I'm reminded of the US RSA export fiasco of the 90s. I unfortunately can't find the cool email signature I learned about the whole thing from, but its home on the internet now seems to be http://www.cypherspace.org/rsa/.
Perhaps someone should come up with a small <5-line snippet that explains some portion of how to defeat Widevine, and then everyone in Israel should, I don't know, configure every mail server they know of to autoinject the fragment into all outgoing mail, or something. And/or configure everyone's browsers to autoinject it into every modified multiline text input field (maybe).
Obviously it wouldn't be able to last. But it would be VERY good publicity. And the thing is, Widevine would constantly be being updated so the instructions would constantly break and need to be changed, so exact-string filtering wouldn't work ;)
So. I'll start, despite not living in Israel: both Chromium and Firefox will use PulseAudio if it's available, and fake soundcard drivers exist for Windows/macOS as well, so sound isn't really problem if you're prepared for an "export" process that takes as long as eg SpotAHEM tracks take to play.
But as they say, it's not about piracy. Piracy is incredibly simple no matter what. I can also just take a camcorder to my screen to capture Netflix no matter what garbage crypto they put in the display connection. But I don't even need to do that, because I have a cheap-ass HDMI splitter from China that already strips HDCP effectively and effortlessly.
It's always about control of something, whether it be the consumer, distribution channels, etc.
TIL about cheap HDMI splitters stripping HDCP. I had no idea this was a thing, that's very interesting. I'm also very surprised that Google even autocompletes "hdmi splitter remove hdcp" (!) and then shows me eBay product listings with "Hdcp Stripper" in the product title. Wow.
I also found https://security.stackexchange.com/questions/124762/how-does... asking how they work, which corroborates that they really do have the key inside. Shakes head Nice...
They are necessary for some people with older receivers or TVs that don't negotiate HDCP properly and give them black screens/no sync situations.
It's almost like there are numerous completely legitimate reasons to break DRM!
just buy a new tv. what, do you hate consumerism? do you hate america?
But Widevine is not just one system, there are multiple security levels. Software-only version (L3) that runs in chrome CDM on desktops (SD quality) can be defeated easily (it uses arxan's TransformIT as an OEMCrypto implementation), but in order to break L1 you'd need to break into the TrustZone which is much harder, and even if you did it on a particular device, Google could revoke certificate for that device or even device model.
Oh. :(
Kinda depressing to know there actually are competent implementations out there.
This worries me because they know they can't implement strong DRM systems while respecting users' right to control their own devices. So with "TrustZone", "Secure Boot" and other things like that, they don't respect that right anymore[0], and unfortunately EFF doesn't point this out in their article.
[0] https://www.gnu.org/philosophy/can-you-trust.en.html
Very good point.
I wonder if this is deliberate: the EFF surely realize this themselves, but maybe they don't want to mention it because of precisely the reason you mention, and the fact that the EFF don't want to jeopardize anyone misinterpreting their opinions and positions on the subject.