Re: [rtcweb] Reminder: Working group last call for draft-ietf-rtcweb-security-arch

Justin Uberti <juberti@google.com> Mon, 04 March 2013 23:30 UTC

Return-Path: <juberti@google.com>
X-Original-To: rtcweb@ietfa.amsl.com
Delivered-To: rtcweb@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 992D921F87BA for <rtcweb@ietfa.amsl.com>; Mon, 4 Mar 2013 15:30:25 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.376
X-Spam-Level:
X-Spam-Status: No, score=-102.376 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, FM_FORGED_GMAIL=0.622, HTML_MESSAGE=0.001, J_CHICKENPOX_56=0.6, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4WJU1dqaz7pu for <rtcweb@ietfa.amsl.com>; Mon, 4 Mar 2013 15:30:24 -0800 (PST)
Received: from mail-qe0-f47.google.com (mail-qe0-f47.google.com [209.85.128.47]) by ietfa.amsl.com (Postfix) with ESMTP id C295221F8698 for <rtcweb@ietf.org>; Mon, 4 Mar 2013 15:30:21 -0800 (PST)
Received: by mail-qe0-f47.google.com with SMTP id q19so4266177qeb.6 for <rtcweb@ietf.org>; Mon, 04 Mar 2013 15:30:21 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=x-received:mime-version:in-reply-to:references:from:date:message-id :subject:to:cc:content-type; bh=S+lLTjYIhtDTkKEwL/lyxbbHgBCEgTMSPwlV1zFQxHs=; b=loAveMLLCmOaQytCNkXrn7jiJBnzRAZxwk22B3ccoiftGN4R6X8596WlD8DUjzfvJ3 2Uu/NtoxB/2CXUqkgZjxUSCCqqGYyaP2EGbLtWvyoQEjX+hZ6N0O9sNf0TSz7BsthJPA jxY8u8E+JXvM5pDYd78xzWPiyiK8f1tk5rz61rRIKzt2sxwAEMNZzi7Gl/F35WdWGLZW TaCloJGJ11tzba0i9agIuOZ89YAcEer7GBV2FoIK8B7/+oRZFReDbC29TJ0/7XWEoldA x80RBEI7P9mDhN5LePR+O+ZxvDzrw9dDLdDyon5zyO6qn/pbtEicsayVKSdBRmjZ/f0w R/Nw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=x-received:mime-version:in-reply-to:references:from:date:message-id :subject:to:cc:content-type:x-gm-message-state; bh=S+lLTjYIhtDTkKEwL/lyxbbHgBCEgTMSPwlV1zFQxHs=; b=ZBC51mM3gqQykSd4nuFbVldNDIgYb1v/wpZYULzOzRPGsbhxyHiUdR/hsWvYPGGIGb znq3fvROwsVidMPOOMMr9gDFGQ9RGJ74oHy8jgPhmbslRbi5tMOi4VLowuO1mN2MJhZj 70Vpnc4yZWPCRRh2CiFEb12tPwc5zAqsZHWBAZf/5Oo5Vx1Q3/CSbEcp6sDg962coaLx l9ViZMRwzTWj0XjwBBxh1Sun8ecN/je2vni63gCDQW5dvGtQNoM2x6CGAyZ6uxccCht9 v/ISc+8pEfSCMTyzLMbNKLoJ/7QWDDZQ/iEU3sGBf/HgHv38XImJ1N0OJS8zfelTtIoq fepg==
X-Received: by 10.229.135.207 with SMTP id o15mr7638305qct.34.1362439821192; Mon, 04 Mar 2013 15:30:21 -0800 (PST)
MIME-Version: 1.0
Received: by 10.229.206.17 with HTTP; Mon, 4 Mar 2013 15:30:00 -0800 (PST)
In-Reply-To: <CA+9kkMAg2grbyg1g94hm3cgV8957j++t55fuQhfWj1e_ZEGXdQ@mail.gmail.com>
References: <CA+9kkMATiwiFNyq3awr-EHwnWb3+ZEsP+Omgiwdev=8swgMrAQ@mail.gmail.com> <95790319-C42C-48E2-A6FD-0E718CCF48FB@csperkins.org> <CA+9kkMAg2grbyg1g94hm3cgV8957j++t55fuQhfWj1e_ZEGXdQ@mail.gmail.com>
From: Justin Uberti <juberti@google.com>
Date: Mon, 4 Mar 2013 15:30:00 -0800
Message-ID: <CAOJ7v-0n2N5LrXQZyaZcCQZqYsHUP5U3Ox_d-RTivd2sCfZqwA@mail.gmail.com>
To: Ted Hardie <ted.ietf@gmail.com>
Content-Type: multipart/alternative; boundary=00248c7690fe9215bc04d721bd17
X-Gm-Message-State: ALoCoQmQOnhPS9SC5HunAAHHsJmVwG1SOd9yqNfYJBImLNu95TXXo09qGSs1rQK8Snsuzus+JBLgNNboPrOCb7IZCNBcAL6U3vdwi9W1EdTeB2Rtha64Y9PzT6mNaryFRCZ81zlJn4i0GnyudqIh9+vrGVKi2rzVWou+4Rj8ZC9wj+W4QZjwgIrmgCEW4R24HcpMNiY9+P2f
Cc: "rtcweb@ietf.org" <rtcweb@ietf.org>, Colin Perkins <csp@csperkins.org>
Subject: Re: [rtcweb] Reminder: Working group last call for draft-ietf-rtcweb-security-arch
X-BeenThere: rtcweb@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Real-Time Communication in WEB-browsers working group list <rtcweb.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/rtcweb>
List-Post: <mailto:rtcweb@ietf.org>
List-Help: <mailto:rtcweb-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 04 Mar 2013 23:30:25 -0000

