Chrome disable WebUSB and WebBluetooth

Watch out for Chrome's new WebUSB and WebBluetooth features: Programs and on the Web (browsers) use more and more APIs for more functions.

But this is not always good.

Two recent additions to Chrome, with the WebUSB and WebBluetooth APIs, allow sites to interact with devices connected to the computer running the browser.Chrome

This can be very useful, but sometimes the addition of new features has unpredictable consequences.

The WebUSB and WebBluetooth APIs, for example, leave security holes that allow highly sophisticated phishing attacks. These attacks could bypass authentication devices devices that use USB Ports, such as the Yubikey device.

Security researchers have recently shown that Chrome browser WebUSB functionality can also be used to communicate directly with two-factor authentication devices, not just the Google U2F API.

The attack bypasses any protection offered by two-factor identity devices.

Chrome prompts you when it encounters a page that is trying to use the WebUSB or WebBluetooth API. The user must allow the login request and type or paste the username and password of the account on the page he wants to log in.

Users should pay attention to the dialogues that appear and ask for permissions. Websites designed for attacks could provide assurances and prompts that the rights they request are necessary for better functionality of the external device.

So if you want to disable the two features from the Chrome you're using, you'll need to install the extensions Disable WebUSB and Disable WebBluetooth .

The two add-ons block APIs in the browser.

So if you don't use the WebUSB and WebBluetooth features, the above extensions are a temporary solution until Google fixes the security.

____________________________________

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.082 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).