It is also less transparent and more difficult to review than, e.g., a Python script. Which would do just the same job. While being even more portable.
It is also less transparent and more difficult to review than, e.g., a Python script. Which would do just the same job. While being even more portable.
> It is also less transparent and more difficult to review than, e.g., a Python script. Which would do just the same job. While being even more portable.
Are you absolutely sure you would catch any malicious payload in some obscure single-purpose Python script?
Open source is great, but it's not a complete replacement for a narrow permission model.
I especially prefer it when the alternative is often some random windows-only binary, probably requiring a driver to be installed at that.
Of course not. But I can at least fairly easily review it. And that is the point.
A review cannot be done as easily with a minified JavaScript webpage or a WebAssembly binary that the WebUSB loader tool would use.
Also, with regards to binary Windows blobs that would require installing Windows drivers - yes, I agree that it is considerably worse than WebUSB. But we can always find something worse..
The point I am trying to make is that WebUSB, although being better than Windows binary blobs, is still less transparent, in my opinion, than e.g. a simple Python script.
Edit: To clarify: Whether the user will actually be able to find potential issues during the said review is a separate topic. But I think that the goal should be to enable users to do so. And make it as simple as possible and user-friendly as possible.
Kinesis' keyboards with their "Clique" keyboard has a web-based configuration tool that does that. Their older "SmartSet" firmware instead exposed a virtual USB drive, with the configuration as a text file, and a firmware update could be done by dropping a new blob in there.