Le 17/11/2014 11:00, Patrick Ohly a écrit :
On Mon, 2014-11-17 at 09:00 +0100, Dominig ar Foll (Intel OTC) wrote:
when I read your reply to Zoltan, I have a different impression of the
work remaining to be done.

At the end of the day, I would favour a very pragmatic approach :

   - how can we enable multi user support fir BT in tizen 3.0
Apropos multi user, can you clarify whether an implementation of phase 1
(user isolation, https://wiki.tizen.org/wiki/Multi-user_Bluetooth) is
good enough if it only works for processes cooperating with NTB? Or does
it also have to protect against malicious users bypassing NTB?
Our goal is to make the task for malicious user as hard pas possible.

I've argued that it is the latter (see also
https://bugs.tizen.org/jira/browse/TC-1411) while the NTB developers
claim that the less secure access control in NTB is good enough for 3.0.
You are correct, as BT FW demon run with the Bluetooth user ID, we will have to filter other user make direct call to BlueZ.
That can be done quite easily via a dbus policy.


Dominig ar Foll
Senior Software Architect
Open Source Technology Centre
Intel SSG


_______________________________________________
Dev mailing list
[email protected]
https://lists.tizen.org/listinfo/dev

Reply via email to