WebRTC is almost here, and it will change the web
venturebeat.com
venturebeat.com
To protect against this attack browsers should warn when certificate changes, there even is a long standing bug for firefox in mozilla:
I haven't seen an easy way to have secure email (without teaching the other side of the conversation cryptography), secure voip/voice (without the trouble above), or secure chat (without using my own server).
I'm not saying easy ways don't exist; I'm saying I don't know what or where they are.
How about using whatever is the easiest, most enjoyable and trouble free setup for her to use.
But none of that is my motivation. My motivation is purely technological. I want secure services as a matter of principle. Since I have yet to find such a thing, I use whatever is easiest, just like everyone else.
Because looked at from a societal level, more secure citizen communications means a society less able to be manipulated / blackmailed / spied on by bad actors, both domestic and foreign. It doesn't matter if this particular mother never says anything interesting / compromising in communications with her child, because there are many other situations where they will. Their child might be a politican, councillor, businessman doing signficant overseas deals, political activist, dissident.
Your logic is faulty on a number of levels:
* assumes only the US government is a potentially bad actor. This is simply not the case.
* assumes the political / technical climate will never become more hostile to milder expressions of dissent between citizens.
* assumes the parent poster's communications with his mother does not contain any interesting information to any potentially bad actors
Ultimately though, with all the theorizing aside, the parent is simply wanting a solution that provides secure communication with family members which is a very uncontroversial, reasonable goal to have.
At the time I was involved, it was less controversial, and so I might have "escaped" surveillance, but I regularly met people who were more than once taunted on open streets by high level people in the security service who'd joke about personal details of their life that they had obtained through surveillance that in no way were relevant to the security services (e.g. asking about the fight some guy had with his wife the previous night).
There are plenty of people today that are in close enough proximity to the types of people and groups who are the subject of security services interests these days that would have every reason to assume that their conversations with their mothers would be monitored just because of either who they are, or who their friends are, or even because of the groups their friend peripherially belongs to.
It's not a situation that is particularly fun to be in, and I understand very well why third parties in situations like that would prefer not to have to think about whether or not someone is listening in for their own gratification.
Pidgin with OTR -- configure and verify keys once, use whatever protocol you want. It is doable and not very difficult right now, the problem really is that no one cares.
Cost to acquire or develop and reliably productize (and risk divulging) targeted attacks for OTR would likely exceed the value your adversaries could extract from your chat with your mom.
And one should trust Apple's or your word because...?
With WebRTC governments would have to perform man-in-the-middle attacks, which is pretty damn hard for P2P-style connections.
Just saying :)
For those down-voting me; I find this attitude very strange. If the tools were present in another widely deployed runtime, but were heavily under utilised then why are people getting so excited about them this time around?
I guess some people just love to hate Flash.
Until flash runs on mobile and/or is an open standard, it won't be relevant to the future of the web most developers (myself included) want to build.
The fact that it has been possible with various other technologies for years is not news (for me)
This is possible through the use of the Flex SDK that is under the open source Mozilla Public License, for some time now.
As for the lake/ocean analogy attempt, not so much.
Yes. Flash has performance and implementation issues. And developers can't do anything to improve the situation.
That is being far too polite for what in all likelihood is the most insecure piece of software in history. Not joking. The frequency of security updates over the last decade is a disgrace. And that is without even talking about the appalling state of affairs on the Mac platform where it is still ridiculously buggy. I mean why has it taken this long to be self-updating ?
Would you have preferred they only released security updates once a year?
But please, do not take my word for it: http://truegryc.blogspot.pt/2010/05/response-to-thoughts-on-...
Remember the first iPhone didn't have an app store! It had a full(ish)-featured web browser that people were expected to write "apps" for. Apple continues to encourage developers to write web apps for the iPhone. They can hardly be threatened by a feature they actively promote and enable.
To the downvoter, you are a pitiful fanboy.
Microsoft --> AJAX[1]. And yes, I know that they aren't saying that Google --> AJAX but it kinda leaves that impression.
----
http://garrettsmith.net/blog/archives/2006/01/microsoft_inve...
If you read the article you linked, it also says this:
"Finally -- 6 years later -- Jesse James Garrett of Adaptive Path coined a catchy phrase: the term Ajax was born."
[1] http://www.adaptivepath.com/ideas/ajax-new-approach-web-appl...
Like the GP that bit about AJAX was just all wrong. Garrett is so astonishingly irrelevant in all of this, as is the AJAX me-too title. Google was very important, but only insofar as they legitimized the technique and made a lot of people realize that this crazy web thing was a lot more powerful than people often thought. And it wasn't gmail -- it was Google Suggests. That was an atomic bomb on webapps that proved that highly dynamic pages were possible and preferable.
Me - using XmlHttp(Request) since 2001.
For more information, check us out at http://WebP2P.org and join in #webp2p on Freenode!
The two things combined should remove a lot of middlemen.
Nah, everyone is just claiming this to be awesome and just happened to forget about NAT routers....
(4 months ago I had a demo working using ROAP and STUN before they switched to JSEP. I'm literally in the middle of upgrading it to the new API.)
The "setup" for the connections in the central server is trivial with a tiny websockets server and a few messages shuttled back and forth.
NAT (Network Address Traversal): exposing only your router's ip address and hiding your own to outside traffic [https://en.wikipedia.org/wiki/Network_address_translation]
ROAP (RTCWeb Offer/Answer Protocol): main voice protocol [https://en.wikipedia.org/wiki/RTCWeb_Offer/Answer_Protocol]
JSEP (JavaScript Session Establishment Protocol): protocol for setting up P2P connection [https://en.wikipedia.org/wiki/JavaScript_Session_Establishme...]
Following are all technologies for punching through NAT...
ICE (Interactive Connectivity Establishment): [https://en.wikipedia.org/wiki/Interactive_Connectivity_Estab...]
STUN (Session Traversal Utilities for NAT): [https://en.wikipedia.org/wiki/STUN]
TURN (Traversal Using Relays around NAT): [https://en.wikipedia.org/wiki/Traversal_Using_Relay_NAT]
(Disclaimer: I know nothing of these technologies, I just looked them up on wikipedia myself)
Why is this source credible?
> imagine it amplified by secure, real-time transmissions of audio and video
Ok, I'm imagining it. And I'll still be imagining it in 12 months time, because WebRTC does nothing to fix the outstanding issues in setting up secure communications.
> Skype, Cisco, and Polycom will all see their conferencing technology commoditized.
Really? Surely you could have said that Cisco / Polycom would be destroyed by Skype, but that didn't happen. Why would in-browser conferencing, which will almost certainly be a worse experience than Skype, which is itself a far worse experience than dedicated conference hardware/software, commoditize conference technology?
And for that matter, why did the wide variety of already-existing browser-based conferencing tech not do this?
Personally I'm more excited about ideas like P2P downloading, and using DHTs to disseminate information.
What would give you that impression?
A site that lets you automatically join a conference call just by visiting a page seems far more usable than Skype.
Stability: For Skype to break, you need to either crash Skype or the entire computer or O/S. For your in-browser conferencing, you just need the web browser to crash.
Connectivity: Skype has put huge amounts of work into punching through firewalls, and has many settings dedicated to that. Furthermore it's a common enough option on SOHO/consumer routers to let it through. P2P browser connectivity just isn't there yet.
Security: Our firewall at work is configured to allow Skype through. I doubt it's configured to let browsers open direct raw socket connections to any IP and port they please. I can't even begin to imagine how a network administrator is supposed to lock these capabilities down, other than completely disallowing them.
UX: Again, Skype is a dedicated program so it can do a lot more. It can keep a little overlay window open in the corner of your screen so you can look at a web page or document but keep an eye on your call. It can hook into the O/S to ensure your microphone is selected and unmuted. It can tell your music player to pause when a call comes in. None of this is possible with a browser (yes, you could add APIs, but where do you stop - are browsers going to become the next JVM, creating a cross-platform API that plasters over the differences between O/S's?)
My last point is mildly tangential: Why would P2P in-browser conferencing disrupt Skype / Polycom when it has literally zero perceivable difference to the end-user compared to regular client-server in-browser conferencing (other than the fact that with P2P you will be able to connect to fewer people than in the client-server model)?
after source code reading (and chrome dev console output observing) you have to realize: 1. there is need of 'signaling server' 2. session encryption keys are exchanged through that server
yes, anyone could setup their small server and call through it an make sure tls / ssl cert of their server is intact etc. that will not be a case for avg Joe. not to mention tat browser itself will be an attack vector.
I fear that Microsoft will push something skype-specific, Google (and possibly Mozilla) vp8 and xmpp/jingle, who knows what Apple will do with Safari. And different clients/browsers won't be able to communicate between themselves.
Nobody can force Microsoft to support open standards, without the leverage of popular adoption and demand. So it makes no sense to wait on Microsoft to support open standards before trying to use them.
So if browsers can't talk to each other, whose fault is that? If Microsoft decides to be the odd man out, it's Microsoft's fault. If everyone else allows open standards to be suppressed as they wait for Microsoft, then they will be responsible for a world where Microsoft controls everything. Is that really what you are looking for here?
Anyway, these days Microsoft has shifted more support away from things like Silverlight, so I think there is a good hope that things will not be just like the bad old days.
That's because this whole codec thing is about patent licensing, not copyright licensing, so the fact that the code is BSD-licensed for copyright purposes is irrelevant.
The result is that for the HTML video tag, for example, it's Apple and Microsoft that don't support VP8 and Theora, and Mozilla and Opera that don't support H.264, all for patent licensing, not copyright, reasons. The corresponding situation with WebRTC is still in flux.
There are only five browsers that count, so why didn't they just say "three of the five major browsers?" Or, if they mean more than 50% of browser installations, are we really at the point where we can get 50% of all browser installations updated within a couple of months?
It does neglect to mention that not all Firefox browsers do self-update so that would need to be factored in.
and it's resulting library, webRTC.io
live streaming video to a webpage, from your phone, that's incredible
http://dl.dropbox.com/u/3531958/iphone/webrtc-opera-mobile-1...
I have read this line as:
These capabilities open the door to a new wave of advanced web security issues.
Okay 2016 when we can use it in Trident.
What exactly does it help to have your video-feed drive around on a broomstick?
I can see the entertainment value for a couple days. But when it's time to get work done again I sure as hell don't see people preferring a video broomstick next to their desk over a plain old skype-window...
Skype is a proprietary service which (last I checked) still requires you to locally install their binary, and is completely under the control of one company... as a risk-averse person I wouldn't bet the farm building on top of any technology which requires me to swear fealty to Skype or Facebook, because who knows what will happen in a year?
That's not quite right. Microsoft invented XMLHTTP, the interface which XHR is based on, in '98 or '99 for Outlook Web Access.