Tuesday, 31 July 2018
- Fwd: Reminder - Re: TPAC 2018 registration now open
- Re: [webauthn] Bad instructions in Android SafetyNet attestation validation steps
- Re: [webauthn] Bad instructions in Android SafetyNet attestation validation steps
Monday, 30 July 2018
Sunday, 29 July 2018
Saturday, 28 July 2018
Friday, 27 July 2018
- [webauthn] Pull Request: fix #712 JSON-serialized client data is wrong
- [w3c/webauthn] acb0f6: fix #712 JSON-serialized client data is wrong
- [webauthn] new commits pushed by equalsJeffH
- Re: [webauthn] NULL or DOMException
- Re: [webauthn] Minor typo - FAR should be FRR
- [webauthn] Pull Request: fix #1015 FAR should be FRR
- [w3c/webauthn] 9dbcd9: fix #1015 FAR should be FRR
- [webauthn] new commits pushed by equalsJeffH
- fyi: Postponed by 8 days - Call for Participation: W3C Workshop on Permissions and User Consent
- Re: [webauthn] Explain how Token Binding IDs get associated with an HTML context.
Thursday, 26 July 2018
- RE: lock the webauthn repo?
- RE: lock the webauthn repo?
- lock the webauthn repo?
- Request to Update Candidate Recommendation for WebAuthn API
- Invite to Dependent WGs to review WebAuthn API CR update
- [w3c/webauthn] 4df371: Built by Travis-CI: 243e72f84a35f7d2774dbfbc8da58e...
- [webauthn] new commits pushed by WebAuthnBot
- [w3c/webauthn] 671ba7: Built by Travis-CI: 243e72f84a35f7d2774dbfbc8da58e...
- [webauthn] new commits pushed by WebAuthnBot
- [w3c/webauthn]
- [w3c/webauthn] 243e72: update acks (#1013)
- [webauthn] Merged Pull Request: update acks
- [webauthn] new commits pushed by equalsJeffH
- Re: [webauthn] Tighten security scope by port
- Re: [webauthn] Minor typo - FAR should be FRR
- Re: [webauthn] Determining length of `attestedCredentialData` when authenticator extensions present.
- Security threat: Username enumeration
- Re: [webauthn] Tighten security scope by port
- Re: [webauthn] SafetyNet response as an extension
- [webauthn] Minor typo - FAR should be FRR
- Re: [webauthn] Determining length of `attestedCredentialData` when authenticator extensions present.
- [webauthn] Security threat: Username enumeration
Wednesday, 25 July 2018
- Re: [webauthn] Clarify behaviour of rawId and id fields for resident key credentials
- Closed: [webauthn] Clarify behaviour of rawId and id fields for resident key credentials
- [webauthn] Pull Request: update acks
- [w3c/webauthn] e95d78: update acks
- [webauthn] new commits pushed by equalsJeffH
- [w3c/webauthn] 8161da: Built by Travis-CI: 81e8056e275eed52606b7eb406ee42...
- [webauthn] new commits pushed by WebAuthnBot
- [w3c/webauthn] 617d83: Built by Travis-CI: 81e8056e275eed52606b7eb406ee42...
- [webauthn] new commits pushed by WebAuthnBot
- [w3c/webauthn]
- [w3c/webauthn] 81e805: fix #24: add reg & authn flow diagrams (#1007)
- [webauthn] new commits pushed by equalsJeffH
- [webauthn] Merged Pull Request: fix #24: add reg & authn flow diagrams
- Closed: [webauthn] need description & illustrations of overall flow: authnr <--> platform API <--> RP
- [w3c/webauthn] 8b0eb7: Precisize "platform" and "device" terminology (#99...
- [webauthn] new commits pushed by equalsJeffH
- Re: [webauthn] Determining length of `attestedCredentialData` when authenticator extensions present.
- Re: [webauthn] Determining length of `attestedCredentialData` when authenticator extensions present.
- Re: [webauthn] Clarify behaviour of rawId and id fields for resident key credentials
- Re: [webauthn] NULL or DOMException
- Re: [webauthn] coalesce HTML references?
- Re: [webauthn] coalesce HTML references?
- Re: [webauthn] NULL or DOMException
- Re: [webauthn] NULL or DOMException
- Re: [webauthn] NULL or DOMException
- Re: [webauthn] NULL or DOMException
- Re: [webauthn] `publicKey` member name in `CredentialCreationRequestOptions` should be `"public-key"`, or vice-versa?
- Re: [webauthn] SafetyNet response as an extension
- LInks wrt publishing revised CR (was: Consensus on CR revision of WebAuthn)
- Re: [webauthn] SafetyNet response as an extension
- Re: [webauthn] SafetyNet response as an extension
- Re: [webauthn] `publicKey` member name in `CredentialCreationRequestOptions` should be `"public-key"`, or vice-versa?
- Re: [webauthn] SafetyNet response as an extension
- [webauthn] Determining length of `attestedCredentialData` when authenticator extensions present.
