Re: [webauthn] Security threat: Username enumeration

Looks okay to me.  I added a sub-PR https://github.com/w3c/webauthn/pull/1058 to use the word "attacker" instead of "user" for the attack scenario.

-- 
GitHub Notification of comment by samuelweiler
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1014#issuecomment-418794281 using your GitHub account

Received on Wednesday, 5 September 2018 16:27:12 UTC