Re: [w3ctag/design-reviews] Private Network Access (aka CORS-RFC1918) (#572)

We discussed this again in our Virtual F2F, and had questions about legacy devices.
As one goal is to ensure that you don't attack devices, legacy devices that can't be updated comes to mind, link printers.
Most of those devices are usually advertised on the local network, so the UA might be able to figure them out and allowing access like a "paired" device (to avoid completely blocking them out).

Another issue is, should the local network be only the ip/netmask range and not the list of all the private ranges?

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/w3ctag/design-reviews/issues/572#issuecomment-919237060

Received on Tuesday, 14 September 2021 15:02:43 UTC