- Re: [webauthn] SafetyNet response as an extension
- Re: [webauthn] SafetyNet response as an extension
- Re: [webauthn] add abort path to createCredential alg to match that added to getAssertion alg
- Closed: [webauthn] add abort path to createCredential alg to match that added to getAssertion alg
- Re: [webauthn] Integrate with Feature Policy and define Feature-Identifier value for WebAuthn
- Re: [webauthn] SafetyNet response as an extension
- Re: [webauthn] Propose SafetyNet as an extension
- Re: [webauthn] SafetyNet response as an extension
- Re: [webauthn] SafetyNet response as an extension
- Re: [webauthn] SafetyNet response as an extension
- Re: [webauthn] SafetyNet response as an extension
- Re: [webauthn] SafetyNet response as an extension
- [w3c/webauthn]
- Re: [webauthn] SafetyNet response as an extension
- Re: [webauthn] SafetyNet response as an extension
- [w3c/webauthn] 3c4c8e: Built by Travis-CI: 0f38025c4acdd36f1e595432ac30aa...
- [w3c/webauthn] bcad9c: Built by Travis-CI: 0f38025c4acdd36f1e595432ac30aa...
- [webauthn] new commits pushed by WebAuthnBot
- [webauthn] new commits pushed by WebAuthnBot
- Re: [webauthn] fix #24: add reg & authn flow diagrams
- [w3c/webauthn] 0f3802: fix #939 add intro abort lang to getAssn (#1006)
- Closed: [webauthn] introductory abort language missing from [[Get]]() section
- [webauthn] Merged Pull Request: fix #939 add intro abort language to #getAssertion
- [webauthn] new commits pushed by equalsJeffH
- [w3c/webauthn] 4580bd: fix 985 add abort path to createCredential alg (#1...
- [webauthn] Merged Pull Request: fix 985 add abort path to createCredential alg
- [webauthn] new commits pushed by equalsJeffH
- [webauthn] SafetyNet response as an extension
- [webauthn] Pull Request: Propose SafetyNet as an extension
- [w3c/webauthn] a0a995: Built by Travis-CI: 7159c08b280b82a9a8d00d35212470...
- [webauthn] new commits pushed by WebAuthnBot
- Re: [webauthn] Integrate with Feature Policy and define Feature-Identifier value for WebAuthn
- [w3c/webauthn] 564198: Built by Travis-CI: 7159c08b280b82a9a8d00d35212470...
- [webauthn] new commits pushed by WebAuthnBot
- [w3c/webauthn] 62cdb5: Clarify behaviour for authnrs not implementing sig...
- [webauthn] Merged Pull Request: Clarify behaviour for authnrs not implementing signature counter
- [webauthn] new commits pushed by emlun
- Closed: [webauthn] Clarify authenticator behaviour when not implementing signature counter
- Re: [webauthn] Clarify behaviour for authnrs not implementing signature counter
- Re: [webauthn] fix 985 add abort path to createCredential alg
- Re: [webauthn] fix #939 add intro abort language to #getAssertion
- Re: [webauthn] fix #24: add reg & authn flow diagrams
- Re: [webauthn] `publicKey` member name in `CredentialCreationRequestOptions` should be `"public-key"`, or vice-versa?
- Re: [webauthn] Clarify authenticator behaviour when not implementing signature counter
- coalesce HTML references?
- [webauthn] Pull Request: Clarify behaviour for authnrs not implementing signature counter
- [webauthn] new commits pushed by emlun
- [w3c/webauthn] 62cdb5: Clarify behaviour for authnrs not implementing sig...
- [webauthn] Clarify authenticator behaviour when not implementing signature counter
- [w3c/webauthn]
- [webauthn] Closed Pull Request: Removed old optional counter step to remove confusions
- Re: [webauthn] Removed old optional counter step to remove confusions
- Re: [webauthn] Removed old optional counter step to remove confusions
Tuesday, 24 July 2018
- 07/25/2018 W3C Web Authentication WG Meeting Agenda
- Re: [webauthn] Integrate with Feature Policy and define Feature-Identifier value for WebAuthn
- Re: Consensus on CR revision of WebAuthn
- Re: Consensus on CR revision of WebAuthn
- [w3c/webauthn] 25b0ff: Built by Travis-CI: 8b0eb719f2061d6d1d7c74a3677884...
- [w3c/webauthn] 791957: Built by Travis-CI: 8b0eb719f2061d6d1d7c74a3677884...
- [webauthn] new commits pushed by WebAuthnBot
- [webauthn] new commits pushed by WebAuthnBot
- [w3c/webauthn] 8b0eb7: Precisize "platform" and "device" terminology (#99...
- [webauthn] new commits pushed by equalsJeffH
- [webauthn] Merged Pull Request: Precisize "platform" and "device" terminology
- Re: [webauthn] Precisize "platform" and "device" terminology
- Re: [webauthn] JSON-serialized client data is wrong
- Consensus on CR revision of WebAuthn
- WebAuthn now on CanIUse
- Re: [webauthn] fix #24: add reg & authn flow diagrams
- Re: [webauthn] need description & illustrations of overall flow: authnr <--> platform API <--> RP
- [webauthn] Pull Request: fix #24: add reg & authn flow diagrams
- [w3c/webauthn] 564fa0: renumber figure references
- [webauthn] new commits pushed by equalsJeffH
- [w3c/webauthn] 6eb470: fix #24: add reg & authn flow diagrams, thanks apo...
- [webauthn] new commits pushed by equalsJeffH
- Re: [webauthn] AppID extension: protocol version number?
