Re: [webauthn] Recovering from Device Loss (#931)

This sounds like a problem for the RP to think about and implement their own work flows, not for the devices to have to share secrets which weakens the whole system.

The same way we have password-reset emails, you need to think about the same for when someone loses a webauthn device. 

-- 
GitHub Notification of comment by Firstyear
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/931#issuecomment-1089465671 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Tuesday, 5 April 2022 22:46:49 UTC