Re: [webauthn] Allow RPs to choose between "required" and "optional" attestation in credentials.create()

Just a couple of comments:

- Keeping in mind that these are not black-and-white issues, the RP *does* have to trust the client. If the client is malicious, it can exfiltrate the user's data, operate on the user's behalf, etc.

- Using a Privacy CA is not a change to webauthn. The spec already calls that out as a possible model. I think that what's happening here is that nobody has seriously looked into actually deploying one. Now that we are, we realize that we need to smooth out some rough edges around that attestation type.

GitHub Notification of comment by balfanz
Please view or discuss this issue at using your GitHub account

Received on Thursday, 12 October 2017 16:29:04 UTC