W3C home > Mailing lists > Public > public-webauthn@w3.org > November 2020

Re: [webauthn] User verification policy leads to ambiguous usage situations. (#1510)

From: Firstyear via GitHub <sysbot+gh@w3.org>
Date: Mon, 02 Nov 2020 00:17:21 +0000
To: public-webauthn@w3.org
Message-ID: <issue_comment.created-720176220-1604276240-sysbot+gh@w3.org>
It affects which credentials can be used in the registration ceremony IE on FF with U2F, a UVP of Required would not select the U2F tokens since this uses CTAP1. This becomes a policy on which credentials *can* be registered in that ceremony, and implies to the user that a relationship here does exist. It also means that the selected policy can affect future usage of the token, and can create surprising behaviour (UVP::Preferred on chrome requesting a password with U2F, but not on FF). 

-- 
GitHub Notification of comment by Firstyear
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1510#issuecomment-720176220 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config
Received on Monday, 2 November 2020 00:17:22 UTC

This archive was generated by hypermail 2.4.0 : Monday, 2 November 2020 00:17:23 UTC