You can configure and update your stuff anywhere where modern browsers can run, and have 0 spyware on your computer
You can configure and update your stuff anywhere where modern browsers can run, and have 0 spyware on your computer
Local software will always live longer and have more respect for my privacy than web based software.
I'm thinking about throwing AI at the problem and either working to make their site work offline, making standard QMK software work with my keyboard, or replacing the firmware with more standard QMK.
As far as I remember, QMK software was extremely annoying from my own perspective, and the Keychron team was also dissatisfied with them (there was something about them being slow to add their keyboards to the app). I can say that I was able to customize my keyboards only after they released their own app.
So huge chance that your problem is caused by QMK, not Keychron.
Regarding app, i'm sure it can be made portable, maybe even via turning it into single file html.
Some things could probably be pushed to the HID layer, but that would require a at least firmware redesign of the mouse, and some kinds of complex shortcuts are probably better done on the computer OS than that of the HID device, which is inevitably working with much less context.
Seems like that would add significant cost for something that can be done well without it.
For more details, go look up the Linux USB Gadget framework. You can even play around with some of it yourself using a Pi Zero 2 W (I did, making it appear to be a USB webcam - I saw guides on how to make it be a serial port and even an ethernet adapter too)
[1] similar to this IIRC: https://github.com/Jombolio/DuckyOneX-Linux
EDIT: turns out that my keychron, at least, is compatible with QMK/VIA and there are already open source alternatives [1] that do the job.
Desktop software is way less reliable than you think – I have a few Akai keyboards I can't configure because they don't work on my Mac already, not to mention how hard it was at least finding this executable for more than decade old keyboard.
It is also less transparent and more difficult to review than, e.g., a Python script. Which would do just the same job. While being even more portable.
> It is also less transparent and more difficult to review than, e.g., a Python script. Which would do just the same job. While being even more portable.
Are you absolutely sure you would catch any malicious payload in some obscure single-purpose Python script?
Open source is great, but it's not a complete replacement for a narrow permission model.
Of course not. But I can at least fairly easily review it. And that is the point.
A review cannot be done as easily with a minified JavaScript webpage or a WebAssembly binary that the WebUSB loader tool would use.
Also, with regards to binary Windows blobs that would require installing Windows drivers - yes, I agree that it is considerably worse than WebUSB. But we can always find something worse..
The point I am trying to make is that WebUSB, although being better than Windows binary blobs, is still less transparent, in my opinion, than e.g. a simple Python script.
Edit: To clarify: Whether the user will actually be able to find potential issues during the said review is a separate topic. But I think that the goal should be to enable users to do so. And make it as simple as possible and user-friendly as possible.
I especially prefer it when the alternative is often some random windows-only binary, probably requiring a driver to be installed at that.
Kinesis' keyboards with their "Clique" keyboard has a web-based configuration tool that does that. Their older "SmartSet" firmware instead exposed a virtual USB drive, with the configuration as a text file, and a firmware update could be done by dropping a new blob in there.