFor some reason, my Jellyfin and Navidrome instances doesn't use Widevine (garbageware) in any way. Radarr, Lidarr, Sonarr, and the other Arrs work beautifully to control what media I want, get it, and store it appropriately. And the files I download from Usenet and Torrents work on any platform powerful enough to play them. I was treated like a criminal when legitimately buying media years ago. Already learned https://xkcd.com/488/ https://xkcd.com/488/ this lesson.
- mattl 4y ago> I was treated like a criminal when legitimately buying media years ago. What happened?
- bionade24 4y ago> What happened? Isn't that obvious? Circumventing the copy protection of your own property is a crime.
- mattl 4y agoNot obvious, sorry.
- zamnos 4y agoYeah but so is speeding on the freeway. People do that all day long and never gets ticket. Other times, people actually get arrested they were speeding so fast. So I ask again, did something actually happen? Did the FBI/whomever show up at your door and someone went to prison? Or is it just that format shifting got deemed illegal and now we're all running around scared?
- bionade24 4y agoThis is different, because we don't have lasting evidence (yet). If circumvent a B-Ray's copy protection some person knowing I ripped them could still report me years after.
- 4y ago
- zenexer 4y agoThe target site is intermittently experiencing the HN Hug of Death, so if you have trouble accessing it, here's an archive link: https://web.archive.org/web/20230309144317/https://www.da.vidbuchanan.co.uk/blog/netflix-on-asahi.html https://web.archive.org/web/20230309144317/https://www.da.vi...
- paines 4y agoThe link in the webarchive pointing to the gist of the script is wrong, for what ever reason (at least the name of the script is completly different). This is the correct gist: https://gist.github.com/DavidBuchanan314/c6b97add51b97e4c3ee95dc890f9e3c8 https://gist.github.com/DavidBuchanan314/c6b97add51b97e4c3ee...
- Retr0id 4y agoIt's the same script, just an earlier revision.
- iLoveOncall 4y ago> I don't care very much about Netflix - the UX offered by BitTorrent is superior What a laughable statement. I'll copy paste all of his blogspots on my blog and say I prefer the UX of my blog.
- kzrdude 4y agoWell, searching for a movie you want to watch often comes up empty on netflix unfortunately. For those use cases, there's a big difference. For just watching what's provided, netflix has a better experience.
- 627467 4y agoI don't get that either. I would love a detailed description of the process to get BitTorrent to fully replace Netflix - though I suppose this description wont be public for legal reasons
- erksa 4y agoAnyone know if Asahi Linux work on the MBAir M2 as a casual driver on the go?
- wetpaws 4y agoWork: yes. Casual driver: no.
- erksa 4y agoI am patiently waiting, the M2 Air is really everything physical I want in a laptop. MacOS is fine, but one can dream right?! :D
- gorbypark 4y agoIt does indeed! Even the alpha GPU drivers work. Not working: speakers, power management isn't ideal and I don't believe Thunderbolt works, although I haven't tried. I'm not sure what a casual driver on the go is..
- erksa 4y agoThanks! I wasn't sure if was even going to bother qualify the statement further. Mostly use it for light browsing or just light coding, nothing substantial. Reading the docs of a newly released framework etc. Some video-calls here and there, but I have other devices if I can use this purpose.
- gorbypark 4y agoYou can see support is coming along nicely, with many things supported in the kernel directly or in one of the two yet-to-be-upstreamed packages. There's no hardware video encoding/decoding and no webcam support yet, so I don't think doing video-calls would be very good at this point. https://github.com/AsahiLinux/docs/wiki/Feature-Support#m2-series-device-specific-support https://github.com/AsahiLinux/docs/wiki/Feature-Support#m2-s...
- Gigachad 4y ago
- PointyFluff 4y ago[dead]
- gray_-_wolf 4y ago> The only officially supported way to use Widevine on Linux is using Chrome on an x86_64 CPU. To be precise it is "The only officially supported way to use Widevine on Linux is using Chrome on an x86_64 CPU using glibc." In other words, even though I have x86_64 cpu, since I'm on alpine, I'm fucked anyway.
- bqmjjx0kac 4y agoI see Alpine Linux uses musl instead of glibc. Theoretically, couldn't you install or build glibc anyway and launch Chrome with LD_LIBRARY_PATH=/path/to/glibc?
- jvanderbot 4y agoYou should see all the "system" libraries I have sitting in /opt/<app>/lib for each <app>
- coldtea 4y agoWhat prevents you from ALSO having glibc?
- rfoo 4y agoWhen people say glibc, they really mean ld.so + libc.so + libm.so + nss + ... And no, glibc really only work with its own dynamic loader (ld.so), and it has to be with same version.
- coldtea 4y agoAgain, what prevents you from ALSO having all those? You just need to point to them and run some programs that require them with those...
- rfoo 4y agoThere can be only one ld.so in each process. Widevine is a plugin-like .so meant to be loaded into Chrome/Chromium. Because it uses glibc, the entire process hosting it must use glibc. So, what prevents me from ALSO HAVING GLIBC CHROMIUM instead of musl Chromium? Nothing, but I hope you get that it propagates further and it's a horrible idea to just glibc everything on Alpine.
