Re: [webauthn] User verification policy leads to ambiguous usage situations. (#1510)

It affects which credentials can be used in the registration ceremony IE on FF with U2F, a UVP of Required would not select the U2F tokens since this uses CTAP1. This becomes a policy on which credentials *can* be registered in that ceremony, and implies to the user that a relationship here does exist. It also means that the selected policy can affect future usage of the token, and can create surprising behaviour (UVP::Preferred on chrome requesting a password with U2F, but not on FF). 

-- 
GitHub Notification of comment by Firstyear
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1510#issuecomment-720176220 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Monday, 2 November 2020 00:17:22 UTC