Re: [webauthn] §6.1.1. Signature Counter Considerations does not explicitly mention constant-zero case (#1734)

By definition that's a decreasing signature counter, so it should be treated as in any other case you have a decreasing signature counter. If we were to say that reverting to zero is an acceptable special case, then there's not much point to the signature counter since a malicious clone could just reset the counter to zero and remain undetected.

-- 
GitHub Notification of comment by emlun
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1734#issuecomment-1139711367 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Friday, 27 May 2022 15:12:58 UTC