Re: [web-nfc] YubiKey NDEF analysis (#543)

I'm not intimately familiar with the current state of the spec or the NFC driver exposed information, which is why I'm curious: is there a way for the browser (not the website, as that would be a fingerprinting risk) to know what device it is currently communicating with? Something akin to VID/PIDs of USB or similar, that would identify the vendor/device make.

I could imagine that certain implementations could choose to harden this particular feature/use case by showing an extra warning or a different permission dialog for accessing security-sensitive information (in particular, accessing devices known to expose OTP-s and passwords via the NDEF interface).

-- 
GitHub Notification of comment by flaki
Please view or discuss this issue at https://github.com/w3c/web-nfc/issues/543#issuecomment-596621907 using your GitHub account

Received on Monday, 9 March 2020 16:06:47 UTC