- Re: [webauthn] NULL or DOMException
- Re: [webauthn] Precisize "platform" and "device" terminology
- Re: [webauthn] Authenticator selection extension needs to define snapshotting behavior
- [webauthn] Pull Request: fix #939 add intro abort language to #getAssertion
- [w3c/webauthn] 397912: fix #939 add intro abort lang to getAssn
- [webauthn] new commits pushed by equalsJeffH
- [webauthn] Pull Request: fix 985 add abort path to createCredential alg
- [w3c/webauthn] 2b1680: fix 985 add abort path to createCredential alg
- [webauthn] new commits pushed by equalsJeffH
- Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
Monday, 23 July 2018
- Re: [webauthn] `publicKey` member name in `CredentialCreationRequestOptions` should be `"public-key"`, or vice-versa?
- Re: [webauthn] `publicKey` member name in `CredentialCreationRequestOptions` should be `"public-key"`, or vice-versa?
- [webauthn] `publicKey` member name in `CredentialCreationRequestOptions` should be `"public-key"`, or vice-versa?
- Re: [webauthn] Removed old optional counter step to remove confusions
Sunday, 22 July 2018
- [webauthn] Pull Request: Removed old optional counter step to remove confusions
- Re: [webauthn] Sign counter alg 507 alternative: optional sig counter
Friday, 20 July 2018
Thursday, 19 July 2018
- Reminder - Re: TPAC 2018 registration now open
- Re: [webauthn] Clarify behaviour of rawId and id fields for resident key credentials
- Re: [webauthn] Clarify behaviour of rawId and id fields for resident key credentials
- Re: [webauthn] Clarify behaviour of rawId and id fields for resident key credentials
- Re: Summit on Recovering from Device Loss in WebAuthn
Wednesday, 18 July 2018
- Re: [webauthn] truncation to 64-byte upper limit doesn't mention character boundaries
- Re: [webauthn] Revise same-origin as ancestor requirements
- Re: [webauthn] Clarify behaviour of rawId and id fields for resident key credentials
- wrt issue #973 truncation to 64-byte upper limit doesn't mention character boundaries
- Re: [webauthn] truncation to 64-byte upper limit doesn't mention character boundaries
- Re: [webauthn] truncation to 64-byte upper limit doesn't mention character boundaries
- Re: [webauthn] Revise same-origin as ancestor requirements
- Re: [webauthn] Revise same-origin as ancestor requirements
- Re: [webauthn] Partial dictionaries for extension outputs may be incorrect use of WebIDL
- Re: [webauthn] Partial dictionaries for extension outputs may be incorrect use of WebIDL
- Re: [webauthn] Revise same-origin as ancestor requirements
- Re: [webauthn] Clarify behaviour of rawId and id fields for resident key credentials
- Re: [webauthn] some RPs may wish to allow multiple registrations to same user account
- Re: [webauthn] AppID extension: protocol version number?
- [w3c/webauthn] 249d60: Built by Travis-CI: 741cef6e2ce342e700b03662f688ef...
- [webauthn] new commits pushed by WebAuthnBot
- [w3c/webauthn]
- [w3c/webauthn] 911864: Make transaction authorization extensions authenti...
- [webauthn] Merged Pull Request: Make transaction authorization extensions authentication exts only
- [webauthn] new commits pushed by emlun
- Closed: [webauthn] Transaction authorization extensions are registration and authentication extension?
- Re: [webauthn] Allow clients to stop the `get` flow when certain conditions are met
- Closed: [webauthn] Allow clients to stop the `get` flow when certain conditions are met
- Re: [webauthn] Allow clients to stop the `get` flow when certain conditions are met
- Re: [webauthn] Make transaction authorization extensions authentication exts only
- [webauthn] Pull Request: Make transaction authorization extensions authentication exts only
- [w3c/webauthn] 911864: Make transaction authorization extensions authenti...
- [webauthn] new commits pushed by emlun
- [w3c/webauthn] 3cc531: Built by Travis-CI: 8d6b9ac209154be39fa6e08bb8e80f...
- [webauthn] new commits pushed by WebAuthnBot
- Re: [webauthn] Transaction authorization extensions are registration and authentication extension?
- [w3c/webauthn] ffcd4d: Built by Travis-CI: 8d6b9ac209154be39fa6e08bb8e80f...
- [webauthn] new commits pushed by WebAuthnBot
- [w3c/webauthn]
- [w3c/webauthn] 862f42: Replace local/remote storage terms with client/ser...
- [w3c/webauthn] 768368: Fix spelling mistake
- [webauthn] new commits pushed by emlun
- [webauthn] Merged Pull Request: Replace local/remote storage terms with client/server side
- [webauthn] new commits pushed by emlun
- [w3c/webauthn]
- [w3c/webauthn]
- [w3c/webauthn] ed3abe: Add two abort paths for getting an assertion.
- [webauthn] new commits pushed by emlun
- [w3c/webauthn] ab9140: Built by Travis-CI: faee219e5bc1b9ceb8c83ccdb316d2...
- [w3c/webauthn] 414651: Built by Travis-CI: faee219e5bc1b9ceb8c83ccdb316d2...
