Re: [webauthn] Remove attestation specification from spec

The comment "The other stuff can go in a registry" reflects a 
misunderstanding of registries - per Jeff Hodges' comments on the 
list.  Normative content must be in a specification.  Registries 
simply contain references to those specifications.  So there's not an 
option to move normative content to a registry.  (We can move 
normative content to other specifications, should we choose to, but I 
think that would just make things harder for developers.)

Given that the SafetyNet attestation type will be widely used, if our 
description of it is presently inadequate, it would be my suggestion 
that we make it adequate, rather than deleting it.  Making things that
 WebAuthN developers will commonly use harder to find and use would do
 no favors to anyone.

-- 
GitHub Notification of comment by selfissued
Please view or discuss this issue at 
https://github.com/w3c/webauthn/issues/108#issuecomment-235984654 
using your GitHub account

Received on Thursday, 28 July 2016 18:33:40 UTC