Re: [webauthn] Specify authenticator attachment for authentication operation (#1267)

@arshadnoor do you think I was asking customizing the spec for our own use cases?
We are willing to support universal authentications if there is and we are going to try to make that one.
This is just real problems for RPs having mobile based users. We cannot say to our users to buy external authenticators and we cannot explain what FIDO2/WebAuthn is in a very limited small screen. If they have external ones, they can use it. And, we are going to support them.

And, this issue is basically raised because of the adoption challenges and the technical soundness.
Current spec does have a way for RP to set authenticator attachment during registration but there is not for authentication.
Still, RP can allow platform only, external authenticators only or both. If we are saying about the ecosystem and disallow such RPs' specific approaches (In fact, I don't agree), we should not provide such option for registration as well.

-- 
GitHub Notification of comment by Kieun
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1267#issuecomment-520059934 using your GitHub account

Received on Friday, 9 August 2019 20:53:13 UTC