Re: [webauthn] Make signature counters a MAY ? (#1590)

on 7-apr-2021 call:
@agl notes that we do not have consensus on this
@nicksteele: the 3 libs he's worked on will raise a flag that the counters do not line up, but will not reject the authn operation
@akshayku: windows  will reject the authn op if counter not incremented
@nicksteele: also, system he's working on uses risk-based assessments of which the signature counter is only one input

bottom line is that rather than change the SHOULD to a MAY, this discussion is more appropriate for those bodies involved in certification of authenticators and fido servers (e.g., FIDO)



-- 
GitHub Notification of comment by equalsJeffH
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1590#issuecomment-815180130 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Wednesday, 7 April 2021 19:49:01 UTC