Use a keyed hash for ICE candidate foundations The foundation of a candidate was the CRC32 of the candidate type, the base address, the protocols and the ICE tie-breaker. The tie-breaker is sent to the remote peer in connectivity checks, so the remote peer could recover the base address of a candidate from its foundation by brute force, also when the address is hidden behind an mDNS name. Adding a secret to the CRC32 input would not be enough, since CRC32 is linear and foundations with known inputs, such as those of relay candidates, could be used to cancel it out. Compute the foundation as a truncated HMAC-SHA256 instead, keyed with a random key that is generated once per process and never sent anywhere. Equal inputs still produce equal foundations within a process and the format (a decimal 32-bit number) is unchanged, but foundations are no longer comparable across processes. Bug: chromium:504578795 Change-Id: If07aee5410d5d29d3a74412b44f9704725e73788 Reviewed-on: https://webrtc-review.googlesource.com/c/src/+/507200 Reviewed-by: Mirko Bonadei <mbonadei@webrtc.org> Commit-Queue: Tomas Gunnarsson <tommi@webrtc.org> Cr-Commit-Position: refs/heads/main@{#48803}
WebRTC is a free, open software project that provides browsers and mobile applications with Real-Time Communications (RTC) capabilities via simple APIs. The WebRTC components have been optimized to best serve this purpose.
Our mission: To enable rich, high-quality RTC applications to be developed for the browser, mobile platforms, and IoT devices, and allow them all to communicate via a common set of protocols.
The WebRTC initiative is a project supported by Google, Mozilla and Opera, amongst others.
See here for instructions on how to get started developing with the native code.
Authoritative list of directories that contain the native API header files.