Re: Request for feedback: Media Capture and Streams Last Call

Hi all,

Sorry for the late reply.

Overall, this spec looks really good, we at CDT just had a few small
suggestions:

   1. It would be nice if there was a simple, user friendly way to revoke
   consent for a stream (especially audio/webcam streams). As it currently
   stands, once consent is granted there doesn't seem to be simple way to
   revoke it.
   2. In section 10.6, it is stated that persistent permissions must be be
   served over HTTPS and have no mixed content. It would be nice to see the
   "definition" of mixed content expanded to include the various issues
   mentioned in Bonneau's recent paper[1]. For example, if a site elects to
   use pinning, it should be considered to have mixed content if it loads
   non-pinned content.

Also, as an aside, we used the TAG questionnaire, and while it was very
useful, we think it could use some tweaking. And in the spirit of open
source, we'll be proposing some tweaks (probably sometime late next week)

[1] http://www.jbonneau.com/doc/KB15-NDSS-hsts_pinning_survey.pdf

Received on Thursday, 4 June 2015 20:02:09 UTC