Re: [webauthn] Can the private keys be used for other cryptographic operations? (#1595)

Allowing a PublicKeyCredential private key to sign arbitrary data structures has an impact on the security model.
It makes keys "unrestricted", see https://fidoalliance.org/specs/fido-v2.0-id-20180227/fido-metadata-statement-v2.0-id-20180227.html#dictionary-metadatastatement-members 

-- 
GitHub Notification of comment by rlin1
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1595#issuecomment-817178042 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Saturday, 10 April 2021 17:50:40 UTC