- [webauthn] new commits pushed by WebAuthnBot
- [webauthn] new commits pushed by WebAuthnBot
- [w3c/webauthn] 50f0f6: Built by Travis-CI: a0d84c1f4c470251453fef8e4171b8...
- [webauthn] new commits pushed by WebAuthnBot
- [w3c/webauthn] 38f9d8: Built by Travis-CI: a0d84c1f4c470251453fef8e4171b8...
- [webauthn] new commits pushed by WebAuthnBot
- [w3c/webauthn] a0d84c: fix 933: authnr does not enforce RP ID being eTLD+...
- [w3c/webauthn] d45d8f: Add table numbers and captions
- [webauthn] Merged Pull Request: fix 933: authnr does not enforce RP ID being eTLD+1 of RP's origin
- [webauthn] new commits pushed by equalsJeffH
- Closed: [webauthn] #sec-authenticator-data section implies authnr enforces RP ID being eTLD+1
- [webauthn] Merged Pull Request: Add table numbers and captions
- [webauthn] new commits pushed by emlun
- Closed: [webauthn] add captions for tables and id attrs so we can link to them
- Re: [webauthn] Transaction authorization extensions are registration and authentication extension?
- Re: [webauthn] Precisize "platform" and "device" terminology
- [w3c/webauthn] ed3abe: Add two abort paths for getting an assertion.
- [webauthn] new commits pushed by emlun
- 07/18/2018 W3C Web Authentication WG Meeting Agenda
- [webauthn] Revise same-origin as ancestor requirements
Tuesday, 17 July 2018
- [w3c/webauthn] 9c34ec: Built by Travis-CI: bf4dbab0541a445b79bcf20f38ccd6...
- [webauthn] new commits pushed by WebAuthnBot
- [w3c/webauthn] ed3abe: Add two abort paths for getting an assertion.
- [webauthn] new commits pushed by agl
- [webauthn] Merged Pull Request: Add two abort paths for getting an assertion
- Summit on Recovering from Device Loss in WebAuthn
- Re: [webauthn] JSON-serialized client data is wrong
Monday, 16 July 2018
- [w3c/webauthn] 280494: Colocate <dfn> of Client with WebAuthn Client
- [webauthn] new commits pushed by emlun
Sunday, 15 July 2018
Saturday, 14 July 2018
Friday, 13 July 2018
- Re: [webauthn] Precisize "platform" and "device" terminology
- [webauthn] Pull Request: fix 933: authnr does not enforce RP ID being eTLD+1 of RP's origin
- [w3c/webauthn] 8f2767: remove inapprop phrase and link some terms
- [webauthn] new commits pushed by equalsJeffH
- Re: [webauthn] Precisize "platform" and "device" terminology
- Re: [webauthn] Precisize "platform" and "device" terminology
- Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
- Re: [webauthn] Precisize "platform" and "device" terminology
- Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
- Re: [webauthn] Precisize "platform" and "device" terminology
- [webauthn] Pull Request: Precisize "platform" and "device" terminology
- [w3c/webauthn] 12e5fb: Add term Client Platform
- [webauthn] new commits pushed by emlun
- [w3c/webauthn] 0c0c79: Built by Travis-CI: f864d09715352ba30390664aa42518...
- [w3c/webauthn] ba407b: Built by Travis-CI: f864d09715352ba30390664aa42518...
- [webauthn] new commits pushed by WebAuthnBot
- [webauthn] new commits pushed by WebAuthnBot
- [w3c/webauthn] f864d0: Fix #593: employ PRECIS RFC8264 et al for 'name'-i...
- Re: [webauthn] Fix #593: employ PRECIS RFC8264 et al for 'name'-ish domstring values
- [webauthn] new commits pushed by equalsJeffH
- [webauthn] Merged Pull Request: Fix #593: employ PRECIS RFC8264 et al for 'name'-ish domstring values
- Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
- Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
Thursday, 12 July 2018
- Re: [webauthn] truncation to 64-byte upper limit doesn't mention character boundaries
- Re: [webauthn] truncation to 64-byte upper limit doesn't mention character boundaries
- fyi: W3C Workshop on Permissions and User Consent
- [webauthn] Pull Request: Replace local/remote storage terms with client/server side
- [w3c/webauthn] 862f42: Replace local/remote storage terms with client/ser...
- [webauthn] new commits pushed by emlun
- Re: [webauthn] Add table numbers and captions
- Re: [webauthn] Add table numbers and captions
- [w3c/webauthn] bc1589: Add caption and number to authenticator types tabl...
- [webauthn] new commits pushed by emlun
- Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
- [w3c/webauthn] e949d5: Built by Travis-CI: 7e5256f6f564fa99f68e4512340214...
- [w3c/webauthn] a0dd8d: Built by Travis-CI: 7e5256f6f564fa99f68e4512340214...
- [webauthn] new commits pushed by WebAuthnBot
- [webauthn] new commits pushed by WebAuthnBot
- [w3c/webauthn]
- [w3c/webauthn] 010874: Replace Client-side-resident Credential Private Ke...
