Protecting against piracy Piracy isn’t new; it’s just gotten easier. While today’s pirates don’t exactly resemble the swashbuckling rogues we might imagine, content theft and re-distribution is certainly alive and well, albeit done behind closed doors. In the US, the FBI’s Anti-Piracy Warning Seal appears on copyrighted materials, such as home media, and explains that offenders may face prison time. However, although the punishment may fit the crime, it doesn’t prevent it from happening. “For a long time,” says Hynard, “the industry’s focus was on
extending that approach so each DRM licence renewal becomes the trust anchor for issuing a fresh, short-lived CDN access token. “Instead of authorising access once at the start of playback, trust can be continuously renewed throughout the session. If a key or CDN token is compromised, its useful lifetime is measured in seconds rather than minutes or hours, dramatically reducing its value to pirates while making large-scale CDN leeching significantly more difficult.” While piracy is a content security threat first and foremost, it is also a commercial one. “It’s no longer just about lost subscription revenue; operators are also paying the hidden cost of CDN leeching, where stolen playback sessions are used to consume content directly from the operator’s own CDN,” Hynard says. “Every unauthorised stream generates CDN egress, origin traffic and infrastructure costs while producing no revenue. At scale, this becomes a content security issue and a significant operational cost.” Take the 2026 FIFA World Cup, the largest tournament to date. Forty- eight teams competed in stadiums across North America, and 6.8 million fans attended the matches. But for those who couldn’t be there in person, they tuned in via broadcast, handled by Fox and Telemundo in the US, Bell Media in Canada, and Televisa and TV Azteca in Mexico. Peacock streamed all 104 games to its subscribers too. The latest World Cup was also a commercial success, generating $8.9bn in revenue (as estimated by FIFA) – and that includes the $485m Fox paid for media rights. Video piracy, however, ran rampant, with the US government seizing over 1000 websites that were streaming matches illegally and, in some cases, trying to turn a profit. While the anti- piracy initiative Operation Offsides caught thousands of copyright- infringement criminals, it didn’t prevent them from stealing content in the first place – and that is where cybersecurity should be heading. Castlab’s approach builds on infrastructure that operators already have. “There’s no requirement
» Whether your content is safe is one thing; whether it’s even real is another. Generative AI has transformed content moderation «
preventing premium content from being decrypted or copied. Today, we’re seeing the problem shift from protecting the content itself to protecting the playback session.” While multi-DRM approaches have been largely successful in preventing leaks, they can’t do much to stop live screen-scraping. “An attacker only needs to authenticate once, obtain a valid playback session, extract a CDN access token and then redistribute it to thousands of unauthorised viewers,” explains Hynard. (CDN, in this case, stands for content delivery network.) “From the CDN’s perspective, those requests often look entirely legitimate, making them difficult to distinguish from paying customers in real time.” Castlabs, which provides software and cloud services to the digital media industry, is working on a solution to this exact issue, blending high-frequency DRM key rotations with short-lived CDN access tokens. “Working with partners, we’ve developed a proof of concept that enables DRM keys to rotate rapidly without the overhead traditionally associated,” Hynard says. “We’re
Powered by FlippingBook