Next steps for accessible authentication

1. We need to set up a review with the web authentication folks and check they are comfortable we are ncreating security problems. Who should set that up? (Options: John, Me, Andrew or Josh as wcag chairs or Janina as APA...)

2. All the comments need to be addressed in github . see:
also we need to check the survey: (although we can disagree with them and try and convince them)

3. We need an exception for when this is not possible with current legislative requirments

4. Possible exception for coping up to four characters ? DO we see a user problem with this?

