Skip to content

device serial number exposes a fixed, global ID #230

@pes10k

Description

@pes10k

The spec exposes (and seems to require) each device's serial number, which will be fixed and (likely) globally unique. Using a device through WebUSB then means that the user can be tracked both across site (any two sites can have access to the same usb device can link the user), across sessions (the same site can re-identify me when i return with the same USB device, even if ive cleared storage) and even across browsers.

It also seems unlikely that sites need the serial number in the vast majority of WebUSB use cases.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions