Tuesday, 31 July 2018
- Fwd: Reminder - Re: TPAC 2018 registration now open
 - Re: [webauthn] Bad instructions in Android SafetyNet attestation validation steps
 - Re: [webauthn] Bad instructions in Android SafetyNet attestation validation steps
 
Monday, 30 July 2018
Sunday, 29 July 2018
Saturday, 28 July 2018
Friday, 27 July 2018
- [webauthn] Pull Request: fix #712 JSON-serialized client data is wrong
 - [w3c/webauthn] acb0f6: fix #712 JSON-serialized client data is wrong
 - [webauthn] new commits pushed by equalsJeffH
 - Re: [webauthn] NULL or DOMException
 - Re: [webauthn] Minor typo - FAR should be FRR
 - [webauthn] Pull Request: fix #1015 FAR should be FRR
 - [w3c/webauthn] 9dbcd9: fix #1015 FAR should be FRR
 - [webauthn] new commits pushed by equalsJeffH
 - fyi: Postponed by 8 days - Call for Participation: W3C Workshop on Permissions and User Consent
 - Re: [webauthn] Explain how Token Binding IDs get associated with an HTML context.
 
Thursday, 26 July 2018
- RE: lock the webauthn repo?
 - RE: lock the webauthn repo?
 - lock the webauthn repo?
 - Request to Update Candidate Recommendation for WebAuthn API
 - Invite to Dependent WGs to review WebAuthn API CR update
 - [w3c/webauthn] 4df371: Built by Travis-CI: 243e72f84a35f7d2774dbfbc8da58e...
 - [webauthn] new commits pushed by WebAuthnBot
 - [w3c/webauthn] 671ba7: Built by Travis-CI: 243e72f84a35f7d2774dbfbc8da58e...
 - [webauthn] new commits pushed by WebAuthnBot
 - [w3c/webauthn]
 - [w3c/webauthn] 243e72: update acks (#1013)
 - [webauthn] Merged Pull Request: update acks
 - [webauthn] new commits pushed by equalsJeffH
 - Re: [webauthn] Tighten security scope by port
 - Re: [webauthn] Minor typo - FAR should be FRR
 - Re: [webauthn] Determining length of `attestedCredentialData` when authenticator extensions present.
 - Security threat: Username enumeration
 - Re: [webauthn] Tighten security scope by port
 - Re: [webauthn] SafetyNet response as an extension
 - [webauthn] Minor typo - FAR should be FRR
 - Re: [webauthn] Determining length of `attestedCredentialData` when authenticator extensions present.
 - [webauthn] Security threat: Username enumeration
 
Wednesday, 25 July 2018
- Re: [webauthn] Clarify behaviour of rawId and id fields for resident key credentials
 - Closed: [webauthn] Clarify behaviour of rawId and id fields for resident key credentials
 - [webauthn] Pull Request: update acks
 - [w3c/webauthn] e95d78: update acks
 - [webauthn] new commits pushed by equalsJeffH
 - [w3c/webauthn] 8161da: Built by Travis-CI: 81e8056e275eed52606b7eb406ee42...
 - [webauthn] new commits pushed by WebAuthnBot
 - [w3c/webauthn] 617d83: Built by Travis-CI: 81e8056e275eed52606b7eb406ee42...
 - [webauthn] new commits pushed by WebAuthnBot
 - [w3c/webauthn]
 - [w3c/webauthn] 81e805: fix #24: add reg & authn flow diagrams (#1007)
 - [webauthn] new commits pushed by equalsJeffH
 - [webauthn] Merged Pull Request: fix #24: add reg & authn flow diagrams
 - Closed: [webauthn] need description & illustrations of overall flow: authnr <--> platform API <--> RP
 - [w3c/webauthn] 8b0eb7: Precisize "platform" and "device" terminology (#99...
 - [webauthn] new commits pushed by equalsJeffH
 - Re: [webauthn] Determining length of `attestedCredentialData` when authenticator extensions present.
 - Re: [webauthn] Determining length of `attestedCredentialData` when authenticator extensions present.
 - Re: [webauthn] Clarify behaviour of rawId and id fields for resident key credentials
 - Re: [webauthn] NULL or DOMException
 - Re: [webauthn] coalesce HTML references?
 - Re: [webauthn] coalesce HTML references?
 - Re: [webauthn] NULL or DOMException
 - Re: [webauthn] NULL or DOMException
 - Re: [webauthn] NULL or DOMException
 - Re: [webauthn] NULL or DOMException
 - Re: [webauthn] `publicKey` member name in `CredentialCreationRequestOptions` should be `"public-key"`, or vice-versa?
 - Re: [webauthn] SafetyNet response as an extension
 - LInks wrt publishing revised CR (was: Consensus on CR revision of WebAuthn)
 - Re: [webauthn] SafetyNet response as an extension
 - Re: [webauthn] SafetyNet response as an extension
 - Re: [webauthn] `publicKey` member name in `CredentialCreationRequestOptions` should be `"public-key"`, or vice-versa?
 - Re: [webauthn] SafetyNet response as an extension
 - [webauthn] Determining length of `attestedCredentialData` when authenticator extensions present.
 - Re: [webauthn] SafetyNet response as an extension
 - Re: [webauthn] SafetyNet response as an extension
 - Re: [webauthn] add abort path to createCredential alg to match that added to getAssertion alg
 - Closed: [webauthn] add abort path to createCredential alg to match that added to getAssertion alg
 - Re: [webauthn] Integrate with Feature Policy and define Feature-Identifier value for WebAuthn
 - Re: [webauthn] SafetyNet response as an extension
 - Re: [webauthn] Propose SafetyNet as an extension
 - Re: [webauthn] SafetyNet response as an extension
 - Re: [webauthn] SafetyNet response as an extension
 - Re: [webauthn] SafetyNet response as an extension
 - Re: [webauthn] SafetyNet response as an extension
 - Re: [webauthn] SafetyNet response as an extension
 - [w3c/webauthn]
 - Re: [webauthn] SafetyNet response as an extension
 - Re: [webauthn] SafetyNet response as an extension
 - [w3c/webauthn] 3c4c8e: Built by Travis-CI: 0f38025c4acdd36f1e595432ac30aa...
 - [w3c/webauthn] bcad9c: Built by Travis-CI: 0f38025c4acdd36f1e595432ac30aa...
 - [webauthn] new commits pushed by WebAuthnBot
 - [webauthn] new commits pushed by WebAuthnBot
 - Re: [webauthn] fix #24: add reg & authn flow diagrams
 - [w3c/webauthn] 0f3802: fix #939 add intro abort lang to getAssn (#1006)
 - Closed: [webauthn] introductory abort language missing from [[Get]]() section
 - [webauthn] Merged Pull Request: fix #939 add intro abort language to #getAssertion
 - [webauthn] new commits pushed by equalsJeffH
 - [w3c/webauthn] 4580bd: fix 985 add abort path to createCredential alg (#1...
 - [webauthn] Merged Pull Request: fix 985 add abort path to createCredential alg
 - [webauthn] new commits pushed by equalsJeffH
 - [webauthn] SafetyNet response as an extension
 - [webauthn] Pull Request: Propose SafetyNet as an extension
 - [w3c/webauthn] a0a995: Built by Travis-CI: 7159c08b280b82a9a8d00d35212470...
 - [webauthn] new commits pushed by WebAuthnBot
 - Re: [webauthn] Integrate with Feature Policy and define Feature-Identifier value for WebAuthn
 - [w3c/webauthn] 564198: Built by Travis-CI: 7159c08b280b82a9a8d00d35212470...
 - [webauthn] new commits pushed by WebAuthnBot
 - [w3c/webauthn] 62cdb5: Clarify behaviour for authnrs not implementing sig...
 - [webauthn] Merged Pull Request: Clarify behaviour for authnrs not implementing signature counter
 - [webauthn] new commits pushed by emlun
 - Closed: [webauthn] Clarify authenticator behaviour when not implementing signature counter
 - Re: [webauthn] Clarify behaviour for authnrs not implementing signature counter
 - Re: [webauthn] fix 985 add abort path to createCredential alg
 - Re: [webauthn] fix #939 add intro abort language to #getAssertion
 - Re: [webauthn] fix #24: add reg & authn flow diagrams
 - Re: [webauthn] `publicKey` member name in `CredentialCreationRequestOptions` should be `"public-key"`, or vice-versa?
 - Re: [webauthn] Clarify authenticator behaviour when not implementing signature counter
 - coalesce HTML references?
 - [webauthn] Pull Request: Clarify behaviour for authnrs not implementing signature counter
 - [webauthn] new commits pushed by emlun
 - [w3c/webauthn] 62cdb5: Clarify behaviour for authnrs not implementing sig...
 - [webauthn] Clarify authenticator behaviour when not implementing signature counter
 - [w3c/webauthn]
 - [webauthn] Closed Pull Request: Removed old optional counter step to remove confusions
 - Re: [webauthn] Removed old optional counter step to remove confusions
 - Re: [webauthn] Removed old optional counter step to remove confusions
 
Tuesday, 24 July 2018
- 07/25/2018 W3C Web Authentication WG Meeting Agenda
 - Re: [webauthn] Integrate with Feature Policy and define Feature-Identifier value for WebAuthn
 - Re: Consensus on CR revision of WebAuthn
 - Re: Consensus on CR revision of WebAuthn
 - [w3c/webauthn] 25b0ff: Built by Travis-CI: 8b0eb719f2061d6d1d7c74a3677884...
 - [w3c/webauthn] 791957: Built by Travis-CI: 8b0eb719f2061d6d1d7c74a3677884...
 - [webauthn] new commits pushed by WebAuthnBot
 - [webauthn] new commits pushed by WebAuthnBot
 - [w3c/webauthn] 8b0eb7: Precisize "platform" and "device" terminology (#99...
 - [webauthn] new commits pushed by equalsJeffH
 - [webauthn] Merged Pull Request: Precisize "platform" and "device" terminology
 - Re: [webauthn] Precisize "platform" and "device" terminology
 - Re: [webauthn] JSON-serialized client data is wrong
 - Consensus on CR revision of WebAuthn
 - WebAuthn now on CanIUse
 - Re: [webauthn] fix #24: add reg & authn flow diagrams
 - Re: [webauthn] need description & illustrations of overall flow: authnr <--> platform API <--> RP
 - [webauthn] Pull Request: fix #24: add reg & authn flow diagrams
 - [w3c/webauthn] 564fa0: renumber figure references
 - [webauthn] new commits pushed by equalsJeffH
 - [w3c/webauthn] 6eb470: fix #24: add reg & authn flow diagrams, thanks apo...
 - [webauthn] new commits pushed by equalsJeffH
 - Re: [webauthn] AppID extension: protocol version number?
 - Re: [webauthn] NULL or DOMException
 - Re: [webauthn] Precisize "platform" and "device" terminology
 - Re: [webauthn] Authenticator selection extension needs to define snapshotting behavior
 - [webauthn] Pull Request: fix #939 add intro abort language to #getAssertion
 - [w3c/webauthn] 397912: fix #939 add intro abort lang to getAssn
 - [webauthn] new commits pushed by equalsJeffH
 - [webauthn] Pull Request: fix 985 add abort path to createCredential alg
 - [w3c/webauthn] 2b1680: fix 985 add abort path to createCredential alg
 - [webauthn] new commits pushed by equalsJeffH
 - Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
 
Monday, 23 July 2018
- Re: [webauthn] `publicKey` member name in `CredentialCreationRequestOptions` should be `"public-key"`, or vice-versa?
 - Re: [webauthn] `publicKey` member name in `CredentialCreationRequestOptions` should be `"public-key"`, or vice-versa?
 - [webauthn] `publicKey` member name in `CredentialCreationRequestOptions` should be `"public-key"`, or vice-versa?
 - Re: [webauthn] Removed old optional counter step to remove confusions
 
Sunday, 22 July 2018
- [webauthn] Pull Request: Removed old optional counter step to remove confusions
 - Re: [webauthn] Sign counter alg 507 alternative: optional sig counter
 
Friday, 20 July 2018
Thursday, 19 July 2018
- Reminder - Re: TPAC 2018 registration now open
 - Re: [webauthn] Clarify behaviour of rawId and id fields for resident key credentials
 - Re: [webauthn] Clarify behaviour of rawId and id fields for resident key credentials
 - Re: [webauthn] Clarify behaviour of rawId and id fields for resident key credentials
 - Re: Summit on Recovering from Device Loss in WebAuthn
 
Wednesday, 18 July 2018
- Re: [webauthn] truncation to 64-byte upper limit doesn't mention character boundaries
 - Re: [webauthn] Revise same-origin as ancestor requirements
 - Re: [webauthn] Clarify behaviour of rawId and id fields for resident key credentials
 - wrt issue #973 truncation to 64-byte upper limit doesn't mention character boundaries
 - Re: [webauthn] truncation to 64-byte upper limit doesn't mention character boundaries
 - Re: [webauthn] truncation to 64-byte upper limit doesn't mention character boundaries
 - Re: [webauthn] Revise same-origin as ancestor requirements
 - Re: [webauthn] Revise same-origin as ancestor requirements
 - Re: [webauthn] Partial dictionaries for extension outputs may be incorrect use of WebIDL
 - Re: [webauthn] Partial dictionaries for extension outputs may be incorrect use of WebIDL
 - Re: [webauthn] Revise same-origin as ancestor requirements
 - Re: [webauthn] Clarify behaviour of rawId and id fields for resident key credentials
 - Re: [webauthn] some RPs may wish to allow multiple registrations to same user account
 - Re: [webauthn] AppID extension: protocol version number?
 - [w3c/webauthn] 249d60: Built by Travis-CI: 741cef6e2ce342e700b03662f688ef...
 - [webauthn] new commits pushed by WebAuthnBot
 - [w3c/webauthn]
 - [w3c/webauthn] 911864: Make transaction authorization extensions authenti...
 - [webauthn] Merged Pull Request: Make transaction authorization extensions authentication exts only
 - [webauthn] new commits pushed by emlun
 - Closed: [webauthn] Transaction authorization extensions are registration and authentication extension?
 - Re: [webauthn] Allow clients to stop the `get` flow when certain conditions are met
 - Closed: [webauthn] Allow clients to stop the `get` flow when certain conditions are met
 - Re: [webauthn] Allow clients to stop the `get` flow when certain conditions are met
 - Re: [webauthn] Make transaction authorization extensions authentication exts only
 - [webauthn] Pull Request: Make transaction authorization extensions authentication exts only
 - [w3c/webauthn] 911864: Make transaction authorization extensions authenti...
 - [webauthn] new commits pushed by emlun
 - [w3c/webauthn] 3cc531: Built by Travis-CI: 8d6b9ac209154be39fa6e08bb8e80f...
 - [webauthn] new commits pushed by WebAuthnBot
 - Re: [webauthn] Transaction authorization extensions are registration and authentication extension?
 - [w3c/webauthn] ffcd4d: Built by Travis-CI: 8d6b9ac209154be39fa6e08bb8e80f...
 - [webauthn] new commits pushed by WebAuthnBot
 - [w3c/webauthn]
 - [w3c/webauthn] 862f42: Replace local/remote storage terms with client/ser...
 - [w3c/webauthn] 768368: Fix spelling mistake
 - [webauthn] new commits pushed by emlun
 - [webauthn] Merged Pull Request: Replace local/remote storage terms with client/server side
 - [webauthn] new commits pushed by emlun
 - [w3c/webauthn]
 - [w3c/webauthn]
 - [w3c/webauthn] ed3abe: Add two abort paths for getting an assertion.
 - [webauthn] new commits pushed by emlun
 - [w3c/webauthn] ab9140: Built by Travis-CI: faee219e5bc1b9ceb8c83ccdb316d2...
 - [w3c/webauthn] 414651: Built by Travis-CI: faee219e5bc1b9ceb8c83ccdb316d2...
 - [webauthn] new commits pushed by WebAuthnBot
 - [webauthn] new commits pushed by WebAuthnBot
 - [w3c/webauthn] 50f0f6: Built by Travis-CI: a0d84c1f4c470251453fef8e4171b8...
 - [webauthn] new commits pushed by WebAuthnBot
 - [w3c/webauthn] 38f9d8: Built by Travis-CI: a0d84c1f4c470251453fef8e4171b8...
 - [webauthn] new commits pushed by WebAuthnBot
 - [w3c/webauthn] a0d84c: fix 933: authnr does not enforce RP ID being eTLD+...
 - [w3c/webauthn] d45d8f: Add table numbers and captions
 - [webauthn] Merged Pull Request: fix 933: authnr does not enforce RP ID being eTLD+1 of RP's origin
 - [webauthn] new commits pushed by equalsJeffH
 - Closed: [webauthn] #sec-authenticator-data section implies authnr enforces RP ID being eTLD+1
 - [webauthn] Merged Pull Request: Add table numbers and captions
 - [webauthn] new commits pushed by emlun
 - Closed: [webauthn] add captions for tables and id attrs so we can link to them
 - Re: [webauthn] Transaction authorization extensions are registration and authentication extension?
 - Re: [webauthn] Precisize "platform" and "device" terminology
 - [w3c/webauthn] ed3abe: Add two abort paths for getting an assertion.
 - [webauthn] new commits pushed by emlun
 - 07/18/2018 W3C Web Authentication WG Meeting Agenda
 - [webauthn] Revise same-origin as ancestor requirements
 
