But with WebUSB a page _can_ communicate directly to a yubikey and pretend it's being asked to authenticate on a different origin. It's been fixed now but it was an interesting bypass:
- https://www.yubico.com/support/issue-rating-system/security-...
- https://www.wired.com/story/chrome-yubikey-phishing-webusb/