- [webauthn] new commits pushed by emlun
- [webauthn] Merged Pull Request: Replace resident key terminology as proposed in #905
- Re: [webauthn] Clarify WebAuthn spec to allow us to return an error to RP when it makes sense
- Re: [webauthn] Add table numbers and captions
- Re: [webauthn] truncation to 64-byte upper limit doesn't mention character boundaries
- [w3c/webauthn] 1e3241: Add link to "attachment modality" reference
- [webauthn] new commits pushed by equalsJeffH
- Closed: [webauthn] Clarify WebAuthn spec to allow us to return an error to RP when it makes sense
- Re: [webauthn] Clarify WebAuthn spec to allow us to return an error to RP when it makes sense
Wednesday, 11 July 2018
- Re: [webauthn] Platform authenticators and key stores
- Re: [webauthn] Fix #593: employ PRECIS RFC8264 et al for 'name'-ish domstring values
- [w3c/webauthn] 4ddc3c: add presentation admonition wrt name-ish strings
- [webauthn] new commits pushed by equalsJeffH
- Re: [webauthn] truncation to 64-byte upper limit doesn't mention character boundaries
- Re: [webauthn] Fix #593: employ PRECIS RFC8264 et al for 'name'-ish domstring values
- Re: [webauthn] Fix #593: employ PRECIS RFC8264 et al for 'name'-ish domstring values
- [webauthn] coalesce HTML references?
- Re: [webauthn] Replace resident key terminology as proposed in #905
- [w3c/webauthn] 1e3241: Add link to "attachment modality" reference
- [webauthn] new commits pushed by equalsJeffH
- Re: [webauthn] Fix #593: employ PRECIS RFC8264 et al for 'name'-ish domstring values
- wrt issue #750 `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
- [w3c/webauthn]
- [w3c/webauthn]
- [w3c/webauthn] 66d00c: Built by Travis-CI: ca80875c6dc6b6f0eb3f4a02f39774...
- [webauthn] new commits pushed by WebAuthnBot
- [w3c/webauthn] dcb394: Built by Travis-CI: ca80875c6dc6b6f0eb3f4a02f39774...
- [webauthn] new commits pushed by WebAuthnBot
- [w3c/webauthn] 699c58: Revert "Add Issue: pointing out that Authenticator...
- [webauthn] new commits pushed by emlun
- [webauthn] Merged Pull Request: Authenticator taxonomy: Authenticator types
- Re: [webauthn] authenticatorGetAssertion has no ConstraintError step for requireUserVerification
- Closed: [webauthn] authenticatorGetAssertion has no ConstraintError step for requireUserVerification
- Re: [webauthn] authenticatorGetAssertion has no ConstraintError step for requireUserVerification
- [w3c/webauthn] 671666: Built by Travis-CI: 005ec66866c2f3329f6c780a9351df...
- [w3c/webauthn] 4e9893: Built by Travis-CI: 005ec66866c2f3329f6c780a9351df...
- [webauthn] new commits pushed by WebAuthnBot
- [webauthn] new commits pushed by WebAuthnBot
- [w3c/webauthn]
- [w3c/webauthn] 905de0: Disambiguate appid extension output behaviour
- [webauthn] Merged Pull Request: Disambiguate appid extension output behaviour
- [webauthn] new commits pushed by emlun
- Closed: [webauthn] What does "the extension was acted upon" mean for the AppID extension?
- Re: [webauthn] Display name content rules?
- Closed: [webauthn] Display name content rules?
- Re: [webauthn] add abort path to createCredential alg to match that added to getAssertion alg
- [w3c/webauthn] 369e2c: Built by Travis-CI: 9033fc6fccd602c3705a43927e11b5...
- [webauthn] new commits pushed by WebAuthnBot
- [webauthn] new commits pushed by WebAuthnBot
- [w3c/webauthn] 11ffca: Built by Travis-CI: 9033fc6fccd602c3705a43927e11b5...
- [w3c/webauthn] 9033fc: fix 364 timeout reasonable range (#971)
- [webauthn] Merged Pull Request: fix 364 timeout reasonable range
- Closed: [webauthn] Constrain the "reasonable range" of timeouts
- [webauthn] new commits pushed by equalsJeffH
- [w3c/webauthn] 8a75d7: Built by Travis-CI: 321e805b763bc86ff996403da6bfd1...
- [w3c/webauthn] 6da4bb: Built by Travis-CI: 321e805b763bc86ff996403da6bfd1...
- [webauthn] new commits pushed by WebAuthnBot
- [webauthn] new commits pushed by WebAuthnBot
- [w3c/webauthn] b9e873: Built by Travis-CI: 7709911ace404df7f6d01151cdef10...
- [webauthn] new commits pushed by WebAuthnBot
- [w3c/webauthn] ae7502: Built by Travis-CI: 7709911ace404df7f6d01151cdef10...
- [webauthn] new commits pushed by WebAuthnBot
- [w3c/webauthn] 7958a9: Built by Travis-CI: fe09a70a41372690257fa3730a6dc8...
- [w3c/webauthn] 321e80: Add recommendation of scoping platform credentials...
- [w3c/webauthn] 91d059: Built by Travis-CI: fe09a70a41372690257fa3730a6dc8...
- [webauthn] Merged Pull Request: Add recommendation of scoping platform credentials to OS accounts
- [webauthn] new commits pushed by WebAuthnBot
- [webauthn] new commits pushed by equalsJeffH
- Closed: [webauthn] Privacy across OS accounts
- [w3c/webauthn] 770991: fix 864: Note regarding CTAP2 integer keys vs weba...
