What is DRM, how does it work, and where does it fail?
DRM in plain English: encrypted video, licences and device security levels, what DRM does well, where it fails in practice, and what to ask a video platform.
On this page 9 sections
DRM, short for digital rights management, is technology that lets a video play only on approved devices, for approved users and under set rules, without handing over a copy that can be freely saved and shared. It combines encrypted video, a licence service that decides who gets the key, and a protected module on the device that decrypts and plays the video. It is good at controlling delivery, and it has well-known gaps once a lecture is on screen.
Try taking a screenshot while a film plays in a streaming app, and on many phones you'll get a black rectangle. That's DRM at work. Here's what it does in outline, where it is strong, where it fails, and what to ask any platform that promises "protected video".
The problem DRM tries to solve
Streaming means sending the video to the viewer's device, and encrypting it is the obvious first step. But encryption alone runs into a paradox: the device has to decrypt the video to play it, so it needs the key. If that key sits in ordinary app or browser memory, a determined person can get hold of it and save a clean copy.
That's the difference between encrypted streaming and DRM. Standard encrypted streaming, often advertised as "AES-128 encrypted" video, lets the player fetch the key and handle it in ordinary memory. It stops casual downloading but not a determined copier. DRM hands the key only to a locked-down component on the device, after a licence check, and tries to keep the key, and ideally the decrypted pictures, out of reach. Our comparison of DRM and encryption goes further into the difference.
How DRM works, in outline
- Encrypted media. Each video is encrypted before it is published. The files can be downloaded by anyone, but they are useless without the key.
- A licence service. It decides who gets keys, for instance whether a student is enrolled and their access hasn't expired, and attaches rules such as expiry dates and offline viewing windows.
- A content decryption module. A trusted component built into the browser or operating system receives the licence, holds the key and decrypts the video.
- The player. The web or app player fetches the video and passes messages between the device's module and the licence service.
In one line: the player asks for a licence → the licence service checks the viewer is entitled → the device's DRM module gets the key and the rules → the video plays.
The three big DRM systems
| System | Made by | Where it runs | Security levels |
|---|---|---|---|
| Widevine | Chrome, Firefox, Chromium-based Edge, Android phones and TVs, and many smart TVs and streaming sticks | L1 (hardware-backed) and L3 (software-only); L2 is rare | |
| FairPlay Streaming | Apple | Safari, iPhone, iPad, Mac and Apple TV | No public tiers; relies on Apple's platform security |
| PlayReady | Microsoft | Edge on Windows, Xbox, and many smart TVs and set-top boxes | SL3000 (hardware-backed) and SL2000 (software-based) |
Because each platform ships its own module, a service that wants DRM on Android phones, iPhones, laptops and TVs usually has to support all three, an arrangement called multi-DRM. Our explainer on multi-DRM covers how the three fit together.
Security levels: where DRM is strong and where it's weak
The most important detail in any DRM setup is where decryption happens.
- Hardware-backed (Widevine L1, PlayReady SL3000, FairPlay on Apple devices): keys and decrypted video stay inside a protected area of the chip, isolated from the main operating system. This is why screenshots of protected video come out black on many phones.
- Software-only (Widevine L3, used by most desktop browsers, and PlayReady SL2000): protection relies on obfuscated code running on the ordinary processor, which is much easier to attack.
The weakness of software-only DRM has been shown in public. In January 2019, a security researcher showed that Widevine's L3 level could be broken; the hardware-backed L1 level wasn't affected. Premium streaming services often limit video quality on software-only devices for this reason. A phone that has been rooted or had its bootloader unlocked may also fall back to software-only protection. Our comparison of Widevine L1 and L3 explains the levels in more detail.
What DRM does well
- It makes downloaded video files useless without a valid licence.
- It enforces access rules such as expiry dates, rental periods and offline viewing windows.
- It blocks screenshots and screen recordings on hardware-backed devices.
- It can require protected connections to external screens.
Where DRM fails in practice
Every one of these gaps is a common way paid lectures leak:
- The analogue hole. DRM can't stop someone filming the screen with a second phone. The camera never touches the protected device.
