Security/B2G/PermissionReview/TCPUDPSocket

From MozillaWiki
Jump to: navigation, search

Exposing SystemXHR

Use cases

Email app is the only gaia app. But commonly similar use to systemXHR except for connecting to 3rd party non-http services.

Threats

  1. Accessing services behind a firewall
  2. Accessing local resources
  3. Exposing insecure services to local network (server socket)
  4. Consuming system resources?

Mitigation Strategies