It looks like this vulnerability is limited to Chrome at the moment. Good to know if using Chrome (or even Epichrome for SSBs) when doing things like online banking.
Chrome lets hackers phish even 'Unphishable' Yubikey users
111–113 of 113 posts
Re: Chrome lets hackers phish even 'Unphishable' Yubikey users
#112Earlier quoted context omitted.
Not every link you click. Only sites that you grant access to the necessary attack surface. The Web USB API can't be attacked by sites that you haven't granted access to it.
What if that privileged website has XSS vulnerability?
What if your unsandboxed native USB utility has an RCE vulnerability?
Re: Chrome lets hackers phish even 'Unphishable' Yubikey users
#113Earlier quoted context omitted.
Nonsense. It works fine on Github, Fastmail, Gandi... it doesn't work on Google because Google uses a different spec. That bug is about making Firefox compatible with the variation that Chrome/Google uses.
That bug mentions that Facebook is also broken. I am kind of surprised that the sites you mention can implement the spec correctly but Facebook and Google can't.
In this case, though, what happened is that Google implemented a different, earlier version of the spec than most everyone else. Mozilla is busy implementing that spec as well to bridge the gap.