Widevine L1 vs L3: security levels explained
Widevine L1 keeps keys in hardware; L3 keeps them in software and was publicly broken in 2019. Why that matters, why apps cap L3 quality, and what to ask.
On this page 11 sections
Widevine L1 means a device decrypts and processes protected video inside a hardware-isolated trusted execution environment (TEE); L3 means it does everything in ordinary software, and L2, which keeps only the cryptography in hardware, is rare. The difference decides how easily the protection can be broken: L3 keeps its keys in software on a device the user controls, and Widevine's software level was publicly broken in 2019. That's why streaming services cap quality on L3 devices, and why the same phone can get HD in one app and SD in another.
What Widevine is
Widevine is Google's DRM system, one of the big three alongside Apple's FairPlay and Microsoft's PlayReady. It runs on Android phones and TVs, ChromeOS, Chromecast and many smart TVs and set-top boxes, and in browsers including Chrome, Firefox, Edge and Opera. Content providers need a licence agreement with Google, which charges no fee for Widevine itself. For how DRM works in general, see our explainer on how DRM works; for serving all three systems from one library, see multi-DRM.
L1, L2 and L3
Android's MediaDrm documentation defines the security levels behind Widevine's labels. In plain terms:
| Level | What happens inside protected hardware | What it means |
|---|---|---|
| L1 | Key handling, decryption, decoding and all handling of the video | Neither apps nor the operating system see keys or decrypted frames; the level services typically require for HD and above |
| L2 | Key handling and decryption only; decoding happens outside | Uncommon; decrypted video still passes through ordinary memory |
| L3 | Nothing: keys are guarded by obfuscated software | Works almost everywhere, and is by far the easiest level to attack |
L1 depends on the phone's chipset and on how the manufacturer has integrated Widevine. An app can't add it.
Why L3 is the weak link
- Keys live in software. At L3, keys are protected only by obfuscated code running on the ordinary processor of a device the user fully controls. Widevine's software level was publicly broken in 2019, and when keys are extracted, the encrypted video files can be decrypted outright into clean copies.
- Decrypted frames are exposed. Without a protected video path, decoded pictures pass through normal memory, so screen capture tools can record them. On L1 devices the same capture usually comes out black, as our explainer on why recordings go black describes.
- Modified phones end up there. A phone that has been rooted or had its bootloader unlocked may report L3 even if it shipped with L1, and those are exactly the phones where other protections are weakest. Our guide to root and emulator detection explains why.
- Desktop browsers usually sit there too. Widevine in desktop browsers has generally run at the software level, where the protected display path isn't available.
How Widevine protection gets bypassed
Even a well-run Widevine setup leaves gaps, and pirates use the easiest one available:
- Attacking the weakest device. Protection is only as strong as the lowest level a service allows. If HD is available to L3 devices, that's where copies come from.
- Recording instead of decrypting. On devices without a protected path, it's simpler to capture the screen than to touch the keys.
- The analogue hole. Even on L1, a second phone pointed at the screen records whatever plays. No DRM can see a camera.
- Valid licences for the wrong people. Widevine checks the device, not the person. A shared password gets every friend a valid licence.
- Side doors. A plain video file in an old app version or an unprotected preview skips Widevine entirely.
Our article on why DRM alone can't stop piracy covers these gaps in depth.
Why the same phone gets HD in one app and SD in another
A phone's Widevine level is the same in every app; what differs is each service's rules. Because L3 is so much easier to attack, services often release their higher qualities only to devices that report a hardware-backed level and cap L3 devices at a lower quality. Another app may allow more, and an app that doesn't use Widevine at all ignores the level completely.
Browsers vary in the same way. Netflix's help centre lists Chrome at up to Ultra HD on Windows but Full HD on a Mac, and Edge at up to Ultra HD on Windows but HD (720p) on a Mac. Same service, same browser name, different ceilings depending on what each platform can protect.
Checking a device's level
Android doesn't show the Widevine level in its settings. Free DRM information apps on the Play Store can read it, and some phone makers list Widevine L1 on their specification pages. If a phone reports L3 when its maker advertises L1, the bootloader may have been unlocked or the phone modified. For an institute, the more useful question is what your video platform does with the answer.
What this means for institutes
Students on L3 phones did nothing wrong, and many of them are exactly the budget-phone users you want to serve. The risk is that the easiest devices to attack get the same access as the hardest. Ask your platform:
- Which of our students' devices get hardware-backed protection, and which fall back to software?
- What quality and download rights do software-only devices get?
- What happens on rooted phones and desktop browsers?
- What protects lectures on devices where screen capture isn't blocked?
- If a copy leaks from an L3 device, can it be traced to the account?
The same questions apply if your platform uses its own encryption rather than Widevine, as our comparison of DRM vs encryption explains.
The legal position
Extracting keys or otherwise getting around DRM to copy paid lectures can be a crime as well as a breach of terms: circumventing an effective technological measure with the intention of infringing copyright is an offence under Section 65A of the Copyright Act, punishable with up to two years in prison and a fine. See our guide to copyright infringement punishment in India. This is general information, not legal advice. For your situation, speak to a lawyer.
Key takeaways
- L1 keeps keys, decryption and decoding inside hardware; L3 does everything in software; L2 is rare.
- Widevine's software level was publicly broken in 2019, and L3 also leaves decrypted frames open to capture.
- Rooted or unlocked phones can end up at the software level, and desktop browsers generally run there.
- Even L1 can't stop a second phone filming the screen or a shared password.
- Ask your platform what quality, downloads and protection each level gets, rather than locking students out.
Where VidSafe fits
VidSafe protects course videos with VidSafe proprietary encryption, screen- and camera-recording detection, account-sharing prevention and RASP in the apps, and it adds visible and invisible watermarks that are extremely hard to remove, even after heavy re-encoding, so a leaked copy can be traced back to the account it came from. See our LMS for coaching institutes.
Frequently asked questions
What is Widevine L3?
Widevine L3 is the software-only security level of Google's Widevine DRM. Keys are protected by obfuscated code running on the main processor, and decrypted video passes through ordinary memory. It works on almost any device, including many desktop browsers, but it's the easiest level to attack and was publicly broken in 2019, so streaming services often limit L3 devices to lower quality.
What is Widevine DRM?
Widevine is Google's digital rights management system. It lets a streaming service encrypt video and deliver the key, inside a licence, only to approved devices, which decrypt and play it under the service's rules. It's built into Android, ChromeOS and many smart TVs, and into browsers such as Chrome, Firefox and Edge. Content providers need a licence agreement with Google.
What is Widevine L1 support?
A phone or tablet with Widevine L1 support decrypts and decodes protected video inside a hardware-isolated trusted execution environment, so neither apps nor the operating system see the keys or decrypted frames. Streaming apps often require L1 for HD playback. Support depends on the chipset and the manufacturer, and some phones lose it when the bootloader is unlocked.