Re: CfC: only allow authenticated origins to call getUserMedia

On Wed, Oct 8, 2014 at 7:30 AM, Anne van Kesteren <annevk@annevk.nl> wrote:

> On Wed, Oct 8, 2014 at 3:56 PM, Eric Rescorla <ekr@rtfm.com> wrote:
> > It is not generally true that *passive* network attackers will be able to
> > watch or listen to users in real-time, even if gUM is used without an
> > authenticated origin.
>
> As Chris pointed out earlier, the difference between passive/active is
> (becoming) marginal:
> http://lists.w3.org/Archives/Public/public-media-capture/2014Oct/0071.html


As Adam Roach has observed on a separate thread, this not a position
that has anything like consensus:

https://groups.google.com/forum/#!searchin/mozilla.dev.platform/roach$20myth/mozilla.dev.platform/sT7hqMyzOEA/ZKUYrNj93ksJ


In any case, my comments were directed towards having an accurate
threat model, and regardless of the ease of active attack, it is not true
that the risks of gUM are the same for active and passive attackers.
I take it from your message that you agree with this point.

-Ekr


> Given the low cost, the vast amounts of information that could be
> collected in this way (even from normally authenticated but now
> sslstripped spoofed resources), it seems very likely this would be
> pursued.
>
>
> --
> https://annevankesteren.nl/
>

Received on Wednesday, 8 October 2014 16:05:41 UTC