- From: Martin Thomson <notifications@github.com>
- Date: Thu, 03 Jul 2025 15:58:17 -0700
- To: w3ctag/design-reviews <design-reviews@noreply.github.com>
- Cc: Subscribed <subscribed@noreply.github.com>
Received on Thursday, 3 July 2025 22:58:21 UTC
martinthomson left a comment (w3ctag/design-reviews#1092) Password credentials are not cross-site (or cross-origin?) in the same way that this is, but using that as justification for this runs afoul of our principles: just because passwords are bad, that doesn't excuse passkeys when they add the same badness. That is, password credentials should not reveal whether a password exists after site state clears. -- Reply to this email directly or view it on GitHub: https://github.com/w3ctag/design-reviews/issues/1092#issuecomment-3033899218 You are receiving this because you are subscribed to this thread. Message ID: <w3ctag/design-reviews/issues/1092/3033899218@github.com>
Received on Thursday, 3 July 2025 22:58:21 UTC