Ian Hickson
2 years agoPublic
Discussions about DRM often land on the fundamental problem with DRM: that it doesn't work, or worse, that it is in fact mathematically impossible to make it work. The argument goes as follows:

1. The purpose of DRM is to prevent people from copying content while allowing people to view that content,

2. You can't hide something from someone while showing it to them,

3. And in any case widespread copyright violations (e.g. movies on file sharing sites) often come from sources that aren't encrypted in the first place, e.g. leaks from studios.

It turns out that this argument is fundamentally flawed. Usually the arguments from pro-DRM people are that #2 and #3 are false. But no, those are true. The problem is #1 is false.

The purpose of DRM is not to prevent copyright violations.

The purpose of DRM is to give content providers leverage against creators of playback devices.

Content providers have leverage against content distributors, because distributors can't legally distribute copyrighted content without the permission of the content's creators. But if that was the only leverage content producers had, what would happen is that users would obtain their content from those content distributors, and then use third-party content playback systems to read it, letting them do so in whatever manner they wanted.

Here are some examples:

A. Paramount make a movie. A DVD store buys the rights to distribute this movie from Paramount, and sells DVDs. You buy the DVD, and want to play it. Paramount want you to sit through some ads, so they tell the DVD store to put some ads on the DVD labeled as "unskippable".

Without DRM, you take the DVD and stick it into a DVD player that ignores "unskippable" labels, and jump straight to the movie.

With DRM, there is no licensed player that can do this, because to create the player you need to get permission from Paramount -- or rather, a licensing agent created and supported by content companies, DVD-CCA -- otherwise, you are violating some set of patents, anti-circumvention laws, or both.

B. Columbia make a movie. Netflix buys the rights to distribute this movie from Columbia, and sells access to the bits of the movie to users online. You get a Netflix subscription. Columbia want you to pay more if you want to watch it simultaneously on your TV and your phone, so they require that Netflix prevent you from doing this.

Now. You are watching the movie upstairs with your family, and you hear your cat meowing at the door downstairs.

Without DRM, you don't have to use Netflix's software, so maybe just pass the feed to some multiplexing software, which means that you can just pick up your phone, tell it to stream the same movie, continue watching it while you walk downstairs to open the door for the cat, come back upstairs, and turn your phone off, and nobody else has been inconvenienced and you haven't missed anything.

With DRM, you have to use Netflix's software, so you have to play by their rules. There is no licensed software that will let you multiplex the stream. You could watch it on your phone, but then your family misses out. They could keep watching, but then you miss out. Nobody is allowed to write software that does anything Columbia don't want you to do. Columbia want the option to charge you more when you go to let your cat in, even if they don't actually make it possible yet.

C. Fox make a movie. Apple buys the rights to sell it on iTunes. You buy it from iTunes. You want to watch it on your phone. Fox want you to buy the movie again if you use anything not made by Apple.

Without DRM, you just transfer it to your phone and watch it, since the player on any phone, whether made by Apple or anyone else, can read the video file.

With DRM, only Apple can provide a licensed player for the file. If you're using any phone other than an iPhone, you cannot watch it, because nobody else has been allowed to write software that decrypts the media files sold by Apple.

In all three cases, nobody has been stopped from violating a copyright. All three movies are probably available on file sharing sites. The only people who are stopped from doing anything are the player providers -- they are forced to provide a user experience that, rather than being optimised for the users, puts potential future revenues first (forcing people to play ads, keeping the door open to charging more for more features later, building artificial obsolescence into content so that if you change ecosystem, you have to purchase the content again).

Arguing that DRM doesn't work is, it turns out, missing the point. DRM is working really well in the video and book space. Sure, the DRM systems have all been broken, but that doesn't matter to the DRM proponents. Licensed DVD players still enforce the restrictions. Mass market providers can't create unlicensed DVD players, so they remain a black or gray market curiosity. DRM failed in the music space not because DRM is doomed, but because the content providers sold their digital content without DRM, and thus enabled all kinds of players they didn't expect (such as "MP3" players). Had CDs been encrypted, iPods would not have been able to read their content, because the content providers would have been able to use their DRM contracts as leverage to prevent it.

DRM's purpose is to give content providers control over software and hardware providers, and it is satisfying that purpose well.

As a corollary to this, look at the companies who are pushing for DRM. Of the ones who would have to implement the DRM, they are all companies over which the content providers already, without DRM, have leverage: the companies that both license content from the content providers and create software or hardware players. Because they license content, the content providers already have leverage against them: they can essentially require them to be pro-DRM if they want the content. The people against the DRM are the users, and the player creators who don't license content. In other words, the people over whom the content producers have no leverage. 
Kevin Marks2 years ago
This is also why it is hard to debate DRM in a technical spec, as it is not a technical agreement primarily, but a legal one. What ends up in the technical spec is the result of legal power plays.+68
Peter Kasting2 years ago
What about Google, who is arguably "pushing for DRM" in the sense of supporting the HTML media EME; but who in this context are basically just creating a "player" (Chrome) -- at least in the sense in which Chrome (software) or Chrome OS (hardware) implements the decryption modules.  Yes, I am aware that one could drag in the larger company context about the Google Play Store or whatever, but I really don't think that's at issue here: I would say that e.g. Netflix is in the role you describe (licensing content and creating a software player) and Google is in some sense a proxy who perceives content as only being available through "leveraged" companies, and is trying to act on the user's behalf to make those companies' content available.

Is Google therefore "leveraged by proxy" because they don't license the content but they do want to make it available, so they effectively are bound by the same rules?  Do you reject my premise that in this instance, Google's direct content licensing is immaterial?  Or is there a third explanation?
Ian Hickson2 years ago
I'm not going to discuss Google specifics here. :-)+13
Brooks Moses2 years ago
What I find interesting -- and well-fit by your model -- is that all the technically-savvy authors I know who have strong opinions on DRM are against it.  Because it's not actually enabling anything that puts more money in their pockets, so it's just acting as friction making it hard for their readers to get to their books.

Book publishers are also in an interesting space; many are also going non-DRM.  Part of that's push from authors, but part of it is also realizing that DRM lets Amazon et al (for a short list of et al) push the publishers around by becoming sole suppliers on certain devices.
So, if the purpose of DRM is to have power over player providers, then why do they bother trying to invent harder to crack variants of DRM? Even if the DRM is trivially crackable, any legal player would have to go through the content provider regardless, so it seems to me that investing lots of effort into hard-to-break DRM is then useless, and in fact counter-productive as you are making things harder on yourself and your partners. Yet we still end up with standards like AACS and BD+ that appear to be entirely about how hard they are to break. +17
Stuart Langridge2 years ago
+Aren Olson one reason is that a good proportion of the people pushing or implementing or requiring DRM systems don't know that their largest benefit is player control. In other words, they believe the hype (that it's about copying).

Also, can't hurt to prevent copying more efficiently or more successfully while you're down there in the text editor anyway.
Stuart Langridge2 years ago
(also also: no individual mass market manufacturer can produce unapproved players. But eventually all the non-mass-market manufacturers individually produce a non-approved player of their own, and that adds up to roughly the same as a mass-market manufacturer. Buying a DVD player which does not respect region encoding, for example, is now easy without delving into weird technical stuff: they're all from unknown manufacturers, but you don't care about that.)+3
Gus Class (Gus)2 years ago
I am ok with DRM, even though the systems are flawed, because the tradeoff is most importantly DRM allows the honest people to be honest.

> Hackers gonna hack... DRM's gonna not play sometimes
Fact: Regardless of the DRM system and scheme you are using, an attacker can compromise the scheme. The devices have the keys you need to decrypt the content, right there, begging to be cracked for a curious attacker.

Fact 2: Regardless of the DRM scheme, sometimes content will not play for legitimate licensees of the content. Sometimes a system clock gets the wrong time, sometimes a cert goes bad, it happens.  However, this is rare and is part of the price you pay for getting restrictive (read that also as cheaper) access to content that is a publisher's bread and butter.

To me, the corner cases where hackers hack the system to break the DRM and where content is broken for legitimate licensees is not that relevant and is not that common.

A little background, I'm biased from experience with DRM systems and from learning about how content publishers think.

I worked in DRM (WM-DRM server, client, DRM for devices) for a few years and I felt ok sleeping at night because - in some light - DRM enables you to create products that content owners otherwise would not let you make.  Our perspective at the time was not that we wanted to have absolute control of the ecosystem, we mostly wanted to just enable the content scenarios that our users wanted in a way that the content providers would allow.

My favorite example is streaming / download models for subscription services. The hotness for us at the time (this was 2005, folks) was DRM for devices and it let you do things like download all the music you wanted, new, old, etc, and play this offline on devices. Were it not for the content protection, most of the content owners simply would never let us distribute their content like this, it was either "buy physical content" or "download crippled content that pretty much installs malware on your machine". Furthermore, were it not for DRM, content owners would never have gotten comfortable with the idea of streaming and digitally distributing their content. By making these inroads with content owners, even though it is a little icky - you can only use these [n] certified players, and can only do x,y,z with content - you now have streaming services like Netflix, Amazon `, and Google Play.

Sure, the experience breaks sometimes, sure it can seem like DRM systems treat paying customers like criminals, and it certainly is annoying to require device certification and in some cases licensing if you want to be blessed to render content...  but I don't see a better way aside from changing the perspective of the content owners to enable such services and scenarios.
David Greifzu2 years ago
DRM does not work for me. If I want something, ill get it. Even if I have to take it by force.+15
Ian Betteridge2 years ago
Pretty much what Steve Jobs said six years ago:

In particular, this: "So if the music companies are selling over 90 percent of their music DRM-free, what benefits do they get from selling the remaining small percentage of their music encumbered with a DRM system? There appear to be none. If anything, the technical expertise and overhead required to create, operate and update a DRM system has limited the number of participants selling DRM protected music. If such requirements were removed, the music industry might experience an influx of new companies willing to invest in innovative new stores and players. This can only be seen as a positive by the music companies."

What was true about music then, is true about movies now.
Kevin Knerr2 years ago
I disagree with your thesis. While you are correct that DRM is not simply about preventing people from copying, it is also not about leverage over distribution channels and devices.

DRM is about preserving and maximizing the revenue stream. DRM is the usher tearing your ticket as you enter the theater (and chasing out the kids who snuck in without paying).

If DRM were limited to those simple functions, it wouldn't be as objectionable as it is. But DRM is being used to send the usher back into the theater and charge you for additional tickets after you've already paid.

By arguing that DRM is about companies, you obscure the fact that the real target of DRM is the wallet of the consumer.
Will Pirnasch2 years ago
Interesting explanation, thank you!
I'm surprised there were no hate trolls here yet that repeat their mantras without understanding.
I actually stopped watching movies from DVDs, because I hated force-watching stupid commercials multiple times. Live goes on without movies, seriously. I'm not missing it.
I think it is a ridiculous situation that DRM forces people that paid for the movie to endure that, and people who downloaded the cracked version not. Similarly, I'm not buying any eBooks, because someone out there has the control to remove them from me at any time. I go with paper books - once I paid for them and have them, they are mine as long as I want them. DRM violates my understanding of ownership, and the only legal answer to sow my disagreement is simply to not buy the stuff.
Joel Webber2 years ago
+Kevin Knerr : I don't think you're actually in disagreement with Ian on this. His thesis may be that content owners want leverage against device manufacturers (both hardware and software), but he points out that the purpose of this leverage is ultimately to extract more cash from the channel, which means ultimately from consumers.

I think the overall thesis makes sense, though I would add that there's at least a small dose of the (2) and (3) cases -- for the simple reason that media company executives are operating to a large extent under a CYA theory. In other words, simplifying or removing DRM schemes might work out perfectly well, but none of them wants to go down in history as the idiot who handed out the keys to the kingdom. I believe this fits with the legitimate points +Gus Class makes above.

Personally, I find it quite unfortunate that content providers have chosen to be so shortsighted on this issue. They may find ways to extract linearly more cash from the channel by attempting to exert so much control (operating under the "if the user derives any additional value, we should be payed more" theory). But in the long run, I believe the extra friction is costing them superlinear revenue. I assert that reducing friction, and allowing users the opportunity to come up with creative uses of the content they've paid for (e.g., Ian's "letting the cat out" example) will increase the size of the market, benefiting everyone.
Drm has slammed the price of ebook rentals at the library it's not longer cost effective... And can only be rented a dozen times before it deletes itself. +3
Kevin Marks2 years ago
Gus, if we're going back to 2005, here are my anti-DRM arguments from then:

A corollary of Ian's point is that any given TPM is not necessarily going to satisfy Big Content, who see this as a power exercise. If you concede to them, they come back with further demands next time.
They're a tiny minority of interesting uses of digital media
David Kane2 years ago
My biggest problem with DRM is that it sort of implies that the things I am buying aren't really mine. When I buy something, I want to own it. I don't want to own it the first 9 times I use it, and then on the 10th it locks me out, or whatever. I paid for this thing, let me do what I want with it. Or, at least stop trying to lie to me by "selling" me things; be honest and "lease" that music to me.+36
Gus Class (Gus)2 years ago
+Kevin Marks :) Completely understood, I wonder what I'd have said had I commented on that then... I guess my short version is that it felt like the lesser of two evils at the time: no digital content from providers vs only pirated content.

Ideally, you should be able to use your content however you want, but if you want to be able to access content without having to own it, DRM seems the most likely way.  

I strongly believe that you don't truly "own" content until it has no restrictions on it and I want for all my content to be in CC because it's awesome to be able to remix and so on... it's just not necessarily possible in all cases.

It's always hard to make a case for DRM because it by design is not a user-centric thing - the joke about DRM is that when it's working correctly the user's experience breaks - but I still don't think that DRM is always terrible and bad...
Lex Spoon2 years ago
Good analysis, including +Joel Webber's point that the technical barriers are so weak that they are essentially just CYA.

I would ask that we consider an implicit assumption, though. Nowadays, most forms of content are being given away for free, not just DRM-free but plain old free. The holdouts are big-budget items including Hollywood movies and AAA computer games.

Is it worth it? The general public strikes me as just as stuck in the past as big-business content providers. Even in an age where the Internet is sweeping the world and changing so many things, we find it hard to imagine that Hollywood would ever go away.

Maybe we'd be better off without it. We don't really know what would fill the vacuum, and it might well be something better. Suppose for the sake of argument, though, that Hollywood goes away and we get no alternate movie-making industry to replace it. In short, we lose Hollywood, but we also lose the DMCA. Is this a good tradeoff? My personal feeling is that even in this worst-case scenario, it's a good deal.
Joel Webber2 years ago
+Lex Spoon Definitely worth exploring. I'm not quite sure how I'd feel in the final analysis, but it's very important to remember that IP rights have not traditionally (until the last century) been considered anywhere near as strong as real property rights. The whole point of the IP regime is subservient to the public good that it's meant to serve, and it must carry its weight in order to be worth continuing. I know this is the case in the US constitution and the tradition of copyright in English common law. I believe it's somewhat less so in the continental tradition (e.g., the French Droits d'Auteur are rather a lot stronger and rooted in a deep-seated notion of an author's rights to control use of his or her creative works), but still worth reconsidering, especially given that the strong IP law is in the process of getting negotiated into myriad treaties -- once it gets ensconced in there it's really hard to back out.+4
Christian Kaiser2 years ago
Ian has correctly laid out that on a fundamental level, DRM cannot work as advertised (for some assumption of what is advertised) and that it is not aligned with creating a good user experience.

Many are angry at historic implementations of DRM because they take control away from the user - control that some of us can wield and therefore enjoy. Often times, the implementations are clumsy and buggy, making things even worse.

However, creating a stalemate doesn't seem to take us forward. It's better to create a setup that allows the world to evolve into a better place.

The past and current ugly situation is IMHO a result between the direct relationship between content owners and technology/DRM providers. This relationship was needed since the media playback tech out in the wild did not support levels of protection that satisfied the needs (perceived or real) of the content owners. It's also not well-aligned with the needs of the user:

Content owners are primarily motivated to protect their revenue out of (perhaps irrational) fear of losing a large part of it, and only secondarily to provide a great user experience. They are also traditionally not very technically savvy.
Technology/DRM providers are primarily motivated to generate increasing revenue from building ever more complex DRM tech, secondarily to satisfy their customers perceived needs, and only tertiary to provide a great user experience.
Unsurprisingly, the resulting user experience was nothing to write home about.

Enter a third player in this game - content distributors (e.g. iTunes, YouTube, Netflix, hulu, ...). Content distributors are middle men between content owners and users, and are primarily motivated to create a great user experience since they have realized that revenue is directly and primarily correlated to it (and not to the robustness of the DRM!).
Content distributors also typically carry the cost of implementing DRM and are thus motivated to minimize it. In order to minimize the cost and to maximize the quality of user experience, they needed to take control of the user experience away from technology/DRM providers. Today, they all have opted to build their own technology stack. Good, because user experiences are better than they were, but not great, because these are all proprietary solutions that lock users into one or the other platform.  

The long game here is that standardization of access to content protection tech from open standards like HTML5 is aligned with everybody's interest:
- users, because the user experience is now in the hands of multiple content distributors who will compete to create ever better user experience at lower cost to the user. Also, content protection can now become more interoperable, thus decreasing platform lock-in in the long term.
- content distributors, because content protection tech becomes cheaper to implement through standardization. It is quite reasonable to expect that the complexity of content protection will evolve towards simpler and perhaps less "secure" solutions if that comes with better user experience and thus more revenue. Cross-platform content distributors reap the biggest benefit.
- content owners, because better user experiences will generate more business and therefore revenue

This is obviously not a certain outcome, but at least it may move us in the right direction until someone comes up with a better idea.
Ian Hickson2 years ago
+Christian Kaiser Any solution that prevents users from doing whatever they want and is legally permissible (other than for anti-circumvention laws) with the content they have purchased is not aligned primarily with the user's interests. The W3C proposal for DRM on the Web fails to address all three of the examples I gave in the original post (A, B, and C), not to mention allowing all the other things legally allowed under fair use.

Your argument rests on the basis that DRM does something to prevent copyright violations. It doesn't. All the content is already available for those who want it without worrying about copyright law. The whole point of my post is that this line of argumentation is a red herring. DRM doesn't solve any copyright-related issues (all the DRM schemes are broken), all it does is limit the availability of players. The only interest that DRM is aligned with is the content providers, because they get to charge legitimate customers more for things that the customers would otherwise be legally able to do (like my A, B, and C examples).

Removing DRM would create a better user experience and result in more business and more revenue, because it would remove the barriers to users using the content in novel legal ways, just like iPods helped music sales. iPods would not have been as successful, and the music industry would not have seen that increase in business, if CDs had DRM the way DVDs do today.
Peter Kasting2 years ago
Careful with your language -- "is legally permissible" is probably not what you want, given the DMCA's anti-circumvention clauses.  "Would otherwise be legally permissible" might be better.+2
Ian Hickson2 years ago
True. Fixed.
Vassil Vassilev2 years ago
Let's not forget there are other markets outside US and Europe. I live in Russia now and cannot buy most content online. Netflix, Apple store & Co. have built a wall. Cannot watch lots of free material either - ABC etc. wouldn't accept outsiders on their sites.
The funniest thing is with Blu Ray - some genius decided he'd make more money creating arbitrarily 3 zones. Now I cannot even buy lots of films till (if ever) they publish them in Russia and even then, they may be lacking English audio or subs. Well, imagine what is left to do, if you can't get something legally - whatever it is, those "clever guys" are not getting the money.
There is a perfect example in books - I first read Eric Flint's '1632' for free at Since then I bought every book he's published - more than 15 (whenever possible, in paper in Europe). I would not have heard of him if not for his approach (Thank you, Eric). Just trying to say it is not only annoying, it's plainly stupid! No offense intended!
Sometimes inertia in thinking can be a very dangerous thing - things have obviously gone wild and out of control. Every following step seems to be logical, but you get something strange in the end.
Just like copyright for material, whose author has been dead and gone for a century. Most probably, the way they keep extending it, forever.
Excuse my long post, if you can.
John Werneken2 years ago
The fundamental problem is that there is no such thing as a content owner, except in the imagination of some national governments. There is no such thing as intellectual property. Ideas can't be owned. Doing certain things with my idea without permission, acknowledgment, or payment, such as renting or selling the idea, certainly can be discouraged and probably should be. But people cannot and will not be prevented from sharing what they have with each other.
People who want to get paid for financing the activities of others (Hollywood, video firms, music firms, book publishers) just better get used to the idea that if they add nothing to the content then they can charge nothing for it either, at least not where it is more convenient to appropriate without paying, due to obnoxious restrictions imposed on paying customers only.

Sometimes the distributor adds value. I’d much rather if I could have one only have a paper book than an e-book, as I can more readily mark up the paper one, or read it in the bathtub by candlelight when the electric power is out, and I don’t have to worry about Google or some other evil conspiracy unplugging some necessary aspect of the electronic ecosystem, as just happened with the Reader. I don’t expect t to get paper books for free, but I also don’t expect to pay NEW, HARDBOUND prices for used, paperback copies.

There’s an analogy to the DRM sphere where in theory nothing is sold and everything is rented at top and quite possibly increasing dollar as time goes on. What the alleged content owners are doing to deserve ANY payment is quite mysterious. Chances are most readers or game players or viewers or listeners or whatever would willingly donate enough to the actual content creator that said creator would actually earn more without a distributor than with one. Only esoteric or nearly unknown digital works really benefit from the publicity/distribution industry – and people don’t grudge paying distributors for those works.
Scott Boone2 years ago
Great article, Ian. But I echo somewhat what Kevin Knerr said…you begin using the term "leverage" in your treatise, but end up using "control". I think it is a mistake to conflate the two, when we all agree that the "control" is ultimately designed to be wielded over the consumer (and the wallet).
This is what was so devious about the DMCA. I remember quite clearly the content companies explicitly stating that the anti-circumvention measures were NOT aimed at consumers, an attempt to curtail "fair use". The duly elected bought it (or were bought off) hook, line, and sinker. I know my elected representatives did. (Arlen Specter, still an R at the time, gave quite a defense of the DMCA at a town hall in which I raised the issue; trotting out the specter of terrorism and undermining military-grade encryption as reasons against my basic "fair use" request to be able to rip DVDs and CDs; he blamed Clinton for it, even though I cheerfully pointed out he had voted to send the DMCA to Clinton's desk for signing.) The content companies knew from the very start what they were trying to accomplish. I'd be flabbergasted if they were not absolutely amazed at how much they had gained, given the onslaught of devices they hadn't even dreamt of (iPods, iPhones, iPads, smartphones, smartTVs).
However, my goal in this quest is to start the conversation "What do we do now?" And that is something you did not get to. Clearly, the content providers are enjoying a significant advantage over consumers, even more lopsided given the technology available to the average buyer…they effectively killed "fair use" through a loophole.

