- From: Firstyear via GitHub <sysbot+gh@w3.org>
- Date: Thu, 12 Jan 2023 01:32:37 +0000
- To: public-webauthn@w3.org
> If you have an rk you get to autofill and if not you enter your username normally. The rk doesnt need to know about residence or non-residence of credentials (which as we know can change, and iirc at least on the authenticators i know and/or tried, the credential id still works after throwing out the rk from the device or restoring from backup (documented for the trezor t iirc)) Exactly my point here. But there are people who want to force rk=required even though both work flows will be needed. rk and autofill is opportunistic, rather than the default, especially when there are devices with extremely limited storage space. -- GitHub Notification of comment by Firstyear Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1822#issuecomment-1379697475 using your GitHub account -- Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config
Received on Thursday, 12 January 2023 01:32:39 UTC