A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item of the Real-Time Communication in WEB-browsers Working Group of the IETF.
Title : Security Considerations for RTC-Web
Author(s) : Eric Rescorla
Filename : draft-ietf-rtcweb-security-03.txt
Pages : 22
Date : 2012-06-05
The Real-Time Communications on the Web (RTC-Web) working group is
tasked with standardizing protocols for real-time communications
between Web browsers. The major use cases for RTC-Web technology are
real-time audio and/or video calls, Web conferencing, and direct data
transfer. Unlike most conventional real-time systems (e.g., SIP-
based soft phones) RTC-Web communications are directly controlled by
some Web server, which poses new security challenges. For instance,
a Web browser might expose a JavaScript API which allows a server to
place a video call. Unrestricted access to such an API would allow
any site which a user visited to "bug" a user's computer, capturing
any activity which passed in front of their camera. This document
defines the RTC-Web threat model and defines an architecture which
provides security within that threat model.
A URL for this Internet-Draft is:
http://www.ietf.org/internet-drafts/draft-ietf-rtcweb-security-03.txt
Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/
This Internet-Draft can be retrieved at:
ftp://ftp.ietf.org/internet-drafts/draft-ietf-rtcweb-security-03.txt
The IETF datatracker page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-ietf-rtcweb-security/
_______________________________________________
I-D-Announce mailing list
I-D-Announce@ietf.org
https://www.ietf.org/mailman/listinfo/i-d-announce
Internet-Draft directories: http://www.ietf.org/shadow.html
or ftp://ftp.ietf.org/ietf/1shadow-sites.txt