[saag] Re: Covert Web-to-App Tracking via Localhost
Michael Richardson <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <[email protected]> |
John, this "localmess" seems to be about "native" apps that listen on 127.0.0.1, to which mobile browers seem not to filter access, or restrict. Seems very serious to me. (Don't install apps to which one can not review/audit their source code. But, that's never been a IETF responsability) **** I don't see how this an IETF *specific* concern, nor do I see how this is enabled by any current IETF process or policy. **** Maybe we don't need an app for every unique interaction, maybe we need e2e informational models for IoT and the like. The IETF is already the lead here. John Mattsson <[email protected]> wrote: > I urge the broader Internet community to reevaluate current approaches, > and to prioritize user privacy and safety over monetary donations from > data-hoarding, surveillance-driven tech giants. Except that maybe we shouldn't accept statements like "TLS 1.3 in widely deployed", yet it's only really browsers, and they (browsers) don't seem to support useful TLS features like mutual authentication with 1.3. The HTTP client authentication gap is a problem that seems to be nobody's problem. -- Michael Richardson <[email protected]> . o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 515 B)
-----BEGIN PGP SIGNATURE----- iQFKBAEBCgA0FiEEbsyLEzg/qUTA43uogItw+93Q3WUFAmhArq8WHG1jcitpZXRm QHNhbmRlbG1hbi5jYQAKCRCAi3D73dDdZcRAB/9kRtPjG47+9yByfYpnxNiQTNbN sb1koEJopK4kmyUhMK8jyFRQYvplMyxAsd42Xq9JdI+ybM33UGfyAsGRn4X9IBPE ySSU2ZpXP06lcWP5G1Q4ki9RVycGj3Ku9PIuG9MjCKzQ8MtuZp/RdYCcd9/kE3DR jdRtIg8TRGaGyQKKoT1PyWRdrAJprsPGoxCbLAcx2taQQVklpzrQMvbM80RSc3nJ Hjirk+/Jzha0k6BOfJjjy7ZZDyZe0gLG6KGHNAdFIbYMP8iuPb8tNfzaWZlBsX9p Tv1Y3AbuLQphKtfNq7cROh+WRj6nFymPY8Me23r+1VwcnK0rkik+Dujd8Gnv =OcQ5 -----END PGP SIGNATURE-----