[whatwg] WebSocket support in HTML5
maher_rj at hotmail.com
Wed Oct 29 01:19:53 PDT 2008
I know I've already replied to this post once, but I came across the following link the other day and thought that it might help update some people, or at least remove some misconceptions, about Policy Files for cross-domain Socket access : -
It's dated 14 April 2008, and has some interesting stuff that I (and evidently others) was not aware of: -
1) Port level granularity eg:
<allow-access-from domain="swf.example.com" to-ports="123,456-458" />
2) Standardizing a port number for the serving of policy files (Couldn't see SSL option)
Adobe has filed with IANA, the Internet Assigned Numbers Authority, to reserve port 843 for the purposes of serving socket policy files. By introducing a centralized location for socket policy files, Flash Player enables a system administrator to define what ports are available through one master policy that overrides any other policy file on the host. If Flash Player 9,0,124,0 cannot retrieve a master policy file from port 843, then it requests a socket policy file on the port where it is trying to connect. However, if a policy file is available from a service on TCP port 843, then Flash Player considers that to be the authoritative set of permissions for that system.
3) Lots of other useful stuff that I feel the WebSocket people are dismissing too lightly
I'm not saying that Adobe/Flex, SUN/Java, and Microsoft/Silverlight can't all be wrong, but I just really hope that isn't one of these Web "standards" where some one is being different just for the hell of it.
It's good to talk.
Cheers Richard Maher
----- Original Message -----
To: Richard's Hotmail
Cc: WHAT working group
Sent: Monday, September 22, 2008 12:09 PM
Subject: Re: [whatwg] WebSocket support in HTML5
Richard's Hotmail wrote:
It's hard to determine the substance of your complaint. It appears you don't really understand the Java, Flex or Silverlight implementations. They are all quite restrictive, just in different ways:
* Java raises a security exception unless the user authorises the socket using an ugly and confusing popup security dialog
* Flex and Silverlight requires the remote server or device also run a webserver (to serve crossdomain.xml). Flex supports connections ONLY to port numbers higher than 1024. The crossdomain files for each platform have different filenames and appear to already be partly incompatible between the two companies, hardly a "standard".
Both Silverlight and Flash/Flex are fundamentally flawed since they run on the assumption that a file hosted on port 80 is an authorative security policy for a whole server. As someone who works in an ISP I assure you this is an incorrect assumuption. Many ISPs run additional services on their webserver, such as databases and email, to save rack hosting costs or for simplicity or security reasons. I would not want one of our virtual hosting customers authorising web visitors access to those services. It is also fundamentally flawed to assume services on ports greater than 1024 are automatically "safe".
These companies chose convienience over security, which quite frankly is why their software is so frequently exploited. However that's between them and their customers, this group deals with standards that must be acceptable to the web community at large.
Other than that it behaves as an asynchronous binary TCP socket. What exactly are you concerned about?
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the whatwg