Chrome 61 to Include WebUSB
- 
 @scottalanmiller said in Chrome 61 to Include WebUSB: Why are you okay with legacy apps doing this but not modern ones? I don't follow any logic here. If you are okay with apps accessing USB, then you are okay with it. If you aren't, why are they there? Let's pick a legacy app, say... Office 2003. If I need to save new data, it pops up and asks me where do I want to save it? I'm okay with his because I know where I am telling the system to save the data. If I am modifying a file, I make my changes and hit save, that's okay too, because I am the one that opened the file to start with. I get to pick where my data is saved. 
 The same for a "modern" application, such as Office 2016. It is fine, it is expected.If www.samsitwebsite.nettries to access my USB Devic, I should get some kind of alert or warning (like a save dialog box or something)We all know that no website (or API) has been hacked or tricked into doing something it wasn't supposed to do. 
- 
 @dafyre said in Chrome 61 to Include WebUSB: Let's pick a legacy app, say... Office 2003. If I need to save new data, it pops up and asks me where do I want to save it? I'm okay with his because I know where I am telling the system to save the data. And if Office 2003 is written in JavaScript and run in a browser, you'd stop being okay with this same chain of events? 
- 
 @scottalanmiller said in Chrome 61 to Include WebUSB: If you are okay with apps accessing USB, then you are okay with it. If you aren't, why are they there? The way this WebUSB description is written makes it sound like it's not going to just provide access to a USB device to any web site that makes use of the API without any kind of warning or dialog box or anything telling me that the USB device is being used. 
- 
 @dafyre said in Chrome 61 to Include WebUSB: The same for a "modern" application, such as Office 2016. It is fine, it is expected. Office 2016 is not fully modernized yet and is still run in a legacy mode with legacy helpers like I described. Why are you okay if they use legacy code to do this but not if modern code does the same task? Why do you care about the code type, rather than the results. 
- 
 @scottalanmiller said in Chrome 61 to Include WebUSB: @dafyre said in Chrome 61 to Include WebUSB: Let's pick a legacy app, say... Office 2003. If I need to save new data, it pops up and asks me where do I want to save it? I'm okay with his because I know where I am telling the system to save the data. And if Office 2003 is written in JavaScript and run in a browser, you'd stop being okay with this same chain of events? Absolutely . Because I get a popup about where the data is going. (See my latest comment) 
- 
 @dafyre said in Chrome 61 to Include WebUSB: We all know that no website (or API) has been hacked or tricked into doing something it wasn't supposed to do. What does this have to do with the price of eggs? We are talking about app capabilities. All apps, modern or legacy can be hacked just the same. 
- 
 @dafyre said in Chrome 61 to Include WebUSB: @scottalanmiller said in Chrome 61 to Include WebUSB: @dafyre said in Chrome 61 to Include WebUSB: Let's pick a legacy app, say... Office 2003. If I need to save new data, it pops up and asks me where do I want to save it? I'm okay with his because I know where I am telling the system to save the data. And if Office 2003 is written in JavaScript and run in a browser, you'd stop being okay with this same chain of events? Absolutely . Because I get a popup about where the data is going. (See my latest comment) And you think this is different? Why? 
- 
 @dafyre said in Chrome 61 to Include WebUSB: @scottalanmiller said in Chrome 61 to Include WebUSB: If you are okay with apps accessing USB, then you are okay with it. If you aren't, why are they there? The way this WebUSB description is written makes it sound like it's not going to just provide access to a USB device to any web site that makes use of the API without any kind of warning or dialog box or anything telling me that the USB device is being used. Same as with legacy apps. Office 2003 could always do this and did. Just because you feel that it always asked you for permission, it didn't. That's a false impression. 
- 
 @scottalanmiller said in Chrome 61 to Include WebUSB: @dafyre said in Chrome 61 to Include WebUSB: @scottalanmiller said in Chrome 61 to Include WebUSB: @dafyre said in Chrome 61 to Include WebUSB: Let's pick a legacy app, say... Office 2003. If I need to save new data, it pops up and asks me where do I want to save it? I'm okay with his because I know where I am telling the system to save the data. And if Office 2003 is written in JavaScript and run in a browser, you'd stop being okay with this same chain of events? Absolutely . Because I get a popup about where the data is going. (See my latest comment) And you think this is different? Why? With any application that is going to access my device, I get some kind of indicator (File Save Dialog, or a progress window, you get the idea). I'm perfectly fine with this as long as there is such an indicator (I see no mention of any type of indicator for this). 
- 
 @dafyre said in Chrome 61 to Include WebUSB: @scottalanmiller said in Chrome 61 to Include WebUSB: @dafyre said in Chrome 61 to Include WebUSB: Let's pick a legacy app, say... Office 2003. If I need to save new data, it pops up and asks me where do I want to save it? I'm okay with his because I know where I am telling the system to save the data. And if Office 2003 is written in JavaScript and run in a browser, you'd stop being okay with this same chain of events? Absolutely . Because I get a popup about where the data is going. (See my latest comment) Just like how it is described in the WebUSB papers? https://developers.google.com/web/updates/2016/03/access-usb-devices-on-the-web 
- 
 @dafyre said in Chrome 61 to Include WebUSB: @scottalanmiller said in Chrome 61 to Include WebUSB: @dafyre said in Chrome 61 to Include WebUSB: @scottalanmiller said in Chrome 61 to Include WebUSB: @dafyre said in Chrome 61 to Include WebUSB: Let's pick a legacy app, say... Office 2003. If I need to save new data, it pops up and asks me where do I want to save it? I'm okay with his because I know where I am telling the system to save the data. And if Office 2003 is written in JavaScript and run in a browser, you'd stop being okay with this same chain of events? Absolutely . Because I get a popup about where the data is going. (See my latest comment) And you think this is different? Why? With any application that is going to access my device, I get some kind of indicator (File Save Dialog, or a progress window, you get the idea). I'm perfectly fine with this as long as there is such an indicator (I see no mention of any type of indicator for this). No, you don't. Some choose to do this, it is 100% voluntary by the app. There is no enforcement of this, unlike WebUSB. So, in reality, WebUSB is the only one you'd be okay with and what you've had all along is actually what is violating your usage rules, you just haven't been aware because most apps either hide this from you or behave. 
- 
 @scottalanmiller said in Chrome 61 to Include WebUSB: @dafyre said in Chrome 61 to Include WebUSB: @scottalanmiller said in Chrome 61 to Include WebUSB: @dafyre said in Chrome 61 to Include WebUSB: Let's pick a legacy app, say... Office 2003. If I need to save new data, it pops up and asks me where do I want to save it? I'm okay with his because I know where I am telling the system to save the data. And if Office 2003 is written in JavaScript and run in a browser, you'd stop being okay with this same chain of events? Absolutely . Because I get a popup about where the data is going. (See my latest comment) Just like how it is described in the WebUSB papers? https://developers.google.com/web/updates/2016/03/access-usb-devices-on-the-web If you knew about this site, that could have avoided three whole pages of back and forth, lol. Thank you. 
- 
 Here is how it works... - Legacy Apps run on the OS and have USB access, period. They are not gated from access and can do anything that they want.
- Modern Apps using WebUSB need to pop up to ask permission for access.
 All apps need peripheral access to work fully. Really, the two should be treated equally. But given deficiencies in legacy apps around security, WebUSB addresses that. 
