Re: [rtcweb] Reminder: Working group last call for draft-ietf-rtcweb-security-arch
Bernard Aboba <bernard_aboba@hotmail.com> Wed, 06 March 2013 03:42 UTC
Return-Path: <bernard_aboba@hotmail.com>
X-Original-To: rtcweb@ietfa.amsl.com
Delivered-To: rtcweb@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B402111E80EE for <rtcweb@ietfa.amsl.com>; Tue, 5 Mar 2013 19:42:36 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -99.392
X-Spam-Level:
X-Spam-Status: No, score=-99.392 tagged_above=-999 required=5 tests=[AWL=1.212, BAYES_00=-2.599, J_CHICKENPOX_56=0.6, MIME_QP_LONG_LINE=1.396, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id U0B1WersLi6G for <rtcweb@ietfa.amsl.com>; Tue, 5 Mar 2013 19:42:35 -0800 (PST)
Received: from blu0-omc2-s5.blu0.hotmail.com (blu0-omc2-s5.blu0.hotmail.com [65.55.111.80]) by ietfa.amsl.com (Postfix) with ESMTP id AFDDF11E80EA for <rtcweb@ietf.org>; Tue, 5 Mar 2013 19:42:35 -0800 (PST)
Received: from BLU404-EAS141 ([65.55.111.71]) by blu0-omc2-s5.blu0.hotmail.com with Microsoft SMTPSVC(6.0.3790.4675); Tue, 5 Mar 2013 19:42:35 -0800
X-EIP: [4vZ+ioH1ydoBVuVSfOwBpjjgWGNClyos]
X-Originating-Email: [bernard_aboba@hotmail.com]
Message-ID: <BLU404-EAS1410F25C40BCDD2E495379D93E40@phx.gbl>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
References: <CA+9kkMATiwiFNyq3awr-EHwnWb3+ZEsP+Omgiwdev=8swgMrAQ@mail.gmail.com> <95790319-C42C-48E2-A6FD-0E718CCF48FB@csperkins.org> <CA+9kkMAg2grbyg1g94hm3cgV8957j++t55fuQhfWj1e_ZEGXdQ@mail.gmail.com> <CAOJ7v-0n2N5LrXQZyaZcCQZqYsHUP5U3Ox_d-RTivd2sCfZqwA@mail.gmail.com> <CABcZeBNf6gL8V9-F5VBG7EqBunThZs0uvS7LKjn8Beg0Qn4ozw@mail.gmail.com> <CABkgnnXQM0Q9gft10FBMbwq0jff4eU1Nb_=gcvPNRbjF+WCpXw@mail.gmail.com>
From: Bernard Aboba <bernard_aboba@hotmail.com>
MIME-Version: 1.0 (1.0)
In-Reply-To: <CABkgnnXQM0Q9gft10FBMbwq0jff4eU1Nb_=gcvPNRbjF+WCpXw@mail.gmail.com>
Date: Tue, 05 Mar 2013 19:42:38 -0800
To: Martin Thomson <martin.thomson@gmail.com>
X-OriginalArrivalTime: 06 Mar 2013 03:42:35.0438 (UTC) FILETIME=[A4121CE0:01CE1A1C]
Cc: "rtcweb@ietf.org" <rtcweb@ietf.org>, Colin Perkins <csp@csperkins.org>
Subject: Re: [rtcweb] Reminder: Working group last call for draft-ietf-rtcweb-security-arch
X-BeenThere: rtcweb@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Real-Time Communication in WEB-browsers working group list <rtcweb.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/rtcweb>
List-Post: <mailto:rtcweb@ietf.org>
List-Help: <mailto:rtcweb-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 06 Mar 2013 03:42:36 -0000
Or at least recommend against granting long term screen sharing permissions. Spying via audio and video is scary, true, but creepy screen sharing takes it to a new level. On Mar 4, 2013, at 17:03, "Martin Thomson" <martin.thomson@gmail.com> wrote: > Does the text say: "screen sharing is a bad idea" ? > > On 4 March 2013 15:36, Eric Rescorla <ekr@rtfm.com> wrote: >> Thanks, Justin. >> >> I have been working on something for this and hope to have some text soon. >> >> -Ekr >> >> >> On Mon, Mar 4, 2013 at 3:30 PM, Justin Uberti <juberti@google.com> wrote: >>> >>> I already sent mail to Eric on this, but one thing that needs >>> consideration in this draft is the use case identified in section 4.2.7 of >>> draft-ietf-rtcweb-use-cases-and-requirements-06, i.e. desktop sharing. >>> Section 5.2 of