Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What are the fingerprinting risks? Can websites gather any data without user consent?

I used WebUSB to flash GrapheneOS onto my Pixel, and to flash WLED on an ESP32 and it felt like magic. I'm erring on the side of this being a net positive.



> Can websites gather any data without user consent?

No, you need to explicitly grant access to every hardware device a website wants to touch. The FUD in this topic is a little out of control.


"Hello GrandMa1950, please plug in your security key and select the device called /dev/ttyUSB0 in the pop-up, so we can authenticate your log in. Thank you!"

I'm fairly sure that would work. The FUD is likely well warranted.


That was my very first concern when I thought about WebUSB too, but Chromium has a block list of Vendor IDs which includes various security keys.

https://chromium.googlesource.com/chromium/src/+/967d11212c9...


Even a lot of reasonably tech-savvy people might not know the difference between the WebUSB consent popup and the security key popup.


Sigh. That's no different than "Please install this App" or even "Please read me this code". Yes, user-mediated authorization is an extremely difficult nut to crack. There will always be holes. There will always be unsophisticated users. But if you agree (and you do, right?) that people want to use external USB devices on their own devices, then you have already accepted that risk.

Freaking out because of the specific technology used to deploy the software is mostly just whining. This being HN, at least 60% of the resistance to web apps having extended capabilities is because of the company building the browser.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: