[notes] 2022-02-07

Hi,

The quick notes from our meeting today; next meeting on March 7 (Feb 21
being a US holiday)

* Accompanying developers in the passkeys journey (Tim, Matt)
  still under investigation

* format for WebAuthn authenticator response output
  https://github.com/w3c/webauthn/issues/1683

* privacy implications of enumerating usernames
  best practive to avoid revealing existence of accounts for an RP
  => UX vs security trade-off (spectrum from webmail to defence contractor)
  (support value of username-less scenario)
  Matt to investigate where best to document that insight

* FIDO AMA on Feb 22

https://fidoalliance.org/event/webinar-ask-fido-anything-developer-spotlight/


* Nick/Matt/Tim looking into organizing a WebAuthn-related Twitter space
event

* WebAuthn conformance check-in - no recent progress
  https://github.com/webauthn-adoption/webauthn-conformance

* Tim preparing pull request to add two reserved bits to authenticators
to express whether a key is exportable (allow RPs to filter exportable
keys) and whether it has been backed-up

* next meeting: March 7 (Feb 21st is a US holiday)

Dom

Received on Monday, 7 February 2022 18:43:23 UTC