After the DMCA Exemption hearings earlier this year, highlighted by the cellphone unlocking brouhaha, I think more people are ready to listen and discuss. Darrell Issa (R-CA) is on record as supporting legislation to return "fair use" rights to consumers to allow them to rip DVDs for viewing on iPads. So I guess my first call to action is to get the content providers to fess up: they are either AGAINST consumers having the right to rip purchased content (as opposed to streaming/limited viewing content) or FOR "fair use" rights. There can be NO MIDDLE GROUND. This was effectively what Steve Jobs did in his letter: he threw down a gauntlet which the content providers couldn't ignore. And from the arguments put forth in the Class 10 exemption hearings (petitioned by Public Knowledge), it is clear that the content providers are solidly on the side AGAINST the consumer enjoying the traditional "fair use" right. 

Which is to say that I feel the MOST EFFECTIVE legislative action would then be to carve out a permanent DMCA exemption for personal, non-commercial format-shifting of content. If the DMCA was not intended to be punitive against consumers (even though we all know it was) then the content providers can't complain too much, at least not publicly, since their entire defense of the DMCA originally hinged on big bad pirates and asian knock-off electronics. Further, to really hit them hard, the legislation should specifically allow for non-commercial (free) "sharing" of such format-shifted content between legitimate content consumers, such that if you have Rome Season 1 on DVD and I have Rome Season 1 on DVD and already ripped mine, I could give you my digital files as long as I do not charge. (In no way should this or would this be construed as license to UPGRADE the quality of the content above what you had purchased; if you bought a DVD you would be committing a copyright violation by trading for a different 1080p Blu-ray HD version of the file.) This would act to reduce the pressure on legal consumers and force the industry to actually pursue real "pirates". I have little thought that part of the legislation would get passed, but the spirit of traditional "fair use" would make for great debate--the idea that you can absolutely loan your Rome DVDs to another friend to watch, then why can't you loan the digital copies as well? As long as you refrain from watching them during that time, and your friend does not keep the files when done watching them...what is the analog difference?

Anyhow, at this point, I'm less concerned with WHO is being controlled, and much more with restoring the fundamental "property" rights law-abiding good consumers lost by way of the DMCA and forcing the content providers to bare their fangs at real scofflaws. With the proliferation of legal sharing, it might even compel the content providers to allow Amazon and Apple, et al, to provide DRM-free and locker-style matching services for video.
Bryan Eastman2 years ago
Good post, thanks.  

I've recently taken up playing the bass thanks to Rocksmith, and I'm on the receiving end of some DRM obnoxiousness.  The built in DRM in the cord means that it flakes out regularly, pissing me off.  This is bad for everyone, except the music licencor.   I'm having a less good experience (bad for me). I'm pissed at Rocksmith and will switch platforms in a second as soon as I find a better implementation (bad for Rocksmith/Ubisoft).  And it's bad for future development to other instruments/platforms because there aren't a flood of 1/4 inch to USB cords reducing the barriers to entry. 

The thing is, I don't think it's actually accomplishing anything for the licencors either.  It think the real "DRM" solution is obvious at this point.  1) Make it easy to pay for it legitimately at a decent price.  2) Make it mildly annoying to get illegally.  3) Don't make step 2 obvious/intrusive to people who paid for it.  4) Ignore the 23 hackers who bother to crack it and the 10k college students who weren't going to pay for in any case.

There are a bunch of good technical solutions for points 2 and 3, and points 1 and 4 is just basic business sense.  
Except that "content providers" are a cartel (or several cartels).  Basic business sense doesn't apply to mono/oligo-poly economics.  This is the long way to say that I think you're just a hair off in your analysis.  It's not about leverage over middle men, specifically (which is what DVD manufacturers/Netflix/Apple are in your example).  It's about maintaining the cartel.  And that means retaining power everywhere, not just end users.  
Ian Hickson2 years ago
+Thodoris Tsiridis It's not impossible to protect content on the Web. The courts do a fine job of it.+1
Paul Cipollone2 years ago
Absolutely spot on.  As a Linux user, I technically break the law every time I watch a DVD on my computer.  That's absolutely wrong, of course.  I have always called this the "Men in Black" dilemma, from the scene in the movie where Tommy Lee Jones says "This little guy is going to replace CD's in a few years...I guess I'll have to buy The White Album again..." 

What you actually purchase when you buy a DVD/CD/whatever, is a license to view/use it.  The physical media is trivial. So if I have purchased a single license, and I only want to USE one license, why should I have to buy ANOTHER license for the same work?  Or to make a backup copy of what I already have, in the event of a loss of the original?  If the studios got this, Tommy Lee would have been able to just trade in his CD for a copy of the new media for a nominal cost (to cover manufacturing, shipping, etc.).  Full price for a copy of what I already have?  That's as insane as paying a lawyer full price, to do up two copies of a contract, and making a Xerox copy of the original illegal. 

And the real thieves who make thousands upon thousands of copies aren't bothered at's just the consumer who is.
Joel C. Salomon2 years ago
By saying, “The purpose of DRM is to give content providers leverage against creators of playback devices,” you seem to be arguing that Stallman is correct in expanding the acronym as “Digital Restrictions Management”.+2
Ian Hickson2 years ago
The expansion "Digital Rights Management" doesn't really make any sense. I mean it would be like calling a gag a "Tool for freedom of speech management".+13
Mike McNertney2 years ago
+Gus Class I completely disagree with your point that DRM allows honest users to be honest.  In fact I think just the opposite.  I am an "honest user," and DRM prevents me from being able to use media in a sensible way.  Sometimes (particularly in the case of DRM for software) it even actively causes me problems when I am trying to use the content within the bounds of what is supposed to be allowed by the DRM.

