<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://www.w3.org/Bugs/Public/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4"
          urlbase="https://www.w3.org/Bugs/Public/"
          
          maintainer="sysbot+bugzilla@w3.org"
>

    <bug>
          <bug_id>25809</bug_id>
          
          <creation_ts>2014-05-19 18:20:59 +0000</creation_ts>
          <short_desc>Security issue: Abuse of &quot;call me&quot; URLs</short_desc>
          <delta_ts>2014-09-25 14:44:29 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebRTC Working Group</product>
          <component>Media Capture and Streams</component>
          <version>unspecified</version>
          <rep_platform>PC</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Cullen Jennings">fluffy</reporter>
          <assigned_to name="Adam Bergkvist">adam.bergkvist</assigned_to>
          <cc>adam.bergkvist</cc>
    
    <cc>dom</cc>
    
    <cc>harald</cc>
    
    <cc>juberti</cc>
    
    <cc>public-media-capture</cc>
    
    <cc>stefan.lk.hakansson</cc>
          
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>106358</commentid>
    <comment_count>0</comment_count>
    <who name="Cullen Jennings">fluffy</who>
    <bug_when>2014-05-19 18:20:59 +0000</bug_when>
    <thetext>The security section should warn people about the risk of having a website that took URL like www.example.com?call=evil or www.example.com?call=+1900-PAY-FLUF. If  the site automatically makes that call if example.com had permission, then an advertisement network can display an add that redirects you to this and the users camera will sending stuff and sending it to an attacker.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>107502</commentid>
    <comment_count>1</comment_count>
    <who name="Harald Alvestrand">harald</who>
    <bug_when>2014-06-09 07:43:38 +0000</bug_when>
    <thetext>Changing subject for better readability.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>107559</commentid>
    <comment_count>2</comment_count>
    <who name="Justin Uberti">juberti</who>
    <bug_when>2014-06-10 00:23:52 +0000</bug_when>
    <thetext>Agree, was thinking about this the other day. We will make changes to our sample apps to prevent this.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>108669</commentid>
    <comment_count>3</comment_count>
    <who name="Adam Bergkvist">adam.bergkvist</who>
    <bug_when>2014-07-03 05:26:00 +0000</bug_when>
    <thetext>The receivers of this info would be web developers, rather than implementers of the spec. Where do we put that kind of info</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>110700</commentid>
    <comment_count>4</comment_count>
    <who name="Dominique Hazael-Massieux">dom</who>
    <bug_when>2014-08-28 09:38:07 +0000</bug_when>
    <thetext>Proposed fix: https://github.com/w3c/mediacapture-main/pull/9

I&apos;m also suggesting more thorough protections against this type of abuse:
http://lists.w3.org/Archives/Public/public-media-capture/2014Aug/0187.html</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>111588</commentid>
    <comment_count>5</comment_count>
    <who name="Stefan Hakansson LK">stefan.lk.hakansson</who>
    <bug_when>2014-09-16 14:17:30 +0000</bug_when>
    <thetext>In the interest of making progress, I propose we add a note of that more feedback is wanted from webappsec on this.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>111596</commentid>
    <comment_count>6</comment_count>
    <who name="Dominique Hazael-Massieux">dom</who>
    <bug_when>2014-09-16 15:29:04 +0000</bug_when>
    <thetext>(In reply to Stefan Hakansson LK from comment #5)
&gt; In the interest of making progress, I propose we add a note of that more
&gt; feedback is wanted from webappsec on this.

I&apos;ve updated PR 9 to that effect.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>112174</commentid>
    <comment_count>7</comment_count>
    <who name="Cullen Jennings">fluffy</who>
    <bug_when>2014-09-25 14:44:29 +0000</bug_when>
    <thetext>Merged dom&apos;s PR to fix this.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>