Re: [webauthn] Make signature counters a MAY ? (#1590)

As side-channel attacks are discovered it seems "getting utility from counters" is only a matter of time? E.g.
- https://tpm.fail/ recovering private keys from Intel fTPMs and STMicroelectronics TPM chips
- [Google Titan keys can be cloned](https://arstechnica.com/information-technology/2021/01/hackers-can-clone-google-titan-2fa-keys-using-a-side-channel-in-nxp-chips/)

-- 
GitHub Notification of comment by bdewater
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1590#issuecomment-812010470 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Thursday, 1 April 2021 16:06:01 UTC