Please [email protected]

Name of API: Wifi API
Reference: http://groups.google.com/group/mozilla.dev.webapi/browse_thread/thread/ed980c42261c5f4a?pli=1

Brief purpose of API: Detect and connect to wifi networks, to support a wifi management app.
General Use Cases: None

Inherent threats: Privacy(identify user, geolocation, based on wifi characteristics), Denial of Service, Unexpected or unauthorized network connections (e.g. connect to home wifi network ?)

Threat severity: High

== Regular web content (unauthenticated) ==
Use  cases for unauthenticated code:None
Authorization model for normal content:
Authorization model for installed content:
Potential mitigations:

== Trusted (authenticated by publisher) ==
Use cases for authenticated code:
* Wifi sniffer app
* Wifi provider connection app (e.g. connect to provider X hotspots with authentication credentials)
Use cases for trusted code: Explicit
Potential  mitigations:

== Certified (vouched for by trusted 3rd party) ==
Use cases for certified code: Wifi Manager
Authorization model: Implicit
Potential mitigations:
_______________________________________________
dev-security mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security

Reply via email to