The article provides a technical deep dive into the security flaws of Widevine L3 DRM, detailing how a vulnerability in the Lenovo TB-X306F tablet allowed the extraction of a device private key by exploiting an unauthenticated TrustZone app. This key could then be used to decrypt streaming video content, highlighting weaknesses in the L3 implementation.
Background
Widevine is Google's digital rights management (DRM) system used by Netflix, Disney+, Amazon Prime, Hulu, and most other major streaming services to prevent video content from being pirated. It has three security levels: L1 (hardware-based, most secure), L2 (hybrid), and L3 (software-only, least secure). L3 is typically used on desktop browsers and cheaper Android devices where dedicated trusted hardware isn't available. The author's deep-dive reverse-engineers the Widevine L3 decryption process — how the encrypted video key is obtained and used on software-only implementations. This is a cat-and-mouse game: security researchers (and pirates) routinely probe L3 for flaws, and Google periodically issues updates to patch discovered exploits. Understanding L3 matters because its relative weakness compared to L1 means attackers can record high-quality streams from desktop browsers with relative ease once a decryption method is found.
Max Weinbach says he had early access to OpenAI's new model GPT-5.6 Sol, calling it his favorite model by far. He highlights that it never gives up and will keep reasoning until it's done. OpenAI announced that GPT-5.6 Sol, along with Terra and Luna, will launch publicly on Thursday, with preview access expanding globally now.
The US government ordered Anthropic to suspend access to its Fable 5 and Mythos 5 models for all customers, citing a potential jailbreak technique that involved asking the model to review a codebase for vulnerabilities—a capability Anthropic says is available in other public models. Access was abruptly cut off on June 12.
Andrej Karpathy announces the release of Claude Fable 5, the same underlying model as Mythos but with added safeguards. He calls it a major step forward, particularly for long problem-solving sessions on difficult tasks, and describes it as state-of-the-art on nearly all benchmarks with exceptional performance in software engineering, research, and vision.
Roman Storm warns that the legal theory in his case could set a precedent making open-source developers liable for how others use their code, potentially criminalizing the mere publication of privacy, messaging, or crypto tools. He notes that developer Michael Lewellen cannot publish lawful code due to prosecution fears, and argues this chilling effect extends beyond any single case.
Meta's engineering culture is deteriorating under Mark Zuckerberg and Scale AI CEO Alexandr Wang, who have introduced keyboard tracking, reassignments to data labeling, and AI-centric performance metrics. Critics argue this incentivizes performative AI use, drives away experienced engineers, and contributed to a major Instagram hijacking incident caused by AI-written and AI-reviewed code.