I don't get this, what about malware pretending to be a browser? Is there a protection against this in protocol
If there's malware on your computer running as you, with access to things like USB devices, it becomes significantly harder (if not impossible) to do anything security critical on it.