Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's nice to be able to flash something without having to give some random software access to your computer, or having to build three different versions of a device flasher for each major OS. It's boosted adoption of ESPHome devices.


Except that you are giving some random software access to your computer, and it's not even software you can decided when to install and update.


I use Linux so I do have a great deal of control over the version of Chrome I occasionally use.


The software is downloaded from a web server.


I'm not sure what you're trying to say. My point is that it's sandboxed in the browser.


You gave that software access to your computer and you don't even control when it updates.


I get that you're trying to win the argument, but you're being opaque.

Any ESP device I have isn't even connected to the Internet so I do control when it updates.


But you just did give some random software access to your computer.


When did I do that? WebUSB gives a website access to a specific USB device, not my entire computer.


Access to a programmable USB device is access to your entire computer. They can program it to emulate a mouse and accept more permissions.


I don't see how WebUSB makes that risk worse. At least I avoid making it easy and running somebody's firmware updater on my computer.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: