3 ms·
If DRM is inevitable, I'd take a properly implemented DRM that's been through community scrutiny than another Sony rootkit fiasco any time.
by edgesrazor 14y ago
If DRM is inevitable, I'd take a properly implemented DRM that's been through community scrutiny than another Sony rootkit fiasco any time.
- yarrel 14y agoHow would you like hooks in your web browser for the Sony root kit? That's what's being proposed at the W3C.
- recoiledsnake 14y agoPlease, that's hyperbole. Sony rootkit and the DRM present in Flash/Silverlight are worlds apart.
- ihsw 14y agoActually the description is apt -- the proposal is when a web page loads then a binary blob (that has OS-level hardware access) will be invoked. It would be as simple as including a highly-insecure JS file rather than installing a browser add-on/plug-in/extension/whatever. The security risks cause me imagine EME news that makes the recent Java 0-day news frighteningly tame.
- pyalot2 14y agoIt is not hyperbole. EME is a plugin API, and the plugin is not specified, and that is what the DRM is. It is inevitable this will result in another rootkit fiasco. But worse than that, the working of the DRM (called a CDM) will also sacrifice your privacy on the web, because it can inevitably act like a "supercookie" over which you will have no control.
- ncallaway 14y agoMy understanding of the proposed EME is that it does not implement any DRM, and DRM implemented for it would likely be opaque software implemented without community scrutiny. The EME (again, by my understanding, I could be wrong) only defines an API to communicate with DRM systems. I don't think this helps us gain any scrutiny over DRM.
- mseebach 14y agoThe reason DRM has to be obscure is to make it hard to extract the key. If the key can be safely store in a hardware component, the need for obscure software goes away, and there's no reason VLC could implement this.
- pyalot2 14y agoYou will get a Sony rootkit fiasco this time around as well. The HTML DRM (EME) is nothing but a plugin API. The plugin is something like Widevines DRM, called a CDM, (already in use on chromebooks) that browsers will no install on your machine without your consent. The working of the CDM/DRM itself is not specified in any way. Repeated request at specification have repeatedly been rebuffed and ridiculed by Google, Netflix and Microsoft.
- gerdusvz 14y agoI agree, there needs to be one open DRM specification that everybody can implement. There can then be discussion and debate about what level of DRM is reasonable; balancing rights of content holders and content consumers. Nobody is going to be perfectly happy but such is life. Every time the drm is broken there can be a new revision of the spec, so if you want to play netflix your browser has to be up to date. Ideally there would an open source reference implementation shared by the open source browsers (webkit,firefox) so the impact on development resources are minimized.