Re: [webauthn] Why does WebAuthn require a challenge when asking the client to register a new credential? (#1355)

I suspect for the same reason you almost universally have to enter an OTP code to verify registration of a new TOTP token -- to validate that you actually have the correct key and can make the signature.

-- 
GitHub Notification of comment by e3b0c442
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1355#issuecomment-566598536 using your GitHub account

Received on Tuesday, 17 December 2019 15:45:36 UTC