Re: [webauthn] Add privacy considerations about credential IDs (#1250)

There are many other ways to use "ambien credentials". For example, you could store a hash of credentialIDs instead of username. All these cases should be part of this privacy concern since no matter what you do, you end up sending credentialIDs for a get().

-- 
GitHub Notification of comment by maxhata
Please view or discuss this issue at https://github.com/w3c/webauthn/pull/1250#issuecomment-528360576 using your GitHub account

Received on Thursday, 5 September 2019 13:22:16 UTC