Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

And the ability to play video without being exploited by Flash vulnerabilities is not a positive thing?


It's not a hell of a lot of change when the DRM blob that gets sent down the wire is just as opaque.


I can only assume you're just posturing because the size and scope of Flash and the size of scope of Flash's security problems are _way_ beyond just a DRM blob.


> size of scope of Flash's security problems are _way_ beyond just a DRM blob.

Not sure about that, considering the Widevine's CVEs on Android have been quite bad with privelege escalation and sandbox escaping.

A bad video can still be enough to burn your system. That's a full security scope right there.


Just the source, because I hate unsourced claims.

[0] http://www.cvedetails.com/cve/CVE-2015-6639/ - Integrity Impact Complete (There is a total compromise of system integrity. There is a complete loss of system protection, resulting in the entire system being compromised.)

It is also worth noting that finding vulnerabilities may be a crime in many jurisdictions [1] (thanks to the DCMA), which would prevent researching coming forward.

[1] https://www.eff.org/deeplinks/2016/03/interoperability-and-w...


But this problem didn't affect sites using DRM, it just undermined sites that preferred not to.

This problem is the reason a lot more sites have rapidly switched to using DRM or other less easily exploitable ways to serve video this year.


At least in Firefox (don't know about Chrome), it's also much more restricted in what it can do.


You can at least disable the DRM and still watch videos without it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: