Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

WebUSB has... some issues.

For example, there's a huge song and dance around a web site only being able to create and use a FIDO2 credential for its own domain (in other words, badactor.example can't get an assertion for goodactor.example). But with WebUSB, you can just have your web site directly communicate with a USB authenticator and send it whatever domain you want, not even using the browser's webauthn APIs!

So... google blocked USB devices that respond with FIDO2 HID Report Descriptors from being usable over WebUSB.

There are just so many of those types of issue, and the standard response seems to be playing whack-a-mole instead of requiring that a USB device be "opt in" or user-selected, which would make more sense to me. It's a huge attack surface.

I don't like that this means you can Do More (TM) with Chrome(ium), but I'm also pretty happy not to have my web browser be allowed to reprogram my motherboard's fan controller hub.



> It's a huge attack surface.

People say this about so many useful Web APIs. Bluetooth, WebGL, WebGPU. The truth is these APIs have largely been exposed to the web for many years now and the promised deluge of vulnerabilities never materialized. Sure, there have been a couple here and there but overall the security mitigations built in have proven very good and the security impact has been very minor compared to the dire warnings people gave. Other areas of the browser continue to be worse.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: