As a user I'm really glad to see this move, along with the move towards android apps on Chrome OS since I'm hoping it will unify the Google-driven ecosystem a bit more.
As a user I'm really glad to see this move, along with the move towards android apps on Chrome OS since I'm hoping it will unify the Google-driven ecosystem a bit more.
- Full TCP/UDP socket support (AFAIK this is never coming to the web platform)
- Bluetooth support (Web platform is getting this, though)
- Filesystem support (e.g. get persistent read/write access to user selected directory. Web platform probably won't get this)
Notably the socket and filesystem permissions are not available to extensions. Most of the other permissions though are available in extensions.
We would have done an extension but there is no USB HID support. Obviously a web app would be a bad idea. Anyone know if there are plans to make the chrome.hid api available to extensions any time soon?
While it could never be allowed unconditionally (because it allows scanning internal networks), I don't see any reason it couldn't be allowed with a permission request.
Never ask users questions that they can't reasonably answer, ie don't do what android did for a long time (looks like this has been improving since N).
Maybe the case of TCP/UDP could be improved by showing a human readable version of the prompt for some well known ports. So a browser would ask "Do you allow webmail.com to use a secure IMAP connexion to mydomain.com?" when webmail.com requests access to mydomain.com:993
Such prompts are going to be super confusing to the majority of users. What is IMAP? What does secure mean? What's a port?
I don't have a solution; I think it's really difficult and interesting problem. For example, you might think a game shouldn't require any permissions, but then it might need internet access to upload scores, access to your address book to invite your friends to play etc. I can't see any easy solutions how you can check the app isn't using these permissions in a malicious way.
As another alternative, which would allow applications like mail clients, SSH clients, VNC clients, and similar, you could treat Internet connections like the web treats file-pickers today: ask the browser to prompt the user for one, and get handed a connection, without the ability for the site to set the target. Combine that with persistence ("allow the site to connect to this host again in the future without prompting?"), and you could easily connect to the handful of servers a user wanted to connect to. That wouldn't let you build a web-based BitTorrent client or similar, but it'd solve many of the problems people want arbitrary connections for.
It is awful that we can't rely on devices to do proper authentication but that is the state of security today.
And you can have a web extension that natively connects to a local program if you need more power. Not self contained but it's possible.