Re: [webauthn] Hybrid transport opt-out and ability for verifiable proof (#2349)

Just to try to bring this discussion back around, @denniskniep if you believe you discovered a protocol vulnerability in FIDO CTAP, please send the details to security-secretariat@fidoalliance.org. That discussion should not continue here as CTAP is not defined by the W3C Web Authentication WG.

I recommend we keep this issue to its original topic which is **a feature request for WebAuthn to provide the ability to limit which transports are used. **

-- 
GitHub Notification of comment by timcappalli
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/2349#issuecomment-3456674442 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Tuesday, 28 October 2025 14:07:19 UTC