- Weaker devices. Desktop browsers with software-only DRM, rooted phones and emulators offer far less protection than a phone with hardware-backed security.
- Mirroring and capture hardware. HDCP, the protection on HDMI links, has well-known weaknesses, and a protected signal isn't always protected all the way to the recorder.
- Shared logins. DRM checks that an account holds a valid licence. It can't tell a paying student apart from five friends using that student's password, which is why account sharing needs separate answers.
- Gaps around the DRM. An old app version, a forgotten API or a download link that never expires can hand out unprotected files, however strong the DRM on the main path.
- Everything that isn't video. PDFs, notes and test papers are outside video DRM altogether.
- Insiders. Staff and freelancers who handle the original recordings work with files that never pass through DRM.
We look at each of these routes, and why they work, in why DRM alone can't stop piracy. Getting round DRM is also a legal matter: under section 65A of India's Copyright Act, 1957, circumventing an effective technological measure with the intention of infringing copyright is an offence punishable with up to two years' imprisonment and a fine.
Questions to ask your video platform
Whether a platform uses DRM or its own protection, the useful questions are about outcomes, not labels:
- How are decryption keys protected on the student's device, and what happens in desktop browsers, on rooted phones and on emulators?
- What happens when a screen recording or screen mirroring starts?
- If a lecture is filmed with a second phone and leaks, can you trace the copy back to the account it came from, even after it has been cropped or re-encoded?
- How do you stop one login being shared by a group, without locking out honest students who change phones?
- Are PDFs and notes protected and traceable too?
- Can any old app version, API or link still serve unprotected files?
- When a student's access ends, does playback stop everywhere, including offline downloads?
Key takeaways
- DRM combines encrypted video with a licence service and a trusted decryption module on the device.
- Widevine, FairPlay and PlayReady cover different platforms, so services that rely on DRM usually support all three.
- Hardware-backed security levels are far stronger than software-only ones, and Widevine's software level was publicly broken in 2019.
- DRM secures delivery and enforces playback rules, but it can't stop camera recording, shared logins, leaked PDFs or insiders.
- Judge any platform by what happens after decryption, and by whether it can trace a leak to its source.
VidSafe protects lectures with VidSafe proprietary encryption and adds visible and invisible watermarks that are extremely hard to remove, even after heavy re-encoding, so a leaked copy can be traced back to the account it came from. Screen- and camera-recording detection, account-sharing prevention, PDF watermarking and RASP complete the picture.
Frequently asked questions
What is DRM in simple words?
DRM is a set of technologies that lets you watch a video without being given a copy you can keep. The video is encrypted, a licence service decides whether you may watch it, and a protected part of your device decrypts and plays it under rules such as an expiry date. Netflix, Prime Video and many course platforms use it to control how their videos are played.
What are Widevine, FairPlay and PlayReady?
They are the three main DRM systems. Widevine, from Google, runs in Chrome, Firefox and on Android. FairPlay, from Apple, runs in Safari and on iPhones, iPads, Macs and Apple TV. PlayReady, from Microsoft, runs in Edge on Windows, on Xbox and on many smart TVs. A service that wants DRM on every common device usually supports all three.
Can DRM be cracked?
Yes, in several ways, which is why no DRM is unbreakable. Software-only levels are the weakest: Widevine's L3 level was publicly broken by a security researcher in 2019. Hardware-backed levels are much harder to attack, but every level is exposed to screen filming, shared logins and compromised devices. Circumventing DRM to infringe copyright is an offence in India under section 65A of the Copyright Act.
Does DRM stop screen recording?
On many phones with hardware-backed DRM, screen recordings of protected video come out black. On desktop browsers that use software-only DRM, through screen mirroring, and on rooted or modified devices, recording often still works. No DRM can stop a second phone filming the screen, which is why a leaked lecture needs to be traceable to its source.
Is DRM the same as encryption?
No. Encryption scrambles the video so it can't be watched without a key. DRM adds rules about who gets that key, on which devices and for how long, and tries to keep the key out of reach on the device. All DRM uses encryption, but encrypted streaming on its own isn't DRM.