8 ms·
Firefox Webserial Addon
- vbezhenar 2y agoFirefox really should stop this idiotic approach with refusing to implement important APIs. It only makes users suffer.
- 01HNNWZ0MV43FF 2y agoBut then people whine when Chromium unilaterally adds stuff. Can't win, huh
- skeeter2020 2y agoor more pointedly how Mozilla is too distracted
- pessimizer 2y agoCan't convince or force everyone else to do what I want, and then when I do what I want without them, people complain. It's such an injustice that I can't do whatever I want whenever I want without people complaining about it. There would be nothing to complain about if they had all just done what I wanted in the first place.
- shiandow 2y agoWhy is it important that a website should have access to my serial ports?
- beeboobaa3 2y agoIt doesn't have access to your "serial ports". It has access to a consent dialog in which you can choose one port to give the website access to, so it can e.g. flash IoT devices for you. Take a look at e.g. https://esphome.io/index.html https://esphome.io/index.html Or just RTFA: https://github.com/kuba2k2/firefox-webserial?tab=readme-ov-file#usage https://github.com/kuba2k2/firefox-webserial?tab=readme-ov-f...
- troupo 2y agoAnd how many consent dialogs will you be willing to call an acceptable number?
- cillian64 2y agoIf that’s the argument against, it could just be denied by default and require the user to go into settings to allow. The annoyance isn’t too bad given webserial is probably only used on occasion, and it means no concerns about consent spam or fingerprinting.
- troupo 2y agoWhy do people willingly ignore all the other APIs that require a consent dialog. And what happens when users are presented with a barrage of them.
- gregmac 2y agoUsers aren't presented with a "barrage" of consent dialogs. There's not even that many of them, and being able to access a serial port is a niche case where it does make sense -- just like accessing a web cam or microphone. It's certainly less annoying than the one for allowing push notifications. Unless, of course, the site is malicious/spammy. It's possible to do all kinds of annoying things, from triggering consent dialogs, to opening new windows, to playing sounds.. and you can even do them in a loop. Adding (or not) a consent dialog for webserial doesn't change that.
- troupo 2y ago> Users aren't presented with a "barrage" of consent dialogs. There's not even that many of them, and being able to access a serial port is a niche case It's amazing that you write this and then immediately find the (almost) right answer: > Unless, of course, the site is malicious/spammy. It's possible to do all kinds of annoying things, from triggering consent dialogs... And then immediately dismiss that as if that wasn't a valid concern: > Adding (or not) a consent dialog for webserial doesn't change that. Yes, yes it changes that. It increases the number of consent dialogs in a system that already has a few of those, and where users are already trained to click "yes" to thousands of annoying popups. Oh, and these are not just empty words. Recently Mozilla relented and implemented WebMIDI. Guess what: https://x.com/denschub/status/1582730985778556931 https://x.com/denschub/status/1582730985778556931 It didn't even require a malicious/spammy site. Just regular ad networks.
- vbezhenar 2y agoBecause device vendor can provide you tools for your device that'll work in browser, protected by browser sandbox, cross-platform and always up to date. Rather than requiring you to install some crappy executables with instructions how to disable Windows protection to be able to install unsigned drivers.
- graemep 2y agoThat sounds like a problem with Windows that should be fixed in Windows. Adding a browser API for such narrow user cases is unnecessary. Even better Windows drivers should be signed as they are supposed to be,
- ale42 2y agoWhy install drivers? Webserial is about serial ports. If you need a driver to actually see your serial port, you need to install it anyway to use webserial.
- ale42 2y agoTools that unlike local apps will go offline when the vendors' web site will go offline at some point. And then the user will have a stupid brick instead of a device. I understand the convenience of using a web-based application, but it has numerous disadvantages that should also be taken in account.
- zamadatix 2y agoA browser based application doesn't need to rely on the vendor's website being up any more than an executable based application needs to. It's definitely an option in each case but one does not imply the other. Distribution access becomes a pain point but in either case the answer is to find archived versions.
- ale42 2y agoSure, but I can easily put an installer on a NAS (or on whatever media I use for long-term storage) and keep it there. Properly archiving a website and making sure it works offline is another story: sometimes it is relatively simple, sometimes there are requests on backend servers and you'd have to reimplement whatever the backend is doing, and it can get a real pain to do.
