Re: [webauthn] Enforce strict same-origin policy on rpId

Hi Angelo, 

We have discussed/debated this design point several times already and 
have landed on the present spec language. 

Rather than regurgitate the arguments in-total, please allow me to 
point you to relevant portions of the immediately prior occurrence:

Re: wrt deprecating eTLD+1 (was: Can we remove the PSL dependency?)  
@balfanz 
https://lists.w3.org/Archives/Public/public-webauthn/2016Aug/0045.html

RE: Can we remove the PSL dependency?    @vijaybh 
https://lists.w3.org/Archives/Public/public-webauthn/2016Jul/0331.html

W3C TAG: Review Web Authentication spec 
https://github.com/w3ctag/spec-reviews/issues/97#issuecomment-175766580
  @balfanz 

Many of us feel that scoping webauthn credentials strictly to same web
 origins will unduly hinder deployability (e.g. see @balfanz's 
detailed comment immediately above). 




-- 
GitHub Notification of comment by equalsJeffH
Please view or discuss this issue at 
https://github.com/w3c/webauthn/issues/241#issuecomment-257708570 
using your GitHub account

Received on Tuesday, 1 November 2016 21:46:08 UTC