Re: [webauthn] Hybrid transport opt-out and ability for verifiable proof (#2349)

What if the WebAuthn responses were sent directly to the Relying Party through a pre-established backchannel? This way, any potential attacker-in-the-middle would never have access to the response data at all.

During the WebAuthn credential creation ceremony, the Relying Party could provide a backchannel URI to which the client platform would later deliver the WebAuthn response directly.

Would introducing such a mechanism be a possible extension or modification within CTAP, or would it conflict with the current architecture principles?

-- 
GitHub Notification of comment by ntrojanowska
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/2349#issuecomment-3456533998 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Tuesday, 28 October 2025 13:41:46 UTC