TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Signal: Multi-device calls with ICE forking

8 点作者 ig0r0超过 4 年前

1 comment

dbrgn超过 4 年前
Interesting technique!<p>Do I understand it correctly that offer and ICE candidates are already exchanged and processed <i>before</i> the callee accepts the call? Isn&#x27;t it quite risky that data received from the network (an SDP offer that needs to be parsed) is passed directly to a gigantic and complex C++ codebase (WebRTC) without any user interaction? This increases the attack surface enormously and also makes vulnerabilities like CVE-2019-17191 possible.<p>(One option how to avoid this would be to cache offer and candidates for unknown contacts, and only process them once a call is accepted...)
评论 #24851314 未加载
评论 #24851438 未加载