I already sent mail to Eric on this, but one thing that needs consideration
in this draft is the use case identified in section 4.2.7 of
draft-ietf-rtcweb-use-cases-and-requirements-06, i.e. desktop sharing.
Section 5.2 of the security doc covers the requirements for consent for
camera access, but not for desktop access.


On Mon, Mar 4, 2013 at 8:43 AM, Ted Hardie <ted.ietf@gmail.com> wrote:

> Hi Colin,
>
> Thanks for reviewing the document.  As you note, there are open
> issues; 5.1, for example, has this:
>
> "This is a  deliberate implementation complexity versus security tradeoff.
>  [[ OPEN ISSUE::  Should we be more aggressive about this?]]"
>
> As far as I am aware,though, the document in each case includes a
> proposal for the Open Issue,
> and it is that which would be in a WG document post last-call.  But if
> folks looked at the document
> and answered the "open issues" within, that would certainly be very
> welcome input.
>
> Were there any Open Issues or other points you wanted to comment on
> directly?
>
> Ted
>
>
> but there
>
> On Mon, Mar 4, 2013 at 4:58 AM, Colin Perkins <csp@csperkins.org> wrote:
> > Ted,
> >
> > This draft has a number of places where open issues are noted (e.g., in
> Sections 5.1 and 5.5, but there are many others). It seems premature to
> issue a working group last call until those are resolved.
> >
> > Colin
> >
> >
> >
> > On 25 Feb 2013, at 23:27, Ted Hardie wrote:
> >> This is a reminder that there is an ongoing last call for
> >> draft-ietf-rtcweb-security-arch-06.  Please send comments, including
> >> those of the "reviewed and no issues" ilk, by March 9th, 2012.
> >>
> >> regards,
> >>
> >> Ted Hardie
> >>
> >> On Thu, Feb 14, 2013 at 8:35 AM, Ted Hardie <ted.ietf@gmail.com> wrote:
> >>> This begins a working group last call for
> >>> draft-ietf-rtcweb-security-arch.  Please send comments to the list by
> >>> March 9, 2013.
> >>>
> >>> regards,
> >>>
> >>> Ted, Cullen, Magnus
> >> _______________________________________________
> >> rtcweb mailing list
> >> rtcweb@ietf.org
> >> https://www.ietf.org/mailman/listinfo/rtcweb
> >
> >
> >
> > --
> > Colin Perkins
> > http://csperkins.org/
> >
> >
> >
> _______________________________________________
> rtcweb mailing list
> rtcweb@ietf.org
> https://www.ietf.org/mailman/listinfo/rtcweb
>