And as a side benefit, also makes it extremely easy to maliciously control hardware. A win for Google on two fronts here.
And as a side benefit, also makes it extremely easy to maliciously control hardware. A win for Google on two fronts here.
You've got the same trust problem for any other exe you download and run though. Any steam game you play could reprogram your device to show profanity for example.
Such implementations exposing all sorts of critical stuff over local HTTP servers are often highly insecure, and are the very reason why WebUSB and other device APIs are being pushed as part of the browser.
Connecting to a USB device requires only a single click. That just requires an attacker making the user believe what he wants, by stressing the user or by misleading or conditioning the user about what it is. It is not a more secure design than the UAC boxes in Windows Vista that users learned to "click be gone" by routine because they were annoying.
I was thrilled when I first heard about WebUSB because I had been looking for a way to configure USB device firmware using a web browser.
However, I learned that it has glaring security flaws:
* The web page bypasses the operating system's driver infrastructure, where VendorID/ProductID pair is used to look up only valid drivers. Some operating systems require USB device drivers to be signed. A web page requires only a click from the user.
* WebUSB allows web access even to devices that don't have explicit support for it. Older devices can have been designed under other pretences of security. Not all hardware engineers even know about WebUSB, so this applies to newer designs too. This is already serious, because there are devices used for 2FA that connect via USB that could be exploited this way.
* A device can not control which of its interfaces that a web page can claim or not claim.
* WebUSB contains no authentication of the web page on the device's behalf. (There was some idea that it should have, but that was removed for convenience )
Not ready for prime-time IMHO.