- jacobmartin 4y ago> Or rather, that was all true at the time when I first investigated Widevine-on-Asahi, several months ago. A few weeks ago, Google decided to enter the 21st century and started shipping aarch64 userspaces on certain Chromebook models. This means that "Widevine-in-Chrome-on-Linux-on-aarch64" does exist. The ChromeOS blob extraction process works as before, and the Pi Foundation conveniently packages it as a .deb for Pi users. Not the point of the article but this is great news that I learned just now. I can finally upgrade to aarch64 chrome on my Raspberry Pis.
- reisse 4y agoThe mere existence of Widevine is a mystery for me. How sensible for Netflix is to invest into DRM at all? It's not a gamedev situation, where DRM lasts long enough to make impact on initial sales. Pirated Netflix shows appear on the torrents same day, and unless they have full-stack protection from the decoder to the screen, not much can be done. They seem to make user experience worse for nothing.
- goosedragons 4y agoI'm sure it's probably a requirement from all the 3rd party media companies. They didn't seem to like VPNs either. But I also wouldn't be surprised if Netflix wants it to keep high quality versions at least off pirate sites.
- alfalfasprout 4y ago4k rips land on usenet super quickly though and they're excellent quality. HDCP is already easily bypassed at this point.
- Scoundreller 4y agoBut probably re-encodes, so filesizes are bigger for close enough quality. A direct crack of the encryption would be best from a space-quality perspective. Doesn’t really matter much though in most of the world as it used to though.
- echelon_musk 4y agoThis is incorrect. See the difference between a scene WEB release and a P2P WEB-Rip. > The landscape of the WEB scene has changed in the last four years. > Subsequently, the ability to defeat DRM has become ubiquitous. https://scenerules.org/n.html?id=2020_WDX.nfo https://scenerules.org/n.html?id=2020_WDX.nfo
- admax88qqq 4y agoFull stack protection from decoder the screen is coming. IIRC you can only play 4k Netflix on a smart TV which controls the entire stack from network to pixels
- catchnear4321 4y ago> Truth be told, I don't care very much about Netflix - the UX offered by BitTorrent is superior.
- go_elmo 4y agogetting what you want fast. It is literally that easy & netflix messes it up with being nondeterministic and screaming at me trailers I've never asked for. My autistic self is o.u.t.
- wilg 4y agoNetflix is designed this way because most of the time people don’t know what they want. So it’s a browse, not a search, interface. But it has search so I don’t really understand why it’s a problem to see things you don’t care about for a second before searching.
- toyg 4y agoBecause the search is pretty bad too, even when you know what you want and you're sure it's there.
- andsoitis 4y agoHow would you improve the search?
- pbmonster 4y agoBetter filters instead of permanently inventing new "categories". Allow me to filter (and sort results) by playtime, IMDB/Letterboxd score, original language, whether I have watched it before, ect. If I don't already know the name of a movie, I just need Netflix to show queries like "a French movie shorter than 2:20h with at least 3.5 stars on Letterboxd".
- yamtaddle 4y agoOther services are browse-mainly, too, but are far less annoying than Netflix. Their UI being so goddamn obnoxious for so long, with apparently no intent to ever change that back to something sane, was part of why I cancelled recently after being a subscriber since the DVD days. (Yes, I used the "stop autoplaying, jesus god who could possibly want that" option they finally added, but it didn't seem to affect all platforms, or else they reset it at some point, I dunno and I wasn't paying Netflix so I could go find out how they screwed it up) Like, it's terrible specifically for browsing, so its being oriented around browsing isn't really a defense of how shit it is. Sitting there chatting with someone about what to watch and you have to keep moving from thing to thing constantly or it screams over your conversation and/or shows you spoilery, distracting shit. WTF. A few others autoplay or play clips/trailers but without sound, which still sucks but is at least better. I shouldn't have to slam the mute button every time I return to the menu just to keep Netflix from doing stupid crap it shouldn't do in the first place.
- bumhole 4y agoAnyone who knows some technical detail about Widevine, please could you explain what is the difference between L1 and L3 (other than resolution/quality)? How does each interoperate with EME? And what sort of process would one need to do, to be able to view an L1 stream on a bespoke Linux distribution, rather than the L3 stream that this person received? How difficult is it to do, and what are the specific challenges?
- mike_hearn 4y agoEME is just an API to access the native code. Levels are primarily about various kinds of hardware protection, I think. The lowest level just uses ordinary software obfuscation in the widevine library that this article is about, and regular updates to change the media keys. Higher levels integrate more with special hardware "APIs" of various kinds. I think you generally cannot play the highest levels on PC hardware at all, it's more meant for Apple TVs and other such devices. Other levels may require things like the Windows protected media path, which lets you upload encrypted video data to the GPU and then it's up to the GPU firmware to decrypt it. So then it becomes a question of understanding how the GPU is decrypting the data and defeating that.
- freeplay 4y agoWidevine has been privately cracked/bypassed. The method hasn't been made public as it would obviously get patched rather quickly (if it even can be patched). That's why Netflix content is available almost immediately on any decent tracker. The quality would not look nearly as good if it was grabbed using a capture card. Like others have mentioned, it's security theater for the content owners who most likely require Netflix to have DRM in place in their contracts.