Tuesday, 17 July 2018
- [w3c/webauthn] 9c34ec: Built by Travis-CI: bf4dbab0541a445b79bcf20f38ccd6...
 - [webauthn] new commits pushed by WebAuthnBot
 - [w3c/webauthn] ed3abe: Add two abort paths for getting an assertion.
 - [webauthn] new commits pushed by agl
 - [webauthn] Merged Pull Request: Add two abort paths for getting an assertion
 - Summit on Recovering from Device Loss in WebAuthn
 - Re: [webauthn] JSON-serialized client data is wrong
 
Monday, 16 July 2018
- [w3c/webauthn] 280494: Colocate <dfn> of Client with WebAuthn Client
 - [webauthn] new commits pushed by emlun
 
Sunday, 15 July 2018
Saturday, 14 July 2018
Friday, 13 July 2018
- Re: [webauthn] Precisize "platform" and "device" terminology
 - [webauthn] Pull Request: fix 933: authnr does not enforce RP ID being eTLD+1 of RP's origin
 - [w3c/webauthn] 8f2767: remove inapprop phrase and link some terms
 - [webauthn] new commits pushed by equalsJeffH
 - Re: [webauthn] Precisize "platform" and "device" terminology
 - Re: [webauthn] Precisize "platform" and "device" terminology
 - Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
 - Re: [webauthn] Precisize "platform" and "device" terminology
 - Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
 - Re: [webauthn] Precisize "platform" and "device" terminology
 - [webauthn] Pull Request: Precisize "platform" and "device" terminology
 - [w3c/webauthn] 12e5fb: Add term Client Platform
 - [webauthn] new commits pushed by emlun
 - [w3c/webauthn] 0c0c79: Built by Travis-CI: f864d09715352ba30390664aa42518...
 - [w3c/webauthn] ba407b: Built by Travis-CI: f864d09715352ba30390664aa42518...
 - [webauthn] new commits pushed by WebAuthnBot
 - [webauthn] new commits pushed by WebAuthnBot
 - [w3c/webauthn] f864d0: Fix #593: employ PRECIS RFC8264 et al for 'name'-i...
 - Re: [webauthn] Fix #593: employ PRECIS RFC8264 et al for 'name'-ish domstring values
 - [webauthn] new commits pushed by equalsJeffH
 - [webauthn] Merged Pull Request: Fix #593: employ PRECIS RFC8264 et al for 'name'-ish domstring values
 - Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
 - Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
 
Thursday, 12 July 2018
- Re: [webauthn] truncation to 64-byte upper limit doesn't mention character boundaries
 - Re: [webauthn] truncation to 64-byte upper limit doesn't mention character boundaries
 - fyi: W3C Workshop on Permissions and User Consent
 - [webauthn] Pull Request: Replace local/remote storage terms with client/server side
 - [w3c/webauthn] 862f42: Replace local/remote storage terms with client/ser...
 - [webauthn] new commits pushed by emlun
 - Re: [webauthn] Add table numbers and captions
 - Re: [webauthn] Add table numbers and captions
 - [w3c/webauthn] bc1589: Add caption and number to authenticator types tabl...
 - [webauthn] new commits pushed by emlun
 - Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
 - [w3c/webauthn] e949d5: Built by Travis-CI: 7e5256f6f564fa99f68e4512340214...
 - [w3c/webauthn] a0dd8d: Built by Travis-CI: 7e5256f6f564fa99f68e4512340214...
 - [webauthn] new commits pushed by WebAuthnBot
 - [webauthn] new commits pushed by WebAuthnBot
 - [w3c/webauthn]
 - [w3c/webauthn] 010874: Replace Client-side-resident Credential Private Ke...
 - [webauthn] new commits pushed by emlun
 - [webauthn] Merged Pull Request: Replace resident key terminology as proposed in #905
 - Re: [webauthn] Clarify WebAuthn spec to allow us to return an error to RP when it makes sense
 - Re: [webauthn] Add table numbers and captions
 - Re: [webauthn] truncation to 64-byte upper limit doesn't mention character boundaries
 - [w3c/webauthn] 1e3241: Add link to "attachment modality" reference
 - [webauthn] new commits pushed by equalsJeffH
 - Closed: [webauthn] Clarify WebAuthn spec to allow us to return an error to RP when it makes sense
 - Re: [webauthn] Clarify WebAuthn spec to allow us to return an error to RP when it makes sense
 
