Hacker News new | ask | show | jobs
by garethadams 4276 days ago
There's no reason it couldn't mean that anyway - if a device is open to the Internet then the URL it serves via Physical Web could easily be its own. But it allows for less-smart devices too.

The biggest problem I can see, as with all proximity devices, is spoofing. How do I know the item listed as "Bus Stop" is actually the bus stop, and not someone's malicious Raspberry Pi hidden in the bush next to it?

1 comments

>How do I know the item listed as "Bus Stop" is actually the bus stop, and not someone's malicious Raspberry Pi hidden in the bush next to it?

The same way you know that top search results are accurate for a given word/phrase. As stated multiple times throughout the introduction[1] the solution for filtering out spam will probably have an implementation similar to internet search engines.

[1]: https://github.com/google/physical-web/blob/master/documenta...

How do I know the top 100 items listed as "Bus Stop" aren't someone's malicious raspberry pi hidden in the bushes, spitting out hundreds of URLs and varying the signal strength so they appear to be coming from different locations and...wait a minute. I think my phone just got DOS'ed.
The addition/counter to the Physical Web proposal I have been discussing with Google prevents these kinds of security issues in many locations/places: meet Geo-Origins --> https://github.com/csuwildcat/geo-origins/blob/master/explai...
You will never stop DOSs. It's trivial (I imagine, can't think why it wouldn't be) to DOS someone's cell signal. Allowing users to see which items are "certified real" and not raspberry pis in bushes is an easy engineering problem we've solved in a number of different contexts.
That's a lot of money to DDOS people's phones at bus stops.
I don't think so. I think the proper analogy, that authors of the proposal have missed, is not search & spam, it's ATM and skimmers. How do you know you're not inserting card into a scanner?...

... well, everything proves that most likely, you have no clue.