Re: [webauthn] Give each authenticator a GUID and add an option to CredentialsContainer: create method to return this GUID if user permits (#2263)

The Authenticator GUID I said is the GUID of the authenticator.

________________________________
发件人: Firstyear ***@***.***>
发送时间: 2025年2月21日 13:02
收件人: w3c/webauthn ***@***.***>
抄送: bigradish ***@***.***>; Mention ***@***.***>
主题: Re: [w3c/webauthn] Give each authenticator a GUID and add an option to CredentialsContainer: create method to return this GUID if user permits (Issue #2263)


Authenticator GUID is the same as AAGUID.

There is no Authenticator UUID that you want.

You can not fingerprint unique webauthn authenticators.

What you want to achieve is not possible. I will not say it again.

If you want to limit account sign ups you need to do it using other mechanisms. Stop trying to abuse webauthn to achieve it.

End of story.

―
Reply to this email directly, view it on GitHub<https://github.com/w3c/webauthn/issues/2263#issuecomment-2673453249>, or unsubscribe<https://github.com/notifications/unsubscribe-auth/ABBYBYI2E2DLLEOYJBLWWCT2Q2XMTAVCNFSM6AAAAABXSH2DKWVHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZDMNZTGQ2TGMRUHE>.
You are receiving this because you were mentioned.Message ID: ***@***.***>

[Firstyear]Firstyear left a comment (w3c/webauthn#2263)<https://github.com/w3c/webauthn/issues/2263#issuecomment-2673453249>

Authenticator GUID is the same as AAGUID.

There is no Authenticator UUID that you want.

You can not fingerprint unique webauthn authenticators.

What you want to achieve is not possible. I will not say it again.

If you want to limit account sign ups you need to do it using other mechanisms. Stop trying to abuse webauthn to achieve it.

End of story.

―
Reply to this email directly, view it on GitHub<https://github.com/w3c/webauthn/issues/2263#issuecomment-2673453249>, or unsubscribe<https://github.com/notifications/unsubscribe-auth/ABBYBYI2E2DLLEOYJBLWWCT2Q2XMTAVCNFSM6AAAAABXSH2DKWVHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZDMNZTGQ2TGMRUHE>.
You are receiving this because you were mentioned.Message ID: ***@***.***>


-- 
GitHub Notification of comment by bigradish
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/2263#issuecomment-2673457288 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Friday, 21 February 2025 05:04:55 UTC