Most DRM makes it so that the only way I can experience content in the way I think I should be able to do so is to break the law.  That is completely the opposite of "allowing honest users to be honest."
Aaron King2 years ago
What nobody seems game to say is that DRM makes the legally purchased content an inferior user experience to the illegally pirated version of the same content.

To me, as a tech worker and a content buyer, this is ridiculous. I should get the premium experience as a paying customer over the guy who paid nothing and downloaded it illegally.

As the guy who bought a movie, I should not be jealous of the premium experience of the law breaker in the next cubicle.

That is what grinds my gears about DRM.
+Aren Olson 
"So, if the purpose of DRM is to have power over player providers, then why do they bother trying to invent harder to crack variants of DRM?"

Speculation here, but courts tend to take a dim view of folks who are blatantly using the law against its intentions. I have gotten the impression that many actors producing DRM are interested in keeping up appearances. Others definitely aren't, and try very hard indeed to make their work difficult to crack, e.g. video game console makers.

Plus from the content industry perspective it's always possible that one of their boffins will come up with some neat unbreakable trick, never mind what all the techies are always going on about how it's fundamentally impossible.
Alex Fink2 years ago
+David Kane For a (for the time being!) light-hearted extension of DRM in that sense, see
Christian Farfan2 years ago
Slow clap.+1
+Gus Class "DRM allows the honest people to be honest." No, you've got it wrong... DRM allows the honest people to be screwed.

First, I've bought tons of stuff I didn't even know was DRMed.  

Who is going to reimburse all the money I spent buying all those Disney VHS movies for my kid?  I squeezed out the $50 to $100 a pop... it seemed reasonable at the time, because these films would be heirlooms ~ like classic children's books ~ that the grandkids would be able to watch one day.  

Except: by the time there are grandkids, the already deteriorated VHS probably won't play.  Assuming there will be some player I'll be able to play them on...

They were NOT honest with me... nobody told me the tape would break down or the players disappear from the face of the earth.

DRM should only ever be allowed if the manufacturer/copyright owner guarantees supporting the product ~ making sure it is playable by the consumer ~ for as long as the copyright runs.  If there are no more machines that will play that format, they need to replace it ~ at NO CHARGE ~ in a version I can use.  DRM denies me the right to back-up or format shift, so the copyright owner/manufacturer must pick up the slack.  
Nice piece.

I've had similar rants, as to this, in the past. I admit you have better "real world" examples than I've tried to pass. What gets me the most is that consumers just accept the arguments of content providers. It's a bit like going to the Fluffy Kitten Slaughter House and watching a video produced by them that shows fluffy kittens frolicking in a meadow; believing that this is the purpose of the Fluffy Kitten Slaughter House Corporation and that of its subsidiaries.
Rick Falkvinge2 years ago
Thank you for this tremendously important insight.+2
The problem with taking a strong anti-DRM stance is that you destroy the business model for rental / instant-streaming services - so case B (Netflix) simply doesn't exist, unless they can assure Colombia I'm not making a copy.
Also, as some commenters have noted, a DRM-free 'pirate' copy often has more utility than the DRM encumbered DVD or iTunes file. For me, an eBook - that I can read on my phone or e-reader or tablet - has a higher utility than a doorstep hardback.

From an economic point of view that's an interesting anomaly - normally a product with higher utility is worth more - yet we value them less. (I will pay 3 times more for a vinyl album than the far more useful MP3 version). That goes some way to explaining why producers are so resistant.
Lastly - I do think there is something faux-naieve about the attitude of most techies towards content production. Building on Ryan's comment about the Fluffy Kitten Slaughter House, it's like eating a diet of sausages while maintaining a position of moral anger about how sausages are made, and the condition of the pigs, and the sausage-makers monopoly of sausage production.

No one is forcing you to eat sausages - your anger is because you like them.
That said - I'm completely against DRM on purchases, and I think we need a stronger legal framework around where DRM is and is not acceptable.

I think it is acceptable on broadcast or subscription based models - where the consumer clearly has no expectation that they would 'own' the content at the end of a time period, and the company providing the service has a responsibility to ensure any copies are transient / deleted.

But it should be illegal on 'purchase' based models, simply on the grounds that it discourages competition between device providers and stores.

On the other hand, I would 'allow' strong digital water-marking, as this would not impact our personal and familial use - and may even go some way to supporting the ability to resell digital content, which would be a positive 'right' not supported by many current models.
(Even, ironically, those with strong DRM)
Ian Hickson2 years ago
+Julian Francis-Lawton How do libraries assure publishers that nobody is copying the books they lend out? How do broadcasters assure content producers that nobody is copying the TV shows they put out?

You don't need DRM to ensure that people do what they say they will do. That's what the trust, honour, and the legal system are for. Which is good, because DRM doesn't actually work to assure those things anyway (nor is its primary purpose to assure those things either, as I describe in the OP).
Libraries - they don't need to, as there isn't really a problem therem but there would be a problem if they did not trust libraries to report accurate lending figures, which is how publishers get their money back. And of course, there will shortly be no public libraries for publishers to worry about.

Broadcasters - they don't - since the advent of the VCR content producers have assumed everyone wants to copy their stuff on broadcast - which is why they hold back terrestrial broadcast rights until well after release to DVD or DRM controlled channels like premium cable and satelite broadcast. Certainly the older UK Sky boxes had an option for the broadcaster to stop output to the VCR socket. I don't know if they disable PVR recording of premium movie channels as they are not a service I'm interested in.

