- From: Rolf Lindemann via GitHub <sysbot+gh@w3.org>
- Date: Sat, 10 Apr 2021 17:50:39 +0000
- To: public-webauthn@w3.org
Allowing a PublicKeyCredential private key to sign arbitrary data structures has an impact on the security model. It makes keys "unrestricted", see https://fidoalliance.org/specs/fido-v2.0-id-20180227/fido-metadata-statement-v2.0-id-20180227.html#dictionary-metadatastatement-members -- GitHub Notification of comment by rlin1 Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1595#issuecomment-817178042 using your GitHub account -- Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config
Received on Saturday, 10 April 2021 17:50:40 UTC