Electronic Frontier Foundation
EFF is the leading civil liberties group defending
your rights in the digital world. » About Us
  • Home
  • About
  • Our Work
  • Deeplinks Blog
  • Press Room
  • Take Action
  • Shop
Home » Deeplinks Blog » August, 2008
  • Deeplinks Archives
    • October, 2011
    • September, 2011
    • August, 2011
    • July, 2011
    • June, 2011
    • May, 2011
    • April, 2011
    • March, 2011
    • More Archives
  • Blog Categories
    • Accessibility for the Reading Disabled
    • Analog Hole
    • Announcement
    • Anonymity
    • Anti-Counterfeiting Trade Agreement
    • Bloggers' Rights
    • Broadcast Flag
    • Broadcasting Treaty
    • CALEA
    • Call To Action
    • CDA 230
    • Cell Tracking
    • Coders' Rights Project
    • Commentary
    • Copyright Trolls
    • Council of Europe
    • Criminalizing Content
    • Development Agenda
    • Digital Books
    • Digital Radio
    • Digital Rights Management
    • Digital Video
    • DMCA
    • DMCA Rulemaking
    • Do Not Track
    • E-Voting Rights
    • EFF Europe
    • EFF15
    • File Sharing
    • FOIA Litigation for Accountable Government
    • Free Speech
    • Free Trade Agreement of the Americas
    • Hollywood v. DVD
    • Innovation
    • Intellectual Property
    • International
    • International Privacy Standards
    • Legal Analysis
    • Legislative Analysis
    • Locational Privacy
    • Mandatory Data Retention
    • miniLinks
    • National Security Letters
    • Net Neutrality
    • News Roundup
    • News Update
    • No Downtime for Free Speech Campaign
    • NSA Spying
    • Online Behavioral Tracking
    • Patents
    • PATRIOT Act
    • Pen Trap
    • Printers
    • Privacy
    • Real ID
    • RFID
    • Search Engines
    • Search Incident to Arrest
    • Security
    • Social Networks
    • Technical Analysis
    • Terms Of (Ab)Use
    • Test Your ISP
    • The COICA Internet Censorship and Copyright Bill
    • The Global Network Initiative
    • Transparency
    • Travel Screening
    • Trusted Computing
    • Video Games
    • Wikileaks
    • WIPO
August 15th, 2008
Email This Digg This Post this to Reddit Share this blog post with delicious Share this on Facebook Tweet this blog post Dent this blog post

DRM for Streaming Music Dies a Quiet Death

Technical Analysis by Fred von Lohmann

Yet another nail has been driven into DRM's coffin, this time for streaming audio (PCPro has a nice overview of the state of DRM for digital music).

Two of the leading on-demand streaming music sites, iMeem and LaLa, are not using DRM on their audio streams, instead sending the music as MP3s dusted with a dash of obfuscation. This is significant because both sites have been licensed by all the major record labels -- the very same record labels that were just last year pushing Congress to require DRM on all noninteractive webcasts. So it looks like the RIAA companies have changed their minds, dropping DRM requirements for the on-demand streaming music services.

This should put an end to legislation to mandate DRM on noninteractive webcasters. After all, why should these webcasters be in a worse position than the free, on-demand music services like LaLa and iMeem?

This also undermines the argument that DRM for music is necessary for subscription services. If the major labels have given up DRM for free, ad-supported (correction: iMeem is ad-supported, LaLa is free for a first listen of a track, 10 cents for repeat listening), on-demand streaming services like LaLa and iMeem, there's no plausible reason to insist on DRM for paid subscription services like Rhapsody and Napster 2.0. After all, there's no reason to think that those who prefer commercial-free subscriptions like Rhapsody are more likely to "pirate" streams than those who prefer ad-supported services like LaLa iMeem.

LaLa and iMeem each take slightly different approaches to streaming music. LaLa uses HTTP to download each requested song as an MP3 to your browser, but relies on aggressive "no-cache" headers and pre-expired date stamps to suggest that your browser not make a copy of the file on your hard drive. Using a packet sniffer to capture the entire HTTP session, however, easily reveals the complete MP3 embedded right after the HTTP headers.

iMeem also downloads and caches each requested song, but sends the MP3 as the audio track of a Flash Video file. This FLV file is typically saved (cached) on your hard drive as an obscurely named temporary file, which is overwritten when you request your next song (we mentioned iMeem's approach back in January, and it's essentially unchanged). Copy this temp file, however, and you can easily extract the audio track from the Flash video, saving it as a stand-alone MP3 file.

(The location of this TemporaryItems folder, and its equivalent on other operating systems, varies significantly depending on operating system and version. On some operating systems it's buried deep within the directory hierarchy, but it can be found automatically with standard tools.)

While the light obfuscation used by iMeem and LaLa might create a "speed bump" of inconvenience for users who want to keep the MP3 files, it doesn't rise to the level of a "technical protection measure" protected by the DMCA. In short, this is yet another example of why there is no legitimate business case for DRM on music -- it doesn't prevent piracy and it's not necessary to enable "new business models" like subscription or ad-supported music. (Of course, as the movie industry has demonstrated, DRM can still be valuable for impeding competition and putting the brakes on disruptive innovation. But it's hard to see how the law should protect those goals.)

Related Issues: Digital Rights Management, DMCA

[Permalink]

Donate to EFF
Make a One-Time Contribution
Join EFF
Become a Member

Subscribe to EFFector

EFF's Newsletter and Action Alerts

Headlines

  • Victory for Reader Privacy
  • The Humble Frozen Synapse Bundle
  • Don't Let Privacy Law Get Stuck in 1986
  • Open Source Security
  • 2011 Pioneer Awards!

Projects

  • Bloggers' Rights
  • Coders' Rights
  • FOIA Project
  • Follow EFF
  • Patent Busting
  • Surveillance Self-Defense
  • Teaching Copyright
  • Takedown Hall of Shame
  • TOSBack
  • Ways To Help
Want to learn how you can defend free speech, stand up for privacy, fight for government transparency, support consumer rights, and protect your right to innovation in the digital world? Visit http://eff.org/fight to find ways to help.
Creative Commons Licensed
  • Thanks
  • RSS Feeds
  • Copyright Policy
  • Privacy Policy
  • Contact EFF