WideLeak: How Over-the-Top Platforms Fail in Android - Université de Rennes Accéder directement au contenu
Communication Dans Un Congrès Année : 2022

WideLeak: How Over-the-Top Platforms Fail in Android

Résumé

Nowadays, most content providers rely on DRM (Digital Right Management) to protect media from illegal distribution. Becoming a major platform for streaming, Android provides its own DRM framework that does not comply with existing DRM standards. Thus, OTT (over-the-top) platforms need to adapt their apps to suit Android design, despite a fragmented ecosystem and little public documentation. Unfortunately, the security implications of how OTT apps leverage Widevine, the most popular Android DRM, have not been studied yet. In this paper, we report the first experimental study on the state of Widevine use in the wild. Our study explores OTT compliance with Widevine guidelines regarding asset protection and legacy phone support. With the evaluation of premium OTT apps, our experiments bring to light that most apps adopt weak and potentially vulnerable practices. We illustrate our findings by showing how to easily recover media content from many OTT apps, including Netflix.
Fichier principal
Vignette du fichier
wideleak.pdf (166.41 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)

Dates et versions

hal-03637107 , version 1 (11-04-2022)

Identifiants

  • HAL Id : hal-03637107 , version 1

Citer

Gwendal Patat, Mohamed Sabt, Pierre-Alain Fouque. WideLeak: How Over-the-Top Platforms Fail in Android. DSN 2022 - 52nd Annual IEEE/IFIP International Conference on Dependable Systems and Networks, Jun 2022, Baltimore, MD, United States. ⟨hal-03637107⟩
189 Consultations
1490 Téléchargements

Partager

Gmail Facebook X LinkedIn More