Google-Supported Web Bluetooth And WebUSB APIs May Make The Internet Less Secure

In its efforts to extend the functionality of web apps, Google has been developing and supporting two new HTML APIs that may end up making the web less safe and compound on the existing security issues of the Internet of Things. The two new APIs are Web Bluetooth, which has already been enabled in the latest version of Chrome, as well as the WebUSB API.

Latest Videos FromTom's Hardware
Contributor

Lucian Armasu is a Contributing Writer for Tom's Hardware US. He covers software news and the issues surrounding privacy and security.

  • __thatguy__
    Yes, if you don't make something web connected it will be more secure than if it is web-connected. If I don't leave my house I'm less likely to be mugged. That doesn't mean I shouldn't leave my house.

    You are suggesting we stop progressing because of a challenge. Shame. Thats such backwards thinking. Implementing security protocols is indeed the correct way to approach this, IOT manufacturers are facing legal backlash and will likely make devices more secure moving forward.
    Reply
  • targetdrone
    It's all fun and games until the Cylons hack the life support systems via the Bluetooth enabled toilets then "flushes" everyone into space.
    Reply
  • bit_user
    19262803 said:
    You are suggesting we stop progressing because of a challenge. Shame. Thats such backwards thinking.
    I think the core point is that the same technological changes needed for Google to integrate with devices are the ones that expose them to hacking. It's not a small point.

    19262803 said:
    Implementing security protocols is indeed the correct way to approach this, IOT manufacturers are facing legal backlash and will likely make devices more secure moving forward.
    It's actually deeper than that. Because there's a "network effect" (https://en.wikipedia.org/wiki/Network_effect). That is to say that even if my device is securely connected to my smart phone, if either my smart phone or my cloud account get hacked, the hacker can still exploit and potentially hack the connected device, which can then potentially be used in further hacking. And even if the device isn't hacked, per se, it still gives a hacker with access to the phone/computer more ways to do damage or exploit the target.

    Security is hard - a lesson we keep learning over and over. This is a problem that really justifies some outside-the-box thinking, and it sounds like that's not happening.

    I think we can agree that it's a false dichotomy to say that the only way to remain secure is to keep devices disconnected.
    Reply