Fingerprinting of WebMIDI devices is already happening in the wild. It was discovered because Firefox prompted for WebMIDI access on some random e-commerce websites, whereas Chrome silently allowed websites to access MIDI devices.
I just would wish, there was a more clear distinction between them.
I think the connection from the browser vendors to the ad companies are not helping with that.
You can let the user accept new entries, but then you're back having to give random nontechnical people enough context and information to make the correct choice when a random website causes the permission dialog to appear. Empirically, that doesn't go too well.