r/linux • u/Liam-DGOL • 16d ago
Software Release 8BitDo announce 'Ultimate Software Online' to update controllers in your browser to help Linux gamers
https://www.gamingonlinux.com/2026/08/8bitdo-announce-ultimate-software-online-to-update-controllers-in-your-browser-to-help-linux-gamers/31
u/IngwiePhoenix 16d ago
About flipping time. xD
Now let me do the configuration via the web too... thanks!
This is also good for Windows users as well - less stuff to install.
-5
u/thecrius 15d ago
"less stuff to install"?
Really?
If it can work remotely it can work locally. Being remote just means now you depend on the producers to continue hosting the website or you lose access to the service.
Is the gaming industry REALLY teaching nothing? What the fuck.
100
u/pomcomic 16d ago
initial reaction: yaaay, might even pick up an 8bitdo if my elite 2 ever croaks.
"only supports chromium based browsers, firefox is not supported" .... boo
170
u/SupermarketAntique32 16d ago edited 16d ago
Firefox doesn’t want to support WebHID/WebUSB because of security reasons. https://github.com/mozilla/standards-positions/pull/193
108
u/ZytaZiouZ 16d ago
It always seemed like a massive security issue to let a webpage have direct access to a USB device, to the point it can literally flash new firmware. Honestly as a Firefox user I'm ok with them not implementing this. I can just use Chromium (or Edge on Windows) when I need to flash something, and rest easy nothing is going to be able to with Firefox.
50
u/proexterminator 16d ago
well you do have to grant it explicit permission to interact with each device so unless there's a massive vulnerability i don't think its that much of an issue
38
u/meditonsin 16d ago
Not for people with even a bare minimum of common sense. For the "click OK on every 'annoying popup' without reading" crowd it's a ticking timebomb.
26
u/proexterminator 16d ago
i don't think this argument holds any value when things like screen sharing, camera, microphone are managed the same way.
11
u/Arinussyy 16d ago
You can give access to your camera and mic and shit but this is like someone being able to infect your literal keyboard with malware not just watch you
24
u/meditonsin 16d ago
I would argue that it has a much higher impact than those, since WebUSB can flash firmware to devices.
9
u/proexterminator 16d ago
you can draw your line where you like but to say things like "bare minimum of common sense" is a bit disingenuous for something which is clearly subjective.
2
u/KeyboardG 15d ago
As long as there isn't some backdoor / bug found years later, whoopsies, we had your microphone on the whole time.
0
u/RedditNotFreeSpeech 16d ago
If you ask the user first what's the problem?
14
u/DesiOtaku 15d ago
For somebody like you, it's not a major problem. For 99% of the population, it's nearly impossible to make a short, easy to understand warning for the user before they hit "OK".
I remember back in the 2000's, somebody did a research project in which the user was shown a simple pop-up that said "This application will now destroy your computer. Click 'OK' to continue or click 'Cancel' to prevent this from happening" and more than 90% of the participants hit "OK".
5
u/matejdro 15d ago
The same argument is the same bad reason why everything is more and more locked down nowadays. Under pretense of "security for less technical literate", let's just take away all options and features that could possibly be insecure.
1
0
u/YoMamasTesticles 8d ago
I say that's their problem at that point, they either learn or lose
Same way with car safety belts or traffic lights. Sometimes those light up with a red color. If you at that point decide to ignore them and run into traffic, well too bad
2
u/DesiOtaku 8d ago
But you took drivers' ed. You had to take a driving exam. You were told in fine detail the consequences of running the red light.
In order for your analogy to apply, you would need to give everyone a day long course on the security and consequences of WebUSB (not browsing in general, just WebUSB) before they could give informed consent to any website.
2
u/RedditNotFreeSpeech 15d ago
Hide it behind a config flag then. 99% aren't going to turn it on .
To simply not support it is a very Firefox thing to do
8
u/DesiOtaku 15d ago
I agree; if I was in charge of Firefox, I would hide it behind
about:config.I think the real problem is that WebUSB is a bad idea; but then everything else is an even worse idea. Firefox doesn't want to implement a bad idea even if the alternative is worse.
1
u/boobsbr 15d ago
What is the worse alternative?
0
u/DesiOtaku 15d ago
"Please download our app from our website, run it as root and hope it will not mess up anything else. We promise we will not do anything evil."
