<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://www.w3.org/Bugs/Public/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4"
          urlbase="https://www.w3.org/Bugs/Public/"
          
          maintainer="sysbot+bugzilla@w3.org"
>

    <bug>
          <bug_id>25271</bug_id>
          
          <creation_ts>2014-04-05 01:24:03 +0000</creation_ts>
          <short_desc>Key Session description of key usage is ambiguous</short_desc>
          <delta_ts>2014-04-29 17:07:20 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>HTML WG</product>
          <component>Encrypted Media Extensions</component>
          <version>unspecified</version>
          <rep_platform>PC</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>LATER</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Joe Steele">steele</reporter>
          <assigned_to name="Adrian Bateman [MSFT]">adrianba</assigned_to>
          <cc>ddorwin</cc>
    
    <cc>mike</cc>
    
    <cc>public-html-media</cc>
          
          <qa_contact name="HTML WG Bugzilla archive list">public-html-bugzilla</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>103445</commentid>
    <comment_count>0</comment_count>
    <who name="Joe Steele">steele</who>
    <bug_when>2014-04-05 01:24:03 +0000</bug_when>
    <thetext>In this section (https://dvcs.w3.org/hg/html-media/raw-file/tip/encrypted-media/encrypted-media.html#key-session) this text &quot;Other MediaKeys objects, CDM instances, and media elements may not access the key session or use its key(s).&quot; is ambiguous. 

You could interpret this to mean that two content streams that share the same key cannot be played at the same time. I believe what is meant here is that the each media element must have it&apos;s own key session, not sharing a common key session. I don&apos;t believe the intent is that the duplicate keys cannot be used in different key sessions.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>103446</commentid>
    <comment_count>1</comment_count>
    <who name="David Dorwin">ddorwin</who>
    <bug_when>2014-04-05 01:34:54 +0000</bug_when>
    <thetext>Yes, a key should not &quot;leak&quot; from one key session or media element to another. Do you have a suggestion for replacement text?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>103483</commentid>
    <comment_count>2</comment_count>
    <who name="Joe Steele">steele</who>
    <bug_when>2014-04-07 16:01:20 +0000</bug_when>
    <thetext>It seems that the goal here is to prevent a malicious site from detecting key usage by using a timing attack. If we make that goal explicit that also resolves the ambiguity. 

What about this text?

&quot;Other MediaKeys objects and media elements may not access the key session. An application in one origin should not be able to detect the existence of keys in another origin via timing.&quot;

This will allow for things like device specific keys in hardware.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>103487</commentid>
    <comment_count>3</comment_count>
    <who name="David Dorwin">ddorwin</who>
    <bug_when>2014-04-07 17:22:51 +0000</bug_when>
    <thetext>In addition to security/privacy, the goal is also to have consistent behavior. If some implementations leak keys and others don&apos;t, applications built for the former might not work with the latter.

Is your concern keys in hardware or provisioned keys? If so, those keys don&apos;t belong to a key session, so this text would not apply.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>103489</commentid>
    <comment_count>4</comment_count>
    <who name="Joe Steele">steele</who>
    <bug_when>2014-04-07 17:30:39 +0000</bug_when>
    <thetext>(In reply to David Dorwin from comment #3)
&gt; In addition to security/privacy, the goal is also to have consistent
&gt; behavior. If some implementations leak keys and others don&apos;t, applications
&gt; built for the former might not work with the latter.
&gt; 
&gt; Is your concern keys in hardware or provisioned keys? If so, those keys
&gt; don&apos;t belong to a key session, so this text would not apply.

I disagree that provisioned keys are part of a key session, as I mentioned in another thread. 

Putting that aside, if those key types should not be covered by this text, then the text should be be more specific about the types of keys it covers. 

For example: 

&quot;An application in one origin should not be able to detect the existence of _content_ keys in another origin via timing.&quot;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>104464</commentid>
    <comment_count>5</comment_count>
    <who name="David Dorwin">ddorwin</who>
    <bug_when>2014-04-25 19:51:25 +0000</bug_when>
    <thetext>This is related to the use case discussion. I don&apos;t think we can make any definitive text proposals at this time, so resolving LATER.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>104691</commentid>
    <comment_count>6</comment_count>
    <who name="Joe Steele">steele</who>
    <bug_when>2014-04-29 17:07:20 +0000</bug_when>
    <thetext>(In reply to David Dorwin from comment #5)
&gt; This is related to the use case discussion. I don&apos;t think we can make any
&gt; definitive text proposals at this time, so resolving LATER.

Agreed. On that note -- a first cut of the use cases is written here:
https://www.w3.org/wiki/HTML/Media_Task_Force#Use_Cases

Please review and modify as needed.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>