public-webauthn@w3.org from September 2018 by subject

09/05/2018 W3C Web Authentication WG Meeting Agenda

09/12/2018 W3C Web Authentication WG Meeting Agenda

09/19/2018 W3C Web Authentication WG Meeting Agenda

[EXTERNAL] Re: Call for Consensus - Web Authentication specification

[w3c/webauthn]

[w3c/webauthn] 02daac: Built by Travis-CI: 9d497577d8fdc272c626efc2583628...

[w3c/webauthn] 0686f5: Reword the Note: in User Handle a bit

[w3c/webauthn] 07ca17: Built by Travis-CI: db351cdea0e4e3efb9adb9b35c1ff1...

[w3c/webauthn] 09a81c: Fix typo

[w3c/webauthn] 0b217c: Built by Travis-CI: 398016e36c8a3a925be918ca3807d2...

[w3c/webauthn] 0ff9ee: Built by Travis-CI: 802613e829023466784acad62c4633...

[w3c/webauthn] 1679de: Issue #294 - Add a non-normative comment about sna...

[w3c/webauthn] 16c4c1: Built by Travis-CI: 5bdcae469479554be47a368cb22adb...

[w3c/webauthn] 175d9f: Clarify user identification in RP assertion verifi...

[w3c/webauthn] 19e76a: update token binding citation

[w3c/webauthn] 1aedd4: Built by Travis-CI: db351cdea0e4e3efb9adb9b35c1ff1...

[w3c/webauthn] 2056fe: Code of Conduct

[w3c/webauthn] 24d91f: Built by Travis-CI: 661a8575fb3156134d64ecdc56208d...

[w3c/webauthn] 28f321: fix: defelopers -> developers (#1067)

[w3c/webauthn] 29bbee: Un-revert change from 8e5f2e0 reverted in daf9522 ...

[w3c/webauthn] 2af689: Fix #1076 - Don't confuse extension optionality in...

[w3c/webauthn] 327af5: Un-revert change from 8e5f2e0 reverted in daf9522

[w3c/webauthn] 38ef98: remove Note, thx emlun ;)

[w3c/webauthn] 397187: Add Credential Loss and Key Mobility section to se...

[w3c/webauthn] 398016: Add Credential Loss and Key Mobility section to se...

[w3c/webauthn] 426512: enumerate supported attstn types for packed attstn...

[w3c/webauthn] 435225: Add missing commas

[w3c/webauthn] 46b133: Built by Travis-CI: 16fee7b5c951ab1bacbd84fe280d88...

[w3c/webauthn] 494d57: Define "bound" for credentials and use the term "s...

[w3c/webauthn] 4d5a9e: clarify relation of user handle as value of 'user....

[w3c/webauthn] 4f790f: Built by Travis-CI: 06c4808ce4fdeefc4c6d6264dd6aee...

[w3c/webauthn] 51fcbe: Built by Travis-CI: 29bbee1b02de1f3607df185aa0ca2e...

[w3c/webauthn] 529747: Fix #1068: Fix a reference to privacy consideratio...

[w3c/webauthn] 5517fe: Address most of @equalsJeffH's review comments

[w3c/webauthn] 5568ae: Built by Travis-CI: a6cc20dd78b480d99ab1dfa918f05e...

[w3c/webauthn] 5721bf: Built by Travis-CI: 76cf6dfb3ef6744c52d3796cd2569f...

[w3c/webauthn] 5c33b6: Add Username Enumeration section to privacy consid...

[w3c/webauthn] 5e8ce8: Built by Travis-CI: 16fee7b5c951ab1bacbd84fe280d88...

[w3c/webauthn] 5fee95: Built by Travis-CI: ee934de2c8524528b5228af565eb72...

[w3c/webauthn] 661a85: token binding ID is a client platform-specific ope...

[w3c/webauthn] 665733: Fix typo in figure 1

[w3c/webauthn] 6899e7: fix an oops

[w3c/webauthn] 693fd4: Built by Travis-CI: ee934de2c8524528b5228af565eb72...

[w3c/webauthn] 6a05ce: Built by Travis-CI: 661a8575fb3156134d64ecdc56208d...

[w3c/webauthn] 6adfc5: Feedback-01

[w3c/webauthn] 76cf6d: Fix typo (#1081)

[w3c/webauthn] 77af8a: Update figure 1 to agree with figure 2 on clientDa...

