Live data from Hacker News

“We are considering adding an extension to restrict the use of WebRTC”

bugzilla.mozilla.org

91–100 of 159 posts

Re: “We are considering adding an extension to restrict the use of WebRTC”

#91
post #57

What the fuck, this leaked your real IP behind VPN since January 2014 and this isn't fixed yet? This sure looks like a Heartbleed-tier high-priority security hole to me. How is this not bigger news?

Fun fact, Eric Rescorla is the outside expert that proposed the NSA backdoored Dual EC_DRBG standard.

Re: “We are considering adding an extension to restrict the use of WebRTC”

#92
post #62

Earlier quoted context omitted.

Citation please.

Nothing to do with WebRTC but it's (allegedly) a tactic that has been used by a US-based LLC known as Prenda via torrents: http://arstechnica.com/tech-policy/2013/06/pirate-bay-data-s... Earlier this week, Prenda faced a new and serious allegation: that it had actually put some pornography on BitTorrent itself, intending for it to be downloaded so that it could start a campaign of lawsuits and threat letters. The Pir…

That is one (alleged) example. I was looking for proof of the widespread use of honeypots yAnonymous mentioned.

Re: “We are considering adding an extension to restrict the use of WebRTC”

#93
post #66

Earlier quoted context omitted.

[deleted]

> a random guy on the internet says something and you think it is true? Yes, if they identify themselves and their company and what they say aligns with my personal experience. > You don't have the foggiest idea what they are really doing with the data. All we know is that they are collecting the data without user's consent. You never have any absolute certainty what anyone does with your data - all you have are hypo…

It's not only about the VPN leak. WebRTC also leaks internal IP addresses which provide additional entropy that can be used for fingerprinting.

Re: “We are considering adding an extension to restrict the use of WebRTC”

#94
post #71

Earlier quoted context omitted.

The web isn't peer to peer. Why would I want a web browser to do peer to peer? Its a web browser!

some people seem to mistake browsers for an operating system.

I'm pretty sure that ship has sailed. Users (and perhaps more important, companies) do, in fact, want web browsers to do everything. Even traditionally heavyweight applications like Microsoft Office and Adobe Photoshop are shifting to the web.

Whether that's a good idea or not is certainly open to debate, but pretending that it's not happening isn't the answer.

Re: “We are considering adding an extension to restrict the use of WebRTC”

#95

Does anyone else feel that there's something terribly odd going on when restricting something needs to be an extension ? IMHO it should be a configuration option, per-site, and off by default. WebRTC also isn't the only thing that applies to.

The recent moves to turn the browser into its own OS are worrying. The problem I see is that no one seems to care. Its full steam ahead and its only later do we realize that these new feature and standards are trivial to abuse. I really wish there was some kind of web mission statement on where browsers are going instead of this kitchen sink approach.

I have no idea what the W3C is thinking. I don't think even the W3C knows what its thinking. Its just being reactionary; trying to turn HTML5 into a "flash killer" and shoving feature after feature into the spec. I don't want to piss on progress, but I think privacy and security concerns get a backseat with W3C members, especially Google, whose very existence is dependent on finding information about users to sell to advertisers. Soon we'll need sandboxing and privacy apps to wrap our browsers in. I really hope Mozilla leads the way to pushing back on this recent mad push of thoughtless progress. A more moderate approach would be very much welcome and having more "off by default" options for easily abused features like P2P in the browser, which is what webrtc really is, makes sense.

Right now I had no idea what my browser is capable of. Can it silently turn on my camera and microphone? Probably. Can it make all sorts of crazy p2p connections to various servers/clients silently? Probably. Its all a little scary.

Re: “We are considering adding an extension to restrict the use of WebRTC”

#96
post #90

Earlier quoted context omitted.

> http://www.pcwelt.de/ratgeber/Die-Abmahnindustrie-Jeden-kann... Estimates of 500,000 yearly C&Ds in Germany from 2011. > http://www.wortfilter.de/news11Q1/news3945.html C&D industry in Germany makes about 400 million a year. Don't have numbers from other countries, but it's definitely a big business in Europe.

Those are about the Abmahnungen, no mention of honeypots.

To get the required log files, they have to seed the files themselves. No other (legal) way to do it.

Swarm information is not enough as it doesn't prove that any data has been transfered.

Re: “We are considering adding an extension to restrict the use of WebRTC”

#97

Chrome users, look here: https://chrome.google.com/webstore/detail/webrtc-block/nphkk... or https://chrome.google.com/webstore/detail/webrtc-leak-preven...

And firefox users here: https://addons.mozilla.org/en-US/firefox/addon/happy-bonobo-...

Re: “We are considering adding an extension to restrict the use of WebRTC”

#98
post #18

How about not disabling it, but merely making use of it visible? (e.g. an icon or a notice in the addressbar) It would discourage reputable sites from abusing it, because users would start asking questions why a news site wants a p2p/videoconference connection.

Because if you really need to be anonymous, it's not good enough to catch it being used after the fact. Notifying the user after the fact sometimes works for things that are nuisances, but isn't good for privacy/security (imagine if your browser would execute unsandboxed JS and show you an icon each time it did it).

It wouldn't have to be after the fact. Firefox already has a little pop-up when sites want to get your location. The options are yes/no/never for this site.

Re: “We are considering adding an extension to restrict the use of WebRTC”

#99
post #71

Earlier quoted context omitted.

some people seem to mistake browsers for an operating system.

I'm pretty sure that ship has sailed. Users (and perhaps more important, companies) do, in fact, want web browsers to do everything. Even traditionally heavyweight applications like Microsoft Office and Adobe Photoshop are shifting to the web. Whether that's a good idea or not is certainly open to debate, but pretending that it's not happening isn't the answer.

It's more of an abstraction layer over operating systems than an operating system. Crippling APIs (try opening a datagram socket. or send icmp pings). No gpu-compute, no shared-state multithreading.

It doesn't manage hardware or anything like that.

People use browsers as if they were an operating system. That does not make it one.

It's like calling a java virtual machine an operating system.

Re: “We are considering adding an extension to restrict the use of WebRTC”

#100
post #62

Earlier quoted context omitted.

Citation please.

Nothing to do with WebRTC but it's (allegedly) a tactic that has been used by a US-based LLC known as Prenda via torrents: http://arstechnica.com/tech-policy/2013/06/pirate-bay-data-s... Earlier this week, Prenda faced a new and serious allegation: that it had actually put some pornography on BitTorrent itself, intending for it to be downloaded so that it could start a campaign of lawsuits and threat letters. The Pir…

If we're talking about instances where "Courts usually believe their 'proof', no matter how bad it is," Prenda Law is not one I'd bring up.

http://arstechnica.com/tech-policy/2015/06/judge-finds-prend...

Post reply on HN