- [webauthn] new commits pushed by WebAuthnBot
- [webauthn] new commits pushed by equalsJeffH
- Closed: [webauthn] CTAP-speaking authenticators use integer-valued CBOR map keys
- [webauthn] Merged Pull Request: fix 864: Note regarding CTAP2 integer keys vs webauthn string keys
- [w3c/webauthn] fe09a7: fix #493: be explicit about "same user" is verifie...
- [webauthn] new commits pushed by equalsJeffH
- Closed: [webauthn] be explict about "same user" is verified at get() time as was verified at create() time
- [webauthn] Merged Pull Request: fix #493: be explicit about "same user" is verified at get() time as was verified at create() time
- [w3c/webauthn] 1f70ea: Built by Travis-CI: 2154486d6af399c3bcbd62a3096213...
- [webauthn] new commits pushed by WebAuthnBot
- [w3c/webauthn] 9b04d6: Built by Travis-CI: 2154486d6af399c3bcbd62a3096213...
- [webauthn] new commits pushed by WebAuthnBot
- Re: [webauthn] fix #493: be explicit about "same user" is verified at get() time as was verified at create() time
- [w3c/webauthn] 1e3241: Add link to "attachment modality" reference
- [webauthn] Merged Pull Request: Authenticator taxonomy: Attachment modality (replaces #842)
- [webauthn] new commits pushed by emlun
- Closed: [webauthn] authenticator taxonomy
- [webauthn] Closed Pull Request: Fix #593 - Refer to RFC 8266 for RP-controlled UI strings
- Re: [webauthn] Fix #593 - Refer to RFC 8266 for RP-controlled UI strings
- Re: [webauthn] Add recommendation of scoping platform credentials to OS accounts
- [webauthn] Pull Request: Disambiguate appid extension output behaviour
- [w3c/webauthn] 905de0: Disambiguate appid extension output behaviour
- [webauthn] new commits pushed by emlun
- Re: [webauthn] Add recommendation of scoping platform credentials to OS accounts
- Re: [webauthn] Add table numbers and captions
- [webauthn] Pull Request: Add table numbers and captions
- [w3c/webauthn] d45d8f: Add table numbers and captions
- [webauthn] new commits pushed by emlun
- Re: [webauthn] What does "the extension was acted upon" mean for the AppID extension?
- [w3c/webauthn] d95918: Address review comments
- [webauthn] new commits pushed by emlun
- Re: [webauthn] add captions for tables and id attrs so we can link to them
- Re: [webauthn] Indicate resident key credential "preferred" during registration and find out what the authenticator offered
- Re: [webauthn] Authenticator taxonomy: Authenticator types
- Re: [webauthn] Add recommendation of scoping platform credentials to OS accounts
- Re: [webauthn] fix 864: Note regarding CTAP2 integer keys vs webauthn string keys
- Re: [webauthn] Authenticator taxonomy: Attachment modality (replaces #842)
- [webauthn] Pull Request: Replace resident key terminology as proposed in #905
- [w3c/webauthn] 010874: Replace Client-side-resident Credential Private Ke...
- [webauthn] new commits pushed by emlun
- [w3c/webauthn]
- [webauthn] Closed Pull Request: Remove undefined macro reference [RP ID]
- Re: [webauthn] Remove undefined macro reference [RP ID]
- Re: [webauthn] What does "the extension was acted upon" mean for the AppID extension?
- [webauthn] Pull Request: Remove undefined macro reference [RP ID]
- [w3c/webauthn] 0a4120: Remove undefined macro reference [RP ID]
- [webauthn] new commits pushed by emlun
- Re: [webauthn] add captions for tables and id attrs so we can link to them
- [w3c/webauthn] 96ba75: Fully qualify modality terms
- Re: [webauthn] Eliminate duplicate terminology
- Re: [webauthn] Public key rules for "packed" attestation type
- Re: [webauthn] Indicate resident key credential "preferred" during registration and find out what the authenticator offered
- [webauthn] Indicate resident key credential "preferred" during registration and find out what the authenticator offered
- Re: [webauthn] add captions for tables and id attrs so we can link to them
- Re: [webauthn] Public key rules for "packed" attestation type
- Re: [webauthn] What does "the extension was acted upon" mean for the AppID extension?
- Re: [webauthn] Public key rules for "packed" attestation type
- Re: [webauthn] What does "the extension was acted upon" mean for the AppID extension?
- Re: [webauthn] truncation to 64-byte upper limit doesn't mention character boundaries
Tuesday, 10 July 2018
- Re: [webauthn] AppID extension: protocol version number?
- Closed: [webauthn] Requesting ability to detect if there is an authenticator available which is capable of resident key credential
- Re: [webauthn] Requesting ability to detect if there is an authenticator available which is capable of resident key credential
- 07/11/2018 W3C Web Authentication WG Meeting Agenda
- Re: [webauthn] Partial dictionaries for extension outputs may be incorrect use of WebIDL
- Re: [webauthn] Requesting ability to detect if there is an authenticator available which is capable of resident key credential
- Re: [webauthn] Eliminate duplicate terminology
- [webauthn] add captions for tables and id attrs so we can link to them
- [w3c/webauthn] f749dc: 'client' rather than 'client platform'
- [webauthn] new commits pushed by equalsJeffH
- Closed: [webauthn] Requesting ability to detect if there is an authenticator available which is capable of resident key credential
- Re: [webauthn] Requesting ability to detect if there is an authenticator available which is capable of resident key credential
- Re: Scribing tomorrow
- Scribing tomorrow
- EnclaveDB: a secure database using SGX
- Re: [webauthn] What does "the extension was acted upon" mean for the AppID extension?
- Re: [webauthn] truncation to 64-byte upper limit doesn't mention character boundaries
Monday, 9 July 2018
- Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
- Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
- Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
- Re: [webauthn] Privacy across OS accounts
- Re: [webauthn] truncation to 64-byte upper limit doesn't mention character boundaries
- Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
- Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
- Re: [webauthn] fix 864: Note regarding CTAP2 integer keys vs webauthn string keys
- Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
- Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
- [w3c/webauthn] 4a2dd4: fix #180: do not totally lose the term "WebAuthn R...
- [webauthn] new commits pushed by emlun
- [w3c/webauthn] 4a2dd4: fix #180: do not totally lose the term "WebAuthn R...
- [webauthn] new commits pushed by emlun
- Re: [webauthn] bikeshed now catching existing lint in master->index.bs
- Re: [webauthn] Privacy across OS accounts
- [w3c/webauthn] ada317: Expand OS acronym in section title
- [webauthn] Pull Request: Add recommendation of scoping platform credentials to OS accounts
- [webauthn] new commits pushed by emlun
- [w3c/webauthn] e132d0: Add recommendation of scoping platform credentials...
- [webauthn] new commits pushed by emlun
- [webauthn] Partial dictionaries for extension outputs may be incorrect use of WebIDL
- Re: [webauthn] What does "the extension was acted upon" mean for the AppID extension?
- [w3c/webauthn]
- Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
- Re: [webauthn] Tighten security scope by port
- Re: [webauthn] Privacy across OS accounts
- Re: [webauthn] truncation to 64-byte upper limit doesn't mention character boundaries
- [webauthn] Requesting ability to detect if there is an authenticator available which is capable of resident key credential
Saturday, 7 July 2018
- Re: [webauthn] truncation to 64-byte upper limit doesn't mention character boundaries
- Re: [webauthn] truncation to 64-byte upper limit doesn't mention character boundaries
Friday, 6 July 2018
- Re: [webauthn] Privacy across OS accounts
- [webauthn] Pull Request: fix 864: Note regarding CTAP2 integer keys vs webauthn string keys
- Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
- [w3c/webauthn] 71da52: polish
- [webauthn] new commits pushed by equalsJeffH
- Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
- [w3c/webauthn] e59483: fix 864: added Note
- [webauthn] new commits pushed by equalsJeffH
- Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
- [w3c/webauthn] 4a2dd4: fix #180: do not totally lose the term "WebAuthn R...
- [webauthn] new commits pushed by equalsJeffH
- [w3c/webauthn] cc7aff: Built by Travis-CI: a96110e1d087a09dada43ceb7fe5a6...
- [w3c/webauthn] 87d5ec: Built by Travis-CI: a96110e1d087a09dada43ceb7fe5a6...
- [webauthn] new commits pushed by WebAuthnBot
- [webauthn] new commits pushed by WebAuthnBot
- [w3c/webauthn] a96110: fix #866: clarify sentence wrt challenges (#977)
- [webauthn] Merged Pull Request: fix #866: clarify sentence wrt challenges
- Closed: [webauthn] Grammar error in Sec 13.1
- [webauthn] new commits pushed by equalsJeffH
- [w3c/webauthn]
- [w3c/webauthn]
- [w3c/webauthn] 4a2dd4: fix #180: do not totally lose the term "WebAuthn R...
- [webauthn] new commits pushed by equalsJeffH
- [w3c/webauthn] 8c453c: Built by Travis-CI: 6a6bf465c54a8ad4737c8064587b66...
- [w3c/webauthn] eb5a10: Built by Travis-CI: 6a6bf465c54a8ad4737c8064587b66...
- [webauthn] new commits pushed by WebAuthnBot
- [webauthn] new commits pushed by WebAuthnBot
- [w3c/webauthn] b4b0d1: Built by Travis-CI: 4a2dd437f11fd5802560c64e3615bc...
- [w3c/webauthn] bc25ca: Built by Travis-CI: 4a2dd437f11fd5802560c64e3615bc...
- [webauthn] new commits pushed by WebAuthnBot
- [w3c/webauthn] 6a6bf4: add domain-only rationale in two places (#975)
- [webauthn] new commits pushed by WebAuthnBot
- Closed: [webauthn] document why only "valid domain" format is allowed for "effective domain"
- [webauthn] new commits pushed by equalsJeffH
- [webauthn] Merged Pull Request: fix #517: add rationale wrt only "valid domain" format is allowed for "effective domain"
- [w3c/webauthn] 4a2dd4: fix #180: do not totally lose the term "WebAuthn R...
