WebAPI Security Discussions: Progress Update

2012-05-01 Thread Lucas Adamski
Hi all, Yes, discussions should sometimes result in progress. As such, I've updated the list of webAPIs with their corresponding discussions, and posted to final versions for discussions which had run their course. https://wiki.mozilla.org/WebAPI (wiki formatting seems broken so the table has

Types of applications: updated

2012-05-01 Thread Lucas Adamski
Please reply-to dev-webapps. There's been much discussion lately of the different types of applications and so I figured this would be a good time to summarize the current state of discussion. From a security perspective, there are 3.5 types of applications. Confused yet? Excellent! ==Types

WebAPI Security Discussion: Power Management

2012-05-01 Thread Lucas Adamski
*Please reply-to dev-weba...@lists.mozilla.org * Name of API: Power Management APIs Reference: https://wiki.mozilla.org/WebAPI/PowerManagementAPI Brief purpose of API: Allow apps to turn off or restart device and catch on-wake events General Use Cases: None Inherent threats: Denial of serviceto

Re: [b2g] WebAPI Security Discussion: Idle API

2012-05-01 Thread Jonas Sicking
Sorry for not responding until now. Was away on vacation. > Inherent threats:  Privacy implication - signalling mulitple windows at > exactly the same time could correlate user identities and compromise privacy I think there's another threat, which is simply monitoring if the user is active on t