Re: [webauthn] Hybrid transport opt-out and ability for verifiable proof (#2349)

> What if the WebAuthn responses were sent directly to the Relying Party through a pre-established backchannel? 

This would effectively be federation then. Credential managers / authenticators in a consumer context do not have a direct relationship with Relying Parties by design. Changing that would essentially be designing a new protocol stack. 

-- 
GitHub Notification of comment by timcappalli
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/2349#issuecomment-3456638925 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Tuesday, 28 October 2025 14:01:52 UTC