Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This conversation last came up here: http://lists.w3.org/Archives/Public/public-speech-api/2012Au...

But it looks like all four points of the security model (including #4 that you've quoted) were retained. Luckily, Chrome is more aggressive on popups than ever, so there's less likelihood, but it's not yet bulletproof.

I agree it looks like Chrome's implementation is not matching this spec. I'll look into if we can tighten this up.



There's a bit more followup on this issue over here http://www.informationweek.com/security/vulnerabilities-and-...

In it, a Chrome representative said: "The security of our users is a top priority, and this feature was designed with security and privacy in mind. We've re-investigated and still believe there is no immediate threat, since a user must first enable speech recognition for each site that requests it. The feature is in compliance with the current W3C standard, and we continue to work on improvements."

Check the informationweek article for more, specifically around the errata to remove that sentence from the spec.


As a side note: is it a good thing that a window obtained through a Window.open() inherits the parent window's permissions?

Right now in Chrome permissions are enabled or disabled globally with exceptions based on hostname patterns. Adding a new option like "Allow popup window to inherit permissions" will solve the issue.

A well-hidden popup window can track your position all day using the geolocation API?


A full reply from Chrome security on the issue: https://code.google.com/p/chromium/issues/detail?id=291258#c...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: