Re: [webauthn] Reflect caching of user gestures in WebAuthn assertion (#2023)

The only channel for penalty will come with trying to pass any certification program the FIDO alliance may produce. There are legitimate points of friction that the pwd mgr vendors are trying to avoid though, and the goal here is to try and produce some middle ground in the spec that allows a good user experience where the passkey providers can declare the truth and the RP can realistically both express, and evaluate policy in a way that doesn’t overly impact user experience.



> On 29 Feb 2024, at 12:48 pm, Firstyear via GitHub <sysbot+gh@w3.org> wrote:
> 
> Theres no penalty for them to lie either. Who's checking and regulating any of this? 
> -- 
> GitHub Notification of comment by Firstyear
> Please view or discuss this issue at https://github.com/w3c/webauthn/issues/2023#issuecomment-1970301302  using your GitHub account
> 
> 
> -- 
> Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Thursday, 29 February 2024 03:35:27 UTC