How to prevent video downloads from your website
Most course video downloads use ordinary gaps: plain file links, download tools, keys any session can fetch and shared logins. What fails, the warning signs and what to ask.
On this page 8 sections
You can't make it impossible for a determined viewer to save a video that plays on their own screen, but you can stop your website from making it easy. In practice, downloads come through a handful of routes: plain file links, download tools that capture whatever the player fetches, decryption keys handed to any logged-in session, shared logins and screen recording. Knowing those routes shows you which defences are cosmetic, such as right-click blocking, and what to demand from your video platform.
How videos actually get downloaded from websites
Piracy of course videos seldom needs clever hacking. It usually exploits one of these ordinary gaps:
- Plain file links. Some course sites upload a lecture to cloud storage and play it straight from that file's address, behind a login page. The login protects the page, not the file. The address works for anyone who has it, in another tab, in a download manager or pasted into a Telegram group, often long after the student's fees have lapsed.
- The browser itself. Right-clicking a video usually offers "Save video as", and built-in video controls often include a download option.
- Download tools and extensions. Browser extensions and desktop downloaders watch the requests a page makes, spot video files and playlists, and fetch the same addresses. The Chrome Web Store's policies forbid extensions that enable unauthorised downloading of copyrighted media, yet note that video downloaders remain available, just not featured. Assume your students have them.
- Stream rippers. Streaming formats split a lecture into hundreds of short segments. That stops one-click saving, but tools exist that read the playlist, download every segment and join them back into one file.
- Keys fetched inside a paying student's session. If a stream is encrypted but the player simply requests its key from a server, software running in the same logged-in session can often request it too. The HLS specification itself says key delivery should be protected (RFC 8216), which shows where the weak point sits.
- Shared logins. One paid account passed around a group gives every member the same access, and every one of them can use the routes above.
- Screen and camera recording. No download is needed at all when someone records the screen or films it with a second phone. See how to stop screen recording on a website.
- Forgotten routes. An old app version that plays plain files, a link in last year's WhatsApp broadcast, an admin tool with a direct download button. One open door undoes everything else.
Why the usual defences fail
| Defence | How it gets bypassed | What it's worth |
|---|---|---|
| Blocking right-click, hiding the download button | Developer tools, keyboard shortcuts, extensions, or anyone who already has the file's address | Stops casual saving only, and annoys honest students |
| Hiding the video's address in scripts | The browser still requests the real files, and any tool watching network traffic sees them | Cosmetic |
| A login page in front of the video | The file's own link works without logging in | Often nothing: it's one of the commonest holes |
| Splitting video into streaming segments | Rippers download and rejoin the segments | Raises the effort, doesn't stop it |
| Encryption with a key the player simply fetches | Tools in a logged-in session fetch the key as the player does | Only as good as the rules on who gets the key |
| Links that expire | Shared and used before they expire, or set to last for days | Depends on how short-lived and personal the links are |
| Checking which site a request came from | That header is easy to fake, and many requests don't send it | A first filter against other websites, not against students |
Our explainers on signed URLs and hotlink protection and HLS encryption go deeper into why expiring links and encrypted streams fail when they're set up carelessly.
Warning signs that your videos are exposed
- A lecture link still works when opened by someone who isn't logged in, or by a student whose access has ended.
- Leaked copies on Telegram are clean and in full original quality. A copy with no screen-recording artefacts often means the file itself was downloaded.
- Whole courses leak in one go, soon after a batch opens, rather than a lecture at a time.
- Old links in emails, WhatsApp broadcasts or outdated app versions still play.
- One account watches from several phones and cities on the same day.
- When a copy leaks, nothing in it tells you whose account it came from.
If several of these apply, the problem is structural, and no front-end trick will fix it. For the wider picture beyond downloads, including recording, account sharing and takedowns, see our guide to protecting online course videos.
What to ask your video platform
- Is any lecture ever available as a plain file, on any device or app version?
- If someone copies a video link and shares it, how quickly does it stop working, and does it work at all for a different person?
- Who can obtain the key to an encrypted lecture, and what is checked first?
- Does access end the moment a student's enrolment or instalment lapses?
- What happens when a download tool or screen recorder is used during playback?
- How many devices can one account use, and can you see where an account is watching from?
- If a lecture leaks, can the copy be traced to the account it came from?
A vendor that answers these clearly, without retreating to "it's encrypted", takes piracy seriously. Our checklist for secure video hosting turns these into a scorecard.
The law is on your side
Copying and sharing paid lectures without permission infringes copyright. Deliberately getting around technical protection such as encryption, with the intention of infringing, is also a separate criminal offence under Section 65A of the Copyright Act, punishable with up to two years in prison and a fine. Our guide to copyright infringement punishment in India explains the sections. This is general information, not legal advice. For your situation, speak to a lawyer.
Key takeaways
- Downloads usually exploit ordinary gaps: plain file links, download tools, keys given to any session, shared logins and old routes.
- Right-click blocking and hidden addresses are cosmetic; they don't change what the browser downloads.
- Segmenting and encrypting a stream only help if nobody but an entitled student can get the key.
- Screen and camera recording need no download at all, so traceable copies matter as much as blocked ones.
- Judge a platform by its answers to specific questions, not by the word "encrypted".
Where VidSafe fits
Upclass gives institutes their own course website and branded apps on Android, iOS, Windows and macOS. VidSafe protects the videos with VidSafe proprietary encryption, screen- and camera-recording detection, account-sharing prevention and PDF watermarking, and it adds visible and invisible watermarks that are extremely hard to remove, even after heavy re-encoding, so a leaked copy can be traced back to the account it came from. See our LMS for coaching institutes.
Related reading: common piracy-protection myths.
Frequently asked questions
Can you disable right click on website?
Yes. A small script can block the right-click menu on a page or just on the video, and some browsers let a page hide the video's download button. But it only stops casual saving. Developer tools, keyboard shortcuts, extensions and anyone who has the file's address get around it easily, and it annoys honest students who want to copy text. Treat it as a speed bump, not protection.
How to protect video from download?
You can't make downloading impossible, but you can make it hard and traceable. Make sure no lecture is ever served as a plain file, that shared links stop working quickly and don't work for anyone else, that keys go only to enrolled students, and that every copy carries the viewer's identity. Then ask your platform how it handles each download route described in this guide.
How to prevent video download from YouTube?
You can't fully prevent it. YouTube's terms forbid downloading without YouTube's permission, but third-party tools still work on public and unlisted videos alike. You can make a video private, turn off embedding and use YouTube's copyright tools against re-uploads. For paid lectures, the real answer is not to host them on YouTube at all; our guide to unlisted YouTube links explains why.