It's also why certain films broadcast by the BBC are not available on catchup (iPlayer) and why they insisted on BBC iPlayer blocking unapproved devices as soon as there was a standard in place to allow it.

This lack of trust has been impacting what we can watch on TV since the 1970s. I also recall that it was a complete shock to them when they found there was a retail market for VHS tapes of films that had already been on television.

I'd like to agree that is what trust and the legal system is for - but I can understand why that trust is low, given people's actual behaviour - nor has the legal system worked particularly well so far, with most cases back-firing on the content producers, and 'the Internet' (or at least those who identify as speaking on behalf of the Internet) being opposed to pretty much any suggested legal approach.

What has worked, of course, is convenience. The PVR over the VCR, and increasingly streaming/cloud based services over download and local storage. I expect that to change the debate significantly, as consumers vote against wanting to 'own' a media library in favour of subscribing to one (or more). It's only in a climate where 'ownership' is the norm that DRM-free streaming is a threat.
Ian Hickson2 years ago
Streaming doesn't need DRM either. Several of the examples I gave in the OP were streaming-specific.
Gareth Adams2 years ago
This is a contrast from your (concise) thoughts last year - - I assume the proposal has changed technically since then, but you had big ethical concerns before, how did you reconcile them?
Ian Hickson2 years ago
+Gareth Adams What is a contrast to that e-mail?

The proposal hasn't changed in any meaningful way, and I have the same concerns now as I had then. I think that what the W3C is doing here is actively harmful, and I refuse to participate in that work. You'll notice that the WHATWG HTML standard doesn't have any support for DRM.
I'm aware streaming doesn't - technically - need DRM - but my point is that the cheaper licence models under which most streaming sites operate are predicated on the restrictions applied to the playback devices.

The multiplexer in your OP is a great idea, and the kind of innovation that DRM-free streaming would allow, but the content owners also know that other innovations would certainly include recording (because that has existed where streaming has been DRM-free or easily cracked), but also devices to redistribute the streams of pay-per-view sporting events or premier movies to your neighbours.

Again - this isn't anything new, this is how they have long differentiated free-to-air broadcast from pay-to-view services.

Change the technology and you change the economics. I
Ian Hickson2 years ago
+Julian Francis-Lawton Sure, that's the point of the OP. The content publishers control the distributors (the streaming sites, in this case), by requiring that they use DRM. They can say they are providing lower prices as an incentive to make the DRM requirement taste less bitter in the negotiations, but at the end of the day that's all it is. It's not like the DRM actually stops the content from being available in copyright-violating venues.
Dave Kay2 years ago
I think your argument boils down to a question of semantics. I'm not saying that the point you are making is invalid... but the idea of multiplexing the Netflix stream, or watching a movie you bought through iTunes on a non-Apple device... is pretty much copying. That's precisely what you have to do - so yes, DRM IS trying to prevent copying - it's just trying to prevent all copying, not just the copying where you give it to a friend or sell it to someone else.
Ian Hickson2 years ago
It's trying to prevent some copying, specifically the kinds of copying (also known as "use") that aren't what the original content provider wants to allow. But it doesn't actually prevent it, all it prevents is the mainstream distributors providing tools that enable those uses easily.+1
peter eckersley2 years ago
This is a pretty clear explanation of why users should fight against DRM at every turn.  Interestingly, it also explains why it isn't clearly in the interests of content creators to support DRM either: there just isn't a clear link between forcing your customers' DVD or Netflix playback experience to suck and actually earning more revenue for ancillary sources.  Such business practices are double-edged swords.

The fact that Hollywood insists on these things is part of the culture of trying to control everything that they developed in a historical era when "exclusive rights" and copyright law were conceptually plausible.  And today, that culture is huge obstacle to building technology that doesn't suck, and to figuring out how to get creators paid without imposing artificial scarcity on things that are no longer naturally scarce.
Steve Faulkner2 years ago
+Ian Hickson wrote:

"I think that what the W3C is doing here is actively harmful, and I refuse to participate in that work. You'll notice that the WHATWG HTML standard doesn't have any support for DRM."

The W3C HTML specification doesn't have any support for DRM and so far the W3C HTML WG have rejected the publication of the EME proposal. Meanwhile your employer has apparently implemented the EME spec (i.e. HTML5 DRM) in all Chrome OS devices, the only browser vendor to do so as far as I know. While I applaud you for speaking up, I am a little unclear how you reconcile your personal opposition to DRM with that of Google who have helped develop DRM in HTML5? While you refuse to participate in the work, it continues apace in the cubicle next to yours.

an addendum after an offline conversation with the sage like +Bruce Lawson

What I can't get my head around is whether allowing built in DRM rather than plugin DRM is so bad and evil that it will destroy the open web or yes it's bad, but not the end as we know it and we have to accept some bad things to bump along with corporate interests? Besides whether we like it or not DRM in HTML is a running code reality.
Oliver Pattison2 years ago
Thanks +Aprotim Sanyal for sharing.

I hear that DRM in music didn't work, but look at the rising music streaming business: music piracy is down somewhat and people are willing to pay nominal amounts for streaming music or consume ads rather than go through the hassle of pirating and maintaining a large music collection. This keeps them locked to a platform like Spotify, Pandora or Rdio, which only runs on certain devices and has severe limitations on the possible library of music available.

That is an example of DRM working: users are limited to a certain context that they can listen to music within. Additionally, if this DRM model continues to succeed, we all end up subject to the whims of a content publishing industry that dictates which music we can easily listen to. I fear a future where people forget that they can purchase and download non-DRM music legally and control their own music library (whether files, or abstracted somehow). If people stop doing that and therefore there is no market for it, it could turn out that the only way to listen to music is through a locked application. This is essentially how the Kindle platform works today, so it's not that far-fetched.

