Intent to Remove: Insecure usage of EME

ยอดดู 1975 ครั้ง

Emily Schechter

8 ธ.ค. 2559 22:27:438/12/59
ถึง,,, Joel Weinberger

Primary eng (and PM) emails,

Link to “Intent to Deprecate” thread


Following our powerful feature policy, we intend to remove support for EME APIs over non-secure contexts at the end of Q1 2017.


Support for non-secure contexts has been removed from EME v1 spec and will not be in the upcoming Proposed Recommendation (PR) or subsequent final Recommendation. The API was included in the original intent-to-deprecate and listed on the Chromium wiki page starting in Feb 2015, and has been showing a deprecation message since May 2015. If approved, the deprecation message will be updated to include the concrete timeframe.

Some usages of EME expose DRM implementations that are not open source, involve access to persistent unique identifiers, and/or run unsandboxed or with privileged access. The risks are increased when exposed via insecure HTTP, because they could be attacked by anyone on the channel. In addition, for implementations that require explicit permissions, permission for an insecure HTTP site can be exploited.

Compatibility Risk

This will break a small number of media sites who do not transition to HTTPS by the time of removal. As these sites transition to HTTPS, the risk becomes lower. We have a good communication channel with many of the sites currently using EME in non-secure contexts, which makes the risk much lower.

EME support in Chrome: since M42 (unprefixed)

Firefox: deprecation plans.

Usage information from UseCounter

EME over insecure origins: 0.002% of page loads (link).

EME over secure origins: 0.009% of page loads (link)

OWP launch tracking bug for EME for broader removal of old powerful features on insecure origins.

Entry on the feature dashboard

Jochen Eisinger

9 ธ.ค. 2559 03:04:189/12/59
ถึง Emily Schechter,,,, Joel Weinberger

Mike West

9 ธ.ค. 2559 04:50:389/12/59
ถึง Jochen Eisinger, Emily Schechter, blink-dev,, Joel Weinberger
Non-OWNER's LGTM. I don't believe any new information has popped up since we decided to deprecate this in non-secure contexts, and the deprecation warning in conjunction with y'all's outreach seems to have been effective in driving the numbers down to levels where I'm confident that the impact to developers is outweighed by the benefits.

Thanks for following through on this!



9 ธ.ค. 2559 05:05:369/12/59
ถึง Mike West, Jochen Eisinger, Emily Schechter, blink-dev, David Dorwin, Joel Weinberger

Software Engineer, Google


9 ธ.ค. 2559 11:44:189/12/59
ถึง Emily Schechter, blink-dev, David Dorwin, Mike West, Joel Weinberger

On Fri, Dec 9, 2016 at 5:27 AM, Emily Schechter <> wrote:
EME over secure origins: 0.009% of page loads (link)

With such a low usage, it looks like you can remove the feature altogether, secure or insecure. ;)​


Chris Harrelson

9 ธ.ค. 2559 12:37:419/12/59
ถึง PhistucK, Emily Schechter, blink-dev, David Dorwin, Mike West, Joel Weinberger

You received this message because you are subscribed to the Google Groups "blink-dev" group.
To unsubscribe from this group and stop receiving emails from it, send an email to


25 ม.ค. 2560 08:53:4025/1/60
ถึง blink-dev,,,,
Will secure origin be required for apps hosted on private networks?  - thinking about impact on internal test systems...

Jochen Eisinger

25 ม.ค. 2560 08:54:2725/1/60
ถึง, blink-dev,,,,
we internal testing, you can always run chrome with command line options to mark individual URLs as secure

21 เม.ย. 2560 14:43:2721/4/60
ถึง blink-dev,,,,,
Can you let me know the command line option to mark individual URLs as secure?

Emily Schechter

21 เม.ย. 2560 14:46:2721/4/60
ถึง, blink-dev,,,, Joel Weinberger, Emily Schechter
There are developer instructions here ("If a feature is powerful and not available on HTTP, and you are a developer that needs to keep testing a feature on a server that does not have a valid certificate, you have several options...")

Xiaohan Wang (王消寒)

21 เม.ย. 2560 14:46:3221/4/60
ถึง, blink-dev,, David Dorwin,,,
(copied from earlier communications)

For development and test, you can:

On Fri, Apr 21, 2017 at 11:43 AM, <> wrote:
ข้อความใหม่ 0 รายการ