9 ms·
A while back I stumbled upon google chromes privacy settings and found things like serial port on your computer to be accessed by websites. Turns out google has
by trustingtrust 3y ago
A while back I stumbled upon google chromes privacy settings and found things like serial port on your computer to be accessed by websites. Turns out google has thrown everything in the mix because they probably want their 'Chromebook' users like children in school to use motion sensors for convertibles to maybe play games via a browser. Websites are just taking advantage of these things. The chrome browser has ruined the internet.
- afavour 3y agoI guess I don’t know how you got from A to B there. I love the idea of kids being able to experiment with serial ports (though I’m not sure what you mean in that context, WebUSB?) in a safe, locked down programming environment. Ideally it wouldn’t mean random web sites request motion data from you but I really don’t see this as ruining the internet.
- xyzelement 3y agoThe browser is essentially the operating system for most computing today so access to peripherals is reasonable. My current job uses USB security keys and I assumed I'd have to configure them in the OS before the browser was aware of them -nope! Chrome knows if the key is in the USB port and can interact with it with my approval, which is exactly right. The leap from access to USB to access to serial is minimal. As long as the right permission checks are in place.
- sznio 3y ago>The browser is essentially the operating system for most computing today so access to peripherals is reasonable. Sure, but the fact that browsers became operating systems is unreasonable in the first place.
- realusername 3y agoSeeing where the mobile world goes, I still prefer my browsers, at least I can modify the websites as I want. Sure it's not great, but the alternatives are worse.
- toastal 3y agoIf it’s proprietary, it can stay in they browser sandbox.
- didntcheck 3y agoNot to mention the sandboxing. I'm glad a lot of the "apps" I use are just "webapps", so that I can trust them less. A user process on a desktop OS is given an insane amount of permissions by default, though this is being fixed, slowly
- realusername 3y agoThat's also a good point yes, the browser sandbox is the strongest that we know of.
- _ea1k 3y agoIDK, that seemed to be the vision even back in the Netscape days.
- PH95VuimJjqBqy 3y agoThat was always the end goal.
- shawnz 3y agoWhy? Isn't the web basically the perfect fully virtualized and sandboxed environment with a highly standardized and open API and a sophisticated, accessible UI toolkit, with elaborate development tools built right in, like we always dreamed of? Isn't the web basically the perfect OS?
- jjoonathan 3y agoYes, and most importantly: nobody owns it. Sure, we all complain about Chrome and its outsized influence, but at the end of the day the standards are more open than not and Safari and Firefox mostly work most of the time on most of the pages. That's a stark contrast to, say, .NET vs Cocoa or Android vs Apple app stores.
- dylan604 3y ago>mostly work most of the time on most of the pages well, that sounds perfectly reasonable that only some pages are not standards compliant. :facepalm:
- jjoonathan 3y ago"Comply or we will break your shit" works better in closed ecosystems. I'll take a little mess over a 30% tax and heavy-handed tempramental moderation any day of the week.
- JohnFen 3y ago> Isn't the web basically the perfect OS? I don't think so at all. Web-based applications tend to suck, and it seems to me that much of the reason is because the browser is very imperfect as an OS.
- nolist_policy 3y agoAnd yet you are posting this on HN, which one could argue is a Web application. And don't forget shopping online, there are a few small web shops out there with great UX. And you can use 20 year old websites just fine, the web has great backwards compatibility too. Web apps don't have to suck.
- repelsteeltje 3y agoWebUSB is actually a W3C open standard. For instance, the BBC:MicroBIT educational dev environment runs in a web browser and allows python code to be pushed to the microcontroller straight from the browser. https://developer.mozilla.org/en-US/docs/Web/API/WebUSB_API https://developer.mozilla.org/en-US/docs/Web/API/WebUSB_API Isn't that neat?! Well, it could be, as long as you browser didn't allow this to be used, probed or even enumerated without explicit consent.
