WebRTC Security: is web-based peer-to-peer ready for primetime? by Lieven Desmet
In this presentation, I will provide the Devoxx audience the necessary insights in this emerging Web technology, and discuss the various security aspects of WebRTC. This content is based on a recent study of the Web Security specifications our research lab has been conducting together with researchers at SAP, W3C and Trinity College Dublin in the context of the European FP7 research project STREWS. Firstly, the overall WebRTC architecture will be presented, and the enabling technologies (such as STUN, TURN, ICE and DTLS-SRTP) will be introduced. This architecture will be illustrated in multiple deployment scenarios. As part of this description, the basic security characteristics of WebRTC will be identified. Secondly, I will discuss how the new WebRTC technology impacts the security model of the current Web. They will highlight some of the weaknesses we have spotted during their security assessment, as well as discuss the open security challenges with the WebRTC technology.