Re: [webauthn] Should an RP be able to provide finer grained authenticator filtering in attestation options? (#1688)

I think terminology and wording is important. An RP can't disable a certain credential export behavior. They can, however, request a second device-specific, hardware bound key and ignore the passkey, if they have a use case that requires this (and results in a degradation of user experience).

Another important note is that an existing platform credential does not automatically become a passkey on platform flag days.

-- 
GitHub Notification of comment by timcappalli
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1688#issuecomment-1000537667 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Thursday, 23 December 2021 21:50:46 UTC