Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Who told you it's going to be sandboxed? It's probably going to be a obfuscated binary blob (it has to of it wants to try ensure that nothing is intercepting it) which will try verifying that OS isn't intercepting data.


Firefox:

https://bugzilla.mozilla.org/show_bug.cgi?id=1021232

https://bugzilla.mozilla.org/show_bug.cgi?id=1021235

The spec talks about both securing the CDM with Sandboxing and preventing fingerprinting, amongst other security + privacy issues that should be addressed:

https://w3c.github.io/encrypted-media/#cdm-security

https://w3c.github.io/encrypted-media/#privacy-fingerprintin...

the spec also says if the CDN isn't sandboxed then the user needs to be warned and prompted to allow exec:

> if a user agent chooses to support a Key System implementation that cannot be sufficiently sandboxed or otherwise secured, the user agent should ensure that users are fully informed and/or give explicit consent before loading or invoking it.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: