You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
"You've heard from the TAG already about whether use of the API ever makes sense in unprivileged contexts. That is, when the user is asked for permission to access their camera, do they understand that they're granting this permission to all network attackers as well as the site they think they're talking to? I suspect this PING email thread is not going to change your minds about that already discussed topic. However, it would be worthwhile to note this security threat in the security considerations section and to note for user agent implementers the difficulty for this permission prompt."
This does not suggest a technical change in when getUserMedia is permitted, but does suggest that section 13 (security and privacy) should have some text explaining the reasoning behind the current spec.
The text was updated successfully, but these errors were encountered:
From Nick Doty's mail on behalf of PING:
"You've heard from the TAG already about whether use of the API ever makes sense in unprivileged contexts. That is, when the user is asked for permission to access their camera, do they understand that they're granting this permission to all network attackers as well as the site they think they're talking to? I suspect this PING email thread is not going to change your minds about that already discussed topic. However, it would be worthwhile to note this security threat in the security considerations section and to note for user agent implementers the difficulty for this permission prompt."
This does not suggest a technical change in when getUserMedia is permitted, but does suggest that section 13 (security and privacy) should have some text explaining the reasoning behind the current spec.
The text was updated successfully, but these errors were encountered: