Re: [rtcweb] Reminder: Working group last call for draft-ietf-rtcweb-security-arch

Bernard Aboba <bernard_aboba@hotmail.com> Wed, 06 March 2013 03:42 UTC

Return-Path: <bernard_aboba@hotmail.com>
X-Original-To: rtcweb@ietfa.amsl.com
Delivered-To: rtcweb@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B402111E80EE for <rtcweb@ietfa.amsl.com>; Tue, 5 Mar 2013 19:42:36 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -99.392
X-Spam-Level:
X-Spam-Status: No, score=-99.392 tagged_above=-999 required=5 tests=[AWL=1.212, BAYES_00=-2.599, J_CHICKENPOX_56=0.6, MIME_QP_LONG_LINE=1.396, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id U0B1WersLi6G for <rtcweb@ietfa.amsl.com>; Tue, 5 Mar 2013 19:42:35 -0800 (PST)
Received: from blu0-omc2-s5.blu0.hotmail.com (blu0-omc2-s5.blu0.hotmail.com [65.55.111.80]) by ietfa.amsl.com (Postfix) with ESMTP id AFDDF11E80EA for <rtcweb@ietf.org>; Tue, 5 Mar 2013 19:42:35 -0800 (PST)
Received: from BLU404-EAS141 ([65.55.111.71]) by blu0-omc2-s5.blu0.hotmail.com with Microsoft SMTPSVC(6.0.3790.4675); Tue, 5 Mar 2013 19:42:35 -0800
X-EIP: [4vZ+ioH1ydoBVuVSfOwBpjjgWGNClyos]
X-Originating-Email: [bernard_aboba@hotmail.com]
Message-ID: <BLU404-EAS1410F25C40BCDD2E495379D93E40@phx.gbl>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
References: <CA+9kkMATiwiFNyq3awr-EHwnWb3+ZEsP+Omgiwdev=8swgMrAQ@mail.gmail.com> <95790319-C42C-48E2-A6FD-0E718CCF48FB@csperkins.org> <CA+9kkMAg2grbyg1g94hm3cgV8957j++t55fuQhfWj1e_ZEGXdQ@mail.gmail.com> <CAOJ7v-0n2N5LrXQZyaZcCQZqYsHUP5U3Ox_d-RTivd2sCfZqwA@mail.gmail.com> <CABcZeBNf6gL8V9-F5VBG7EqBunThZs0uvS7LKjn8Beg0Qn4ozw@mail.gmail.com> <CABkgnnXQM0Q9gft10FBMbwq0jff4eU1Nb_=gcvPNRbjF+WCpXw@mail.gmail.com>
From: Bernard Aboba <bernard_aboba@hotmail.com>
MIME-Version: 1.0 (1.0)
In-Reply-To: <CABkgnnXQM0Q9gft10FBMbwq0jff4eU1Nb_=gcvPNRbjF+WCpXw@mail.gmail.com>
Date: Tue, 05 Mar 2013 19:42:38 -0800
To: Martin Thomson <martin.thomson@gmail.com>
X-OriginalArrivalTime: 06 Mar 2013 03:42:35.0438 (UTC) FILETIME=[A4121CE0:01CE1A1C]
Cc: "rtcweb@ietf.org" <rtcweb@ietf.org>, Colin Perkins <csp@csperkins.org>
Subject: Re: [rtcweb] Reminder: Working group last call for draft-ietf-rtcweb-security-arch
X-BeenThere: rtcweb@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Real-Time Communication in WEB-browsers working group list <rtcweb.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/rtcweb>
List-Post: <mailto:rtcweb@ietf.org>
List-Help: <mailto:rtcweb-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 06 Mar 2013 03:42:36 -0000

Or at least recommend against granting long term screen sharing permissions. Spying via audio and video is scary, true, but creepy screen sharing takes it to a new level.

