News: 1612202047

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Chrome 89 beta: Google presses on with 'advanced hardware interactions' that Mozilla, Apple see as harmful

(2021/02/01)


Google has released a beta of Chrome 89, adding further hardware interaction APIs even though Mozilla and Apple consider many of these features harmful, as well as introducing a desktop-sharing API for Windows and Chrome OS.

New features in Chrome 89 to interact with hardware begin with the WebHID (Human Interface Devices) API, which lets developers write JavaScript to communicate with devices such as gamepads or keyboards using device-specific logic, rather than relying on the devices to implement standard APIs like the [1]Gamepad API .

[2]

"The inability to access uncommon or unusual HID devices is particularly painful, for example, when it comes to gamepad support. Gamepad inputs and outputs are not well standardized and web browsers often require custom logic for specific devices. This is unsustainable and results in poor support for the long tail of older and uncommon devices," [3]said Google's Chromium team.

[4]

The new web sharing dialog on Windows. The detail will vary depending on which applications have registered with the operating system

[5]

Chrome 89 also supports Web NFC (Near Field Communications), meaning that web applications can read and write NFC tags. Applications include things like scanning badges at events, provisioning services, or directing users to additional content.

Another new feature is the Web Serial API, which enables direct communication between web applications and devices with serial ports. This is in addition to the [6]WebUSB API, which has been supported since [7]Chrome 61 – but is not supported in Firefox or Safari for security and privacy reasons. More on this below.

Web-sharing APIs already implemented for Chrome on Android (since Chrome 75) have now been added on Windows and Chrome OS. The idea is to replace the little buttons optimistic websites display for sharing content to Twitter, Facebook, and the like, with a single Share button that calls the operating system's sharing feature.

The feature also allows sharing files such as picture or plain text documents (the range of file extensions supported is [8]limited ). Firefox does not support web sharing, but it is in Microsoft Edge (81 and higher) and Safari (12.1 and higher on macOS, 12.2 on iOS).

Native support for decoding AVIF images has been added to Chrome on Android (it was already in desktop Chrome). There are also some CSS tweaks. The V8 JavaScript engine is updated to 8.9 and now has [9]top-level await , which improves the process for importing JavaScript modules.

[10]

Mozilla states its position on 'harmful' APIs such as WebUSB – but users may just think Firefox is broken

Enhanced device support in Chrome further closes the gap between web and native applications but also increases the potential attack surface. Mozilla's [11]current standards position on the WebUSB API, for example, is that it is harmful.

To that end, it has said that "because many USB devices are not designed to handle potentially malicious interactions over the USB protocols and because those devices can have significant effects on the computer they're connected to, we believe that the security risks of exposing USB devices to the Web are too broad to risk exposing users to them or to explain properly to end users to obtain meaningful informed consent."

Other APIs considered harmful by Mozilla include the Serial API and Web NFC.

The difficulty is that when users find features supported by Chrome that do not work in Mozilla's Firefox they may simply regard Firefox as broken and it becomes another factor in Chrome’s dominance. See for example [12]this GitHub issue on WebADB, an application which lets you access the Android debug API from a browser. It is hard to communicate to users that a feature may be missing for their protection.

[13]

Apple's WebKit team is also [14]opposed to many of these APIs, including Web NFC, Web HID, Serial API and WebUSB, "due to fingerprinting, security, and other concerns". ®

Get our [15]Tech Resources



[1] https://developer.mozilla.org/en-US/docs/Web/API/Gamepad_API/Using_the_Gamepad_API

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YBiIAl3wJOx4u7CN7D4FVAAAAI8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://blog.chromium.org/2021/01/chrome-89-beta-advanced-hardware.html

[4] https://regmedia.co.uk/2021/02/01/sharing.jpg

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YBiIAl3wJOx4u7CN7D4FVAAAAI8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://developer.mozilla.org/en-US/docs/Web/API/USB

[7] https://www.theregister.com/2017/09/07/chrome_61/

[8] https://docs.google.com/document/d/1tKPkHA5nnJtmh2TgqWmGSREUzXgMUFDL6yMdVZHqUsg/

[9] https://www.chromestatus.com/feature/5767881411264512

[10] https://regmedia.co.uk/2021/02/01/harmful.png

[11] https://mozilla.github.io/standards-positions/#webusb

[12] https://github.com/webcompat/web-bugs/issues/62926

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YBiIAl3wJOx4u7CN7D4FVAAAAI8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[14] https://webkit.org/tracking-prevention/#anti-fingerprinting

[15] https://whitepapers.theregister.com/

Good on 'em

Chris Gray 1

I for one will continue to support Mozilla and Firefox in this.

The web, as Google sees it, is intended to be unsafe (from the user's point of view) and to provide Google with the maximum access to user information and the user's hardware. That's how they make most of their money, after all.

Re: Good on 'em

RegGuy1

Defo. Chrome is shit. I didn't realise this until I used it to log into gmail. I found they were logging me into everywhere. Fuck off. I choose when I log in. And worse, by being logged in it became MUCH easier to buy stuff.

