Security/B2G/PermissionReview: Difference between revisions

Jump to navigation Jump to search
Line 131: Line 131:
In conclusion:
In conclusion:


*There is just one APIs that are not exposed to hosted content and that could reduce the functionality of a Video Hosted App: NFC. For experimenting purposes we are disabling that functionality from the apps,but we should explore if there is any way to expose that functionality to hosted content, either by opening part of these APIs only or by using a service that expose the functionality (instead of exposing APIs).
*There is just one APIs that is not exposed to hosted content and that could reduce the functionality of a Video Hosted App: NFC. For experimenting purposes we are disabling that functionality from the apps,but we should explore if there is any way to expose that functionality to hosted content, either by opening part of these APIs only or by using a service that expose the functionality (instead of exposing APIs).
*Think about how the themeable capability could be used by any app willing to be “themed”.
*Think about how the themeable capability could be used by any app willing to be “themed”.
*Device Storage: Read/Write: This should be re-assessed as the protection defined for Trusted Hosted Apps does not seem to be enough from a security point of view.  
*Device Storage: Read/Write: This should be re-assessed as the protection defined for Trusted Hosted Apps does not seem to be enough from a security point of view.  
Confirmed users
1,225

edits

Navigation menu