Re: [webauthn] Biometric Criteria Extension

@selfissued 

>Providing no data of this is kind is better than providing data that provides a false sense of security.

How would you feel about this if the specified requirement in the extension, instead of

>If the client supports this extension, it MUST NOT use a biometric authenticator whose FAR or FRR **does not match** the bounds as provided.

was something more like this?

>If the client supports this extension, it MUST NOT use a biometric authenticator whose FAR or FRR **is not certified by an authoritative source to match** the bounds as provided.


-- 
GitHub Notification of comment by emlun
Please view or discuss this issue at https://github.com/w3c/webauthn/pull/510#issuecomment-363137849 using your GitHub account

Received on Monday, 5 February 2018 16:27:29 UTC