Widevine L1 vs L3: security levels explained

Widevine L1 keeps keys in hardware; L3 keeps them in software and was publicly broken in 2019. Why that matters, why apps cap L3 quality, and what to ask.

7 min read
On this page 11 sections
  1. What Widevine is
  2. L1, L2 and L3
  3. Why L3 is the weak link
  4. How Widevine protection gets bypassed
  5. Why the same phone gets HD in one app and SD in another
  6. Checking a device's level
  7. What this means for institutes
  8. The legal position
  9. Key takeaways
  10. Where VidSafe fits
  11. Frequently asked questions

Widevine L1 means a device decrypts and processes protected video inside a hardware-isolated trusted execution environment (TEE); L3 means it does everything in ordinary software, and L2, which keeps only the cryptography in hardware, is rare. The difference decides how easily the protection can be broken: L3 keeps its keys in software on a device the user controls, and Widevine's software level was publicly broken in 2019. That's why streaming services cap quality on L3 devices, and why the same phone can get HD in one app and SD in another.

What Widevine is

Widevine is Google's DRM system, one of the big three alongside Apple's FairPlay and Microsoft's PlayReady. It runs on Android phones and TVs, ChromeOS, Chromecast and many smart TVs and set-top boxes, and in browsers including Chrome, Firefox, Edge and Opera. Content providers need a licence agreement with Google, which charges no fee for Widevine itself. For how DRM works in general, see our explainer on how DRM works; for serving all three systems from one library, see multi-DRM.

L1, L2 and L3

Android's MediaDrm documentation defines the security levels behind Widevine's labels. In plain terms:

LevelWhat happens inside protected hardwareWhat it means
L1Key handling, decryption, decoding and all handling of the videoNeither apps nor the operating system see keys or decrypted frames; the level services typically require for HD and above
L2Key handling and decryption only; decoding happens outsideUncommon; decrypted video still passes through ordinary memory
L3Nothing: keys are guarded by obfuscated softwareWorks almost everywhere, and is by far the easiest level to attack

L1 depends on the phone's chipset and on how the manufacturer has integrated Widevine. An app can't add it.

  • Keys live in software. At L3, keys are protected only by obfuscated code running on the ordinary processor of a device the user fully controls. Widevine's software level was publicly broken in 2019, and when keys are extracted, the encrypted video files can be decrypted outright into clean copies.

  • Decrypted frames are exposed. Without a protected video path, decoded pictures pass through normal memory, so screen capture tools can record them. On L1 devices the same capture usually comes out black, as our explainer on why recordings go black describes.

  • Modified phones end up there. A phone that has been rooted or had its bootloader unlocked may report L3 even if it shipped with L1, and those are exactly the phones where other protections are weakest. Our guide to root and emulator detection explains why.

  • Desktop browsers usually sit there too. Widevine in desktop browsers has generally run at the software level, where the protected display path isn't available.

How Widevine protection gets bypassed

Even a well-run Widevine setup leaves gaps, and pirates use the easiest one available:

  • Attacking the weakest device. Protection is only as strong as the lowest level a service allows. If HD is available to L3 devices, that's where copies come from.

  • Recording instead of decrypting. On devices without a protected path, it's simpler to capture the screen than to touch the keys.

  • The analogue hole. Even on L1, a second phone pointed at the screen records whatever plays. No DRM can see a camera.

  • Valid licences for the wrong people. Widevine checks the device, not the person. A shared password gets every friend a valid licence.

  • Side doors. A plain video file in an old app version or an unprotected preview skips Widevine entirely.

Our article on why DRM alone can't stop piracy covers these gaps in depth.

Why the same phone gets HD in one app and SD in another

A phone's Widevine level is the same in every app; what differs is each service's rules. Because L3 is so much easier to attack, services often release their higher qualities only to devices that report a hardware-backed level and cap L3 devices at a lower quality. Another app may allow more, and an app that doesn't use Widevine at all ignores the level completely.

Browsers vary in the same way. Netflix's help centre lists Chrome at up to Ultra HD on Windows but Full HD on a Mac, and Edge at up to Ultra HD on Windows but HD (720p) on a Mac. Same service, same browser name, different ceilings depending on what each platform can protect.

Checking a device's level

Android doesn't show the Widevine level in its settings. Free DRM information apps on the Play Store can read it, and some phone makers list Widevine L1 on their specification pages. If a phone reports L3 when its maker advertises L1, the bootloader may have been unlocked or the phone modified. For an institute, the more useful question is what your video platform does with the answer.

What this means for institutes

Students on L3 phones did nothing wrong, and many of them are exactly the budget-phone users you want to serve. The risk is that the easiest devices to attack get the same access as the hardest. Ask your platform:

  1. Which of our students' devices get hardware-backed protection, and which fall back to software?

  2. What quality and download rights do software-only devices get?

  3. What happens on rooted phones and desktop browsers?

  4. What protects lectures on devices where screen capture isn't blocked?

  5. If a copy leaks from an L3 device, can it be traced to the account?

The same questions apply if your platform uses its own encryption rather than Widevine, as our comparison of DRM vs encryption explains.

Extracting keys or otherwise getting around DRM to copy paid lectures can be a crime as well as a breach of terms: circumventing an effective technological measure with the intention of infringing copyright is an offence under Section 65A of the Copyright Act, punishable with up to two years in prison and a fine. See our guide to copyright infringement punishment in India. This is general information, not legal advice. For your situation, speak to a lawyer.

Key takeaways

  • L1 keeps keys, decryption and decoding inside hardware; L3 does everything in software; L2 is rare.

  • Widevine's software level was publicly broken in 2019, and L3 also leaves decrypted frames open to capture.

  • Rooted or unlocked phones can end up at the software level, and desktop browsers generally run there.

  • Even L1 can't stop a second phone filming the screen or a shared password.

  • Ask your platform what quality, downloads and protection each level gets, rather than locking students out.

Where VidSafe fits

VidSafe protects course videos with VidSafe proprietary encryption, screen- and camera-recording detection, account-sharing prevention and RASP in the apps, and it adds visible and invisible watermarks that are extremely hard to remove, even after heavy re-encoding, so a leaked copy can be traced back to the account it came from. See our LMS for coaching institutes.

Frequently asked questions

What is Widevine L3?

Widevine L3 is the software-only security level of Google's Widevine DRM. Keys are protected by obfuscated code running on the main processor, and decrypted video passes through ordinary memory. It works on almost any device, including many desktop browsers, but it's the easiest level to attack and was publicly broken in 2019, so streaming services often limit L3 devices to lower quality.

What is Widevine DRM?

Widevine is Google's digital rights management system. It lets a streaming service encrypt video and deliver the key, inside a licence, only to approved devices, which decrypt and play it under the service's rules. It's built into Android, ChromeOS and many smart TVs, and into browsers such as Chrome, Firefox and Edge. Content providers need a licence agreement with Google.

What is Widevine L1 support?

A phone or tablet with Widevine L1 support decrypts and decodes protected video inside a hardware-isolated trusted execution environment, so neither apps nor the operating system see the keys or decrypted frames. Streaming apps often require L1 for HD playback. Support depends on the chipset and the manufacturer, and some phones lose it when the bootloader is unlocked.

Share this article

Looking for something else?

Talk to Us