On Mar 8, 2012, at 4:15 PM, Charles Pritchard wrote:
In my imaginary life, I would write a CDMs baseline using websockets masking key, and add it to that specification as the default keysystem.
<http://tools.ietf.org/html/rfc6455>
Vendors and authors have mature websockets masking code.
http://tools.ietf.org/html/rfc6455#section-5.3
http://dev.w3.org/html5/websockets/
Content would be masked on the network (CDN?) all the way through to the media element (CDMs) stream processing.
So the network sends the whole file websockets masked, it gets unmasked by the browser as the file is read.
This would typically look like a blob:*: uri to debugging tools when running a url inspector.
Charles - I'm not sure I understand the point of using WebSockets masking.
I just read that part of the spec, and masking appears intended to avoid data being inadvertently interpreted by intermediaries, since it was discovered that some intermediaries would interpret HTTP requests embedded in websockets frames and this could open the possibility of a cache poisoning attack.
In this case we do not have any such problem of accidental interpretation of media data. Masking doesn't hide the data from anyone deliberately trying to read it.
What am I missing ?
...Mark