Re: [webauthn] Add authenticatorDisplayName to credProps (#1880)

> > Google and GitHub, and probably many others, also have similar nickname prompts during registration, but don't attempt to prefill the nickname field.
> 
> Speaking for GitHub.com, we do attempt to propose a nickname, based on browser and OS, for all security keys today. However, for passkeys we will drop this behavior since e.g. "Chrome on MacOS" is an actively bad nickname for your Dashlane passkey, and will be quite a poor UX when it comes to lifecycle management as the user attempts to understand what passkey they are unregistering. I don't believe users will come up with a better nickname on their own though, since they are unlikely to understand the source of their passkey provider.

There is also a strong likelihood that users will be confused by the UI/UX presented by chrome that may mislead them to misname the key itself. About the best an RP could do here with this nickname field is to fill it in with a nice display name of the site itself. 

Has any user testing or research actually been done on this feature with real humans to see how they will use / misuse this feature proposition? 

-- 
GitHub Notification of comment by Firstyear
Please view or discuss this issue at https://github.com/w3c/webauthn/pull/1880#issuecomment-1563666346 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Friday, 26 May 2023 00:37:58 UTC