Google’s Widevine L3 Video Streaming DRM Platform, Used by Netflix and Others, Allegedly Cracked

Advertisement
By Roydon Cerejo | Updated: 3 January 2019 11:33 IST
Highlights
  • Buchanan claims he’s broken the Widevine L3 DRM platform
  • It’s used by all the major video streaming services
  • It technically lets you download and play the video in any player

David Buchanan claims that the Widewine L3 DRM is vulnerable to a DFA attack

Photo Credit: Twitter/ David Buchanan

Widevine is a digital rights management (DRM) platform owned by Google that allows content providers like Netflix, HBO, etc., to stream video content to end users in a secure environment, in order to avoid unlawful duplication and distribution of their content (aka: piracy). However, security researcher David Buchanan claims to have broken Google's Widevine L3 DRM, which would technically allow you to download an unencrypted copy of a video stream so it can be played on pretty much any standalone video player.

Buchanan tweeted that the Whitebox AES-128 cryptography used by the Widevine L3 platform is vulnerable to a “well-studied DFA (differential fault analysis) attack" that can be used to recover the original key, and then decrypt the stream. He also boasts that it took him just a “few evenings” worth of work to crack this. With the decryption key in hand, Buchanan claims that the videos can be streamed with FFmpeg, which would make it very easy to record and convert the streamed video to any of the popular formats. Buchanan hasn't shared any details on how this is actually accomplished, but added he took the help of Philippe Teuwen and the Side-Channel Marvels project.

For now, it is unclear if Buchanan reported the vulnerability to Google before his disclosure on Twitter. He said he doesn't consider this a bug, adding that DRM is flawed by design. He suggested Google can make the DRM more DFA-resistant with more obfuscation, but that "would slow down performance."

Advertisement

While this is a big blow for streaming services, we have to keep in mind that Widevine L3 is at a lower security level, which means your video streams are usually capped at sub-HD resolutions. For HD video streaming and higher, content providers rely on the Widevine L1 DRM platform, which is more secure as all the cryptography and content processing is performed within a Trusted Execution Environment (TEE) inside your device's processor, which is a lot harder to crack. That's also the reason why phones like the Xiaomi Poco F1 (Review) and the OnePlus 5T (Review) were unable to playback streaming HD videos when they first launched. Widevine is currently used by all major streaming services like Netflix, HDO, Disney, Jio, Prime Video, Facebook, etc., to stream content on devices running Android and on browsers like Chrome and Firefox.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Widevine, Google, DRM, Widevine L3
Advertisement

Related Stories

Popular Mobile Brands
  1. Ray-Ban Meta Glasses Will Go on Sale via Amazon, Flipkart on This Date
  2. Canon EOS R6 Mark III With 7K Video Recording Support Launched in India
  3. Top OTT Releases This Week: Baramulla, Maharani Season 4, Bad Girl, and More
  4. Oppo Could Launch the Reno 15 Series During Its Double Eleven Event
  5. Airtel Begins Transition to Dual 5G Network in India to Roll Out 5G Advanced
  6. Samsung Galaxy S26 Ultra Tipped to Launch Without Major Camera Upgrades
  7. GTA 6 Has Been Delayed by Six Months, Will Launch in November 2026
  8. WhatsApp Business Accounts May Also Get Usernames: See Launch Timeline
  9. Google Pixel Watch 4 Finally Goes on Sale in India: See Price, Features
  10. Realme GT 8 Pro Will Launch in India on This Date
  1. Apple Swift Student Challenge to Return in February 2026; Apple Highlights Winning Student Developers' Apps
  2. Google Warns Users of AI-Driven Scams Targeting Job Seekers and Businesses
  3. TSMC Reportedly Informs Apple of Higher Chip Fabrication Costs Under 5nm Next Year
  4. Oppo Reno 15 Series China Launch Reportedly Set During Double Eleven Event on November 17
  5. Grand Theft Auto 6 Delayed Again, Rockstar Games Sets New November 2026 Launch Date
  6. Is the Universe Slowing Down? Astronomers Detect Signs of Fading Dark Energy
  7. Mystery Deepens as Interstellar Comet 3I/ATLAS Brightens Unexpectedly Near the Sun
  8. Scientists Create Bullet-Proof Fiber Stronger and Thinner Than Kevlar
  9. The Kardashians Season 7 Now Streaming on JioHotstar: Everything You Need to Know About the Glamorous Reality Series
  10. Mithra Mandali Now Available for Streaming on Amazon Prime Video: What You Need to Know
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.