Re: [Bug 25809] Security issue: Abuse of "call me" URLs

On 28/08/14 23:29, Martin Thomson wrote:
> On 28 August 2014 03:24, Harald Alvestrand <harald@alvestrand.no> wrote:
>>> We could for instance prevent getUserMedia from operating without an
>>> "engagement gesture" (see
>>> https://dvcs.w3.org/hg/pointerlock/raw-file/default/index.html#glossary
>>> ).
>>
>> I'm hesitant to go that route. This would add an extra activation step
>> to pages whose only purpose is to send video - for instance, it would
>> require an engagement gesture before starting the video on
>> apprtc.appspot.com.
>
>
> I find this tempting, despite the costs here.  The permissions prompt
> is a popup of a sort, so applying the same protection makes a great
> deal of sense.  It's obviously a non-issue on sites where permissions
> are persisted, so I'm inclined quite favourably toward this.

I thought this was specifically for sites with persisted permissions.



Received on Monday, 1 September 2014 06:52:35 UTC