Tha's why I like to be logged OUT of Amazon and elsewhere. I decide when I log in.

Chrome is just a tool to collect data. And ChromeOS, poo, poo, poo.

Just poo.

Re: Good on 'em

overunder

Need a $GME like event for browsers.

#NoMoreGoo

Re: Good on 'em

Aitor 1

What they want is a full OS like env with WASM, so essentially they could deploy full apps everywhere, as all devices have the same target.

Oh, and essentially they want random ppl executing binaries that can access credit cards, etc. What could go wrong.. as if this hadnt been tried before.

emacs

theOtherJT

They really need to stop trying to turn their web-browser into an operating system. I already have one of those.

Re: emacs

David 132

Only a matter of time ‘til Chrome implements SystemD.

Or will it be the other way round?

Just wait...

IGotOut

...until Apple remove it from the store on privacy grounds

Watch a rapid change of mind by Google.

Looking at the

Boris the Cockroach

RS232 bit , I'm thinking "eeeeeeeeeeeeeek Stuxnet made easy"

"a single Share button that calls the operating system's sharing feature"

Pascal Monett

What ? They've pushed that bull to the OS level ?

Today's operating systems are turning into everything-and-the-kitchen-sink levels of madness.

Looking forward to the day where I can have a toaster service to command my IoT toaster and set the darkness on the bread. Not.

Re: "a single Share button that calls the operating system's sharing feature"

ecofeco

"Are you sure you don't want some nice toast?"

...regard Firefox as broken...

Ken Hagan

...right up to the day of the first exploit against these APIs and the "discovery" that only Chrome is affected.

The opposite of MS

Jamie Jones

MS were accused of absorbing the browser into the OS.

Google are absorbing the OS into the browser.

Stop it. The web browser is meant to be used to access websites, not be some great big security threat with access to everything.

When the only tool you have is a hammer....

And it's crap. Witness chromeOS. The only thing worthwhile on that is the Linux subsytem, and the android compatibility. Why did you add android capability, Google? So we could run an android BROWSER, or so we could run APPLICATIONS?

I have some intensive android-only stuff (don't ask!) and fed up with the slowness of the converted android-TV box to android-desktop box ( [1]http://www.welshgit.net/photos/computers/desktop/android/ ), bought the most expensive Chromebox I could find.... It doesn't get used much.. The android parts run brilliantly fast, but the chromeos shite keeps getting in the way.

Also, my mum's eyesight is very bad - she's legally blind. She tries to use a chromebook tablet because it's meant to have good accedsability features... So why do they insist that on a tablet that will never leave her house, she HAS to enter either a login password or PIN on startup?

Why does it force start chrome everytime, despite the fact she's using android applications?

Why can't the colour of the lower bar be changed so she can see it clearly? It's black - clashes with the color of the tablets case.

Why, when you change the default "screen size" (fonts, image scaling etc) does the setting go back to default after reboot?

As for Chrome, I had problems for a while debugging intermitently failing sessions on a site.... Turns out some of the links on the site (not mine) were linked to www.site.com and others to just site.com -- the session cookie was set for the exact domain only, and bloody chrome now doesn't show the "www" part of the address, so the 2 sites were reported as the same one... WTF?

Also for chrome, I continually manually edit URLs in the URL bar. Now, every bloody time, you have to hit an extra "edit" icon to do the same.

Youtube?? The recomendations page is now full of shite, and "stories" and a sorta crude tik-tok section. Oh, and the changes made to the "drag video position" bar are so brain dead, they have to be taking the piss.. Apparently it was because "people kept accidentally seeking to the end of the video when they wanted to actually hit "fullscreen". Yes, that was another bozo design cockup. The solution anyone normal would have done would have been to reduce the size of the seek-bar, so the fullscreen button is to the right of it, at a suitable distance, but no.. can't be logical, can we?

And don't get me started on the number of scam videos youtube seems to not care showing.... Most generally have something like "the government wants to ban this", or similar, and then go on to make up more false claims about some gadget they see for 10times what you can get elsewhere.

Phew, sorry, got into a bit of a rant there!

[1] http://www.welshgit.net/photos/computers/desktop/android/

Re: The opposite of MS

dajames

... why do they insist that on a tablet that will never leave her house, she HAS to enter either a login password or PIN on startup?

The password on a Chromebook isn't a password for the Chromebook, it's a password for the Google account that the Chromebook is using. Without a password anyone could access that account from anywhere on any device.

RE : Stop it. The web browser is meant to be used to access websites

Howard Sway

No, the Chrome web browser is meant to be used by websites to access you.

We are very nervous about the release of Windows 2000. This OS takes up
gigabytes of hard drive space. When users 'upgrade' to Win2K, they won't have
any space on their hard drive for our products! We really hate Chairman Bill.

-- An anonymous spokesperson for Corel