3 ms·
(Hey Randall! :-) Yes, it requires an extension and that's the way it ought to be. Explicit user-intent, properly sandboxed. Allowing any website to arbitrari
by dshankar 12y ago
(Hey Randall! :-)
Yes, it requires an extension and that's the way it ought to be. Explicit user-intent, properly sandboxed.
Allowing any website to arbitrarily capture your entire desktop screen (or any application screen) is an enormous security risk that shouldn't be taken lightly, so an extension seems like the right decision.
- cpncrunch 12y agoHere's the issue...our product is an html5 cross-platform web conferencing platform. Users simply click on a link to join a session. Our product isn't an extension - it's simply html and javascript. So basically you're saying that we either need to change the architecture of our app for Chrome so that it is an extension, or else put the screen-sharing part into an extension. (I'm guessing our entire app would need to be an extension, due to 'sandboxing', although I'm not certain). To be honest I'm not sure why we should change to an extension just for chrome (and just to get screen sharing). It's a bit like telling us we need to rewrite our app in NaCl just for chrome :) Ideally I would like a cross-platform screen sharing feature in getUserMedia, similar to how it worked in Chrome (but without the user having to set any flags). I don't really buy the arguments in http://tools.ietf.org/html/draft-ietf-rtcweb-security-06#section-4.1.1 http://tools.ietf.org/html/draft-ietf-rtcweb-security-06#sec.... Worst case is a dumb user gives permission to screen share to a dodgy site which then reads their bank balance and/or emails (but can't get access to any passwords). If that's a concern then why not just have a small preview window showing exactly what is being shared?
- dshankar 12y agoHi! I think you missed the security implications of the current getUserMedia model for screen access. While you wish to have the easiest user experience (no extension, one click screen share/capture), this is a dangerous problem. Let me explain... when a user currently enables the #enable-usermedia-screen-capture flag in Chrome, this allows any JavaScript on any webpage to capture a chromeDesktopSource such as a window or tab without being initiated or approved by the user. Imagine a malicious website or advertisement that now calls getUserMedia and takes a screencap of your personal email account, bank account or private chat. The user may or may not notice the Chrome notice saying "http://website http://website is sharing your screen" (paraphrased) but even if the user noticed it and pressed "Stop" the damage has already been done. It only takes a fraction of a second for a malicious app to screencap each browser tab. By Chrome 35, you will no longer have to set any flags, but you will not be able to get the chromeDesktopSource without first going through the chooseDesktopMedia API. Each time a website wants access to a Desktop Source (screen, tab, or window), it will have to explicitly ask the user for a source and permission via the Chrome dialog. Does that make more sense now? Hope it helps.
- dshankar 12y agoOne more clarification: this is for chromeDesktopSource - I do not believe you'll have to use chooseDesktopMedia or create an extension to get access to the webcam video or audio stream. This is just about desktop media (screen, tab or app window) access.
- cpncrunch 12y agoI can't find any reference to chromeDesktopSource anywhere - is that correct? Currently there is a prompt every time when you request the desktop chromeMediaSource: 'screen' - it says something like 'Allow this web page to share your screen'. It definitely does not just grab your screen automatically with no prior warning. According to the WebRtc bug report the ONLY way you will now be able to access the desktop is via an extension. Chrome are doing this because they believe there are too many risks in desktop sharing, and even putting a bigger, scarier warning isn't sufficient because many users apparently ignore warnings.