Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

PING: Document tradeoff for non-HTTPS usage of getUserMedia #249

Closed
alvestrand opened this issue Sep 21, 2015 · 1 comment
Closed

PING: Document tradeoff for non-HTTPS usage of getUserMedia #249

alvestrand opened this issue Sep 21, 2015 · 1 comment
Assignees

Comments

@alvestrand
Copy link
Contributor

From Nick Doty's mail on behalf of PING:

"You've heard from the TAG already about whether use of the API ever makes sense in unprivileged contexts. That is, when the user is asked for permission to access their camera, do they understand that they're granting this permission to all network attackers as well as the site they think they're talking to? I suspect this PING email thread is not going to change your minds about that already discussed topic. However, it would be worthwhile to note this security threat in the security considerations section and to note for user agent implementers the difficulty for this permission prompt."

This does not suggest a technical change in when getUserMedia is permitted, but does suggest that section 13 (security and privacy) should have some text explaining the reasoning behind the current spec.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants