Hacker News new | ask | show | jobs
by numpad0 460 days ago
Only the initial SDP needs to be fudged. The attacker could just set up two clients that pretends to be the sender/recipient. Then the data can just go through regular Google TURN servers.