- From: Firstyear via GitHub <sysbot+gh@w3.org>
- Date: Mon, 03 Jul 2023 22:51:14 +0000
- To: public-webauthn@w3.org
> So _in principle_, we could make `challenge` optional when and only when the RP sets `attestation: "none"`. But again, I don't think this very marginal benefit is worth the added complexity. And we just know there are RP's that would make challenge optional whet attestation is direct/indirect. Better to do the secure and correct thing by default. -- GitHub Notification of comment by Firstyear Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1915#issuecomment-1619231311 using your GitHub account -- Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config
Received on Monday, 3 July 2023 22:51:16 UTC