Re: WebAPI Security Discussion: Settings API

2012-04-29 Thread Lucas Adamski
Hmm, so I'm not sure exactly where we came out on this discussion. As Mounir pointed out, discussion of Wifi, Bluetooth and other network-y APIs should be held in those respective APIs (and yes, those have not yet been posted). Is it likely that this API is really focused on certified apps tha

Re: [b2g] WebAPI Security Discussion: Settings API

2012-04-17 Thread Jim Straus
Comments in line below On Apr 17, 2012, at 4:08 PM, Adrienne Porter Felt wrote: > > > On Mon, Apr 16, 2012 at 7:42 PM, Jim Straus wrote: > On Apr 16, 2012, at 10:24 AM, Adrienne Porter Felt wrote: > > > -- Changing the wallpaper or ringtone: Let all apps do it, but provide an > > "undo" mecha

Re: [b2g] WebAPI Security Discussion: Settings API

2012-04-17 Thread Adrienne Porter Felt
On Mon, Apr 16, 2012 at 7:42 PM, Jim Straus wrote: > On Apr 16, 2012, at 10:24 AM, Adrienne Porter Felt wrote: > > > -- Changing the wallpaper or ringtone: Let all apps do it, but provide an > > "undo" mechanism in Settings that changes it back to what it was prior to > > that app altering it. >

Re: [b2g] WebAPI Security Discussion: Settings API

2012-04-16 Thread Jim Straus
Comments inline below On Apr 16, 2012, at 10:24 AM, Adrienne Porter Felt wrote: > I'm not sure all Settings should be treated as either one of two levels > (accessible with no user involvement, or not accessible at all). I think > different Settings should be handled individually. Here are some

Re: WebAPI Security Discussion: Settings API

2012-04-16 Thread Adrienne Porter Felt
I'm not sure all Settings should be treated as either one of two levels (accessible with no user involvement, or not accessible at all). I think different Settings should be handled individually. Here are some suggestions for a few possible Settings parameters: -- Vibrating the phone and changin

WebAPI Security Discussion: Settings API

2012-04-15 Thread Lucas Adamski
Please reply-to dev-weba...@lists.mozilla.org Name of API: Settings API Reference: https://bugzilla.mozilla.org/show_bug.cgi?id=678695 Brief purpose of API: API to configure device settings General Use Cases: None Inherent threats: *Access sensitive configuration data (wifi passwords etc) *Chan