W3C home > Mailing lists > Public > public-webrtc@w3.org > September 2011

Re: PeerConnection Data Channel

From: Matthew Kaufman <matthew.kaufman@skype.net>
Date: Sun, 04 Sep 2011 20:55:17 -0700
Message-ID: <4E644825.5070208@skype.net>
To: Eric Rescorla <ekr@rtfm.com>
CC: Justin Uberti <juberti@google.com>, public-webrtc@w3.org
On 9/3/2011 8:10 AM, Eric Rescorla wrote:
> On Fri, Sep 2, 2011 at 11:17 AM, Matthew Kaufman
> <matthew.kaufman@skype.net>  wrote:
>
>> DTLS is even
>> more obvious of course.
> Indeed. Experience has shown that designing even this kind of simple security
> protocol is hard. In this case it seems extraordinarily inadvisable
> given that we
> have a well-defined IETF Standards Track protocol designed specifically for
> the purpose of securing datagram transmissions.
>

This just gives more weight to:
  prefer DTLS-SRTP for media (and DTLS for data)
  allow plain RTP for media (but not allow data when plain RTP is in use)
  disallow SRTP (and data) with any other type of keying (i.e. SDES)

or, perhaps even better, disallow plain RTP for media as well.

Matthew Kaufman
Received on Monday, 5 September 2011 03:56:21 UTC

This archive was generated by hypermail 2.3.1 : Monday, 23 October 2017 15:19:25 UTC