Re: [webauthn] Authenticator flag to indicate internal knowledge of rk (discoverable credential creation). (#1761)

_(Discussed 2022/09/12 at TPAC in Vancouver)_
Without attestation there's no way of knowing whether the bit reported by the authenticator can be trusted, so I think we have to rule out that this has any value in the absence of attestation. If we argue that attestation is required, I think this "bit" is better fitted for metadata reported (by the MDS server) as part of many other properties of the authenticator.

-- 
GitHub Notification of comment by christiaanbrand
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1761#issuecomment-1244554337 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Monday, 12 September 2022 21:54:37 UTC