How DRM gets cracked, and why no DRM is unbreakable

No DRM is unbreakable. How it gets defeated in practice, from the analogue hole and software-only levels to HDCP strippers, compromised devices, shared logins and insiders.

10 min read
On this page 11 sections
  1. Why no DRM is unbreakable
  2. Route 1: the analogue hole
  3. Route 2: weaker, software-only security levels
  4. Route 3: HDCP strippers
  5. Route 4: compromised devices
  6. Route 5: leaked, shared and sold credentials
  7. Route 6: insiders
  8. What this means for an institute
  9. What to ask a vendor
  10. Key takeaways
  11. Frequently asked questions

DRM usually gets cracked by going around it rather than by breaking its encryption: filming the screen, attacking the weaker software-only versions that run on ordinary computers, stripping protection from the video cable, using a compromised device, or simply logging in with someone else's account. No DRM is unbreakable, because the device that has to decrypt the video sits in the hands of the person you are protecting it from. For an institute, the useful question isn't whether a platform's protection can be broken, but what happens when it is.

Why no DRM is unbreakable

DRM has a problem that ordinary encryption doesn't. When a bank encrypts a transfer, the only people with keys are the bank and you, and you want the data protected. With DRM, the video has to be decrypted on the viewer's own laptop or phone, so the key has to reach a device the viewer controls. DRM tries to keep that key, and the decrypted pictures, out of the viewer's reach, either by locking them inside protected hardware or by hiding them in deliberately confusing software.

Both approaches raise the cost of an attack; neither makes one impossible. Hidden software can be studied for as long as an attacker likes. Protected hardware is much harder to attack, but it still has to send pictures to a screen and sound to a speaker, and it trusts that the account asking for a licence belongs to a paying customer. Every route below exploits one of those facts. Our explainer on what DRM is and how it works covers the pieces involved.

There's also an economic twist. A single successful break doesn't produce one copy; it produces a clean file that can be copied endlessly. That's why pirates only need to succeed once for each lecture, while a platform has to hold every door shut every time.

Route 1: the analogue hole

The oldest way round DRM needs no technical skill at all. However well the video is protected on its way to the screen, it ends up as light and sound in a room, and a second phone on a stand can record it. Security engineers call this the analogue hole. No DRM system can see a separate camera, because the camera never touches the device playing the video.

For films, a camera copy is a poor substitute. For lectures, it often isn't. A student watching a leaked economics or polity class needs a readable board and a clear voice, and a mid-range phone captures both. That makes the analogue hole a bigger problem for coaching institutes than for film studios; our guide to camcording with a phone camera looks at it in detail.

Route 2: weaker, software-only security levels

Each DRM system has levels. Hardware-backed levels, such as Widevine L1 and PlayReady SL3000, keep keys and decrypted video inside a protected area of the chip. Software-only levels, such as Widevine L3 and PlayReady SL2000, rely on obfuscated code running on the ordinary processor, where an attacker can watch and probe it. Chrome and Firefox on Windows, Mac and Linux computers use Widevine's software-only level, because ordinary computers usually lack the trusted hardware it needs.

That weakness has been demonstrated in public. In January 2019, a security researcher announced that he had broken Widevine's software-only level, L3, allowing content protected at that level to be decrypted. The hardware-backed L1 level wasn't affected, and many streaming services already allowed only lower-resolution playback on L3 for exactly this reason.

Why this route matters: a recovered key produces a perfect digital copy, with no camera wobble or lost quality. For a course platform whose students often watch in a desktop browser, the software-only level may be where much of its viewing happens. Our comparison of Widevine L1 and L3 explains the levels in more detail.

Route 3: HDCP strippers

When protected video leaves a laptop or set-top box for a monitor or TV, a separate protection called HDCP encrypts the signal on the cable, so that a capture device plugged in between can't record it. Many DRM systems require HDCP for high-quality output.

HDCP has a long record of weaknesses. In 2010, a master key for HDCP was published online, and Intel, which developed HDCP, confirmed it was genuine. Devices that strip HDCP from a signal, or quietly downgrade it to an older, weaker version, are sold openly, some of them looking like ordinary splitters or converters. With one in place between a player and a capture device, the recorder receives an unprotected signal. The DRM on the player has done its job perfectly and still loses the video. Our guide to HDCP and screen mirroring explains why the cable is such a weak link.

Route 4: compromised devices

DRM assumes the device's operating system is behaving as designed. Rooted Android phones, jailbroken iPhones, emulators running on a computer and modified copies of an app all break that assumption. On such devices, an attacker can watch an app while it works, switch off protections such as recording blocks, or run many copies of one account automatically. Some phones also lose their hardware-backed DRM level once they are rooted or their bootloader is unlocked, dropping to the weaker software level.

Modified "premium" versions of popular apps, with protections stripped out, are regularly passed around outside the app stores. They can also carry malware, which is one more reason students should stay away from them. Our guide to root, jailbreak and emulator detection explains why spotting these devices is an arms race.

