Closed murillo128 closed 5 years ago
Pull request on CSP spec: https://github.com/w3c/webappsec-csp/pull/287
What's the status here?
Since this is a new feature, and we've stopped adding new features, I'm moving this to the NV repo.
With merger of PR 38, closing this issue.
As explained in here: https://github.com/w3c/webappsec-csp/issues/92 WebRTC bypass the CSP security policies for connect-src and a malicious script could use webrtc to leak data to a rogue server.
Note that it is not even needed to use datachannels at all, as you could leak data (at low rate) to a specially crafted TURN server on the username:
IMHO this should be covered at the CSP spec, but we should add a warning at the security and privacy section of the webrtc spec until this is solved.