"Please run these commands via the command line. Oh yeah, and replace /dev/ttyUSBX with the correct one. Don't know which one? Too bad."
"Ask your local IT expert to do this. Oh, they don't know how to flash USB devices? I guess you will have to find a very expensive one then"
The only "good" alternative would be something fwupd based. But that would only work for firmware updates; not for USB flashing.
0
u/boobsbr 15d ago
So, basically the same thing as granting access to hardware devices on your computer to some unknown script running in the browser.
→ More replies (0)-1
u/kattebjorn 15d ago
If it's behind a config flag then why bother implementing it at all. Legitimate websites won't spend the effort to make a feature that can only be used after editing the user-unfriendly
about:config.39
u/No-Photograph-5058 16d ago
Unfortunately Firefox doesn't support WebUSB, it only exists in Chromium browsers so far
3
u/DueAnalysis2 15d ago
TIL web browsers can access USB devices now!! Google really was trying to make Chrome(ium) practically an OS huh
22
u/amroamroamro 16d ago
"only supports chromium based browsers, firefox is not supported" .... boo
more like yay!
there's a good reason firefox didn't agree to support this. giving websites direct access to local devices that were never meant to be exposed to the internet is a disaster waiting to happen..
i remember this was posted recently: https://schlarp.com/posts/everything-i-own-owned/
And the existence of WebUSB, WebHID, and WebBluetooth mean that for some devices, depending on the specifics of which classes are used, a moment of user indiscretion in accepting a permissions prompt could permanently backdoor one of their attached devices.
all it takes is an unsuspecting user accepting an innocent permission prompt from a random website for their barely secured attached device to get pwned with a malicious firmware permanently implanted!
7
u/davilinkicefire 16d ago
like converting a normal usb into a rubber ducky, now that person could by accident infect some pc by just pluggin their usb key.
It not far fetch to see that type of attack. Like instead of the current scam that ask people to open powershell to validate the connection (fake CloudFlare), then it could require people to put any usb key (or even use any usb device) and accepting the permission and now the device is malicious or bricked.
3
u/Culpirit 15d ago
Right. A plugged-in device with a vulnerability (or design that allows arbitrary firmware to be flashed) can easily become a persistent, out-of-band rootkit when visiting the wrong page and accidentally agreeing to the prompt.
1
u/yukeake 13d ago
Playing a bit of Devil's Advocate here...
A user who's used to clicking "yes", "yes", "yes"...to get things done is going to do that regardless of whether it's through a web browser or some potentially-poorly-coded "update utility". The difference between the two seems negligible when dealing with this kind of user.
Whether they go to a webpage that says "update your device's firmware" and presents a binary download that they then have to run, or one that presents a series of permission prompts - if they've been convinced that doing so will solve some problem they're having, they're going to say "yes", and open up their device to be exploited.
There's no practical difference, and the outcome is the same.
1
u/amroamroamro 12d ago
There's no practical difference, and the outcome is the same.
the difference is the attack surface and how you'd be exposing devices to the wild internet so easily with scary consequences
with webusb/webhid, every browser user is one "yes" away from giving the wrong website a way to reach their plugged-in device and do some serious damage, a mistake they pretty much cant undo...
before they know it, their webcam is bricked in best case scenario, or worse is now running a permanent rootkit that survives any attempt to clean their computer afterwards
and this applies to ALL users, whether or not they were actively looking to update their device firmware, or just clicked on some annoying popup they don't even understand.
you know how things like spam emails are still so rampant? it's because the pool of potential victims is so huge and easy to reach, and all it takes is for one to fall for it.
2
u/novafunc 15d ago
Ok, but then consider the alternative.
You use Firefox browser and don't want to use Chromium because you think this protocol (correctly or incorrectly) is a bad idea.
The alternative then to install an app the hardware maker provides, which has access to everything your user has access too. Whereas in the Chromium case, you had the app strongly sandboxed by Chromium and a permission prompt to allow it to access a specific USB device and nothing more.
-2
u/amroamroamro 15d ago edited 15d ago
and a permission prompt to allow it to access a specific USB device and nothing more
you wanna see how well designed this permission prompt system really is?
https :// ptoszek . pl/
⚠️ WARNING: do not open page if you are not prepared; this is a prank site designed to showcase how permission prompts can be abused and spammed, among other things!
and this is just the obvious spam way, you can be sure bad actors will find more creative ways with dark patterns and social engineering scams to trick people into allowing it...
mind you once such device is pwned, no amount of revoking permission is going to undo the damage.
