[rtcweb] Mirja Kühlewind's Discuss on draft-ietf-rtcweb-security-11: (with DISCUSS and COMMENT)

Mirja Kühlewind <ietf@kuehlewind.net> Thu, 28 February 2019 18:00 UTC

Return-Path: <ietf@kuehlewind.net>
X-Original-To: rtcweb@ietf.org
Delivered-To: rtcweb@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 2719B12F1AB; Thu, 28 Feb 2019 10:00:08 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 8bit
From: Mirja Kühlewind <ietf@kuehlewind.net>
To: The IESG <iesg@ietf.org>
Cc: draft-ietf-rtcweb-security@ietf.org, Sean Turner <sean@sn3rd.com>, rtcweb-chairs@ietf.org, sean@sn3rd.com, rtcweb@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 6.92.1
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <155137680815.28736.10104782585142415268.idtracker@ietfa.amsl.com>
Date: Thu, 28 Feb 2019 10:00:08 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/rtcweb/EQMudXInQPKVba02HTFVIdLN3m8>
Subject: [rtcweb] Mirja Kühlewind's Discuss on draft-ietf-rtcweb-security-11: (with DISCUSS and COMMENT)
X-BeenThere: rtcweb@ietf.org
X-Mailman-Version: 2.1.29
List-Id: Real-Time Communication in WEB-browsers working group list <rtcweb.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rtcweb/>
List-Post: <mailto:rtcweb@ietf.org>
List-Help: <mailto:rtcweb-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 28 Feb 2019 18:00:08 -0000

Mirja Kühlewind has entered the following ballot position for
draft-ietf-rtcweb-security-11: Discuss

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to https://www.ietf.org/iesg/statement/discuss-criteria.html
for more information about IESG DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-rtcweb-security/



----------------------------------------------------------------------
DISCUSS:
----------------------------------------------------------------------

I think this document is clearly informational. Other RTCweb documents should
refer this document informatively and only reference the sec arch doc
normatively.


----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

I would have also expected some discussion about the risks to the user if the
browser gets corrupted, as indicated by the trust model presented in
draft-ietf-rtcweb-security-arch. Alternatively, this document could go in the
appendix of draft-ietf-rtcweb-security-arch instead.