W3C home > Mailing lists > Public > public-webauthn@w3.org > December 2019

Re: [webauthn] Why does WebAuthn require a challenge when asking the client to register a new credential? (#1355)

From: Nick Mooney via GitHub <sysbot+gh@w3.org>
Date: Tue, 17 Dec 2019 19:36:43 +0000
To: public-webauthn@w3.org
Message-ID: <issue_comment.created-566716089-1576611402-sysbot+gh@w3.org>

Yes, the challenge is present to prevent replay attacks. There are other controls that could fail outside of TLS to enable a replay attack at various points between the authenticator / client / server.

GitHub Notification of comment by nickmooney
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1355#issuecomment-566716089 using your GitHub account
Received on Tuesday, 17 December 2019 19:36:44 UTC

This archive was generated by hypermail 2.4.0 : Tuesday, 5 July 2022 07:26:39 UTC