Wednesday, 11 July 2018
- Re: [webauthn] Platform authenticators and key stores
 - Re: [webauthn] Fix #593: employ PRECIS RFC8264 et al for 'name'-ish domstring values
 - [w3c/webauthn] 4ddc3c: add presentation admonition wrt name-ish strings
 - [webauthn] new commits pushed by equalsJeffH
 - Re: [webauthn] truncation to 64-byte upper limit doesn't mention character boundaries
 - Re: [webauthn] Fix #593: employ PRECIS RFC8264 et al for 'name'-ish domstring values
 - Re: [webauthn] Fix #593: employ PRECIS RFC8264 et al for 'name'-ish domstring values
 - [webauthn] coalesce HTML references?
 - Re: [webauthn] Replace resident key terminology as proposed in #905
 - [w3c/webauthn] 1e3241: Add link to "attachment modality" reference
 - [webauthn] new commits pushed by equalsJeffH
 - Re: [webauthn] Fix #593: employ PRECIS RFC8264 et al for 'name'-ish domstring values
 - wrt issue #750 `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
 - [w3c/webauthn]
 - [w3c/webauthn]
 - [w3c/webauthn] 66d00c: Built by Travis-CI: ca80875c6dc6b6f0eb3f4a02f39774...
 - [webauthn] new commits pushed by WebAuthnBot
 - [w3c/webauthn] dcb394: Built by Travis-CI: ca80875c6dc6b6f0eb3f4a02f39774...
 - [webauthn] new commits pushed by WebAuthnBot
 - [w3c/webauthn] 699c58: Revert "Add Issue: pointing out that Authenticator...
 - [webauthn] new commits pushed by emlun
 - [webauthn] Merged Pull Request: Authenticator taxonomy: Authenticator types
 - Re: [webauthn] authenticatorGetAssertion has no ConstraintError step for requireUserVerification
 - Closed: [webauthn] authenticatorGetAssertion has no ConstraintError step for requireUserVerification
 - Re: [webauthn] authenticatorGetAssertion has no ConstraintError step for requireUserVerification
 - [w3c/webauthn] 671666: Built by Travis-CI: 005ec66866c2f3329f6c780a9351df...
 - [w3c/webauthn] 4e9893: Built by Travis-CI: 005ec66866c2f3329f6c780a9351df...
 - [webauthn] new commits pushed by WebAuthnBot
 - [webauthn] new commits pushed by WebAuthnBot
 - [w3c/webauthn]
 - [w3c/webauthn] 905de0: Disambiguate appid extension output behaviour
 - [webauthn] Merged Pull Request: Disambiguate appid extension output behaviour
 - [webauthn] new commits pushed by emlun
 - Closed: [webauthn] What does "the extension was acted upon" mean for the AppID extension?
 - Re: [webauthn] Display name content rules?
 - Closed: [webauthn] Display name content rules?
 - Re: [webauthn] add abort path to createCredential alg to match that added to getAssertion alg
 - [w3c/webauthn] 369e2c: Built by Travis-CI: 9033fc6fccd602c3705a43927e11b5...
 - [webauthn] new commits pushed by WebAuthnBot
 - [webauthn] new commits pushed by WebAuthnBot
 - [w3c/webauthn] 11ffca: Built by Travis-CI: 9033fc6fccd602c3705a43927e11b5...
 - [w3c/webauthn] 9033fc: fix 364 timeout reasonable range (#971)
 - [webauthn] Merged Pull Request: fix 364 timeout reasonable range
 - Closed: [webauthn] Constrain the "reasonable range" of timeouts
 - [webauthn] new commits pushed by equalsJeffH
 - [w3c/webauthn] 8a75d7: Built by Travis-CI: 321e805b763bc86ff996403da6bfd1...
 - [w3c/webauthn] 6da4bb: Built by Travis-CI: 321e805b763bc86ff996403da6bfd1...
 - [webauthn] new commits pushed by WebAuthnBot
 - [webauthn] new commits pushed by WebAuthnBot
 - [w3c/webauthn] b9e873: Built by Travis-CI: 7709911ace404df7f6d01151cdef10...
 - [webauthn] new commits pushed by WebAuthnBot
 - [w3c/webauthn] ae7502: Built by Travis-CI: 7709911ace404df7f6d01151cdef10...
 - [webauthn] new commits pushed by WebAuthnBot
 - [w3c/webauthn] 7958a9: Built by Travis-CI: fe09a70a41372690257fa3730a6dc8...
 - [w3c/webauthn] 321e80: Add recommendation of scoping platform credentials...
 - [w3c/webauthn] 91d059: Built by Travis-CI: fe09a70a41372690257fa3730a6dc8...
 - [webauthn] Merged Pull Request: Add recommendation of scoping platform credentials to OS accounts
 - [webauthn] new commits pushed by WebAuthnBot
 - [webauthn] new commits pushed by equalsJeffH
 - Closed: [webauthn] Privacy across OS accounts
 - [w3c/webauthn] 770991: fix 864: Note regarding CTAP2 integer keys vs weba...
 - [webauthn] new commits pushed by WebAuthnBot
 - [webauthn] new commits pushed by equalsJeffH
 - Closed: [webauthn] CTAP-speaking authenticators use integer-valued CBOR map keys
 - [webauthn] Merged Pull Request: fix 864: Note regarding CTAP2 integer keys vs webauthn string keys
 - [w3c/webauthn] fe09a7: fix #493: be explicit about "same user" is verifie...
 - [webauthn] new commits pushed by equalsJeffH
 - Closed: [webauthn] be explict about "same user" is verified at get() time as was verified at create() time
 - [webauthn] Merged Pull Request: fix #493: be explicit about "same user" is verified at get() time as was verified at create() time
 - [w3c/webauthn] 1f70ea: Built by Travis-CI: 2154486d6af399c3bcbd62a3096213...
 - [webauthn] new commits pushed by WebAuthnBot
 - [w3c/webauthn] 9b04d6: Built by Travis-CI: 2154486d6af399c3bcbd62a3096213...
 - [webauthn] new commits pushed by WebAuthnBot
 - Re: [webauthn] fix #493: be explicit about "same user" is verified at get() time as was verified at create() time
 - [w3c/webauthn] 1e3241: Add link to "attachment modality" reference
 - [webauthn] Merged Pull Request: Authenticator taxonomy: Attachment modality (replaces #842)
 - [webauthn] new commits pushed by emlun
 - Closed: [webauthn] authenticator taxonomy
 - [webauthn] Closed Pull Request: Fix #593 - Refer to RFC 8266 for RP-controlled UI strings
 - Re: [webauthn] Fix #593 - Refer to RFC 8266 for RP-controlled UI strings
 - Re: [webauthn] Add recommendation of scoping platform credentials to OS accounts
 - [webauthn] Pull Request: Disambiguate appid extension output behaviour
 - [w3c/webauthn] 905de0: Disambiguate appid extension output behaviour
 - [webauthn] new commits pushed by emlun
 - Re: [webauthn] Add recommendation of scoping platform credentials to OS accounts
 - Re: [webauthn] Add table numbers and captions
 - [webauthn] Pull Request: Add table numbers and captions
 - [w3c/webauthn] d45d8f: Add table numbers and captions
 - [webauthn] new commits pushed by emlun
 - Re: [webauthn] What does "the extension was acted upon" mean for the AppID extension?
 - [w3c/webauthn] d95918: Address review comments
 - [webauthn] new commits pushed by emlun
 - Re: [webauthn] add captions for tables and id attrs so we can link to them
 - Re: [webauthn] Indicate resident key credential "preferred" during registration and find out what the authenticator offered
 - Re: [webauthn] Authenticator taxonomy: Authenticator types
 - Re: [webauthn] Add recommendation of scoping platform credentials to OS accounts
 - Re: [webauthn] fix 864: Note regarding CTAP2 integer keys vs webauthn string keys
 - Re: [webauthn] Authenticator taxonomy: Attachment modality (replaces #842)
 - [webauthn] Pull Request: Replace resident key terminology as proposed in #905
 - [w3c/webauthn] 010874: Replace Client-side-resident Credential Private Ke...
 - [webauthn] new commits pushed by emlun
 - [w3c/webauthn]
 - [webauthn] Closed Pull Request: Remove undefined macro reference [RP ID]
 - Re: [webauthn] Remove undefined macro reference [RP ID]
 - Re: [webauthn] What does "the extension was acted upon" mean for the AppID extension?
 - [webauthn] Pull Request: Remove undefined macro reference [RP ID]
 - [w3c/webauthn] 0a4120: Remove undefined macro reference [RP ID]
 - [webauthn] new commits pushed by emlun
 - Re: [webauthn] add captions for tables and id attrs so we can link to them
 - [w3c/webauthn] 96ba75: Fully qualify modality terms
 - Re: [webauthn] Eliminate duplicate terminology
 - Re: [webauthn] Public key rules for "packed" attestation type
 - Re: [webauthn] Indicate resident key credential "preferred" during registration and find out what the authenticator offered
 - [webauthn] Indicate resident key credential "preferred" during registration and find out what the authenticator offered
 - Re: [webauthn] add captions for tables and id attrs so we can link to them
 - Re: [webauthn] Public key rules for "packed" attestation type
 - Re: [webauthn] What does "the extension was acted upon" mean for the AppID extension?
 - Re: [webauthn] Public key rules for "packed" attestation type
 - Re: [webauthn] What does "the extension was acted upon" mean for the AppID extension?
 - Re: [webauthn] truncation to 64-byte upper limit doesn't mention character boundaries
 
Tuesday, 10 July 2018
- Re: [webauthn] AppID extension: protocol version number?
 - Closed: [webauthn] Requesting ability to detect if there is an authenticator available which is capable of resident key credential
 - Re: [webauthn] Requesting ability to detect if there is an authenticator available which is capable of resident key credential
 - 07/11/2018 W3C Web Authentication WG Meeting Agenda
 - Re: [webauthn] Partial dictionaries for extension outputs may be incorrect use of WebIDL
 - Re: [webauthn] Requesting ability to detect if there is an authenticator available which is capable of resident key credential
 - Re: [webauthn] Eliminate duplicate terminology
 - [webauthn] add captions for tables and id attrs so we can link to them
 - [w3c/webauthn] f749dc: 'client' rather than 'client platform'
 - [webauthn] new commits pushed by equalsJeffH
 - Closed: [webauthn] Requesting ability to detect if there is an authenticator available which is capable of resident key credential
 - Re: [webauthn] Requesting ability to detect if there is an authenticator available which is capable of resident key credential
 - Re: Scribing tomorrow
 - Scribing tomorrow
 - EnclaveDB: a secure database using SGX
 - Re: [webauthn] What does "the extension was acted upon" mean for the AppID extension?
 - Re: [webauthn] truncation to 64-byte upper limit doesn't mention character boundaries
 
Monday, 9 July 2018
- Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
 - Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
 - Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
 - Re: [webauthn] Privacy across OS accounts
 - Re: [webauthn] truncation to 64-byte upper limit doesn't mention character boundaries
 - Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
 - Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
 - Re: [webauthn] fix 864: Note regarding CTAP2 integer keys vs webauthn string keys
 - Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
 - Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
 - [w3c/webauthn] 4a2dd4: fix #180: do not totally lose the term "WebAuthn R...
 - [webauthn] new commits pushed by emlun
 - [w3c/webauthn] 4a2dd4: fix #180: do not totally lose the term "WebAuthn R...
 - [webauthn] new commits pushed by emlun
 - Re: [webauthn] bikeshed now catching existing lint in master->index.bs
 - Re: [webauthn] Privacy across OS accounts
 - [w3c/webauthn] ada317: Expand OS acronym in section title
 - [webauthn] Pull Request: Add recommendation of scoping platform credentials to OS accounts
 - [webauthn] new commits pushed by emlun
 - [w3c/webauthn] e132d0: Add recommendation of scoping platform credentials...
 - [webauthn] new commits pushed by emlun
 - [webauthn] Partial dictionaries for extension outputs may be incorrect use of WebIDL
 - Re: [webauthn] What does "the extension was acted upon" mean for the AppID extension?
 - [w3c/webauthn]
 - Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
 - Re: [webauthn] Tighten security scope by port
 - Re: [webauthn] Privacy across OS accounts
 - Re: [webauthn] truncation to 64-byte upper limit doesn't mention character boundaries
 - [webauthn] Requesting ability to detect if there is an authenticator available which is capable of resident key credential
 
Saturday, 7 July 2018
- Re: [webauthn] truncation to 64-byte upper limit doesn't mention character boundaries
 - Re: [webauthn] truncation to 64-byte upper limit doesn't mention character boundaries
 
Friday, 6 July 2018
- Re: [webauthn] Privacy across OS accounts
 - [webauthn] Pull Request: fix 864: Note regarding CTAP2 integer keys vs webauthn string keys
 - Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
 - [w3c/webauthn] 71da52: polish
 - [webauthn] new commits pushed by equalsJeffH
 - Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
 - [w3c/webauthn] e59483: fix 864: added Note
 - [webauthn] new commits pushed by equalsJeffH
 - Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
 - [w3c/webauthn] 4a2dd4: fix #180: do not totally lose the term "WebAuthn R...
 - [webauthn] new commits pushed by equalsJeffH
 - [w3c/webauthn] cc7aff: Built by Travis-CI: a96110e1d087a09dada43ceb7fe5a6...
 - [w3c/webauthn] 87d5ec: Built by Travis-CI: a96110e1d087a09dada43ceb7fe5a6...
 - [webauthn] new commits pushed by WebAuthnBot
 - [webauthn] new commits pushed by WebAuthnBot
 - [w3c/webauthn] a96110: fix #866: clarify sentence wrt challenges (#977)
 - [webauthn] Merged Pull Request: fix #866: clarify sentence wrt challenges
 - Closed: [webauthn] Grammar error in Sec 13.1
 - [webauthn] new commits pushed by equalsJeffH
 - [w3c/webauthn]
 - [w3c/webauthn]
 - [w3c/webauthn] 4a2dd4: fix #180: do not totally lose the term "WebAuthn R...
 - [webauthn] new commits pushed by equalsJeffH
 - [w3c/webauthn] 8c453c: Built by Travis-CI: 6a6bf465c54a8ad4737c8064587b66...
 - [w3c/webauthn] eb5a10: Built by Travis-CI: 6a6bf465c54a8ad4737c8064587b66...
 - [webauthn] new commits pushed by WebAuthnBot
 - [webauthn] new commits pushed by WebAuthnBot
 - [w3c/webauthn] b4b0d1: Built by Travis-CI: 4a2dd437f11fd5802560c64e3615bc...
 - [w3c/webauthn] bc25ca: Built by Travis-CI: 4a2dd437f11fd5802560c64e3615bc...
 - [webauthn] new commits pushed by WebAuthnBot
 - [w3c/webauthn] 6a6bf4: add domain-only rationale in two places (#975)
 - [webauthn] new commits pushed by WebAuthnBot
 - Closed: [webauthn] document why only "valid domain" format is allowed for "effective domain"
 - [webauthn] new commits pushed by equalsJeffH
 - [webauthn] Merged Pull Request: fix #517: add rationale wrt only "valid domain" format is allowed for "effective domain"
 - [w3c/webauthn] 4a2dd4: fix #180: do not totally lose the term "WebAuthn R...
 - [webauthn] new commits pushed by equalsJeffH
 - [webauthn] Merged Pull Request: fix #180: do not totally lose the term "WebAuthn Relying Party"
 - Closed: [webauthn] do not totally lose the term "WebAuthn Relying Party"
 - Re: [webauthn] Add two abort paths for getting an assertion
 - [webauthn] add abort path to createCredential alg to match that added to getAssertion alg
 - Re: [webauthn] Tighten security scope by port
 - Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
 - Re: [webauthn] Platform authenticators and key stores
 - RE: WebAuthn/WebPayments/PSD2 Demos
 - Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
 - Re: WebAuthn/WebPayments/PSD2 Demos
 - [w3c/webauthn] 62d97b: Remove old references to deleted use case descript...
 - [webauthn] new commits pushed by emlun
 - [w3c/webauthn] 8babb6: Address @selfissued's review comments
 - [webauthn] new commits pushed by emlun
 - Re: [webauthn] Allow clients to stop the `get` flow when certain conditions are met
 - Re: [webauthn] authenticatorGetAssertion has no ConstraintError step for requireUserVerification
 - Reminder and additional information - Re: TPAC 2018 registration now open
 - Re: [webauthn] Transaction authorization extensions are registration and authentication extension?
 - Re: [webauthn] Platform authenticators and key stores
 - Re: [webauthn] truncation to 64-byte upper limit doesn't mention character boundaries
 