- lxgr 3y agoTo my knowledge, no browser allows any usage of WebUSB without a prompt. WebAuthN is different, since it does not provide sites low-level peripheral access – WebAuthN and CTAP have been designed for specifically this environment and go to great lengths to make fingerprinting hard. As long as you don’t actually use an authenticator on a site to store a credential, it won’t be able learn anything about it.
- repelsteeltje 3y agoNot sure about this, but I think from JavaScript you can absolutely probe stuff without explicit user consent. For instance, without accessing any USB device I can try: if(!navigator.usb) { console.log("learned that browser does not have USB capability"); } else { console.log("learned that browser has USB capability"); navigator.usb.getDevices().then((devices) => { devices.forEach((device) => { console.log(device.productName); console.log(device.manufacturerName); }); }); } (Which is useful for fingerprinting.)
- nolist_policy 3y agoOkay, so you can learn that Chrome supports WebUSB and Firefox doesn't. But you already knew that from the User-Agent header...
- repelsteeltje 3y agoHahah, so you think. But now you have additional telemetry to show that this wasn't cURL forging a Chrome (or Firefox) user-agent header. Finger printing sounds sophisticated, but it's just collecting the bits and pieces into something that (mostly, probabilistically) identifies you. And then tracking you, surveilling you till you're somewhere where they can identify you. From there: profit!
- criddell 3y ago> The browser is essentially the operating system for most computing today You're right, and it's such a bummer. I often think about how interesting it would be if we didn't end up with the Chrome/Safari browser duopoly and Windows/macOS duopoly on the desktop and Android/iOS duopoly for mobile. How cool would it be to see what the Amiga, Atari ST, Spectrum, OS/2, BeOS, etc... could have become with another couple of decades development. Even Windows and macOS would probably be different if they had to compete in a healthy, diverse ecosystem. Instead, further concentration is probably going to happen once Apple allows alternate browsers. At that point, there isn't much to stop Google's Chrome from becoming the only application platform that really matters.
- echelon 3y ago> Instead, further concentration is probably going to happen once Apple allows alternate browsers. At Not if the DoJ forces Google to abandon Chrome. Which they should. Apple and Google should lose their app store monopolies (including first party default preference), Google should lose the Chrome monopoly. These are incredibly harmful to technology and competition. Each company has plenty of money, attached user base, and engineering headcount to continue to be wildly successful and profitable without operating in a way that damages the rest of the tech sector.
- j45 3y agoI’d probably add WebOS to that list too even though it’s currently living on in LG tvs. The idea of WebOS is strong enough it seems to have lived on through Palm, HP, LG and now also a forked version. It really was late to the mobile os race, but ahead of its time. https://www.webosose.org/docs/tutorials/web-apps/developing-built-in-web-apps/ https://www.webosose.org/docs/tutorials/web-apps/developing-... And more generally: https://www.webosose.org/ https://www.webosose.org/
- j45 3y ago> The browser is essentially the operating system for most computing today The browser is more of a universal user interface than a universal OS. Of course something like chromeOS/ChromiumOS is an OS what boots directly into a browser, but it’s not a universal interface. Maybe WebOS was a step in that direction being a mobileOS that was all html and JavaScript. Screenshots: https://www.webosose.org/docs/guides/getting-started/webos-ose-ui-guide/ https://www.webosose.org/docs/guides/getting-started/webos-o... https://www.webosose.org/docs/tutorials/web-apps/developing-built-in-web-apps/ https://www.webosose.org/docs/tutorials/web-apps/developing-...
- JohnFen 3y ago> The browser is essentially the operating system for most computing today so access to peripherals is reasonable I suppose. Not for me, though, as I don't (and won't) use web apps or complex websites. I sorely wish there was a browser that simply didn't have that capability.
