7 ms·
No thanks. I'll accept it in my browser when they fix the security implications this raises, and when the Spec is no longer in draft.
by Orygin 6mo ago
No thanks. I'll accept it in my browser when they fix the security implications this raises, and when the Spec is no longer in draft.
- gear54rus 6mo agoAnd I'll just fire up a chrome instance which I specifically keep for when my daily driver firefox decides to spazz out and not implement basics in 2026 :'(
- lpcvoid 6mo agoHow do you make sure that technically illiterate people don't just click away the requestDevice() popup? IMHO a browser offering device level USB access is a security nightmare and there is no way this can ever be made safe and convenient at the same time.
- zb3 6mo agoThey can click everything away, so maybe educate them or buy an ios device for your relatives instead of breaking computing for everyone else.
- lpcvoid 6mo agoFair, but remember that we are the <~1% of people who even know what webusb is. I'm not sure I share your view on this. Maybe an about:config switch to enable it would be enough to stop casuals from pwning their peripherals.
- barnabee 6mo agoI’d be ok with an about:config switch, but given that many people will install anything, paste arbitrary text into terminals, and share their password/pin code with complete strangers for almost no reason, I think we need to stop making our tools less powerful in pursuit of an impossible goal.
- Orygin 6mo ago> breaking computing for everyone else How is not implementing a Draft spec, which may compromise security badly, breaking computing? Overreacting much?
- zb3 6mo agoThis is not just an isolated incident, it's the whole trend of limiting capabilities in the name of security and that's what I was referring to. However in this particular case, even the security argument doesn't hold, either I: a) know that I want to use USB - in that case I'll switch browsers or download a native binary (even more unsafe), it's not that I'd decide that I no longer want to flash my smartphone b) I don't understand what's happening but I follow arbitrary instructions anyway - WebUSB changes nothing.
- skydhash 6mo agoSo instead of using trusted vendors or requiring tools with auditable code, we just allow everyone to be able to access the user’s devices?
- CamperBob2 6mo agoWhat a concept. We could call it "Personal Computing."
- skydhash 6mo agoNot really that personal when every webpage is itching to put their hands on it.
- Orygin 6mo agoA native binary can be verified by anti malware systems, and once installed and working, poses no security risk. A 0day in a browser for the WebUSB system would allow any website to mess with arbitrary USB devices connected to your computer. While the browser sandbox is generally safe, it is also a huge target, and with a security risk like that, it wouldn't surprise me if it's a prime target for black hats.
- troupo 6mo ago> They can click everything away, so maybe So maybe don't populate the browser with dozens of features requiring permission popups?
- exe34 6mo agoYou can ask them to type one of the following sentences: "I know what I'm doing, and giving a random website access to my USB host is the right thing to do." "I'm an idiot."
- gear54rus 6mo agoYou simply don't. This quest of saving idiots from themselves is not gaining anyone anything and meanwhile other people get more and more useless restrictions.
- Orygin 6mo agoOr you can just not give a loaded shotgun to every browser user on the off chance they need to interact with 1 (one) usb device per year.
- leptons 6mo agoOr you can just not use the web at all. If you're so scared of it, why are you using it with browsers that have implemented all kinds of APIs that probably already scare you? You may as well just use the Lynx browser if you really want want to put your money where your (security) mouth is. It doesn't do anything, not even display images or CSS or run Javascript.
- limagnolia 6mo agoIsn't that the same excuse Gooogle is using to lrevent folks from installing what they want on Android phones?
- baby_souffle 6mo agoEssentially, yeah.
- skydhash 6mo agoI do not agree with Google on preventing apk installation. But unknown apk is a different risk profile than letting unknown entities to access local usb devices. The main issue in the former case is that google is posing itself as a gatekeeper instead of following a repo model like Debian or FreeBSD. That’s wanting control over people’s device. Allowing USB access is just asking to break the browser sandbox, by equating the browser with the operating system.
- mvdtnz 6mo agoI'm tired of my computing being kneecapped in service of incompetent boomers. Enough is enough. If they're going to fall for dumb scams let them.
- yjftsjthsd-h 6mo agoAre you calling WebUSB a basic feature? Because I'm willing to discuss whether we should have it, but that seems like an exaggeration.
- Retr0id 6mo agoThe security implications of not having WebUSB are having to install untrustworthy native drivers every time you want to interface with a USB device.
- skydhash 6mo agoThat sounds like a Windows problem.
- Retr0id 6mo agoI'm not familiar with the Windows platform but although you can have userspace USB drivers on linux, you still need to be able to run code that can talk to the sysfs interface.
