Other work needed ?- was Re: Proposed Charter Changes

Hi, regardless of anything to do with charters, I just wanted to learn a but more about what you had in mind with the following:

> On May 7, 2015, at 7:29 AM, Göran Eriksson AP <goran.ap.eriksson@ericsson.com> wrote:
> 
> * harmonization with rest of WebAppSec (and others) about Web platform
> security evolution

Thoughts on what's needed? I worry that much of the security will be largely unchangeable by the time we ship 1.0 so want to check if there is anything we need to deal with now. Of course agree harmonization is good, just not sure what is needed. 

> * General User Security and Privacy improvements

Again, I worry that later things will only make the privacy worse not better so love to hear what you have in mind. 

> * Delegation use cases (Web app from one origin, part of find and
> connect, TURN, conference servers from another provider (and origin))
> for verticals like Financial, E-health and Manufacturing

As long as  TURN credentials are coordinated between the TURN provider and web provider (and there is work to improve that as you know), it seems to work now to get TURN servers from one provider, conferencing servers from another, and build the website on yet another origin, and the rendezvous servers could be via another service.  For example, I've seen apps with PubHub for rendezvous, Tropo for media server, and webserver off Heroku. Something more needed?

Received on Monday, 11 May 2015 16:40:52 UTC