Hacker News new | past | comments | ask | show | jobs | submit login

so if I understood it right, Firefox is vulnerable to the problem they wanted to avoid but without giving us WebUSB?



No, because the device they are accessing needs to be specifically built for this use case. So you would need to give the user a malicious device then use a malicious webpage. The attack scenario isn't impossible, but is far less then those that are possible with WebUSB.


While not impossible, I just can't think of a good reason why you'd need them to access a malicious webpage when you've already gotten them to install a malicious device.


No, USB is vulnerable to malicious devices.




Consider applying for YC's Summer 2025 batch! Applications are open till May 13

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: