Re: [rtcweb] Reminder: Working group last call for draft-ietf-rtcweb-security-arch

Martin Thomson <martin.thomson@gmail.com> Tue, 05 March 2013 01:02 UTC

Return-Path: <martin.thomson@gmail.com>
X-Original-To: rtcweb@ietfa.amsl.com
Delivered-To: rtcweb@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 534FE21F8999 for <rtcweb@ietfa.amsl.com>; Mon, 4 Mar 2013 17:02:57 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.899
X-Spam-Level:
X-Spam-Status: No, score=-2.899 tagged_above=-999 required=5 tests=[AWL=0.100, BAYES_00=-2.599, J_CHICKENPOX_56=0.6, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zbI2fBwQd2WK for <rtcweb@ietfa.amsl.com>; Mon, 4 Mar 2013 17:02:56 -0800 (PST)
Received: from mail-wg0-f45.google.com (mail-wg0-f45.google.com [74.125.82.45]) by ietfa.amsl.com (Postfix) with ESMTP id 4E53D21F893D for <rtcweb@ietf.org>; Mon, 4 Mar 2013 17:02:56 -0800 (PST)
Received: by mail-wg0-f45.google.com with SMTP id dq12so4754954wgb.0 for <rtcweb@ietf.org>; Mon, 04 Mar 2013 17:02:55 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:x-received:in-reply-to:references:date:message-id :subject:from:to:cc:content-type; bh=CDKBq/Hd2o+IMtkpeKEGew/P5uu8VPw/2m5z5+bHyuM=; b=H5x4TOSfGrEboPm0TQY9lJ+GBy0CN+FTrPpupWwGxI7uHTknskCRwPOhGzNayIUUe1 PkSXOhz6vAh8HzcoVQO8ym7yD3rjgYBakHxFJJLF4yKbx6FSCeHJg4pSw1voO75oAafl nauE9gODFK84mV5Nql+fF/gPbxBQEVX9/LxVtz0Lq5oTtxAPNeNi1AoV5uMry0xjag79 AkgMvyy8Yb+pBveBpI/1MhwTFYN5vDJZcol1c9gCqcpPn2NaUoU6XWlgJgeNt+djsfD8 +Aw1+a1vU8UalDUIvDOeGidAh4Wih/CEOBALIOkgvLulHDuxmxNw8zET47C1U9cLipd/ AINg==
MIME-Version: 1.0
X-Received: by 10.180.80.35 with SMTP id o3mr15452687wix.9.1362445375502; Mon, 04 Mar 2013 17:02:55 -0800 (PST)
Received: by 10.194.5.135 with HTTP; Mon, 4 Mar 2013 17:02:55 -0800 (PST)
In-Reply-To: <CABcZeBNf6gL8V9-F5VBG7EqBunThZs0uvS7LKjn8Beg0Qn4ozw@mail.gmail.com>
References: <CA+9kkMATiwiFNyq3awr-EHwnWb3+ZEsP+Omgiwdev=8swgMrAQ@mail.gmail.com> <95790319-C42C-48E2-A6FD-0E718CCF48FB@csperkins.org> <CA+9kkMAg2grbyg1g94hm3cgV8957j++t55fuQhfWj1e_ZEGXdQ@mail.gmail.com> <CAOJ7v-0n2N5LrXQZyaZcCQZqYsHUP5U3Ox_d-RTivd2sCfZqwA@mail.gmail.com> <CABcZeBNf6gL8V9-F5VBG7EqBunThZs0uvS7LKjn8Beg0Qn4ozw@mail.gmail.com>
Date: Mon, 4 Mar 2013 17:02:55 -0800
Message-ID: <CABkgnnXQM0Q9gft10FBMbwq0jff4eU1Nb_=gcvPNRbjF+WCpXw@mail.gmail.com>
From: Martin Thomson <martin.thomson@gmail.com>
To: Eric Rescorla <ekr@rtfm.com>
Content-Type: text/plain; charset=UTF-8
Cc: "rtcweb@ietf.org" <rtcweb@ietf.org>, Colin Perkins <csp@csperkins.org>
Subject: Re: [rtcweb] Reminder: Working group last call for draft-ietf-rtcweb-security-arch
X-BeenThere: rtcweb@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Real-Time Communication in WEB-browsers working group list <rtcweb.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/rtcweb>
List-Post: <mailto:rtcweb@ietf.org>
List-Help: <mailto:rtcweb-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 05 Mar 2013 01:02:57 -0000

Does the text say: "screen sharing is a bad idea" ?

On 4 March 2013 15:36, Eric Rescorla <ekr@rtfm.com> wrote:
> Thanks, Justin.
>
> I have been working on something for this and hope to have some text soon.
>
> -Ekr
>
>
> On Mon, Mar 4, 2013 at 3:30 PM, Justin Uberti <juberti@google.com> wrote:
>>
>> I already sent mail to Eric on this, but one thing that needs
>> consideration in this draft is the use case identified in section 4.2.7 of
>> draft-ietf-rtcweb-use-cases-and-requirements-06, i.e. desktop sharing.
>> Section 5.2 of the security doc covers the requirements for consent for
>> camera access, but not for desktop access.
>>
>>
>> On Mon, Mar 4, 2013 at 8:43 AM, Ted Hardie <ted.ietf@gmail.com> wrote:
>>>
>>> Hi Colin,
>>>
>>> Thanks for reviewing the document.  As you note, there are open
>>> issues; 5.1, for example, has this:
>>>
>>> "This is a  deliberate implementation complexity versus security
>>> tradeoff.
>>>  [[ OPEN ISSUE::  Should we be more aggressive about this?]]"
>>>
>>> As far as I am aware,though, the document in each case includes a
>>> proposal for the Open Issue,
>>> and it is that which would be in a WG document post last-call.  But if
>>> folks looked at the document
>>> and answered the "open issues" within, that would certainly be very
>>> welcome input.
>>>
>>> Were there any Open Issues or other points you wanted to comment on
>>> directly?
>>>
>>> Ted
>>>
>>>
>>> but there
>>>
>>> On Mon, Mar 4, 2013 at 4:58 AM, Colin Perkins <csp@csperkins.org> wrote:
>>> > Ted,
>>> >
>>> > This draft has a number of places where open issues are noted (e.g., in
>>> > Sections 5.1 and 5.5, but there are many others). It seems premature to
>>> > issue a working group last call until those are resolved.
>>> >
>>> > Colin
>>> >
>>> >
>>> >
>>> > On 25 Feb 2013, at 23:27, Ted Hardie wrote:
>>> >> This is a reminder that there is an ongoing last call for
>>> >> draft-ietf-rtcweb-security-arch-06.  Please send comments, including
>>> >> those of the "reviewed and no issues" ilk, by March 9th, 2012.
>>> >>
>>> >> regards,
>>> >>
>>> >> Ted Hardie
>>> >>
>>> >> On Thu, Feb 14, 2013 at 8:35 AM, Ted Hardie <ted.ietf@gmail.com>
>>> >> wrote:
>>> >>> This begins a working group last call for
>>> >>> draft-ietf-rtcweb-security-arch.  Please send comments to the list by
>>> >>> March 9, 2013.
>>> >>>
>>> >>> regards,
>>> >>>
>>> >>> Ted, Cullen, Magnus
>>> >> _______________________________________________
>>> >> rtcweb mailing list
>>> >> rtcweb@ietf.org
>>> >> https://www.ietf.org/mailman/listinfo/rtcweb
>>> >
>>> >
>>> >
>>> > --
>>> > Colin Perkins
>>> > http://csperkins.org/
>>> >
>>> >
>>> >
>>> _______________________________________________
>>> rtcweb mailing list
>>> rtcweb@ietf.org
>>> https://www.ietf.org/mailman/listinfo/rtcweb
>>
>>
>>
>> _______________________________________________
>> rtcweb mailing list
>> rtcweb@ietf.org
>> https://www.ietf.org/mailman/listinfo/rtcweb
>>
>
>
> _______________________________________________
> rtcweb mailing list
> rtcweb@ietf.org
> https://www.ietf.org/mailman/listinfo/rtcweb
>