Re: [webauthn] Syncing Platform Keys, Recoverability and Security levels (#1640)

@cyberphone There is a technology preview by Apple which uses a secret/private key synchronization mechanism to synchronize PublicKeyCredentials (including private key) across devices. A single registered credential could be used on any Apple device.

AFAIK this has never been forbidden by WebAuthn, Apple is just the first large-scale authenticator to indicate intent to implement this sort of behavior. It does surface questions around what should happen when the RP security posture does not accept such behavior.

-- 
GitHub Notification of comment by dwaite
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1640#issuecomment-881639600 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Friday, 16 July 2021 18:32:11 UTC