- [webauthn] new commits pushed by equalsJeffH
- [webauthn] Merged Pull Request: fix #180: do not totally lose the term "WebAuthn Relying Party"
- Closed: [webauthn] do not totally lose the term "WebAuthn Relying Party"
- Re: [webauthn] Add two abort paths for getting an assertion
- [webauthn] add abort path to createCredential alg to match that added to getAssertion alg
- Re: [webauthn] Tighten security scope by port
- Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
- Re: [webauthn] Platform authenticators and key stores
- RE: WebAuthn/WebPayments/PSD2 Demos
- Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
- Re: WebAuthn/WebPayments/PSD2 Demos
- [w3c/webauthn] 62d97b: Remove old references to deleted use case descript...
- [webauthn] new commits pushed by emlun
- [w3c/webauthn] 8babb6: Address @selfissued's review comments
- [webauthn] new commits pushed by emlun
- Re: [webauthn] Allow clients to stop the `get` flow when certain conditions are met
- Re: [webauthn] authenticatorGetAssertion has no ConstraintError step for requireUserVerification
- Reminder and additional information - Re: TPAC 2018 registration now open
- Re: [webauthn] Transaction authorization extensions are registration and authentication extension?
- Re: [webauthn] Platform authenticators and key stores
- Re: [webauthn] truncation to 64-byte upper limit doesn't mention character boundaries
Thursday, 5 July 2018
- Re: [webauthn] Tighten security scope by port
- Re: [webauthn] Consider allowing RPs to indicate that they want platform authenticators to be synced across devices
- Re: [webauthn] truncation to 64-byte upper limit doesn't mention character boundaries
- Re: [webauthn] authenticatorGetAssertion has no ConstraintError step for requireUserVerification
- Re: [webauthn] AppID extension: protocol version number?
- Re: [webauthn] SafetyNet Attestation Clarifications
- Re: [webauthn] SafetyNet Attestation Clarifications
- Re: [webauthn] Authenticator taxonomy: Authenticator types
- Re: [webauthn] Add two abort paths for getting an assertion
- Re: [webauthn] fix 364 timeout reasonable range
- Re: [webauthn] Decoding TPM `certInfo` and `pubArea`?
- Re: [webauthn] fix #180: do not totally lose the term "WebAuthn Relying Party"
- Re: [webauthn] fix #517: add rationale wrt only "valid domain" format is allowed for "effective domain"
- Re: [webauthn] fix #866: clarify sentence wrt challenges
- Closed: [webauthn] Decoding TPM `certInfo` and `pubArea`?
- Re: [webauthn] Decoding TPM `certInfo` and `pubArea`?
- Re: [webauthn] Decoding TPM `certInfo` and `pubArea`?
Wednesday, 4 July 2018
- Re: [webauthn] Decoding TPM `certInfo` and `pubArea`?
- Re: [webauthn] Decoding TPM `certInfo` and `pubArea`?
- Re: [webauthn] Decoding TPM `certInfo` and `pubArea`?
- Re: [webauthn] Decoding TPM `certInfo` and `pubArea`?
- Re: [webauthn] Decoding TPM `certInfo` and `pubArea`?
- [webauthn] Decoding TPM `certInfo` and `pubArea`?
- Re: [webauthn] Authenticator taxonomy: Authenticator types
- [webauthn] authenticatorGetAssertion has no ConstraintError step for requireUserVerification
- [w3c/webauthn] 2abe4c: Rewrite Authenticator taxonomy section introductio...
- [webauthn] new commits pushed by emlun
- Closed: [webauthn] credential id privacy
- Re: [webauthn] credential id privacy
Tuesday, 3 July 2018
- Re: [webauthn] AppID extension: protocol version number?
- Re: [webauthn] What does "the extension was acted upon" mean for the AppID extension?
- Re: [webauthn] What does "the extension was acted upon" mean for the AppID extension?
- Re: [webauthn] AppID extension: protocol version number?
- Re: [webauthn] What does "the extension was acted upon" mean for the AppID extension?
- Re: [webauthn] What does "the extension was acted upon" mean for the AppID extension?
- [webauthn] What does "the extension was acted upon" mean for the AppID extension?
- 07/04/2018 W3C Web Authentication WG Meeting Agenda - Meeting cancelled
Monday, 2 July 2018
- [webauthn] Public key rules for "packed" attestation type
- [webauthn] Clarification of valid prIdHash value requested in section 7 when using AppID extension
- Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
- [w3c/webauthn] e243c2: revise RP ID definition and Note (#970)
- [webauthn] new commits pushed by emlun
- Re: [webauthn] WIP: Authenticator taxonomy (replaces #842)
- [w3c/webauthn] e243c2: revise RP ID definition and Note (#970)
- [webauthn] new commits pushed by emlun
- Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
- Re: [webauthn] WIP: Authenticator taxonomy (replaces #842)
- [w3c/webauthn] 46d1fd: Remove now unused image file
- [w3c/webauthn] 46d1fd: Remove now unused image file
- [webauthn] new commits pushed by emlun
- [webauthn] new commits pushed by emlun
- [webauthn] Pull Request: WIP: Authenticator taxonomy: Use cases
- [w3c/webauthn] 699c58: Revert "Add Issue: pointing out that Authenticator...
- [webauthn] new commits pushed by emlun
- [w3c/webauthn] 265fd3: Remove draft of use case descriptions
- [webauthn] new commits pushed by emlun
- Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
- [webauthn] MUST authenticators still perform self attestation?
- Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way