Re: [webauthn] Remove attestation specification from spec

There's a reason that the contributed FIDO specs contained 
descriptions of the attestation formats that they did - because 
they're practically needed by implementers for things to work 
end-to-end.  For instance, I know that when I tried to read the actual
 TPM specs they were essentially incomprehensible.  We need to keep 
our summary of it to help developers using WebCrypto.  Likewise, the 
Android assertions will be commonly used, so it's a help to developers
 to keep a description of them.  We should take deleting this useful 
text off of the table.

Yes, we could move these descriptions into a different spec, but that 
only would make it harder for developers to understand end-to-end what
 they need to know to build systems using WebAuthN.  Therefore, I 
believe that we should leave things as they are.

-- 
GitHub Notification of comment by selfissued
Please view or discuss this issue at 
https://github.com/w3c/webauthn/issues/108#issuecomment-235977239 
using your GitHub account

Received on Thursday, 28 July 2016 18:08:00 UTC