How to prevent video downloads from your website

Most course video downloads use ordinary gaps: plain file links, download tools, keys any session can fetch and shared logins. What fails, the warning signs and what to ask.

7 min read
On this page 8 sections
  1. How videos actually get downloaded from websites
  2. Why the usual defences fail
  3. Warning signs that your videos are exposed
  4. What to ask your video platform
  5. The law is on your side
  6. Key takeaways
  7. Where VidSafe fits
  8. Frequently asked questions

You can't make it impossible for a determined viewer to save a video that plays on their own screen, but you can stop your website from making it easy. In practice, downloads come through a handful of routes: plain file links, download tools that capture whatever the player fetches, decryption keys handed to any logged-in session, shared logins and screen recording. Knowing those routes shows you which defences are cosmetic, such as right-click blocking, and what to demand from your video platform.

How videos actually get downloaded from websites

Piracy of course videos seldom needs clever hacking. It usually exploits one of these ordinary gaps:

  • Plain file links. Some course sites upload a lecture to cloud storage and play it straight from that file's address, behind a login page. The login protects the page, not the file. The address works for anyone who has it, in another tab, in a download manager or pasted into a Telegram group, often long after the student's fees have lapsed.

  • The browser itself. Right-clicking a video usually offers "Save video as", and built-in video controls often include a download option.

  • Download tools and extensions. Browser extensions and desktop downloaders watch the requests a page makes, spot video files and playlists, and fetch the same addresses. The Chrome Web Store's policies forbid extensions that enable unauthorised downloading of copyrighted media, yet note that video downloaders remain available, just not featured. Assume your students have them.

  • Stream rippers. Streaming formats split a lecture into hundreds of short segments. That stops one-click saving, but tools exist that read the playlist, download every segment and join them back into one file.

  • Keys fetched inside a paying student's session. If a stream is encrypted but the player simply requests its key from a server, software running in the same logged-in session can often request it too. The HLS specification itself says key delivery should be protected (RFC 8216), which shows where the weak point sits.

  • Shared logins. One paid account passed around a group gives every member the same access, and every one of them can use the routes above.

  • Screen and camera recording. No download is needed at all when someone records the screen or films it with a second phone. See how to stop screen recording on a website.

  • Forgotten routes. An old app version that plays plain files, a link in last year's WhatsApp broadcast, an admin tool with a direct download button. One open door undoes everything else.

Why the usual defences fail

DefenceHow it gets bypassedWhat it's worth
Blocking right-click, hiding the download buttonDeveloper tools, keyboard shortcuts, extensions, or anyone who already has the file's addressStops casual saving only, and annoys honest students
Hiding the video's address in scriptsThe browser still requests the real files, and any tool watching network traffic sees themCosmetic
A login page in front of the videoThe file's own link works without logging inOften nothing: it's one of the commonest holes
Splitting video into streaming segmentsRippers download and rejoin the segmentsRaises the effort, doesn't stop it
Encryption with a key the player simply fetchesTools in a logged-in session fetch the key as the player doesOnly as good as the rules on who gets the key
Links that expireShared and used before they expire, or set to last for daysDepends on how short-lived and personal the links are
Checking which site a request came fromThat header is easy to fake, and many requests don't send itA first filter against other websites, not against students

Our explainers on signed URLs and hotlink protection and HLS encryption go deeper into why expiring links and encrypted streams fail when they're set up carelessly.

Warning signs that your videos are exposed

  • A lecture link still works when opened by someone who isn't logged in, or by a student whose access has ended.

  • Leaked copies on Telegram are clean and in full original quality. A copy with no screen-recording artefacts often means the file itself was downloaded.

  • Whole courses leak in one go, soon after a batch opens, rather than a lecture at a time.

  • Old links in emails, WhatsApp broadcasts or outdated app versions still play.

  • One account watches from several phones and cities on the same day.

  • When a copy leaks, nothing in it tells you whose account it came from.

If several of these apply, the problem is structural, and no front-end trick will fix it. For the wider picture beyond downloads, including recording, account sharing and takedowns, see our guide to protecting online course videos.

What to ask your video platform

  1. Is any lecture ever available as a plain file, on any device or app version?

  2. If someone copies a video link and shares it, how quickly does it stop working, and does it work at all for a different person?

  3. Who can obtain the key to an encrypted lecture, and what is checked first?

  4. Does access end the moment a student's enrolment or instalment lapses?

  5. What happens when a download tool or screen recorder is used during playback?

  6. How many devices can one account use, and can you see where an account is watching from?

  7. If a lecture leaks, can the copy be traced to the account it came from?

A vendor that answers these clearly, without retreating to "it's encrypted", takes piracy seriously. Our checklist for secure video hosting turns these into a scorecard.

The law is on your side

Copying and sharing paid lectures without permission infringes copyright. Deliberately getting around technical protection such as encryption, with the intention of infringing, is also a separate criminal offence under Section 65A of the Copyright Act, punishable with up to two years in prison and a fine. Our guide to copyright infringement punishment in India explains the sections. This is general information, not legal advice. For your situation, speak to a lawyer.

Key takeaways

  • Downloads usually exploit ordinary gaps: plain file links, download tools, keys given to any session, shared logins and old routes.

  • Right-click blocking and hidden addresses are cosmetic; they don't change what the browser downloads.

  • Segmenting and encrypting a stream only help if nobody but an entitled student can get the key.

  • Screen and camera recording need no download at all, so traceable copies matter as much as blocked ones.

  • Judge a platform by its answers to specific questions, not by the word "encrypted".

Where VidSafe fits

Upclass gives institutes their own course website and branded apps on Android, iOS, Windows and macOS. VidSafe protects the videos with VidSafe proprietary encryption, screen- and camera-recording detection, account-sharing prevention and PDF watermarking, and it adds visible and invisible watermarks that are extremely hard to remove, even after heavy re-encoding, so a leaked copy can be traced back to the account it came from. See our LMS for coaching institutes.

Related reading: common piracy-protection myths.

Frequently asked questions

Can you disable right click on website?

Yes. A small script can block the right-click menu on a page or just on the video, and some browsers let a page hide the video's download button. But it only stops casual saving. Developer tools, keyboard shortcuts, extensions and anyone who has the file's address get around it easily, and it annoys honest students who want to copy text. Treat it as a speed bump, not protection.

How to protect video from download?

You can't make downloading impossible, but you can make it hard and traceable. Make sure no lecture is ever served as a plain file, that shared links stop working quickly and don't work for anyone else, that keys go only to enrolled students, and that every copy carries the viewer's identity. Then ask your platform how it handles each download route described in this guide.

How to prevent video download from YouTube?

You can't fully prevent it. YouTube's terms forbid downloading without YouTube's permission, but third-party tools still work on public and unlisted videos alike. You can make a video private, turn off embedding and use YouTube's copyright tools against re-uploads. For paid lectures, the real answer is not to host them on YouTube at all; our guide to unlisted YouTube links explains why.

Share this article

Looking for something else?

Talk to Us