Open
Description
The spec exposes (and seems to require) each device's serial number, which will be fixed and (likely) globally unique. Using a device through WebUSB then means that the user can be tracked both across site (any two sites can have access to the same usb device can link the user), across sessions (the same site can re-identify me when i return with the same USB device, even if ive cleared storage) and even across browsers.
It also seems unlikely that sites need the serial number in the vast majority of WebUSB use cases.
Metadata
Metadata
Assignees
Labels
No labels