# Myths
1. that DRM doesn’t work; that it exists to protect creators, but since it is easily cracked and can be worked around, it is largely ineffective and irrelevant
2. that DRM in HTML5 is a necessary compromise to finally bring an end to the proliferation of proprietary browser plugins such as Adobe Flash Player and Micrisoft Silverlight
3. that the web needs DRM in HTML5 in order for Hollywood and other media giants to finally start giving the Web priority over delivering media over traditional means
# Reality
1. DRM is not about protecting copyright. That is a straw man. DRM is about limiting the functionality of devices and selling features back in the form of services. (https://plus.google.com/107429617152575897589/posts/iPmatxBY...)
2. DRM in HTML5 doesn’t obviate proprietary browser plug-ins, it encourages them. (https://www.eff.org/deeplinks/2013/03/defend-open-web-keep-d...)
3. The Web doesn’t need big media; big media needs the Web. (http://blogs.computerworlduk.com/open-enterprise/2013/02/bbc...)
# So sign the petition
Although, I do see the point that some parties could hide behind the "We need DRM to protect our copyright\prevent piracy" flag and instead use it to lock-in consumers and build a walled-garden.
There is nothing to be won by resisting hooks for DRM in the browser however appealing it seems to take a principled stand. The content suppliers will gleefully go with native apps, flash, silverlight, even Emscripten-cross-compiled codecs. With content consumption going mobile, the push for native apps is even stronger.
Really, all you'll do by resisting this, is teach the majority of consumers who don't know any better that the Web sucks, and all of the enjoyable things they want are to be found on iOS or other proprietary locked down distribution platforms. That if you want apps that deliver the stuff you are interested in, you have to look outside the web.
Back when Chrome proposed dropping H264 support, I was infuriated, even though I fully support WebM as the mandatory to implement codec. I don't think "purity" really serves the platform, flexibility does, and the best way to register you don't like DRM is to simply stop consuming any and all media which uses it. Not just Web media, but all media that's DRMed.
A DRM free HTML5 spec is not going to force Hollywood to allow you to play Games of Thrones on your open source Linux browser.
If they really want to ship DRM, they can do it using the same tools everyone else uses, without special monopoly-preserving treatment or 'protected media paths' or kernel hooks or tailor-made plugin APIs. Big Media is no more deserving of special treatment or protection than any of the other industries that want to build apps on the web, and the idea of dedicating time and resources to babysitting a dying industry when there are REAL PROBLEMS that could be solved instead is ridiculous.
The problem is that they know as well as we do that DRM doesn't work, and DRM especially doesn't work without the aid of special kernel/software hooks like the Windows PMP and OS X's anti-debugging protections. This is why they're so desperate to get DRM baked into the HTML5 spec and baked into browsers. The reality is though, adding DRM to browsers produces no value for anyone other than the lazy big media companies that can't adapt to the modern world. It doesn't produce value for consumers, it doesn't produce value for developers outside of big media, and it doesn't produce value for the people who actually produce video and audio content. All it does is enrich IP lawyers and executives.
Furthermore, the idea that lacking DRM somehow makes the web 'suck' is preposterous. Do you know anything about the web? If the web sucks that's entirely separate from whether or not it can play encrypted video. If it sucks, it's because browsers are full of security problems, websites are poorly designed and poorly engineered, web accessibility for the disabled is poor, web performance is miserable in many markets, and ISPs like Comcast continually abuse their monopoly status to overcharge and under-deliver. Encrypted video is so far from a real-world concern or priority for ordinary people that suggesting it's somehow NECESSARY for the web to not suck makes you look absolutely raving insane.
It's just dumb. DRM is just dumb. It doesn't work for anything but the most naive case. It won't prevent distribution of "pirated" content, ever.
I'm not asking for a DRM-free world, but I still hold out hope that if we continue to push back forcefully enough we might at least get rid of some of the abject nonsense being inflicted on us. Seriously (and without getting into any details), look at the middleware layers of a consumer OS some day to see all the spots where DRM has its greasy fingers. Must it be in HTML too?
In this case, forget consumers. Once in a while, something is more important than appeasing the masses.
A DRM free HTML5 spec is not going to force Hollywood to allow you to play Games of Thrones on your open source Linux browser.
Neither is a DRM-infested spec. Instead, you have uninformed consumers Googling for "how can I watch Game of Thrones Season 2 Episode 3 online for free", getting infested with malware, but still watching the show for free.
A DRM laden HTML5 spec will mean "my open source Linux browser" will not be able to support the entire HTML5 spec. This is far more unacceptable to me.
Pirates are becoming increasingly professional and Hollywood gets to decide if they will spend their legal advantage on defending incompatibility schemes or making money, unless the browsers help them out with the former.
A DRM free HTML5 spec won't have any effect on you being able to watch Game of Thrones on your open source Linux browser aside from maybe giving you an opportunity to pay HBO for it.
At least a compiled-to-JS codec or encryption module would be JS, so it would run on the web everywhere. Unlike Flash, Silverlight, and also the EME stuff as mentioned in the article, all of which require proprietary code, and so will only run in some browsers and some platforms.
In that case, there was a bunch of push-back against the broadcast flag, the proposal died, and now all kinds of stuff gets broadcast in the clear. When push came to shove, the content producers didn't actually need the broadcast flag, and their business models still work without it just as well as they did before.
The same needs to happen with the EME proposal; people who care about this kind of thing need to push back and kill it just like with the broadcast flag.
Most Internet users don't care where their browser vendor leads them. Like you said, consumers are sheep.
What's wrong with that? Keep the junk out of the browser!
Therefore, it is the moral duty of those behind html5 to make sure that interests of consumers are not compromised.
For me, what it all comes down to is this: HTML5 is supposed to have open standards, so if I implement those standards' specifications in my own web browser, I expect to be able to view and use websites that are HTML5-conformant.
If DRM goes through, this is what will probably happen: Internet Explorer and Google Chrome (two closed source browsers) will definitely implement it. Opera might implement it (who really knows what they'll do?). Chromium and Firefox probably won't implement it. DRM content will likely only be viewable on those two browsers, and only on a supported platform. If you use Firefox on Linux Mint, you're SOL. If you developed your own web browser, you're SOL. Even if you use Firefox on some closed source operating system like OS X, you're SOL.
The web is still open by default, versus other platforms being closed by default. The best architecture is to support fine-grained plugins with well-defined semantics than just some big black box <object> element that could be running anything.
That's not to say that HTML5 EME addresses this, just that nobody is going to be forced to use HTML5 in any case. (It's possible that a proprietary but common CDM standard could be created to allow the least common denominator on mobile, since the regular route of browser plugins won't work there, but that would be its own can of worms.)
Noone will force you to use DRM on your website. Noone will force you to browse websites that use DRM.
What do you care what others choose to do with their sites and content, unless you believe you have the right to access everything everyone creates, in an unrestricted fashion, for free, in perpetuity.
If that isn't automatically bad to you on the face of it (it is to me, I want to be able to use random-OS-of-the-month as long as it has a good browser), you create a scenario where those on top stay on top by the grace of already being on top.
If you want to stay legal and watch their content, you bet they will. Major networks will require their distributors to use this DRM. Sure, you don't have to use their content, but the point of fighting it is that we want to use their content and are trying to prevent them from this step.
In other words, it's a "standard" that deliberately sets up a situation where behavior across browsers will differ.
Suggestions that the interface between the CDM and the browser actually be standardized have been made ... and ignored.
This came as a proposal from Google. It was tested in Chromium first. The DRM is essential for their "World-saving" ChromeOS that nobody really cares about.
I predicted this catastrophe when everyone was attacking Flash.
The Tiger Tree Hash system is already being deployed for this purpose in other systems.
Should they try to keep web as open as possible or should they play to the tunes of Google and Microsoft and introduce features that benefit them.
As I see it, web standards should be as open as possible.
Seems like mostly a distinction without a practical difference. Some browser platforms won't be able to ship with the bindings for this, likely the same browser platforms that can't ship the NPAPI plugin.
If some orgs or people want a means to retrict the playing of media in HTML5 by downloading keys from a license server then so be it. The HTML5 standard should be as inclusive as it needs to be to represent the needs of all parties. If enough parties desire this functionality then who are we to say they cannot or should not have it.
However, I really can't see the point of doing DRM in html5, it will just result in browsers becoming the equivalent of the evil plugin everyone hates(only certain browsers/platforms will be able to run the content).
Why not just leave html5 video open, and let those who wish to distribute DRM'd content build their own client-side players for the OS's they wish to support. Or let them build apps on top of Adobe AIR or Silverlight out of browser.
I know it wouldn't act retrospectively, and I'm not sure if any OSS libraries are actually in use in any DRM software, but it may at least set a trend. I'd love to see the next open source game changer be open to all except those who oppose openness :-)
Right now DRM depends on proprietary plug-ins. If this is allowed in HTML5, DRM will still depend on proprietary plug-ins.
What is different?
edit: also, browser vendors don't have to implement it if they don't want to. Really, I don't like this DRM thing that much, but I am kind of indifferent to this.
Once it's implemented, you can just patch Firefox or Chromium to dump the unencrypted video stream before sending it to the H.264/WebM codec, and you get an universal method to trivially liberate all "DRM"-encumbered web content.
http://permalink.gmane.org/gmane.org.freeculture.discuss/681...
Honestly, rants like this sound a lot like "allowing same-sex marriages will destroy the sanctity of marriage" and alike. How exactly?
Will the ability to have DRM'ed content in HTML suddenly shut down "the open web"? No.