Re: [webauthn] document and mitigate fingerprinting and disclosure risk of capabilities and extensions (#2320)

@timcappalli we don't have much experience with appointing additional people who can do not just a review, but also write up a suggested Working Group view of what fingerprinting risks and mitigations are available and advisable, at least not with a spec as complex as WebAuthn.

Our intention has been that the [Mitigating Browser Fingerprinting](https://w3c.github.io/fingerprinting-guidance/) document would be useful to editors of specifications in conducting that analysis themselves. But if it was not sufficient to help someone with that deep subject matter expertise to consider and document the fingerprinting risks and mitigations, that would be good to know. And especially if there are specific stumbling blocks or issues, that would be useful feedback for the editors of that document (myself included).

-- 
GitHub Notification of comment by npdoty
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/2320#issuecomment-3520041658 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Wednesday, 12 November 2025 05:19:30 UTC