Comment by codetrotter
5 years ago
> harder DRM measures
Is that even possible for Spotify at this point?
The OP project is speaking to Spotify servers through the same means that official clients are, but the official clients are not just on iOS, Android, macOS and Windows.
There’s official Spotify clients on almost every platform imaginable. Everything from PS4 to built into TVs. And even a lot of stereo systems have Spotify Connect built into them.
Spotify Connect works by having these other devices streaming and playing the media, and your computer or phone acting as a “remote” for choosing the songs to be played. See https://www.spotify.com/us/connect/
Basically they’d have to break a lot of official clients, many of which probably cannot be updated, if they were to change their DRM scheme. How do you update a receiver for example? Well, you might be able to flash a new firmware with a USB stick. But for regular people, they are not going to do that. And the DRM scheme, at least as of yet, would be defeated by the reverse engineers as DRM always is. And hopefully continues to be.
So at least as of yet I think they would hurt people with official clients more than they would hurt anyone using an unofficial client.
And even people using unofficial clients are probably paying customers.
Besides what’s the point anyways, everyone knows that if you really really want to rip audio you don’t need to circumvent any DRM at all. You can play the song on your computer or your phone and take the analog signal that is going to the speakers and digitize it again and make an imperfect but still good copy of any audio. Admittedly it doesn’t scale anywhere near as good as automatically stripping DRM though.
Music publishers could demand better DRM in their contracts, though. That would lock out any devices incapable of receiving DRM updates, but it's certainly a possibility. If Spotify would refuse to budge, their platform would lose access to a lot of songs. If they agree, their users would have a terrible experience, only being able to play some songs on some devices.
In order for Spotify to have any decent user experience, they need to nip any DRM bypass as scale in the bud before the publishers find out, through cease and desist or worse. If better DRM becomes the only solution, everyone loses.
The difference between official and unofficial clients is that Spotify can have some (contractual) power over the official clients, like demand that music is cached encrypted, demand a certain limit for cached music, etc. Unofficial clients aren't bound by any contract, so the developers could easily do something they shouldn't be doing according to the terms and conditions Spotify lays out (or the terms and conditions of the copyright holders that Spotify must uphold).
> Is that even possible for Spotify at this point?
Spotify are using Widevine on their web client, which is considerably more annoying to deal with than the encryption method used in the files fetched by Psst.
Nothing is stopping them from only serving files from the endpoint that serves Widevine protected files.
Then again, Widevine L3 has been broken[0], Google just keeps rotating the private keys used in the content decryption module.
[0]: https://github.com/Satsuoni/widevine-l3-guesser
Something is stopping them: all the old devices that already know how to speak Spotify.
Spotify is built on bringing your music library with you everywhere. If your car or five year old stereo stops being able to play spotify songs, why would you still pay for a Premium account? 2% loss doesn't sound like much, but at Spotify's scale, that would mean loosing 2 million paying customers. If they pay $5 /month, that's not pocket change.
One thing that could be done - and which is already what's being done by most video streaming companies - is to just propose really poor audio qualities to devices/softwares with less DRM capabilities and only unlock the better qualities when e.g. Widevine L1 or PlayReady SL3000 is available.
What's more, media-oriented devices like smart tvs or game consoles usually have those requirements.
This is a great point. It's truly no different than a third party manufacturer writing some device firmware to connect with Spotify.
But as a sibling has posted, this is a posture / plausible deniability thing.
I've looked it up a few years ago, so this may have changed, but at the time you couldn't just ask Spotify for the SDK / docs to build your own Connect client. I don't remember the details, but you'd have to jump through some hoops, at which point I stopped looking since I wasn't about to build anything industrial. I expect some terms would be that you'd at least try to protect the keys.