- From: Firstyear via GitHub <noreply@w3.org>
- Date: Thu, 04 Jun 2026 03:11:50 +0000
- To: public-webauthn@w3.org
This removes agency and consent from the user - what if they intend to configure the credential manager for that site? We need to move away from RP's trying to "guide everything with 100 options" - users need to be in control of the process and able to make their own choices around their credentials. It's not for you to decide how I interact. The bigger issue is that there seems to be intent to "convert" people forcefully and without consent - it's an anti pattern to be enrolling passkeys silently or forcefully on login, and that pattern itself already *turns people off the technology*. Amazon is a great example here, where they attempt to force passkey creation on login, and there are already many reports of people rejecting this and refusing to engage with passkeys after this anti-pattern was used against them. I believe Ali-express does this as well, attempting to create a passkey on *every single page load* if you aren't logged in. -- GitHub Notification of comment by Firstyear Please view or discuss this issue at https://github.com/w3c/webauthn/issues/2432#issuecomment-4618609245 using your GitHub account -- Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config
Received on Thursday, 4 June 2026 03:11:51 UTC