4 ms·
Why scary?
by jaflo 10y ago
Why scary?
- Waterluvian 10y agoHaven't read the spec and am totally uninitiated in this kind of thing. But doesn't it add a very broad surface for attack?
- akerro 10y agoAt least this one has a section "security", WebUSB that was designed by Google employees didn't have that section.
- m_eiman 10y agoI would be surprised if this isn't used to subvert the firmware of various BLE-enabled devices.
- IshKebab 10y agoYou need to confirm connection to devices. Web pages can't just suddenly connect to any nearby BLE device.
- TeMPOraL 10y agoNo, you don't. You only need to confirm stuff if you want an authenticated connection, which is a special type of connection. Devices may or may not allow you to change stuff regardless of whether the connection is authenticated or not. For instance, I have a cheap lost key tracker at my desk that can be made to beep loudly without an authenticated connection. Moreover, there's no authenticated connection required to browse the services a BLE device exposes. GATT services are considered public information, so you can easily exfiltrate metadata about (discoverable) devices present without anyone noticing. (source: I read a BLE book over the last weekend)
- IshKebab 10y agoYes you do. When you want to connect to a device the browser UI shows you a list of devices and you have to select one and click connect. Source: I've actually implemented a WebBluetooth-controlled device. Also, Google. https://developers.google.com/web/updates/2015/07/interact-with-ble-devices-on-the-web#scan_for_bluetooth_devices https://developers.google.com/web/updates/2015/07/interact-w...
- TeMPOraL 10y agoI meant confirming on BLE device, you mean confirming in the browser. At least from the BLE device side you don't have to explicitly confirm anything as long as the device is broadcasting connectable advetising packets.
- IshKebab 10y agoWell sure. That is up to the BLE device. There's nothing broken about that and WebBluetooth doesn't change anything.
- m_eiman 10y agoYou also need to enable macros for Word "viruses" to work, but somehow they do… IMHO, this increases the attack surface of browsers by a fair amount to little practical gain. But then I'm not impressed with the "browsers are all you need" mentality, so I'm a bit biased.
- stephenr 10y agoIt's the web. Scary should be your default position until it's shown that something is secure. Then consider the quality of your average javascript developer, and it goes from an evil clown outside your childhood bedroom window, to an evil clown in your closet with his pants down and a nickname picked out for you already.