[Bug 26332] Applications should only use EME APIs on secure origins (e.g. HTTPS)

https://www.w3.org/Bugs/Public/show_bug.cgi?id=26332

--- Comment #85 from David Dorwin <ddorwin@google.com> ---
(In reply to Bob Lund from comment #83)
> Wouldn't another alternative be a normative requirement that requests from
> CDM are encrypted?

That would be a form of identifier protection, but that can only hope to
address a subset of privacy-related concerns. Also, such a requirement would
need to be very detailed and prescriptive to ensure the appropriate privacy
properties.

-- 
You are receiving this mail because:
You are the QA Contact for the bug.

Received on Wednesday, 15 October 2014 22:06:56 UTC