Re: [webauthn] Add transport used during authentication to assertion payload (#1668)

This field isn't part of the signed collected client data, so can't this be tampered with during the response? This may lead to failse assumptions of security/validity of this data. There is already a signed extension for this purpose, so how is this an improvement? 

-- 
GitHub Notification of comment by Firstyear
Please view or discuss this issue at https://github.com/w3c/webauthn/pull/1668#issuecomment-915656064 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Thursday, 9 September 2021 00:09:52 UTC