[w3c/webauthn] 7c75d6: Adopt consistent case for section headings

[w3c/webauthn] 802613: Issue #1045 - Add Platform-Specific Implementation...

[w3c/webauthn] 80eaff: Spell out that values expressing attestation type ...

[w3c/webauthn] 845e92: Add missing commas

[w3c/webauthn] 89604c: Built by Travis-CI: e8ba348b5605c8a8ea1d3e6514d6c5...

[w3c/webauthn] 8e5f2e: Make implementation-specificness of attestn.verif....

[w3c/webauthn] 9a99d4: Fix typo

[w3c/webauthn] 9b2016: Built by Travis-CI: daf95225fc9edfe0a894c747d91b2c...

[w3c/webauthn] 9d4975: fix #403: user handle - account relationship (#105...

[w3c/webauthn] 9e97b5: Built by Travis-CI: b90f7f53e713a8a2cc36c8b973acd6...

[w3c/webauthn] a095a9: Built by Travis-CI: 28f32160e6a6b03847d523fc6237ec...

[w3c/webauthn] a7773d: Built by Travis-CI: 76cf6dfb3ef6744c52d3796cd2569f...

[w3c/webauthn] ad1e2c: Built by Travis-CI: 426512a1d8a9d056b544e8b68a807d...

[w3c/webauthn] ad6743: fix 403

[w3c/webauthn] af62ff: Built by Travis-CI: 28f32160e6a6b03847d523fc6237ec...

[w3c/webauthn] b25408: Add links, thanks @equalsJeffH!

[w3c/webauthn] b8f7ac: Built by Travis-CI: 426512a1d8a9d056b544e8b68a807d...

[w3c/webauthn] b90f7f: add 'spec roadmap' section (#375)

[w3c/webauthn] be2f5d: Built by Travis-CI: 1679de2d1c989ff6de8331d1ee4a15...

[w3c/webauthn] be30a2: Add note about Basic and AttCA being indistinguish...

[w3c/webauthn] bf6a60: Built by Travis-CI: 06c4808ce4fdeefc4c6d6264dd6aee...

[w3c/webauthn] c60b97: Built by Travis-CI: e8ba348b5605c8a8ea1d3e6514d6c5...

[w3c/webauthn] c90bd2: Built by Travis-CI: 398016e36c8a3a925be918ca3807d2...

[w3c/webauthn] cc945b: Built by Travis-CI: daf95225fc9edfe0a894c747d91b2c...

[w3c/webauthn] cf07d2: update per emlun's comment, thx!

[w3c/webauthn] d054b3: fix misspelling

[w3c/webauthn] d38d12: Built by Travis-CI: 2056feede7550649ff61bdfce17d96...

[w3c/webauthn] d4faac: enumerate supported attstn types for packed attstn...

[w3c/webauthn] d7e181: fix #360

[w3c/webauthn] daf952: Clarify use of authorization lists in Android Key ...

[w3c/webauthn] dbc455: fix oopsies and try to polish

[w3c/webauthn] e29dba: Adopt consistent case for section headings

[w3c/webauthn] e320eb: use 'attacker' instead of 'user'

[w3c/webauthn] e6467a: revise Note, thx emlun!

[w3c/webauthn] e8ba34: cognitive-accessibility consideration (#1075)

[w3c/webauthn] e8f7a2: Built by Travis-CI: 1679de2d1c989ff6de8331d1ee4a15...

[w3c/webauthn] e9f033: Built by Travis-CI: 29bbee1b02de1f3607df185aa0ca2e...

[w3c/webauthn] ed89ef: Built by Travis-CI: 802613e829023466784acad62c4633...

[w3c/webauthn] ef1fcc: Built by Travis-CI: 9d497577d8fdc272c626efc2583628...

[w3c/webauthn] f23c10: Built by Travis-CI: a6cc20dd78b480d99ab1dfa918f05e...

