Re: [web-nfc] "A Better Q"

>The security context (URL + Certificate) of the invoking Web page must also be available so that the OOB communication performed by the App in the phone can prove where it got its invocation from to the server it typically calls.

NFC is not made to be secure. Do not expect to use it for banking or any data that require secure transaction. Even with a context or unique data, the transaction can catch and replay by anyone.

-- 
GitHub Notification of comment by Liryna
Please view or discuss this issue at https://github.com/w3c/web-nfc/issues/128#issuecomment-306175113 using your GitHub account

Received on Monday, 5 June 2017 12:25:21 UTC