- Gigachad 4y agoThis is why audio and video drm is so useless. All the cracking teams have their own methods which they don’t need to publish. Unlike video game drm where the cracks have to be published with the game.
- mike_hearn 4y agoIt's actually a bit dangerous for ripping groups to do that if they're in countries friendly to western interests, because the media companies can initiate a traitor tracing protocol to figure out where the leaks are coming from and then initiate prosecutions. Traitor tracing algorithms are well known in the literature and some are undetectable. When this game was playing out with BluRay, it wasn't possible for the media groups to directly attack the ripper makers because the primary developers were in Antigua which had a WTO ruling against the USA allowing Antiguans to ignore US intellectual property rights. I forget the political background. Later I think someone in China started doing it too. The point is though, that the tech converted (for a time) the problem from one of intractable scale to one of "if we get these two companies then the issue disappears because they're the only ones who have the knowledge". That opens up all sorts of new strategies for the media companies to pursue. They may not work, but, the situation is definitely not the same as before. BTW video game cracks don't have to be published with the game. They can just publish the patches to the game files without releasing any tools they created to make those patches.
- rowanG077 4y agoWhy would a capture card look any worse? Isn't it capturing lossless video output? Just because of the re-encode?
- Havoc 4y agoMany judge success on this by "do i get 1080". I've found this to be incredibly deceptive for nix and DRM on netflix. My experience has been that even managing 1080 on a nix platform the experienced quality is substantially worse. Thoughout I was going insane, but checked bitrate and sure enough netflix at 1080 was streaming at much lower rate than on windows 1080.
- seizethegdgap 4y agoWould changing the user agent to a Windows release of Chrome make any difference?
- Havoc 4y agoI do not know. I jumped through all the hoops suggested at the time by the various get netflix to work on linux guides. Extensions and right browser and DRM enabled and whatever other stuff they recommended. No dice on comparable quality. I should add that there is always the possibility that there was some gfx driver or codec dynamic at play that I don't understand...but ultimately if it's visually noticably worse that's a fatal flaw regardless of reason.
- MBCook 4y agoThe article mentions there are three levels of Widevine DRM. I wonder if the level available to Linux (three) not only limits resolution but bitrate, at least as far as what Netflix is willing to serve.
- favorited 4y ago> Addendum: The EME API is a good thing! (kinda) Hard agree. There was so much nerdrage when the EME was being considered for standardization, as if by not standardizing an API we'd be preventing DRM from existing. People acted like Tim Berners-Lee was stabbing the collective internet in the back when he endorsed it. The choice was between a standardized web-based DRM, or a wild west of incompatible proprietary DRM. Personally, I'm glad I don't need Silverlight to watch Netflix anymore.
- Gigachad 4y agoThere is also the opinion that having a Wild West of incompatible proprietary garbage would result in DRM being less popular because it caused too much friction for users. Of course some stuff would still have it, but less would than the current state where it’s easy and invisible to users until you hit an unsupported system.
- MBCook 4y ago> …would result in DRM being less popular because it caused too much friction for users. I agree. But that wouldn’t lead to more content freely available. It would lead to more content being locked in apps and unavailable in the browser. Do you think they would’ve made an app for Linux? I don’t. The dream that all content be available DRM free isn’t happening any time soon. Rights holders clearly don’t want it and I don’t think anyone could marshal a big enough boycott to change that. So the choice is DRM or no content at all. Given that EME is a good outcome.
- shrimp_emoji 4y agoIt happened for music! I wonder why. But it makes music the one digital good I don't torrent on the reg cuz it's easier to just search it up on Amazon than on some torrent site. (The one weird exception is discographies, since they don't sell those for some reason. For them, archivists' torrents got you covered.)
- 4y ago
- dtx1 4y agoAs a linux user i skimmed the page and realized about half way through that i'll just pirate stuff anyway and never deal with that kind of bs.
- Zuiii 4y agoPiracy is increasingly becoming the ONLY option for many people. It's fascinating how this industry became it's own worst enemy.
- sammy2255 4y agoWhat’s Widevine? Also it sounds like linux complexities made this unnecessarily difficult
- MrOwnPut 4y agoWidevine is Google's DRM. Their lack of linux support makes it difficult. The point of the article is to support it instead of bypassing it, thus not violating DMCA.
- kuon 4y agoNetflix quality is crap on Linux, I just torrent everything as it is simpler and I can use a player that allow me to put the subtitles where I want. I know I say this bluntly but I came to a point where I cannot get all this nonsense about not trusting the user. I buy music on band camp that I do not "distribute". I do not believe removing DRM would yield to higher unauthorized distribution. Also do not be fooled by resolution, low bitrate 1080p can look worse than 480p, and many services are quietly throttling bandwidth. High quality 1080p should be 8-10mb/s.
- lobocinza 4y agoI don't remember about Netflix but Prime Video on Linux was capped to HD resolution (at least one year ago) so I went back to that thing that is more convenient and free.