[w3c/webauthn] f73e78: cognitive

[w3c/webauthn] fd0e06: link other occurrances of 'map'

[webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way

[webauthn] About the canonical CBOR encoding form

[webauthn] Add Credential Loss and Key Mobility section to security considerations

[webauthn] Add Username Enumeration section to privacy considerations

[webauthn] Adding the way to get trust anchors for CTAP1/U2F authenticators

[webauthn] address needs of various webauthn spec audiences

[webauthn] Adopt consistent case for section headings

[webauthn] Ambiguous/wrong instructions in Android Key Attestation Statement Format verification procedure

[webauthn] Authenticator selection extension needs to define snapshotting behavior

[webauthn] Clarify use of authorization lists in Android Key Attestation

[webauthn] Clarify user identification in RP assertion verification operation

[webauthn] Clarify which user to authenticate if userHandle is not present

[webauthn] Closed Pull Request: PR 1052 review suggestion

[webauthn] cognitive

[webauthn] cognitive-accessibility consideration

[webauthn] Document wide review

[webauthn] Editorial: WebAuthn or WebAuthN

[webauthn] Ensure hard-coded step references in RP ops are correct

[webauthn] Explain how Token Binding IDs get associated with an HTML context.

[webauthn] FIDO U2F supports Attestation CA (AttCA)?

[webauthn] Fix #1059: Update figure 1 to agree with figure 2 on clientDataJSON naming

[webauthn] Fix #1068: Fix a reference to privacy considerations

[webauthn] Fix #1076 - Don't confuse extension optionality in Sec 10

[webauthn] fix #403: user handle - account relationship

[webauthn] Fix typo

[webauthn] fix: defelopers -> developers

[webauthn] Highlight Basic/AttCA ambiguity in definitions and verification procedures

[webauthn] Issue #1045 - Add Platform-Specific Implementation Guidance

[webauthn] Issue #294 - Add a non-normative comment about snapshotting BufferSources

[webauthn] Leap of Faith not only for Self and None Attestation Types

[webauthn] Merged Pull Request: add 'spec roadmap' section

[webauthn] Merged Pull Request: Add Credential Loss and Key Mobility section to security considerations

[webauthn] Merged Pull Request: Add Username Enumeration section to privacy considerations

[webauthn] Merged Pull Request: Adopt consistent case for section headings

[webauthn] Merged Pull Request: Clarify use of authorization lists in Android Key Attestation

[webauthn] Merged Pull Request: cognitive

[webauthn] Merged Pull Request: enumerate actual supported attstn types for packed attestation statement format

[webauthn] Merged Pull Request: Fix #1059: Update figure 1 to agree with figure 2 on clientDataJSON naming

[webauthn] Merged Pull Request: Fix #1068: Fix a reference to privacy considerations

[webauthn] Merged Pull Request: Fix #1076 - Don't confuse extension optionality in Sec 10

[webauthn] Merged Pull Request: fix #403: user handle - account relationship

[webauthn] Merged Pull Request: Fix typo

[webauthn] Merged Pull Request: fix: defelopers -> developers

[webauthn] Merged Pull Request: Highlight Basic/AttCA ambiguity in definitions and verification procedures

[webauthn] Merged Pull Request: Issue #1045 - Add Platform-Specific Implementation Guidance

[webauthn] Merged Pull Request: Issue #294 - Add a non-normative comment about snapshotting BufferSources

[webauthn] Merged Pull Request: Make implementation-specificness of attestn.verif. return values more explicit

[webauthn] Merged Pull Request: note that obtaining a token binding ID is a client platform-specific operation

[webauthn] Merged Pull Request: Spell out that values expressing attestation type are implementation specific

[webauthn] Merged Pull Request: Un-revert change from 8e5f2e0 reverted in daf9522

[webauthn] Merged Pull Request: use 'attacker' instead of 'user'

[webauthn] Missing steps of checking pubKeyCredParams during registration step at RP server

[webauthn] Mobile support

[webauthn] new commits pushed by akshayku

[webauthn] new commits pushed by emlun

[webauthn] new commits pushed by equalsJeffH

[webauthn] new commits pushed by jcjones

[webauthn] new commits pushed by plehegar

[webauthn] new commits pushed by samuelweiler

[webauthn] new commits pushed by WebAuthnBot

[webauthn] new commits pushed by YubicoDemo

[webauthn] No way to specify transports during registration step

[webauthn] No way to verify requireResidentKey during registration step at RP side

[webauthn] NULL or DOMException

[webauthn] Packed attestation statement format supports all types but None ?

[webauthn] PR 1052 review suggestion

[webauthn] Pre-registration discovery for roaming authenticators

[webauthn] Provide transport information during registration.

[webauthn] Pull Request: Add Credential Loss and Key Mobility section to security considerations

[webauthn] Pull Request: Adopt consistent case for section headings

[webauthn] Pull Request: Clarify use of authorization lists in Android Key Attestation

[webauthn] Pull Request: Clarify user identification in RP assertion verification operation

[webauthn] Pull Request: cognitive

[webauthn] Pull Request: enumerate actual supported attstn types for packed attestation statement format

[webauthn] Pull Request: Fix #1059: Update figure 1 to agree with figure 2 on clientDataJSON naming

[webauthn] Pull Request: Fix #1068: Fix a reference to privacy considerations

[webauthn] Pull Request: Fix #1076 - Don't confuse extension optionality in Sec 10

[webauthn] Pull Request: fix #403: user handle - account relationship

[webauthn] Pull Request: Fix typo

[webauthn] Pull Request: fix: defelopers -> developers

[webauthn] Pull Request: Highlight Basic/AttCA ambiguity in definitions and verification procedures

[webauthn] Pull Request: Issue #1045 - Add Platform-Specific Implementation Guidance

[webauthn] Pull Request: Issue #294 - Add a non-normative comment about snapshotting BufferSources

[webauthn] Pull Request: Issue 1084 figure typo

[webauthn] Pull Request: Make implementation-specificness of attestn.verif. return values more explicit

[webauthn] Pull Request: note that obtaining a token binding ID is a client platform-specific operation

[webauthn] Pull Request: PR 1052 review suggestion

[webauthn] Pull Request: Spell out that values expressing attestation type are implementation specific

[webauthn] Pull Request: Un-revert change from 8e5f2e0 reverted in daf9522

[webauthn] Pull Request: update token binding citation

[webauthn] Pull Request: use 'attacker' instead of 'user'

[webauthn] Section 10: extensions are OPTIONAL

[webauthn] Security threat: Username enumeration

[webauthn] Spell out that values expressing attestation type are implementation specific

[webauthn] Typo

[webauthn] Typo in Android SafetyNet verification procedure

[webauthn] Typo in Figure 1?

[webauthn] Un-revert change from 8e5f2e0 reverted in daf9522

[webauthn] Unspecified CBOR encoding of high-valued integer numbers due to unspecified threshold

[webauthn] Update Figure 1 to follow up the spec modification

[webauthn] update token binding citation

[webauthn] update token binding reference to ref the actual RFC

[webauthn] Verify signature first in RP operations?

[webauthn] Wrong Registration Ceremony Privacy Reference

All PropRec PRs ready to merge

Call for Consensus - Web Authentication specification

Closed: [webauthn] About the canonical CBOR encoding form

Closed: [webauthn] address needs of various webauthn spec audiences

Closed: [webauthn] Adopt consistent case for section headings

Closed: [webauthn] Ambiguous/wrong instructions in Android Key Attestation Statement Format verification procedure

Closed: [webauthn] Authenticator selection extension needs to define snapshotting behavior

Closed: [webauthn] Clarify which user to authenticate if userHandle is not present

Closed: [webauthn] cognitive-accessibility consideration

Closed: [webauthn] Document wide review

Closed: [webauthn] Editorial: WebAuthn or WebAuthN

Closed: [webauthn] Ensure hard-coded step references in RP ops are correct

Closed: [webauthn] Explain how Token Binding IDs get associated with an HTML context.

Closed: [webauthn] FIDO U2F supports Attestation CA (AttCA)?

Closed: [webauthn] Mobile support

Closed: [webauthn] No way to specify transports during registration step

Closed: [webauthn] Packed attestation statement format supports all types but None ?

Closed: [webauthn] Pre-registration discovery for roaming authenticators

Closed: [webauthn] Section 10: extensions are OPTIONAL

Closed: [webauthn] Security threat: Username enumeration

Closed: [webauthn] some RPs may wish to allow multiple registrations to same user account

Closed: [webauthn] Typo in Android SafetyNet verification procedure

Closed: [webauthn] Update Figure 1 to follow up the spec modification

Closed: [webauthn] User agent / key management [authenticator] interoperability requirements?

Closed: [webauthn] Wrong Registration Ceremony Privacy Reference

Substitute minutes of W3C Web Authn meeting 26-Sep-2018

Summit on Recovering from Device Loss in WebAuthn

TPAC 2018 - Registration fees and hotel bookings

Transition Request: Web Authentication to Proposed Recommendation

WebAuthn demo at TPAC Dev meetup?

wrt "meta pull-requests" milestone...

Last message date: Saturday, 29 September 2018 01:21:47 UTC