Re: [webauthn] Which "pubKeyCredParams" to use? (#1757)

We have issues with ed25519 in webauthn-rs just because it's not properly supported in the ecosystem cryptographically, but that's "our problem". 

RS256 is okay, but the risk is sometimes they'll be signed with RS1 (yes, sha 1) so implementors need to be careful of that.

-- 
GitHub Notification of comment by Firstyear
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1757#issuecomment-1321271589 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Sunday, 20 November 2022 23:16:42 UTC