- Lerc 6mo agoThe Linux problem is more Hope every time you want to interface with a USB device.
- monegator 6mo agoNot really, as long as the firmware developers used OS 2.0 descriptors (For the rare occurences that our customer is using 7 or earlier, we tell them to use zadig and be done with it.)
- PunchyHamster 6mo agoYou can have userspace drivers for usb devices in Linux
- scottbez1 6mo agoHow does the security of userspace drivers compare to having drivers within a sandboxed web environment with access to only the devices you’ve explicitly allowlisted?
- bigfishrunning 6mo ago
- zb3 6mo agoWhat are the security implications this raises that downloading native programs (needed for example to flash my smartphone) doesn't raise?
- barnabee 6mo agoNone. People will follow any instruction presented to them when they think it will get them something they want. Mozilla’s stance here is infuriating.
- troupo 6mo ago> What are the security implications this raises that downloading native programs (needed for example to flash my smartphone) doesn't raise? 1. Permission popups fatigue 2. Usually users select the apps they install, most sites are ephemeral. And yes, even with apps, especially on Android, people click through permission dialogs without looking because they are often too broad and confusing. With expected results such as exfiltrating user data.
- oofdere 6mo ago> Permission popups fatigue Native apps also have this, and it's worse because they usually just ask for sweeping admin access on windows, unlike WebUSB which just brings up a device selection menu
- troupo 6mo ago> Native apps also have this, and it's worse because they usually just ask for sweeping admin access on windows On iOS they only pop up the menu when they try to access the required functionality, and there's a limited number of things they can do. > unlike WebUSB which just brings up a device selection menu So the user has to contend with permissions on phones, in desktop OSes, but 26 more potential permissions [1] from a browser are fine because a) it's just a single permission window and b) the browser exists in total vacuum from all other user experiences. [1] Counted in Chrome settings -> Site settings -> permissions. Why Chrome? Because they are the ones pushing all the hardware APIs, among others
- leptons 6mo agoThe spec is still in draft because Apple refuses to let it move forward - because WebUSB, WebBluetooth and other APIs would compete with their app store, where they can make money from purchases made through apps. They prioritize profits over progress. It has nothing to do with security, as WebUSB has no ability to interact with any device unless the user explicitly allows each and every website that requests access to do so. It's the same security as any other browser API that requests access.
- JimDabell 6mo ago> The spec is still in draft because Apple refuses to let it move forward This is untrue. Web standards need two independent implementations. Google can’t convince any other rendering engine besides their own to implement it. It doesn't take a single no from Apple to veto it; it takes a single yes from anybody outside of Blink to move it forward. Nobody is doing that. Here is what Mozilla have to say about WebUSB: > Because many USB devices are not designed to handle potentially-malicious interactions over the USB protocols and because those devices can have significant effects on the computer they're connected to, we believe that the security risks of exposing USB devices to the Web are too broad to risk exposing users to them or to explain properly to end users to obtain meaningful informed consent. It also poses risks that sites could use USB device identity or data stored on USB devices as tracking identifiers. — https://mozilla.github.io/standards-positions/#webusb https://mozilla.github.io/standards-positions/#webusb Until Google can convince anybody outside of Blink to implement it, it is not a standard it’s a Blink-only API.
- leptons 6mo agoApple has provided no alternative, and no suggestions for how to improve the draft. They are not helping advance the draft only for selfish reasons. They also won't allow any other browser on iOS for the same selfish reasons. Apple continues to use abusive business tactics, and it's why they are being sued by the DOJ in an antitrust lawsuit. Them not implementing and not even suggesting changes to WebUSB and WebBluetooth are just further examples of it. https://www.justice.gov/archives/opa/media/1344546/dl?inline https://www.justice.gov/archives/opa/media/1344546/dl?inline >Because many USB devices are not designed to handle potentially-malicious interactions over the USB protocols and because those devices can have significant effects on the computer they're connected to So the alternative is installing questionable drivers from questionable websites that give an attacker full-access to the entire computer. This is far less good for security, and is unfortunately the norm right now. >we believe that the security risks of exposing USB devices to the Web are too broad to risk exposing users to them or to explain properly to end users to obtain meaningful informed consent. So is every other browser API that's currently implemented that requires explicit approval from a user. It's nonsense to single out WebUSB specifically. > It also poses risks that sites could use USB device identity or data stored on USB devices as tracking identifiers. Bullshit. You have to explicitly allow WebUSB to interact with any website that requests it. It does NOT allow arbitrary tracking, and this sentence proves that whatever Mozilla writes about it is disingenuous, trying to incite hysteria about an API.