Re: [rtcweb] What is consent?

Eric Rescorla <ekr@rtfm.com> Thu, 13 September 2012 00:14 UTC

Return-Path: <ekr@rtfm.com>
X-Original-To: rtcweb@ietfa.amsl.com
Delivered-To: rtcweb@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E814B21F85C3 for <rtcweb@ietfa.amsl.com>; Wed, 12 Sep 2012 17:14:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.977
X-Spam-Level:
X-Spam-Status: No, score=-102.977 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, FM_FORGED_GMAIL=0.622, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id q0cca70E0lAh for <rtcweb@ietfa.amsl.com>; Wed, 12 Sep 2012 17:14:41 -0700 (PDT)
Received: from mail-wi0-f172.google.com (mail-wi0-f172.google.com [209.85.212.172]) by ietfa.amsl.com (Postfix) with ESMTP id 142FF21F85A3 for <rtcweb@ietf.org>; Wed, 12 Sep 2012 17:14:40 -0700 (PDT)
Received: by wibhi8 with SMTP id hi8so4650202wib.13 for <rtcweb@ietf.org>; Wed, 12 Sep 2012 17:14:40 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:x-originating-ip:in-reply-to:references:from:date :message-id:subject:to:cc:content-type:content-transfer-encoding :x-gm-message-state; bh=O05TiqIJp7f6xEUkAx2AmulEyxvl9FgNCffSZKR5YTw=; b=ElDRTSvJZaMLg9FK+kcQGgyfn21AcXRi2qJHNgLdfzWTYy/cXwyrJrxd/eu6O+D+II 3lgLXz4HShn68m7jI0Atj3iB32XNeH4cl0msEVefKimXamYxEASbb4a0rwA73GharAel UwcS4YMw9bsqCeUv0fmzgs/10U6R2BPEnkCN1tR7Yc3TTj208wJj173/GAxYnlFs3SYs QEM2ds+q1XnalG6GnWco8/NbBPMJ1nKjb+VTpBnvJqEShBe9NTxRt38Ptrx7J5uF9JJX YuVb2Vli0a8+P+hnY2NIRRt49aiymFKJ3dcHHyk6uskXyzdn4xJUeDpP8WQ20+v8f6fU tryA==
Received: by 10.216.138.200 with SMTP id a50mr100445wej.155.1347495279907; Wed, 12 Sep 2012 17:14:39 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.223.1.197 with HTTP; Wed, 12 Sep 2012 17:13:59 -0700 (PDT)
X-Originating-IP: [74.95.2.173]
In-Reply-To: <BLU401-EAS3659768F4AA0A4679588F5593910@phx.gbl>
References: <CABkgnnXAPZ5BN=CUwYdEpHKbCLBxctqpONL==QWf_WwgrNEK_A@mail.gmail.com> <CABcZeBNnoQwJu1MYSW=6q6pkrgXSPSUtVyOsngrPP6b8GaegdQ@mail.gmail.com> <CABkgnnUNhka8OJsiNCV5iOvU_cGyvt_y8=DN6qnud3Xr-dy1iQ@mail.gmail.com> <CABcZeBNddHgHnkZ5b2N4i-np3WuY51f6WHkBdT5mHBsieLMDow@mail.gmail.com> <BLU169-DS48211D4056CB291285DD4393930@phx.gbl> <08c301cd9076$a2405c40$e6c114c0$@com> <BLU401-EAS3820748E547AD9D27E1220893920@phx.gbl> <DA165A8A2929C6429CAB403A76B573A5146A00B9@szxeml534-mbx.china.huawei.com> <BLU401-EAS46055078032CCFBDDFD2C2B93920@phx.gbl> <CABkgnnUMcFx15qytVNo2G67CX84TLZ_29UMB5EzJ=WqRF5o1GQ@mail.gmail.com> <0c2301cd910d$7f4bd150$7de373f0$@com> <CABkgnnUMsoOT954Jgd=jq6jjrhLV0uqSL6R4148mYtFMPG-JaQ@mail.gmail.com> <50511D4C.9040805@alvestrand.no> <BLU401-EAS3659768F4AA0A4679588F5593910@phx.gbl>
From: Eric Rescorla <ekr@rtfm.com>
Date: Wed, 12 Sep 2012 17:13:59 -0700
Message-ID: <CABcZeBPYkHqwk5yMe3_uhojz=aAamMwf19nJ5JB13O27+jVfOQ@mail.gmail.com>
To: Bernard Aboba <bernard_aboba@hotmail.com>
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: quoted-printable
X-Gm-Message-State: ALoCoQmilfl7Tu4wLdPes0gTb4Z0eNXdO47uch663SK6up+nFwJVSfLGtvmm1J5l2s78CvfBf98t
Cc: "rtcweb@ietf.org" <rtcweb@ietf.org>
Subject: Re: [rtcweb] What is consent?
X-BeenThere: rtcweb@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Real-Time Communication in WEB-browsers working group list <rtcweb.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/rtcweb>
List-Post: <mailto:rtcweb@ietf.org>
List-Help: <mailto:rtcweb-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 13 Sep 2012 00:14:42 -0000

By not returning consent checks.

On Wed, Sep 12, 2012 at 5:02 PM, Bernard Aboba
<bernard_aboba@hotmail.com> wrote:
> On Sep 12, 2012, at 6:40 PM, "Harald Alvestrand" <harald@alvestrand.no> wrote:
>>
>> The browser being used to stage an attack will of course not know this value, since its signalling is controlled by the attacker, but the browser being attacked will be able to tell the difference between a within-contract amount of data and an out-of-contract amount of data.
>>
>>              Harald
>
> [BA] Correct, but how does the receiver turn off the spigot? Is this handled via circuit breakers?
> _______________________________________________
> rtcweb mailing list
> rtcweb@ietf.org
> https://www.ietf.org/mailman/listinfo/rtcweb