Οι Ομάδες Google δεν υποστηρίζουν πλέον νέες αναρτήσεις ή εγγραφές στο Usenet. Το ιστορικό περιεχόμενο παραμένει ορατό.

WebAPI Security Discussion: Web Bluetooth API

24 προβολές
Παράβλεψη και μετάβαση στο πρώτο μη αναγνωσμένο μήνυμα

Lucas Adamski

μη αναγνωσμένη,
9 Μαΐ 2012, 2:31:31 μ.μ.9/5/12
ως dev-w...@lists.mozilla.org, dev-w...@lists.mozilla.org, dev-se...@lists.mozilla.org, dev-b2g
Please reply-to dev-w...@lists.mozilla.org

Name of API: Web Bluetooth API
Reference: https://bugzilla.mozilla.org/show_bug.cgi?id=674737
https://wiki.mozilla.org/WebAPI/WebBluetooth

Brief purpose of API: The aim of WebBluetooth is to establish a DOM API to set up and communicate with Bluetooth devices. This includes setting properties on adapters and devices, scanning for devices, bonding, and socket initialization for audio and communication.

General Use Cases:

Inherent threats: Privacy, access to sensitive user devices, de-anonimization based on bluetooth state

Threat severity: high

== Regular web content (unauthenticated) ==
Use cases: None
Authorization model for normal content: None
Authorization model for installed content: None
Potential mitigations:

== Trusted (authenticated by publisher) ==
Use cases: None
Authorization model: None
Potential mitigations:

== Certified (vouched for by trusted 3rd party) ==
Use cases:
Read bluetooth adapter state
Start/Stop device discovery
List discoverd devices
Pair with device
Authorization model: Implicit
Potential mitigations: Status indicator showing active bluetooth connection, user can click the status indicator to cancel the connection. Any limit on types of devices?

Notes: Non-certified use cases are out of scope for 1.0. We will consider those for a subsequent release.

pther...@mozilla.com

μη αναγνωσμένη,
4 Ιουν 2012, 1:40:37 π.μ.4/6/12
ως mozilla.d...@googlegroups.com, dev-w...@lists.mozilla.org, dev-w...@lists.mozilla.org, dev-se...@lists.mozilla.org, dev-b2g
Final call for comments on this API. Please reply to dev-w...@lists.mozilla.org before COB Jun 4.

pther...@mozilla.com

μη αναγνωσμένη,
4 Ιουν 2012, 1:40:37 π.μ.4/6/12
ως mozilla-d...@lists.mozilla.org, dev-w...@lists.mozilla.org, dev-w...@lists.mozilla.org, dev-se...@lists.mozilla.org, dev-b2g
Final call for comments on this API. Please reply to dev-w...@lists.mozilla.org before COB Jun 4.



On Thursday, 10 May 2012 04:31:31 UTC+10, Lucas Adamski wrote:
0 νέα μηνύματα