W3C home > Mailing lists > Public > public-webauthn@w3.org > January 2022

Re: [webauthn] Device-bound key extension (#1658)

From: Emil Lundberg via GitHub <sysbot+gh@w3.org>
Date: Tue, 25 Jan 2022 06:58:38 +0000
To: public-webauthn@w3.org
Message-ID: <issue_comment.created-1020868076-1643093916-sysbot+gh@w3.org>
The point of this extension is not to signal that a credential is multi-device, it's to "extend" a multi-device credential with one or more hardware-bound keys that don't migrate to other devices along with the multi-device key. So when the RP sees one of those hardware-bound keys for the second and subsequent time, that's a stronger assurance of authenticity than just the multi-device key.

-- 
GitHub Notification of comment by emlun
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1658#issuecomment-1020868076 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config
Received on Tuesday, 25 January 2022 06:58:39 UTC

This archive was generated by hypermail 2.4.0 : Tuesday, 5 July 2022 07:26:45 UTC