Re: [webauthn] Enforce backup eligibility during assertion (#1791)

> This has now lead to Apple's iOS and macOS sending BE=true during registration, but BE=false during subsequent usage of the credential during assertion ceremonies.

This is likely a bug. I, personally, am not seeing this behavior on the latest betas.

> Additionally it is confusing to an RP today when at registration a permanent property is changing between registration and assertion.

It cannot change after registration. We already have normative text about this: https://w3c.github.io/webauthn/#sctn-credential-backup

"The value of the [BE](https://w3c.github.io/webauthn/#authdata-flags-be) [flag](https://w3c.github.io/webauthn/#authdata-flags) is set during [authenticatorMakeCredential](https://w3c.github.io/webauthn/#authenticatormakecredential) operation and MUST NOT change."

-- 
GitHub Notification of comment by timcappalli
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1791#issuecomment-1231742129 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Tuesday, 30 August 2022 14:24:10 UTC