Route 5: leaked, shared and sold credentials

The simplest crack isn't a crack at all. DRM checks whether an account is entitled to a licence; it has no idea who is holding the phone. A login shared with friends, sold in a Telegram group, phished from a student or guessed because the password was reused elsewhere gets a perfectly valid licence, and every protection works exactly as designed while the wrong person watches. Combine a shared login with a camera or a compromised device, and one paid account can supply a whole leak channel. Why logins are so hard to lock down is covered in our guide to students sharing accounts.

Route 6: insiders

Some of the cleanest leaks never touch DRM. Faculty, video editors, back-office staff and outside vendors often handle the original recordings before they are protected, and anyone with access to an admin panel may be able to reach content, keys or student accounts. Former staff whose access was never removed are a classic gap. Insider leaks can't be solved by DRM at all; they need tight access control, logs of who downloaded what, and copies that can be traced.

What this means for an institute

  • Assume a bypass exists. Every route above is well known and has been used. Judge a platform by what happens after a bypass, not by claims that its protection "can't be broken".

  • You're as strong as your weakest path. The protection on your best-supported phone doesn't matter if a desktop browser, an old app version or a forgotten download link is weaker.

  • Low-tech routes matter most. Cameras, shared logins and insiders need no technical skill, so anyone in a batch can use them, while breaking DRM itself takes rare expertise.

  • Traceability is your fallback. When a copy escapes, you need to know which account it came from, so you can close that account, act on your terms of use and, if needed, go to court.

  • The law helps, after the fact. Under section 65A of India's Copyright Act, 1957, circumventing an effective technological measure with the intention of infringing copyright is an offence punishable with up to two years' imprisonment and a fine. Sharing or selling the resulting copies infringes copyright under section 51, and knowingly doing so is an offence under section 63. Our guide to copyright infringement penalties in India covers the detail.

What to ask a vendor

  1. What happens on the weakest device you support: desktop browsers, old Android phones, rooted or jailbroken phones and emulators?

  2. If the key for one lecture were recovered, how much of our library would be exposed?

  3. What happens when a screen is mirrored, or video is sent to an external display or capture device?

  4. How do you notice modified copies of our app, and what happens when one is used?

  5. How do you stop one login being shared or sold, without locking out honest students who change phones?

  6. If a lecture leaks anyway, can you trace the copy back to the account it came from, even after it has been cropped, re-encoded or screen-recorded?

  7. Who, on your side and ours, can reach original files, keys and student accounts, and is that access logged?

  8. How quickly do you respond when a new bypass becomes public?

A vendor who answers these clearly is taking piracy seriously. One who only repeats that its protection is "unbreakable" is telling you something too.

Key takeaways

  • No DRM is unbreakable, because the viewer's own device has to decrypt the video and the picture has to reach a screen.

  • Software-only levels are the weakest; Widevine's L3 level was publicly broken in 2019, while hardware-backed L1 wasn't affected.

  • HDCP strippers, compromised devices, shared logins and insiders all defeat DRM without breaking its encryption.

  • For coaching institutes, the low-tech routes, cameras, shared logins and insiders, need no skill at all, which makes them the biggest risk.

  • Ask vendors what happens after a bypass, and whether a leaked copy can be traced to its source.

VidSafe adds visible and invisible watermarks that are extremely hard to remove, even after heavy re-encoding, so a leaked copy can be traced back to the account it came from. It also brings VidSafe proprietary encryption, screen- and camera-recording detection, account-sharing prevention, PDF watermarking and RASP to institutes' apps and players.

Frequently asked questions

Can DRM be cracked?

Yes. DRM has been defeated in several ways: software-only security levels have been broken, HDCP on video cables can be stripped, compromised devices let attackers switch protections off, and no DRM can stop a camera filming the screen or a shared login receiving a valid licence. Hardware-backed DRM is much harder to attack directly, which is why leaks usually go around it rather than through it.

Has Widevine been cracked?

Its software-only level has. In January 2019, a security researcher publicly announced that he had broken Widevine L3, the level most desktop browsers use. The hardware-backed L1 level, used on many Android phones, TVs and streaming devices, wasn't affected. That's why many streaming services allow only lower resolutions on software-only devices.

What is an HDCP stripper?

It's a device that sits on an HDMI connection and removes HDCP, the copy protection on the cable, or downgrades it to an older, weaker version. The screen or recorder on the other side then receives an unprotected signal. Such devices are sold openly, some looking like ordinary splitters or converters, which is why DRM that relies on HDCP for output protection has a weak link at the cable.

Is cracking DRM illegal in India?

Circumventing an effective technological measure, such as DRM or encryption, with the intention of infringing copyright is an offence under section 65A of the Copyright Act, 1957, punishable with up to two years' imprisonment and a fine. Sharing or selling the copies infringes copyright under section 51, and knowingly doing so is an offence under section 63. This is general information, not legal advice.

Is there any DRM that can't be broken?

No. Hardware-backed DRM is far harder to attack than software-only DRM, but every system shares the same limits: the video must be shown on a screen, the viewer's device must hold the key, and the account asking for a licence may not belong to the person watching. Good protection makes leaking harder, riskier and traceable rather than impossible.

Share this article

Looking for something else?

Talk to Us