3 ms·
Isn't the browser supposed to stop pages from making connections to machines other than the server they were downloaded from? Has that requirement been dropped
by pre 14y ago
Isn't the browser supposed to stop pages from making connections to machines other than the server they were downloaded from?
Has that requirement been dropped? Or does this do something strange to get around it?
- ShirsenduK 14y agoWelcome to the world of impossibilities with WebRTC. http://en.wikipedia.org/wiki/WebRTC http://en.wikipedia.org/wiki/WebRTC
- pre 14y agoHummm. I've found that same-origin policy annoying on occasion but always assumed it was there for good reason and that it was important my browser couldn't just open sockets to any old machine. Was I wrong? Was that not important? Did I go though all that pain for nothing? Does this WebRTC thing have an on/off switch?
- ShirsenduK 14y agoWebRTC is for Real-time communication between browsers. Same-origin policy applies to communication between browser and the server. http://www.w3.org/TR/webrtc/ http://www.w3.org/TR/webrtc/. There are ways to turn it off on your browser, but why would you? :). The tech is yours to be used.
- anonymouz 14y ago> The tech is yours to be used. Well, the tech is for every website to be used, as a visitor to the site that may or may not benefit me. I think that was the reason for the same-origin policy and is, probably the source of concern of the OP. Personally, I use NoScript and RequestPolicy to deal with it. After all, just because JavaScript exists does not mean I want any random website to execute arbitrary code on my machine (especially not with WebRTC).
- ShirsenduK 14y agoThe user decides what he intends to share. His files, his webcam, his printers, etc.
- PommeDeTerre 14y agoExperience has shown that many users just grant such access when prompted, without thinking about it. Prompts like that also do absolutely nothing to stop malicious use, hidden under a facade of legitimacy. For example, somebody could put together a demo purportedly showing "serverless pure JavaScript P2P file sharing in the browser" solely to trick people into using something harmful. (I'm not saying that's necessarily going on here, of course.)
- iSnow 14y agoI strongly suspect they are using something built on WebRTC.