4 ms·
Basic authentication is covered in Section 11[0] There are more thoughts on tightening up authentication in the last section "Tightening and tidying" Apologie
by cookie_monsta 2y ago
Basic authentication is covered in Section 11[0]
There are more thoughts on tightening up authentication in the last section "Tightening and tidying"
Apologies if I have misunderstood your comment
[0]https://github.com/lvidgen/WebRTC/blob/master/FOSS_TURN_Server/howto.md#11-add-some-authentication https://github.com/lvidgen/WebRTC/blob/master/FOSS_TURN_Serv...
- ranger_danger 2y agoAuthentication still requires the client to have access to the password, where you can just take it and use it for any other purpose. Unless you're asking every user to manually input a TURN password and they promise not to give it out, you're basically forced to reveal it to every visitor of your site.
- cookie_monsta 2y agoyes, but you can block cross origin requests to both the credentials server and the PeerJS server which I understand prevents this: "relaying any traffic they want, without any of your own web sites or WebRTC apps involved" Again, not an expert. This problem only really exists for "ad-hoc" connections where you don't want people to have to set up accounts. coturn has the ability to do standard authentication by checking credentials stored in databases
- mtud 2y agoYou can generate short-lived and single-use credentials for users.
- ranger_danger 2y agoYes, but, if this is a public website that anyone can use, then an abuser using your TURN server for other purposes can also grab a single-use credential from the site, making it a bit pointless.