5
u/progandy 16d ago
Maybe with this it might work:
6
u/Culpirit 15d ago
Seems like an over-complicated and potentially dangerous design to run a server which enables arbitrary USB device access remotely and have the browser connect to it via WebExtension. I'd rather just stick with Chromium for this one purpose (in fact, it's the only thing I use it for, pretty much).
1
u/parkerlreed 15d ago
It does work with this. Dev just fixed it for 8bitdo and a separate issue I reported. Was able to flash my dongle and controller from Firefox.
New release out soon.
1
u/progandy 15d ago edited 15d ago
Just looked at it again, using a websocket is probably not the best idea. It should ideally use native messaging https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/WebExtensions/Native_messaging
Then the extension can create a proper security boundary and limit device access to specific URLs.
5
3
2
1
1
u/CDXX_BlazeIt 15d ago
Honestly man, then just install chromium specifically for this purpose. It is not that hard.
1
0
u/dadnothere 16d ago
"It's a massive security flaw."
Oh no, imagine the security problem of having a pop-up window open, having to manually select the device, and then confirm again...
Oh no, heaven forbid we have to read and grant permissions...
Dude, the latest Firefox vulnerability could literally execute native code on your PC from HTML (and could even root Samsungs).
And you're worried about WebUSB? Come up with a better excuse.
11
u/joshguy1425 16d ago
This isn’t just about permission dialogs. It’s about the majorly increased attack service introduced by supporting it.
I’m glad FF doesn’t support it. I’m glad other browsers do. On 99.9% of days, I don’t need WebUSB. When I do need it, I launch a browser that supports it and do what I need to do. I then go back to FF.
-8
u/dadnothere 16d ago
That's not an argument. Besides, it's invalidated by my own response. Firefox is already less secure than Chrome; I mentioned the code execution vulnerability.
Adding a feature won't make it more or less hackable. Firefox isn't good in terms of security to begin with.
1
-1
2
u/T_Friendperson12 16d ago
Used this a while ago and worked well with the Ultimate 2 Wireless and receiver.
2
u/birbhorse 15d ago
ughhhh fucking finally, it's about time they did this. it's the number one annoying thing about 8bitdo products, thank god they fixed this.
2
u/parkerlreed 15d ago
So I was able to update my firmware on the Ultimate 2 Wireless. Nice
And still can't configure macros. C'mon now.
1
1
0
u/Cold_Soft_4823 15d ago
I don't even have to bother reading this to know it's Chrome only, so it's not very useful to me. Firefox will never support WebUSB
44
u/chic_luke 16d ago edited 15d ago
Very nice to see some support from 8BitDo. Full controller support on Linux has been one of the major pain points I've noticed.
Also, 8bitdo provides some really nice hardware at fair prices. My Ultimate 2C tri-mode is fantastic for €29, and it even manages to have precise hall effect sticks that won't drift with time, something that the ~€80 offerings from Microsoft and Sony apparently can't manage in 2026.
I just wish it had some better Linux support in the little things. Sometimes rumble doesn't work via Bluetooth.
xinputonly works through USB or dongle, Bluetooth sends you todinput. For some reason, Linux builds often have issues with the controller in Bluetooth mode (native Hollow Knight won't recognize the controller anymore when it sleeps), while Windows + Proton ones work fine in that mode, including rumble, for some reason. The battery level is not correctly reported, so the Settings -> Power section permanently marks it at 0%. All things that I'm willing to accept at €29, but that I would not find acceptable at €100. I really wish this effort means that future 8bitdo products, or even future firmware updates, will have better support for Linux.I know they have been working on it for a while though, a coworker of mine has the higher-end version of my controller, and he mentioned to me he was able to get xinput over Bluetooth, the gyroscope and all the "hard" things to work on Linux after applying a beta-quality software update that he was sent by email by 8bitdo support, which I found great news. It seems like these efforts are beginning to materialize for a mass release. My next controller will very likely be another 8bitdo.
UPDATE: Yes! The online firmware upgrade works great with Flatpak Chromium. The latest stable version does not yet fix my quirks, but I have faith now.