There are more thoughts on tightening up authentication in the last section "Tightening and tidying"
Apologies if I have misunderstood your comment
[0]https://github.com/lvidgen/WebRTC/blob/master/FOSS_TURN_Serv...
Unless you're asking every user to manually input a TURN password and they promise not to give it out, you're basically forced to reveal it to every visitor of your site.
Again, not an expert. This problem only really exists for "ad-hoc" connections where you don't want people to have to set up accounts. coturn has the ability to do standard authentication by checking credentials stored in databases
* Your TURN server should provide APIs that allow you to verify that allocations/permissions are only created for your users.
* Use an auth mechanism that has an expiry time. Like [0]
[0] https://github.com/pion/turn/tree/master/examples/lt-cred-ge...
coturn provides these APIs, they're not covered in the writeup, though
> * Use an auth mechanism that has an expiry time. Like [0]
This is how the credentials server in the write up works