Re: [webauthn] Sign counter alg 507

I would make it -1 or any negative number, that way those that want to use the value to protect against differential power analasis in the future can, without blowing up verification. 

In any event -1=ffffffff is safer to use as a flag than 0.  If we use a valid value for the flag it will wind up always being a question or confusion for developers.


-- 
GitHub Notification of comment by ve7jtb
Please view or discuss this issue at https://github.com/w3c/webauthn/pull/539#issuecomment-328159077 using your GitHub account

Received on Friday, 8 September 2017 17:00:35 UTC