Re: [webauthn] Why does WebAuthn require a challenge when asking the client to register a new credential? (#1355)

https://www.w3.org/TR/webauthn-2/#sctn-security-considerations-rp

Yes, the challenge is present to prevent replay attacks. There are other controls that could fail outside of TLS to enable a replay attack at various points between the authenticator / client / server.

-- 
GitHub Notification of comment by nickmooney
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1355#issuecomment-566716089 using your GitHub account

Received on Tuesday, 17 December 2019 19:36:44 UTC