- beefnugs 2y agoI just ran into this recently: provisioning some older HSMs require creating an executable sent to customers. Windows defender now blocks these by default just because they have some kind of encryption going on in them. Mozilla is correct, this is very dangerous to just freely allow access. But some people really need it. And IOT and firmware stuff really needs it to exist somehow. I dont know why active purposeful allow button isn't good enough however
- josephcsible 2y agoWhy can't the executable be compiled on the customer's computer? And just "some kind of encryption" isn't enough to look like a virus. Is it doing something evil like encrypting its own code?
- tmottabr 2y agonot at all.. At least in windows, anything that is not signed with a code signing certificate that is known and that have good reputation will be blocked by windows and\or anti-virus. There are some small devs that i have seen needing to get a new cert, for whatever reason, and got new versions of their software start being blocked for a few weeks until the new cert got known.
- phatfish 2y agoI think they have the right approach, ignore the peanut gallery.
- ravenstine 2y agoTell that to Apple first, then maybe we can talk about Mozilla. Web Serial, or lack thereof, is the least of the web's problems right now.
- wpm 2y agoThis is an important API in that I refuse to use a browser that implements it.
- praseodym 2y agoMozilla's position on the Web Serial API and their reason not to implement this in Firefox: "Devices that offer serial interfaces often expose powerful, low-level functions over the interface with little or no authentication. Exposing that sort of capability to the web without adequate safeguards presents a significant threat to those devices. A user deliberately installing a site-specific add-on may be adequate, given sufficiently understandable consent copy." (https://mozilla.github.io/standards-positions/#webserial https://mozilla.github.io/standards-positions/#webserial)
- IshKebab 2y agoSeems like a cop-out. If you are worried about adequate safeguards.... just implement it with adequate safeguards! And how many users that need safeguards are going to be actually using serial devices anyway? I wish people would be more honest about this sort of stuff. I am sure that the real reason is they just don't have enough resources to implement and support this very niche API.
- madeofpalk 2y agoThe "just" is doing a lot of work here. It's not Mozilla's job to contribute back to every spec they disagree with. This feedback is given to those championing the specs, and it's up to them to build something better.
- RobotToaster 2y agoWe already have authorisation popup boxes for websites that want to use stuff like webcams, it doesn't seem unreasonable for them to just give a popup authorisation for web serial with a warning that it could set your printer on fire.
- madeofpalk 2y agoYou can read through the conversations to understand more of the context https://github.com/mozilla/standards-positions/issues/100#issuecomment-411931908 https://github.com/mozilla/standards-positions/issues/100#is... https://github.com/mozilla/standards-positions/issues/95#issuecomment-403139745 https://github.com/mozilla/standards-positions/issues/95#iss... https://github.com/mozilla/standards-positions/issues/336 https://github.com/mozilla/standards-positions/issues/336 The main struggle is around giving informed consent that explains the risks. Understandably, browsers don't want to ship a "Set my printer on fire" button. The web is held to a higher standard because it's so much more hostile than the native app environments, with arbitary code being executed, without permission, from unknown and untrustable origins.
- squarefoot 2y agoInteresting and useful from a technical standpoint, but brings all sorts of caveats, including but not limited to security and potential dependency on remote services that the user has no control on.
- lxe 2y agoThis finally unlocks the ESPHome and other hobbyist ecosystems for Firefox. Bizarre why they are so vehemently against supporting this API.
- deleted 2y ago[deleted]
- pessimizer 2y agoYou can't find it bizarre that some people think it might be bad to give your browser access to your ports.
- magicalhippo 2y agoIt significantly lowers the barrier of entry for installing and updating the ESP devices. And it's just a serial port, not raw disk access or similar. Obviously it should have a proper permission prompt similar to web camera and such.
- j45 2y agoWhy through a web broswer? Seems pretty easy to "copy an paste this line in your command line", or maybe a simple installer app wrapped up for each OS in Flutter. I agree zero friction would be nice, but this example is pretty deep in hardware and details
- throw10920 2y agoThey don't find it bizarre - they're using that word to emotionally manipulate readers of their comment.
- j45 2y agoNot bizarre at all. Lots of history available on the need for browsers to remain independent and secured away from the computer itself or security is no longer a thing.
- Am4TIfIsER0ppos 2y agoA document reader has no need for serial port access. Or is this for receiving html over serial?