W3C

- DRAFT -

Web Authentication Working Group Teleconference

01 Aug 2018

Attendees

Present
agl, akshay, christiaan, jfontana, john_Bradley, LukeWalker, selfissued, apowers, jeffh, jcj_moz
Regrets
Chair
jfontana
Scribe
weiler

Contents


<jeffh> hm, having headset troubles w/mic

<jeffh> hear me now?

<scribe> scribenick: weiler

draft CR build

apowers: I did a diff. not a CR build

weiler: i need the version with the CR boilerplate
... I'll send instruction to adam

PR 1017

agl: fine by me
... trivial.

akshay: fine.

selfissued: fine

apowers: will merge

PR 1016

akshay will merge.

jeffh

jfontana: ...
... sam proposed you keep doing what you're doing and figure we'll work out details in the background.

jeffh: yes.

PR 375

jeffh: I'm not going to get anything done this week. I'll be back next week.
... I want to work on this one. needs polishing.

others

jfontana: those were the only 3 PRs under PR milestone.

jeffh: we need to triage 7 issues w/ no milestone

https://github.com/w3c/webauthn/issues/1004

jeffh: this needs to get fixed. it will break things.
... this is the kind of bug we get if we move too fast.

jcj: need to decide, change spec, change implementations, and do backward-compatibility

jeffh: do you agree with the two options?

jcj: not sure. but I see the problem

agl: no opinion re: answer. .... this is unfortunate, but it's hardly untrodden territory.

jcj: right answer might be member name without the dash. and pick what we're really doing.

jeffh: haven't heard from chrome or edge.

agl: need to gather chrome and edge and anyone else who wants to weigh in. and we need to pick.

agl & ahskay will explore.

jcj: I can do code changes at the end of the month

jfontana: can we do this on list before the next mtg?

jeffh: this is not highest priority;

sam: do you want to do a temporary patch?

jeffh: I'd do an inline issue

jfontana: sounds good.

jcj: +1

jefh: i'll do it.

jfontana: does this affect CR?

sam: no. just make sure adam generates the doc w/o this pull.

https://github.com/w3c/webauthn/issues/988

sam: that's already tagged for PR

agl: this may be a misunderstanding on my part. i thought these were required, when they're optional. might not be a problem.
... I think we should close it.
... default is optional

selfissued: close it.

agl: I'll write up something and close. and if emil wants to reopen it, he can.

back to 1004

sam: should this be with a PR milestone

jeffh: once this CR ships, should milestione to be moved from PR to Rec?

sam: my understanding is that breaking changes require an eclusion opportunity.
... I don't see why 1004 would require that, thought

https://github.com/w3c/webauthn/issues/1011

akshay: @@. would like google's opinion now.

christiaan: let's close this and move on. this is supposed to give you insight into the.... leave it the way it is.

selfissued: the functionality giri wants is not specific to safetynet. as described, this is misguided.

john_bradley: agree. removing this now will just cause us grief.

christiaan will write summary and close.

https://github.com/w3c/webauthn/issues/1012

jeffh: this is reasonable. mark for PR.

selfissued: assign it to someone?

https://github.com/w3c/webauthn/issues/1014

john_bradley: this is a bigger problem than webauthn
... this is not about the authenticator. this is about the RP having a different response.. in case someone is testing for the existence of accounts.
... we could put something in. but this is very generic.

sam: this is far beyond our scope, but no harm in doing in.

john_bradley: I would not belabor it.
... dashlane does it wrong.

agl: maybe if acct doesn't exist, they respond w/ randomly generated cred.id?

selfissued: can we file this v. tag doc and not here?

sam: no; think we should include it here.

agl: if RP really cares, suggest random?

chistiaan: some RPs don't care.

john_bradley: unless you track them v. accounts, attacker could see if they change.

agl: psedu randomfunc based on name

akshay: this is a general problem....

jfontana: add guidance and close it.

agl: if someone writes it. ....

selfissued: we should assign it or close it.

many voices say close.

sam: I think closing is wrong.

john_bradley: will write a sentence and close.

https://github.com/w3c/webauthn/issues/1018

selfissued: should not just close.

https://github.com/w3c/webauthn/issues/1019

adjourned.

Summary of Action Items

Summary of Resolutions

[End of minutes]

Minutes formatted by David Booth's scribe.perl version 1.152 (CVS log)
$Date: 2018/08/01 18:04:02 $

Scribe.perl diagnostic output

[Delete this section before finalizing the minutes.]
This is scribe.perl Revision: 1.152  of Date: 2017/02/06 11:04:15  
Check for newer version at http://dev.w3.org/cvsweb/~checkout~/2002/scribe/

Guessing input format: Irssi_ISO8601_Log_Text_Format (score 1.00)

Succeeded: s/agl/christiaan/
Succeeded: s/christiann/christiaan/
Succeeded: s/no/not/
Present: agl akshay christiaan jfontana john_Bradley LukeWalker selfissued apowers jeffh jcj_moz
Found ScribeNick: weiler
Inferring Scribes: weiler
Found Date: 01 Aug 2018
People with action items: 

WARNING: IRC log location not specified!  (You can ignore this 
warning if you do not want the generated minutes to contain 
a link to the original IRC log.)


[End of scribe.perl diagnostic output]