Issue #1: Privacy of User Input Problem One application subscribes to digits to get a credit card #. With credit card #, “transfers” call. Don’t want next application to be able to “reach back” and get credit card #. Options So what, who cares? Do no quarantining (buffering of digits) – You can only get digits from the moment your SUBSCRIBE gets processed. Matter of Local Policy Flush buffer after dialog state change, offer/answer media change (reINVITE), or target refresh request |