- 
 @dafyre said in Chrome 61 to Include WebUSB: @scottalanmiller said in Chrome 61 to Include WebUSB: @dafyre said in Chrome 61 to Include WebUSB: @scottalanmiller said in Chrome 61 to Include WebUSB: @dafyre said in Chrome 61 to Include WebUSB: Let's pick a legacy app, say... Office 2003. If I need to save new data, it pops up and asks me where do I want to save it? I'm okay with his because I know where I am telling the system to save the data. And if Office 2003 is written in JavaScript and run in a browser, you'd stop being okay with this same chain of events? Absolutely . Because I get a popup about where the data is going. (See my latest comment) Just like how it is described in the WebUSB papers? https://developers.google.com/web/updates/2016/03/access-usb-devices-on-the-web If you knew about this site, that could have avoided three whole pages of back and forth, lol. Thank you. I didn't, but it was obvious that it had to exist. You have to admit, thinking that all web sites suddenly had peripheral access without any security, totally different than anything that web protocols have ever done, was not even remotely in the realm of reason to assume, even if some paper made it sound that way. I posted that the moment that I found it. But it is just what you had to know going in. Also, much of this discussion is other things... like explaining why apps would use USB, how USB has no function if apps can't use it and how legacy apps have not had the imagined security in the past. 
- 
 Example to test USB access... add a USB sound card, there is no pop up or notification but "all" apps with sound get instant access to it. Same thing with a USB hard drive. No pop ups, but apps have access without the user knowing. In fact, it is common for apps to use peripherals and unless that peripheral does something to alert the end user, the end user would never know that they were being accessed. You can print, look at web cams, play music, listen to microphones, access filesystems, all without telling the user anything at all, ever. Good apps rarely do this, but even good ones do sometimes because people expect these things to work. None of my USB devices ... keyboard, mouse, headphones, printer, webcam, microphone... have any user interaction for use. Not a one of them today. 
- 
 In my example of our application from 1999... this is how we were able to make it work. We built our own WebUSB equivalent and because we did it using VB6 originally (and later C#, we aren't proud of the VB stuff) we were able to access the USB and RS232 without the users knowing. There is no user interaction at all for our app that has been doing this since NT4 and has worked the same on every Windows version since. With WebUSB, we can simplify the process a lot, but it will get complicated in that for the first time ever, there will be USB security to deal with for the end users. 
- 
 @dafyre said in Chrome 61 to Include WebUSB: @scottalanmiller said in Chrome 61 to Include WebUSB: @dafyre said in Chrome 61 to Include WebUSB: @scottalanmiller said in Chrome 61 to Include WebUSB: @dafyre said in Chrome 61 to Include WebUSB: Let's pick a legacy app, say... Office 2003. If I need to save new data, it pops up and asks me where do I want to save it? I'm okay with his because I know where I am telling the system to save the data. And if Office 2003 is written in JavaScript and run in a browser, you'd stop being okay with this same chain of events? Absolutely . Because I get a popup about where the data is going. (See my latest comment) And you think this is different? Why? With any application that is going to access my device, I get some kind of indicator (File Save Dialog, or a progress window, you get the idea). I'm perfectly fine with this as long as there is such an indicator (I see no mention of any type of indicator for this). No, you are totallywrong here . Apps access your devices al, the time without telling you a damned thing. 
- 
 Another Setting to end up here probably: 
  
- 
 @stuartjordan said in Chrome 61 to Include WebUSB: Another Setting to end up here probably: 
  another setting to disable on my network..... 
- 
 @scottalanmiller said in Chrome 61 to Include WebUSB: Example to test USB access... add a USB sound card, there is no pop up or notification but "all" apps with sound get instant access to it. Same thing with a USB hard drive. No pop ups, but apps have access without the user knowing. In fact, it is common for apps to use peripherals and unless that peripheral does something to alert the end user, the end user would never know that they were being accessed. You can print, look at web cams, play music, listen to microphones, access filesystems, all without telling the user anything at all, ever. Good apps rarely do this, but even good ones do sometimes because people expect these things to work. None of my USB devices ... keyboard, mouse, headphones, printer, webcam, microphone... have any user interaction for use. Not a one of them today. All of these things work through system APIs, the main one I'm personally concerned about (but apparently the webUSB will prompt) is storage, and also the camera/microphone. The applications probably in general don't know they are working with USB, they only know they are working with a sound card. The system handles the interface to USB, but the sound APIs handle the access for the application. Obvious exclusions would be something like iTunes. It knows about the hardware directly. The camera software would be the same. 





