Are we living in the same universe? We manage a fleet of tablets (both Apple and Android) for a healthcare company whose EMR is web-based. And because of that Sarafi has made our lives miserable. So much so that we're migrating to Chromebooks.
I've been developing for the web for 15 years. The first half was spent battling Internet Explorer. Now it's Safari.
This is such a wild, absolute statement it's not even worth discussing this with you anymore.
Or simple things like supporting 100vh consistently. Is that estoric?
I didn't take WebUSB seriously until I steered someone to flashing a small firmware onto something and they could do it straight from the browser! And it was a nice workflow too, just a few button and a permission click.
Two other examples I can think of are flashing Via (keyboard) firmware and Poweramp using WebADB via WebUSB to make gaining certain permissions very easy for the layman. I imagine it's gonna get more and more user in enterprise too.
Firefox is seriously behind by refusing to implement it.
Consider the fact that Chromium has to specifically blacklist Yubikey and other known WebAuthn vendor IDs, otherwise any website could talk to your Yubikey pretending to be a browser and bypass your 2FA on third party domains.
I'm conflicted on WebUSB because it's convenient but on the balance I think it's too dangerous to expose to the general public. I don't know how it could be made safer without sacrificing its utility and convenience.
On top of that, straight from Yubico's site:
".. The user must approve access on a per website, per device basis .."
This isn't any more a security hole than people clicking "yes" on UAC prompts that try to install malware.
Of course, but a phishing website "fake-bank.com" could collect user's username, password, and then prompt them to touch their yubikey. This wouldn't trigger any alarm bells because it's part of the expected flow.
> This isn't any more a security hole than people clicking "yes" on UAC prompts that try to install malware.
Yes it is. The only reason why Yubikeys are immune to phishing and TOTP codes aren't is because a trusted component (the browser) accurately informs the security key about the website origin. When a phishing website at "fake-bank.com" is allowed to directly communicate with the security key there's nothing stopping it from requesting credentials for "bank.com"
You are right that it was a security hole in Chrome <67. Which is almost a decade in the past by now.
Now you have a crappy app that only works on some devices, and now with no tabs, no links, text you cannot select anymore because they used the wrong component, etc.
Ugh.
Recently on HN: https://www.bugsappleloves.com/
For values of “just work” close to 0.
Make a picture, connect with a Windows PC, iOS needs a password, then the picture is not visible to the PC, disconnect, go with Apple photos to look at the picture, repeat connecting, with password, now it is visible.
Try to set up a hotspot, there is no button to turn the hotspot on/off.
So yes, it “just works"
There is. You can even put it on the settings drawer. Look for "personal hotspot".
I don't have a mac anymore, but IIRC you could even turn it on from the paired mac. This definitely still works between iphones. When I take out my old iphone from the drawer to use as a GPS on my bike, with no sim card, it will connect to my regular iphone's hotspot automatically.
I’m confused, which button? Do Android phones come with a physical button to enable hotspot?