I am so tired of being treated like a drooling idiot "for my own good".
I am so tired of being treated like a drooling idiot "for my own good".
Do users understand that by clicking "allow" on a website, an attacker can re-flash their mouse with firmware which causes the mouse to present itself as some obscure USB device which activates a vulnerable driver? That by clicking "allow" on a pop-up from a website, the website can abuse their keyboard to install a key logger or botnet? Should a user be expected to understand this?
I don't know how valid this fear is in practice. Has anyone done a study?
An attacker could try to convince users to select something specific but that depends on the actual devices that are present and the "default" option to a confused non-technical person is to just cancel out of the list.