Re: [webauthn] Cross origin authentication without iframes (#1667)

Apparently the Payment WG are considering an alternative approach:
https://github.com/w3c/webpayments/wiki/Agenda-TPAC2021
In the _preliminary_ schedule under the privacy moniker, you find:

<table><tr><td>
<b>Instrument selection managed by the browser (Adrian Hope-Bailie). Display, selection, storage</b>
</td></tr></table>

Properly implemented such a solution does not share PII with _untrusted third parties_ (merchants) in addition to offering a consistent (standardized!) payment provider/network independent UX.  No modifications to WebAuthn would be needed either since the payment application runs at a higher privilege level than ordinary Web code.

-- 
GitHub Notification of comment by cyberphone
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1667#issuecomment-946353571 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Tuesday, 19 October 2021 04:17:05 UTC