Your DRM Can Watch You Too: Exploring the Privacy Implications of Browsers (mis)Implementations of Widevine EME

08/10/2023
by   Gwendal Patat, et al.
0

Thanks to HTML5, users can now view videos on Web browsers without installing plug-ins or relying on specific devices. In 2017, W3C published Encrypted Media Extensions (EME) as the first official Web standard for Digital Rights Management (DRM), with the overarching goal of allowing seamless integration of DRM systems on browsers. EME has prompted numerous voices of dissent with respect to the inadequate protection of users. Of particular interest, privacy concerns were articulated, especially that DRM systems inherently require uniquely identifying information on users' devices to control content distribution better. Despite this anecdotal evidence, we lack a comprehensive overview of how browsers have supported EME in practice and what privacy implications are caused by their implementations. In this paper, we fill this gap by investigating privacy leakage caused by EME relying on proprietary and closed-source DRM systems. We focus on Google Widevine because of its versatility and wide adoption. We conduct empirical experiments to show that browsers diverge when complying EME privacy guidelines, which might undermine users' privacy. For instance, we find that many browsers gladly give away the identifying Widevine Client ID with no or little explicit consent from users. Moreover, we characterize the privacy risks of users tracking when browsers miss applying EME guidelines regarding privacy. Because of being closed-source, our work involves reverse engineering to dissect the contents of EME messages as instantiated by Widevine. Finally, we implement EME Track, a tool that automatically exploits bad Widevine-based implementations to break privacy.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
03/03/2021

Exploring Privacy Implications in OAuth Deployments

Single sign-on authentication systems such as OAuth 2.0 are widely used ...
research
01/31/2022

Privacy Limitations Of Interest-based Advertising On The Web: A Post-mortem Empirical Analysis Of Google's FLoC

In 2020, Google announced they would disable third-party cookies in the ...
research
04/20/2022

Exploring Widevine for Fun and Profit

For years, Digital Right Management (DRM) systems have been used as the ...
research
03/16/2022

One Bad Apple Can Spoil Your IPv6 Privacy

IPv6 is being more and more adopted, in part to facilitate the millions ...
research
10/24/2021

The privacy protection effectiveness of the video conference platforms' virtual background and the privacy concerns from the end-users

Due to the abrupt arise of pandemic worldwide, the video conferencing pl...
research
06/13/2023

Is Your Wallet Snitching On You? An Analysis on the Privacy Implications of Web3

With the recent hype around the Metaverse and NFTs, Web3 is getting more...
research
09/29/2021

Conflicting Privacy Preference Signals in the Wild

Privacy preference signals allow users to express preferences over how t...

Please sign up or login with your details

Forgot password? Click here to reset