Narrowbeer: A Practical Replay Attack Against the Widevine DRM
Florian Roudot, Mohamed Sabt
摘要
Streaming services like Netflix, Prime Video, and HBO Max rely on DRM solutions to ward off piracy. By enabling the distribution of encrypted content, DRM systems prevent subscribed users from downloading the streamed content, as well as unauthorized users from having access to it.
Google Widevine, one of the most deployed DRMs, provides a fully software-based solution on desktop platforms to ensure portability. In this paper, we empirically investigate the security protections implemented by Widevine to counter an attacker tampering with its interactions within its environment, namely with the operating system and the hosting browser. Focusing on randomness and time, we uncover new flaws in the Widevine license acquisition process, particularly targeting the freshness and expiration of the licenses. To demonstrate the effectiveness of our findings, we develop Narrowbeer, a practical replay attack allowing legitimate users to generate never-expiring licenses, and enabling unauthorized users to reuse these licenses to access premium content without subscription. Finally, we validate our attack against real-world streaming services by succeeding in repeatedly playing the same license on different desktop devices.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper2
相关 Paper
- Digital Hole: Bypassing Commercial Audio DRM Solutions with DReaMcatcherBjörn Ruytenberg, Mohammad Sina Karvandi, Herbert Bos, Erik van der Kouwe 等EuroSys 2026
- StreamingTag: a scalable piracy tracking solution for mobile streaming servicesXinqi Jin, Fan Dang, Qi-An Fu, Lingkun Li 等MobiCom 2022 · 被引用 2 次
- WMCopier: Forging Invisible Watermarks on Arbitrary ImagesZiping Dong, Chao Shuai, Zhongjie Ba, Peng Cheng 等NeurIPS 2025 · 被引用 2 次
- THEMIS: Towards Practical Intellectual Property Protection for Post-Deployment On-Device Deep Learning ModelsYujin Huang, Zhi Zhang, Qingchuan Zhao, Xingliang Yuan 等USENIX Security 2025
- CATER: Intellectual Property Protection on Text Generation APIs via Conditional WatermarksXuanli He, Qiongkai Xu, Yi Zeng, Lingjuan Lyu 等NeurIPS 2022 · 被引用 106 次