the security doc covers the requirements for consent for >>> camera access, but not for desktop access. >>> >>> >>> On Mon, Mar 4, 2013 at 8:43 AM, Ted Hardie <ted.ietf@gmail.com> wrote: >>>> >>>> Hi Colin, >>>> >>>> Thanks for reviewing the document. As you note, there are open >>>> issues; 5.1, for example, has this: >>>> >>>> "This is a deliberate implementation complexity versus security >>>> tradeoff. >>>> [[ OPEN ISSUE:: Should we be more aggressive about this?]]" >>>> >>>> As far as I am aware,though, the document in each case includes a >>>> proposal for the Open Issue, >>>> and it is that which would be in a WG document post last-call. But if >>>> folks looked at the document >>>> and answered the "open issues" within, that would certainly be very >>>> welcome input. >>>> >>>> Were there any Open Issues or other points you wanted to comment on >>>> directly? >>>> >>>> Ted >>>> >>>> >>>> but there >>>> >>>> On Mon, Mar 4, 2013 at 4:58 AM, Colin Perkins <csp@csperkins.org> wrote: >>>>> Ted, >>>>> >>>>> This draft has a number of places where open issues are noted (e.g., in >>>>> Sections 5.1 and 5.5, but there are many others). It seems premature to >>>>> issue a working group last call until those are resolved. >>>>> >>>>> Colin >>>>> >>>>> >>>>> >>>>> On 25 Feb 2013, at 23:27, Ted Hardie wrote: >>>>>> This is a reminder that there is an ongoing last call for >>>>>> draft-ietf-rtcweb-security-arch-06. Please send comments, including >>>>>> those of the "reviewed and no issues" ilk, by March 9th, 2012. >>>>>> >>>>>> regards, >>>>>> >>>>>> Ted Hardie >>>>>> >>>>>> On Thu, Feb 14, 2013 at 8:35 AM, Ted Hardie <ted.ietf@gmail.com> >>>>>> wrote: >>>>>>> This begins a working group last call for >>>>>>> draft-ietf-rtcweb-security-arch. Please send comments to the list by >>>>>>> March 9, 2013. >>>>>>> >>>>>>> regards, >>>>>>> >>>>>>> Ted, Cullen, Magnus >>>>>> _______________________________________________ >>>>>> rtcweb mailing list >>>>>> rtcweb@ietf.org >>>>>> https://www.ietf.org/mailman/listinfo/rtcweb >>>>> >>>>> >>>>> >>>>> -- >>>>> Colin Perkins >>>>> http://csperkins.org/ >>>>> >>>>> >>>>> >>>> _______________________________________________ >>>> rtcweb mailing list >>>> rtcweb@ietf.org >>>> https://www.ietf.org/mailman/listinfo/rtcweb >>> >>> >>> >>> _______________________________________________ >>> rtcweb mailing list >>> rtcweb@ietf.org >>> https://www.ietf.org/mailman/listinfo/rtcweb >>> >> >> >> _______________________________________________ >> rtcweb mailing list >> rtcweb@ietf.org >> https://www.ietf.org/mailman/listinfo/rtcweb >> > _______________________________________________ > rtcweb mailing list > rtcweb@ietf.org > https://www.ietf.org/mailman/listinfo/rtcweb
- [rtcweb] Reminder: Working group last call for dr… Ted Hardie
- Re: [rtcweb] Reminder: Working group last call fo… Colin Perkins
- Re: [rtcweb] Reminder: Working group last call fo… Ted Hardie
- Re: [rtcweb] Reminder: Working group last call fo… Justin Uberti
- Re: [rtcweb] Reminder: Working group last call fo… Eric Rescorla
- Re: [rtcweb] Reminder: Working group last call fo… Martin Thomson
- Re: [rtcweb] Reminder: Working group last call fo… Bernard Aboba
- Re: [rtcweb] Reminder: Working group last call fo… Oscar Ohlsson
- Re: [rtcweb] Reminder: Working group last call fo… Richard Barnes