Re: [webauthn] Device-bound key extension (#1658)

This is a lot of extra energy/effort to verify if a credential is multi-device - some RP's may want the stronger signature checking of validation that the sync credential was signed off in the sync process, but many RP's would benefit from a simple credProps boolean flag for "multi-device: true" which is a simpler signal for them to understand. Can the proposal be extended with this as well? 

-- 
GitHub Notification of comment by Firstyear
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1658#issuecomment-1020673667 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Tuesday, 25 January 2022 00:04:37 UTC