Announcements
DIAL Specification 2.2.1 Released
DIAL 2.2.1 is now available. We recommend that devices which implement DIAL include support for the most current version of DIAL. Highlights of this release include: Further closure of security gaps around CORS. For additional details please review the DIAL Protocol Specification. DIAL Reference Software corresponding to the current specification can be found in Sample Implementations. |
Dial Specification 2.2 Released
DIAL 2.2 is now available. We recommend that devices which implement DIAL include support for the most current version of DIAL. Highlights of this release include:
For additional details please review the DIAL Protocol Specification. DIAL Reference Software corresponding to the current specification can be found in Sample Implementations. |
DIAL Specification 1.7.2 Released
An attack vector on DIAL-enabled devices was reported to us by NCC Group. This attack allows Javascript code running on a second-screen DIAL device to launch an application on a first-screen DIAL device. This Javascript can be embedded in any website, especially through 3rd party ad delivery mechanisms. The previous version of DIAL (1.7.1) supports CORS headers but doesn't specify any access policy. The reference DIAL server implementation also doesn't impose any restriction on the Origin, which allows Javascript XHR requests coming from any domain to be executed by the DIAL server. To solve the issue, the DIAL 1.7.2 spec was updated to define a CORS access policy on the DIAL server that doesn’t break compatibility with existing devices. The new CORS access policy will:
The benefits of this solution are:
|
DIAL Specification 1.7 Released
DIAL Specification 1.7 is now available. We recommend that devices which implement DIAL include support for the most current version of DIAL. Highlights of this release include:
For additional details please review the DIAL Protocol Specification. DIAL Reference Software corresponding to the current specification can be found in Sample Implementations. |
Subscribe to this feed for changes & updates
Subscribe to this page's RSS feed to be notified of updates to the DIAL Protocol Specification, the sample software posted here, and other news or site changes. |