W3C home > Mailing lists > Public > public-webauthn@w3.org > January 2022

Re: [webauthn] Device-bound key extension (#1658)

From: Firstyear via GitHub <sysbot+gh@w3.org>
Date: Tue, 25 Jan 2022 00:04:35 +0000
To: public-webauthn@w3.org
Message-ID: <issue_comment.created-1020673667-1643069074-sysbot+gh@w3.org>
This is a lot of extra energy/effort to verify if a credential is multi-device - some RP's may want the stronger signature checking of validation that the sync credential was signed off in the sync process, but many RP's would benefit from a simple credProps boolean flag for "multi-device: true" which is a simpler signal for them to understand. Can the proposal be extended with this as well? 

-- 
GitHub Notification of comment by Firstyear
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1658#issuecomment-1020673667 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config
Received on Tuesday, 25 January 2022 00:04:37 UTC

This archive was generated by hypermail 2.4.0 : Thursday, 24 March 2022 20:38:44 UTC