W3C home > Mailing lists > Public > public-media-capture@w3.org > October 2014

Re: CfC: only allow authenticated origins to call getUserMedia

From: Justin Uberti <juberti@google.com>
Date: Tue, 7 Oct 2014 11:00:26 -0700
Message-ID: <CAOJ7v-1_9U6-0aGx1UBYxJ6+cEvLpCg_RQLx3UvbXfH+=fi48Q@mail.gmail.com>
To: Anne van Kesteren <annevk@annevk.nl>
Cc: Stefan HÃ¥kansson LK <stefan.lk.hakansson@ericsson.com>, "public-media-capture@w3.org" <public-media-capture@w3.org>
On Tue, Oct 7, 2014 at 9:04 AM, Anne van Kesteren <annevk@annevk.nl> wrote:

> On Tue, Oct 7, 2014 at 5:59 PM, Justin Uberti <juberti@google.com> wrote:
> > 2) this breaks real, existing applications, e.g. http://webcamtoy.com/
>
> It seems they could easily move to use an authenticated origin, no?
>
>
> > 3) makes trying/experimenting with webrtc difficult, e.g.
> > http://jsfiddle.net, or http://localhost
>
> Same for jsfiddle.net. localhost is already an authenticated origin.
>
>
> Some short term breakage should not outweigh long term pervasive
> monitoring.
>
>
These are just some arbitrarily selected examples. The point is that short
term breakage would not be insignificant.

While I agree that we should encourage web developers to upgrade to HTTPS,
singling out WebRTC developers seems like the wrong way to go about this.
Received on Tuesday, 7 October 2014 18:01:13 UTC

This archive was generated by hypermail 2.4.0 : Friday, 17 January 2020 16:26:30 UTC