RE: Comments on the EME opinion

From: Mark Watson [mailto:watsonm@netflix.com] 

> ​It's a UA/CDM combination and probably not in the short term, though we'd evaluate on cost vs market share grounds if/when we came to it.​

This is very concerning and exactly the kind of scenario the TAG is against (https://www.w3.org/Bugs/Public/show_bug.cgi?id=27053).

It is important for the spec to set a baseline such that no such discrimination against different lower-marketshare UA/CDM combinations takes place (either because it is technically impossible---hard to imagine, but ideal---or at the very least because no technical incentives to do so exist). One way of doing this would be to require all UAs to require HTTPS. This seems especially important given that smaller UAs may not have the pull with DRM vendors to address security and privacy concerns in a different way, that works over insecure transports.

Received on Thursday, 23 October 2014 18:07:09 UTC