That's a bit strong. A website can't force a user to anything. The point is that to use the feature nefariously without the user knowing it's happening is relatively easy to prevent by putting the feature behind a permissions flag. If the user actively wants a website to be able to make connections they can say yes.
If the user doesn't know then they ought to be saying no, but really they won't and they'll say yes if the warning isn't scary enough. The browser vendors could also do things like throttling connections or asking for permission again if things look too weird.
This. Defaults matter. You cannot introduce a privacy sensitive feature just with a permission dialog box. You must expect that most users just click through, and continue to protect those "dumb" users.
- legitimate websites using this feature for valid purposes, such as to control devices on your local network
- targeted malware attacks trying to hack devices on your local network
I’m certain we will not start getting popups for this on any mainstream website.
So as long as this permissions thing is more than a simple yes/no dialog, I’m not worried.
Even if you don’t consider bad intentions, the security implications are huge. Imagine if Zoom had used this feature. The security fiasco a few months back would’ve been made a whole lot worse.