Re: [webauthn] define "self-signed basic attestation type" "SSBasic" (#1499)

> > Need to have a proper impact analysis and collect feedback from certified servers before this change is approved
> 
> I am not sure that WebAuthn needs to do that. In principal we can support new attestation formats like apple attestation, without first checking what existing Fido servers do.
> 
> As long as this behavior fails in a safe way in servers, eg the worst that happens in existing servers is that the the attestations are considers invalid, I don't see a problem. New servers will support it like the apple attestation.

Please note that FIDO Alliance is in no way trying to dictate the work of this group and the comment is not our official stance on this topic. 
From my perspective I am working to coordinate on our end, as it relates to certification, for a more cohesive ecosystem and understand the changes that we would potentially need to incorporate in order to support that end goal. 

-- 
GitHub Notification of comment by RaeHayward
Please view or discuss this issue at https://github.com/w3c/webauthn/pull/1499#issuecomment-709441713 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Thursday, 15 October 2020 16:27:53 UTC