== "credential ID" not signed over by authenticatorGetAssertion operation ==
I note that in [authenticatorGetAssertion operation](https://w3c.github.io/webauthn/#op-get-assertion), the "credential ID" not signed over -- i.e., it is not included in `authenticator data` because no `attObj` is contained in the `authenticator data` returned by this operation.  As I (vaguely) recall, we discussed this long ago and determined that the worst downside of a buggy authenticator returning an incorrect credential ID is that the RP will not look up the correct cred public key with which to verify the returned signed `authenticator data` (aka assertion) and the overall ceremony would thus end in error. 

we should probably document this rationale and consequence somewhere in the spec. 