Thursday, 5 July 2018
- Re: [webauthn] Tighten security scope by port
 - Re: [webauthn] Consider allowing RPs to indicate that they want platform authenticators to be synced across devices
 - Re: [webauthn] truncation to 64-byte upper limit doesn't mention character boundaries
 - Re: [webauthn] authenticatorGetAssertion has no ConstraintError step for requireUserVerification
 - Re: [webauthn] AppID extension: protocol version number?
 - Re: [webauthn] SafetyNet Attestation Clarifications
 - Re: [webauthn] SafetyNet Attestation Clarifications
 - Re: [webauthn] Authenticator taxonomy: Authenticator types
 - Re: [webauthn] Add two abort paths for getting an assertion
 - Re: [webauthn] fix 364 timeout reasonable range
 - Re: [webauthn] Decoding TPM `certInfo` and `pubArea`?
 - Re: [webauthn] fix #180: do not totally lose the term "WebAuthn Relying Party"
 - Re: [webauthn] fix #517: add rationale wrt only "valid domain" format is allowed for "effective domain"
 - Re: [webauthn] fix #866: clarify sentence wrt challenges
 - Closed: [webauthn] Decoding TPM `certInfo` and `pubArea`?
 - Re: [webauthn] Decoding TPM `certInfo` and `pubArea`?
 - Re: [webauthn] Decoding TPM `certInfo` and `pubArea`?
 
Wednesday, 4 July 2018
- Re: [webauthn] Decoding TPM `certInfo` and `pubArea`?
 - Re: [webauthn] Decoding TPM `certInfo` and `pubArea`?
 - Re: [webauthn] Decoding TPM `certInfo` and `pubArea`?
 - Re: [webauthn] Decoding TPM `certInfo` and `pubArea`?
 - Re: [webauthn] Decoding TPM `certInfo` and `pubArea`?
 - [webauthn] Decoding TPM `certInfo` and `pubArea`?
 - Re: [webauthn] Authenticator taxonomy: Authenticator types
 - [webauthn] authenticatorGetAssertion has no ConstraintError step for requireUserVerification
 - [w3c/webauthn] 2abe4c: Rewrite Authenticator taxonomy section introductio...
 - [webauthn] new commits pushed by emlun
 - Closed: [webauthn] credential id privacy
 - Re: [webauthn] credential id privacy
 
Tuesday, 3 July 2018
- Re: [webauthn] AppID extension: protocol version number?
 - Re: [webauthn] What does "the extension was acted upon" mean for the AppID extension?
 - Re: [webauthn] What does "the extension was acted upon" mean for the AppID extension?
 - Re: [webauthn] AppID extension: protocol version number?
 - Re: [webauthn] What does "the extension was acted upon" mean for the AppID extension?
 - Re: [webauthn] What does "the extension was acted upon" mean for the AppID extension?
 - [webauthn] What does "the extension was acted upon" mean for the AppID extension?
 - 07/04/2018 W3C Web Authentication WG Meeting Agenda - Meeting cancelled
 
Monday, 2 July 2018
- [webauthn] Public key rules for "packed" attestation type
 - [webauthn] Clarification of valid prIdHash value requested in section 7 when using AppID extension
 - Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
 - [w3c/webauthn] e243c2: revise RP ID definition and Note (#970)
 - [webauthn] new commits pushed by emlun
 - Re: [webauthn] WIP: Authenticator taxonomy (replaces #842)
 - [w3c/webauthn] e243c2: revise RP ID definition and Note (#970)
 - [webauthn] new commits pushed by emlun
 - Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
 - Re: [webauthn] WIP: Authenticator taxonomy (replaces #842)
 - [w3c/webauthn] 46d1fd: Remove now unused image file
 - [w3c/webauthn] 46d1fd: Remove now unused image file
 - [webauthn] new commits pushed by emlun
 - [webauthn] new commits pushed by emlun
 - [webauthn] Pull Request: WIP: Authenticator taxonomy: Use cases
 - [w3c/webauthn] 699c58: Revert "Add Issue: pointing out that Authenticator...
 - [webauthn] new commits pushed by emlun
 - [w3c/webauthn] 265fd3: Remove draft of use case descriptions
 - [webauthn] new commits pushed by emlun
 - Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way
 - [webauthn] MUST authenticators still perform self attestation?
 - Re: [webauthn] `CredentialRequestOptions` make otherwise valid values invalid in an undesirable way