This should probably be updated to point to the w3 proposal document, but I'm interested. For a while now I've wanted to have this functionality, but short of using flash (or sticking yet another backend server between processes) this has been impossible.
It's a shame that the section on security is so short. Hopefully someone will address that soon.