Unfortunately, even if I wanted to rely on a streaming service, I wouldn't be able to find some of my favorite music. Less well-known artists aren't even getting paid properly because of small or non-existent profit margins of the business. I hate to imagine a future of music that is determined by a small group of companies that want to spoon-feed customers exceedingly narrow bands of popular taste.
Sorry to bore - but my point is that if there is no leverage over what the playback devices can do (which I agree with you IS the significant point of DRM) then there is no practical difference between a streaming and 'purchase' based model - which will certainly impact any negotiation with respect to costs.

Or put another way - using iTunes right now I have a choice between an over-priced rental or an over-priced download for double the price.

But with what you are arguing for, there is simply no rental model - I'm only offered the over-priced download. I gain some freedoms, but I lose the 'freedom' to sacrifice utility for price.

(I'm not wholly averse to this - there are plenty of areas where I'd impose my views on child labour or animal welfare over other people's choice to put price over ethics)
Ian Hickson2 years ago
+Julian Francis-Lawton You don't need the user-hostile aspects of DRM (encryption and obfuscation) to implement a rental scheme. iTunes can know when to delete the file whether or not the file is encrypted. Encrypting the file doesn't do anything useful — it doesn't stop copyright violations, since the files are all already available unencrypted online. All it does is stop the inexperienced legitimate customers who have rented the content from using it during the rental period in the way they want.

For example, encrypted videos downloaded from iTunes won't play when screen sharing is active. So as a legitimate user trying to watch my movie during the rental period, I can't screen-share with my media center Mac Mini to control playback. How absurd is that?

Saying you need DRM to do rentals or streaming is like saying a library can't loan books because nobody will return them, or you can't play music on FM radios because FM doesn't have DRM. You know what, most customers are perfectly honest and will not break the license. Those who will are going to do so regardless of the DRM, because the DRM is broken anyway.

The content providers know this. They're not doing the DRM to prevent copyright violations. They do DRM so that they can control the playback software creators.
Gorden Chorney2 years ago
I have nothing to add to this conversation but I do want to thank everyone here for their insight and taking the time to explain the (pros? and) cons of DRM.  I can see a lot of you have put a lot of thought into this.  It's challenging to wrap my head around some of the things discussed.  I get the impression that most of you are 'in the business' in one form or another, so to speak.+2
Christian Kaiser2 years ago
I'd like to echo that sentiment. Really interesting discussion, great points overall. I think we all agree that DRM is not a good solution, and in the long term, business models will/must evolve that make DRM irrelevant.

I guess it comes down to how one sees the world make progress.
As always, on one end of the spectrum, we have the supporters of a dogmatic and uncompromising stance who aim to eventually get their way (perhaps with some blood spilled along the way), and on the other end, we have a group of pragmatists who seem to be comfortable with (sometimes ugly) compromises if they move things in the right direction.

History is full of examples for each of these strategies working in some cases and failing in others. Would be great if we could quantifying the relative odds of success. Seems hard though. :-)
Georg Lobanov2 years ago
Hi all together,
can anybody tell what the advantage of adding DRM to the html5 standard is.
The only advantage that I can see is to content distributors which can use a standardized api instead of a bunch of technologies (flash, silverlight) when using web technologies to distribute content.
I can see no advantages for consumers nor for content providers.
Christian Kaiser2 years ago
It allows HTML5 to be a platform of consideration for premium media consumption applications today.
The alternative is to wait for current business models to be disrupted. The risk is that closed platforms will win the living room (by virtue of major content distributors investing in them instead of in HTML5) while we wait.
Steve Faulkner2 years ago
+Henri Sivonen
as against HTML5 + Flash?
Steve Faulkner2 years ago
so the implementations in chrome devices don't provide some idea?
Roland Orre2 years ago
DRM controls me! I started collecting DVDs first after DeCSS, before I considered it risky and useless. Now likely have around 700 DVDs.
Blu-Ray, no way, as long as I'm not sure the Blu-Ray DRM is completely safely cracked for all future. (purchased one disk 5 years ago, of curiosity that's all).
Georg Lobanov2 years ago
+Henri Sivonen
Hi Mr. Sivonen,
thank you. That's the point. It seems that embedding DRM key management mechanisms is overestimated.
To me there are no crucial advantage of DRM inside html5 and trully said I can see no crucial disadvantages of DRM inside of html5.
If html5 specification would include some DRM mechanisms, even then this would not guarantee that content will play inside your browser or whatever, because decryption will be up to the OS or a closed source implementation trying to prevent the user from copying and watching content on other devices or in some other manner not covered by the licence argreement.
If content providers would not trust an OS e.g. linux (as they already seem not to do), then there will be no legal implementation of DRM on open linux systems, and DRM inside of html5 will not remedy this problem at all.
I'm willing to pay for the rental of content, but I don't want to be forced to buy some hardware just to figure out, that the hardware that I purchased is crap or the store the hardware is bound to is crap, as video availablity in google's Play Store in Europe (Germany) is!
Randall Arnold2 years ago
+John Werneken IP does not protect ideas.  This is a common fallacy that I wish would just die.

IP protects the rendition of ideas.  As originally intended, it was designed to protect the "little guy" from heavy-handed corporate interests.  In recent years that purpose has been corrupted.  Don't make the mistake of blaming the original intent for the current corruption.
Roland Orre2 years ago
What kind of world are you living in +Randall Arnold, in theory immaterial rights like patents (I refuse to use the weird collective term abbreviated  by IP...) would cover an implementation of a specific idea, but then came these abominations denoted "software patents" and "business model patents". Have you ever seen a software patent covering a specific method implemented in some particular language? No, it's pure monopolism on ideas!
Also when you study material patents you'll find that it's merely the idea behind a design which is patented. Then in English it's also a little confusing as "patents" can refer to "design patents" (bascially a specific pattern or shape) as well as the "idea patents" which most people associate with patents.