On Mar 4, 2013, at 17:03, "Martin Thomson" <martin.thomson@gmail.com> wrote:

> Does the text say: "screen sharing is a bad idea" ?
> 
> On 4 March 2013 15:36, Eric Rescorla <ekr@rtfm.com> wrote:
>> Thanks, Justin.
>> 
>> I have been working on something for this and hope to have some text soon.
>> 
>> -Ekr
>> 
>> 
>> On Mon, Mar 4, 2013 at 3:30 PM, Justin Uberti <juberti@google.com> wrote:
>>> 
>>> I already sent mail to Eric on this, but one thing that needs
>>> consideration in this draft is the use case identified in section 4.2.7 of
>>> draft-ietf-rtcweb-use-cases-and-requirements-06, i.e. desktop sharing.
>>> Section 5.2 of the security doc covers the requirements for consent for
>>> camera access, but not for desktop access.
>>> 
>>> 
>>> On Mon, Mar 4, 2013 at 8:43 AM, Ted Hardie <ted.ietf@gmail.com> wrote:
>>>> 
>>>> Hi Colin,
>>>> 
>>>> Thanks for reviewing the document.  As you note, there are open
>>>> issues; 5.1, for example, has this:
>>>> 
>>>> "This is a  deliberate implementation complexity versus security
>>>> tradeoff.
>>>> [[ OPEN ISSUE::  Should we be more aggressive about this?]]"
>>>> 
>>>> As far as I am aware,though, the document in each case includes a
>>>> proposal for the Open Issue,
>>>> and it is that which would be in a WG document post last-call.  But if
>>>> folks looked at the document
>>>> and answered the "open issues" within, that would certainly be very
>>>> welcome input.
>>>> 
>>>> Were there any Open Issues or other points you wanted to comment on
>>>> directly?
>>>> 
>>>> Ted
>>>> 
>>>> 
>>>> but there
>>>> 
>>>> On Mon, Mar 4, 2013 at 4:58 AM, Colin Perkins <csp@csperkins.org> wrote:
>>>>> Ted,
>>>>> 
>>>>> This draft has a number of places where open issues are noted (e.g., in
>>>>> Sections 5.1 and 5.5, but there are many others). It seems premature to
>>>>> issue a working group last call until those are resolved.
>>>>> 
>>>>> Colin
>>>>> 
>>>>> 
>>>>> 
>>>>> On 25 Feb 2013, at 23:27, Ted Hardie wrote:
>>>>>> This is a reminder that there is an ongoing last call for
>>>>>> draft-ietf-rtcweb-security-arch-06.  Please send comments, including
>>>>>> those of the "reviewed and no issues" ilk, by March 9th, 2012.
>>>>>> 
>>>>>> regards,
>>>>>> 
>>>>>> Ted Hardie
>>>>>> 
>>>>>> On Thu, Feb 14, 2013 at 8:35 AM, Ted Hardie <ted.ietf@gmail.com>
>>>>>> wrote:
>>>>>>> This begins a working group last call for
>>>>>>> draft-ietf-rtcweb-security-arch.  Please send comments to the list by
>>>>>>> March 9, 2013.
>>>>>>> 
>>>>>>> regards,
>>>>>>> 
>>>>>>> Ted, Cullen, Magnus
>>>>>> _______________________________________________
>>>>>> rtcweb mailing list
>>>>>> rtcweb@ietf.org
>>>>>> https://www.ietf.org/mailman/listinfo/rtcweb
>>>>> 
>>>>> 
>>>>> 
>>>>> --
>>>>> Colin Perkins
>>>>> http://csperkins.org/
>>>>> 
>>>>> 
>>>>> 
>>>> _______________________________________________
>>>> rtcweb mailing list
>>>> rtcweb@ietf.org
>>>> https://www.ietf.org/mailman/listinfo/rtcweb
>>> 
>>> 
>>> 
>>> _______________________________________________
>>> rtcweb mailing list
>>> rtcweb@ietf.org
>>> https://www.ietf.org/mailman/listinfo/rtcweb
>>> 
>> 
>> 
>> _______________________________________________
>> rtcweb mailing list
>> rtcweb@ietf.org
>> https://www.ietf.org/mailman/listinfo/rtcweb
>> 
> _______________________________________________
> rtcweb mailing list
> rtcweb@ietf.org
> https://www.ietf.org/mailman/listinfo/rtcweb