Fully agree:
- The attack is not an attack but
normal SFU behavior (the attack would be impersonation and/or deep
fakes)
- Trying to prevent it, PERC forbids to
rewriting ssrc which break most known SFUs up to date
- The attack is not prevented
IMHO PERC fails for WebRTC because it
is not truly end to end, just browser to browser, as it doesn't
take into consideration the role of the js app.
Only a e2ee solution integrated with
IdP and isolated media streams which allows the receiver to assert
the identity of the received packet would prevent impersonation
and deep fakes. Without it, the user *MUST* trust the js
application so that it doesn't send the media to an alternative
server or create deep fakes as Bernard is stating.
Best regards
Sergio
On 21/02/2019 19:40, Bernard Aboba
wrote:
|