Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This doesn't really fix the problem though. If WebUSB exists in peoples' browsers, and if a game on a web page asks to connect to your joystick, or some other peripheral, people are going to do it anyway, regardless of the risks. And plenty of USB devices already exist that will never be maintained by their manufacturers again. There are huge quantities of USB devices in existence where software support is completely limited to the driver CD that comes in the box - those manufacturers don't care about adding their devices to a public registry, or controlling how firmware is updated.

Furthermore, this public registry idea also implies that a USB VID/PID directly correlates with a device. There are USB devices in existence that emulate another USB device in order to utilize built-in drivers (inbox drivers) and maintain compatibility with existing software. There are also different USB devices that use the same VID/PID to identify themselves, because in order to obtain a VID/PID, you have to pay a licensing fee, which is not always feasible to everyone. If this public registry is used, it may create conflicts. If the CORS-like public registry entries are always trusted by the browser, it could even create security concerns where remote computers are allowed to seize control of local USB devices.

It would certainly be concerning if USB devices were firmware updated without users' consent, simply by going to the website of the manufacturer. Or even a web advertisement that connects to USB devices...

In the future we may even see some kind of attack on web servers in order to gain access to the USB devices of unsuspecting users...



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: