Re: [webauthn] continuous assertion (#1785)

> > user presence and interaction is a really core part of how these devices work
> 
> Yes and no. At least CTAP2 actually can perform `getAssertion` without user presence (also called "silent authentication"), it's just that WebAuthn requires that browsers always set the "require UP" option. 

Ahh yes, I was thinking the general case with things like TPM's or touchid etc. If we can guarantee it's ctap2, then sure. But I still think this might be better solved outside of webauthn since the end goal here is "bind a http session to a device".



-- 
GitHub Notification of comment by Firstyear
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1785#issuecomment-1203331882 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Tuesday, 2 August 2022 23:59:32 UTC