19:09:44 RRSAgent has joined #webauthn 19:09:44 logging to https://www.w3.org/2021/02/24-webauthn-irc 19:09:47 RRSAgent, make logs Public 19:09:47 Meeting: Web Authentication WG 19:10:13 wseltzer has changed the topic to: 24 Feb https://lists.w3.org/Archives/Public/public-webauthn/2021Feb/0188.html 19:52:06 jfontana has joined #webauthn 19:52:15 present+ 19:55:17 present+ 20:01:23 nsteele has joined #webauthn 20:01:33 present+ 20:01:46 dveditz has joined #webauthn 20:01:53 present+ 20:03:16 elundberg has joined #webauthn 20:03:49 mattmiller has joined #webauthn 20:04:50 present+ 20:08:09 tony: not expecting any changes 20:08:14 ..everyone agree 20:08:16 present+ agl, akshay, davidturner, davidwaite, elundberg, jeremyerickson, johnbradley, nadalin, matthewmiller, raerivera, sbweeden, timcappalli 20:08:23 jeffH: this will be renaming the master branch 20:08:29 Tony: yes. 20:09:02 ...no PRs until Level 3. 20:10:54 tony: any level 3 issues we want to look at? 20:15:10 agl: we can talk about what we are referencing 20:15:29 ...a web site wished to use a usernameless flow 20:15:39 ...need to give some icon to click 20:16:13 https://www.irccloud.com/pastebin/0gNc4dIo/ 20:16:19 ...we want something in the background, pop up a non-module design, maybe have something subtle 20:16:29 thansk 20:17:11 tony: a few issues here. 20:17:38 -> https://docs.google.com/document/d/11hWpUPAnblPtkn1f7AIQW0ujoiu_BAKzlMVhZKQPiW8/ Explainer: WebAuthn Conditional/Hinted UI 20:18:12 s|https://www.irccloud.com/pastebin/0gNc4dIo/|-> https://docs.google.com/document/d/11hWpUPAnblPtkn1f7AIQW0ujoiu_BAKzlMVhZKQPiW8/ Explainer: WebAuthn Conditional/Hinted UI| 20:18:24 agl: remote desktop may be a thing, we might look at that in Level 3 20:18:59 ...accommodation could be small or large. maybe remote desktop or browser stuff 20:19:08 ...may want to consider for L3 20:20:09 MMiller: not much of a jump to a bad actor doing something with remote session 20:20:24 agl: FIDO has a proximity assumption 20:20:37 ...it has some idea they are sending to the correct machine. 20:20:55 agl: no magic answer 20:23:18 bradley: would a remote software you could have a desktop authenticator, but this is probably long way down the road 20:23:46 jeremy: clarification. do we care about proximity or is it channel binding 20:25:16 agl: explains proximity and FIDO and remote 20:25:49 jeremy: i don't see channel binding in this. 20:26:02 ...proximity is hard to measure 20:26:14 ...trying to think about this in new ways 20:26:41 lundberg: physical proximity is less relevant than if reg. ceremony is mediated by the browser. 20:27:47 jeremy: you could today forward a USB device, you extend the channel, hopefully over a secure connection 20:28:42 jeffh: proximity thing is between user and authenticator they actually touch. we have that. it is transitive auth. down to remote machine 20:30:51 bradley: seen interesting work on remoting 20:31:18 jeremy: would this then relate to VMware 20:31:47 ... are there issues with this 20:32:08 bradley: doesn't always work. failure is remote software in my ming 20:32:14 ...mind 20:32:31 jeremy: what is the spec clarifying 20:33:08 ^ that was me lol 20:34:14 akshay: we would be looking to local platform for RP, but won't use remote platform authenticator, phishing would be a real problem 20:34:23 agl: that matches our expectations. 20:34:48 ...details wouldn't be that clear 20:35:24 ...chrome has had this for a decade. have to work on the functionality. 20:36:46 tony: anymore to discuss? 20:37:06 ...adjourn. 20:41:17 rrsagent, make logs public 20:41:27 rrsagent, draft minutes 20:41:27 I have made the request to generate https://www.w3.org/2021/02/24-webauthn-minutes.html jfontana 20:41:52 Zakim, list attendees 20:41:52 As of this point the attendees have been jfontana, wseltzer, nsteele, dveditz, jeffh, agl, akshay, davidturner, davidwaite, elundberg, jeremyerickson, johnbradley, nadalin, 20:41:55 ... matthewmiller, raerivera, sbweeden, timcappalli 20:42:16 Chairs: Nadalin, Fontana 20:43:22 Web page updated with minutes 20:43:35 Zakim, bye 20:43:35 leaving. As of this point the attendees have been jfontana, wseltzer, nsteele, dveditz, jeffh, agl, akshay, davidturner, davidwaite, elundberg, jeremyerickson, johnbradley, 20:43:35 Zakim has left #webauthn 20:43:46 rrsagent, bye 20:43:46 I see no action items