Security/B2G/PermissionReview/TCPUDPSocket

From MozillaWiki
Jump to navigation Jump to search

Exposing SystemXHR

Use cases

Email app is the only gaia app. But commonly similar use to systemXHR except for connecting to 3rd party non-http services.

Threats

  1. Accessing services behind a firewall
  2. Accessing local resources
  3. Exposing insecure services to local network (server socket)
  4. Consuming system resources?

Mitigation Strategies