Re: [Minutes] 21 June 2021 SPC Task Force

Hi all,

Having done some digging, I need to correct myself from this meeting. When
we moved to allow SPC enrollment to happen in an iframe (for Origin Trial
#2), our security/privacy folks were the ones who asked for an explicit
browser enrollment UX, to make sure that the user was aware of what was
happening.

This decision isn't necessarily final, and I'm following up internally to
see what might change if WebAuthn themselves allow cross-origin creation of
credentials, but for now let's proceed assuming an enrollment browser UX is
required (at least by Chrome; other browsers may make different decisions).

Apologies for misleading folks earlier!

Thanks,
Stephen

On Mon, 21 Jun 2021 at 13:14, Ian Jacobs <ij@w3.org> wrote:

> Dear WPWG,
>
> Minutes from today's SPC task force call:
>   https://www.w3.org/2021/06/21-wpwg-spc-minutes
>
> We continued our discussion about the nature of “enrollment” and the
> proximity of SPC to Web Authentication. We plan to continue this
> discussion at the 24 June WPWG meeting.
>
> Next task force call: 28 June.
>
> Ian
> --
> Ian Jacobs <ij@w3.org>
> https://www.w3.org/People/Jacobs/
> Tel: +1 718 260 9447 <+1%20718-260-9447>
>
>
>
>
>
>

Received on Monday, 21 June 2021 18:07:37 UTC