- denton-scratch 3y ago> The browser is essentially the operating system That's a fashionable observation; I think it's a kind of illness. The idea that you can take over anyone's computer, and make it do things the user doesn't want done, and doesn't know are being done, makes some web-developer's heads swim; they can turn the whole internet into a sort of distributed supercomputer for their own private use. WHATWG bears a lot of responsibility for this. A real operating system doesn't download and execute code from unverified remote locations. Nearly every website nowadays tries to load and execute in the browser code from any number of remote locations, without the user's approval or even knowledge. By default, I only allow 1st-party JS, which I consider to be an extremely liberal policy.
- nolist_policy 3y ago> A real operating system doesn't download and execute code from unverified remote locations. Sorry, but that is pretty much the standard way to install apps on windows. That the browsers execute untrusted code all the time and still are secure is an advantage of web technology.
- skydhash 3y ago> Sorry, but that is pretty much the standard way to install apps on windows. Maybe now, but when I was on XP and, later, Windows 7, you only had a handful of software you would use (I have all of them on a CD, and later on an HDD). Things like VLC, Notepad++, Codeblocks, Office, and others. It requires trust, but these programs did not phone home, AFAIK, every second. That's what we lost, trust in our computer and the software programs running on it. And now, it is a hostile relation between customers and software developers. I wasn't concerned about VLC tracking the file I opened with it, or Office scanning my documents.
- denton-scratch 3y ago> That the browsers execute untrusted code all the time and still are secure But they aren't secure. Most of that untrusted code is doing stuff that's of no value to the user, and is positively against the express interests of many users.
- deleted 3y ago[deleted]
- kody 3y agoMy students were able to program Arduino devices from their Chromebooks because of this tech. That would have been inaccessible to them if they had to use a "real" OS, which the school did not provide.
- skydhash 3y agoA failure of the school, then.
- markdog12 3y agoYou have to explicitly grant permission for a site to use a serial port.
- panki27 3y agoAnd it can be rather practical. I've flashed firmware onto some devices using an online tool.
- deepspace 3y agoThe existence of the Web Serial API is a godsend for working with many embedded devices. The ability to flash a device directly from the web instead of futzing around with a commandline tool feels like magic. Unfortunately, Mozilla decided that this (and other related functionality) is "harmful". https://mozilla.github.io/standards-positions/#webserial https://mozilla.github.io/standards-positions/#webserial It is a shame, because the overlap between people who use Firefox as their main browser, and people who tinker with microcontrollers is likely pretty large.
- jeroenhd 3y agoSerial ports are everywhere and these APIs can provide quite a lot of fingerprinting capabilities. I understand why Mozilla is hesitant. "Why does a browser need to give access to a serial port" is a good question. Certain web tools have definitely proven useful (especially when using an Android device to flash microcontrollers!) but if you asked the average internet user 20 years ago if their browser should provide websites with access to their serial ports, you'd get laughed at. I hope Mozilla reconsiders their positions on this, because this is just one of those reasons I keep Chrome installed. I need it very rarely, but when I do, it's often because Mozilla made a choice I disagreed with (like their decision to remove anything resembling PWAs on desktop Firefox, which is why I have a bunch of Chrome shortcuts in my application launcher now).
- markdog12 3y ago> "Why does a browser need to give access to a serial port" Why does a program need to give access to a serial port? > if you asked the average internet user 20 years ago if their browser should provide websites with access to their serial ports, you'd get laughed at What if you included "Only if you allow it"?
- jeroenhd 3y agoWebserial let's Home Assistant users flash their ESPHome devices without downloading or compiling any software. WebUSB let Google update my Stadia Controller to a normal controller after they shut down their cloud services. It also offers firmware updates for some Pixel phones. These are all quite useful tools. I've never used WebMIDI but it's older than the other Web* APIs. When you have a use case for them, the APIs are a lot better than figuring out a cross platform serial port protocol (or, more realistically, writing a Windows application and letting the Linux/macOS/Android users figure it out themselves). WebSerial/USB/Bluetooth doesn't do anything unless you permit it to. If websites used this feature, you've clicked "okay" when mapquest.com asked to use your serial port.