Re: [webauthn] Add privacy considerations about credential IDs (#1250)

> "by only providing a username" may sound like it excludes the case where
> a username is derived from "ambient credentials" such as cookies.

It does exclude that case - unless the "ambient credential" is just an unauthenticated username with no session key, which wouldn't really make much sense.

-- 
GitHub Notification of comment by emlun
Please view or discuss this issue at https://github.com/w3c/webauthn/pull/1250#issuecomment-528339549 using your GitHub account

Received on Thursday, 5 September 2019 12:26:59 UTC