W3C

– DRAFT –
Web Authentication WG

22 September 2021

Attendees

Present
elundberg, jfontana, matthewmiller, selfissued
Regrets
-
Chair
John Fontana, Tony Nadalin
Scribe
jfontana

Meeting minutes

tony: cancel meeting during FIDO Plenary Oct. 19

MMiller: have a BOF on exportable keys.

MMiller: there is a quesiton about exporting. target it more to exportability across devices.

https://github.com/w3c/webauthn/pull/1670

elundberg: some outstanding qustions.
… add for #1621
… won't do this right now, and remove the section in question.
… look also at #1668. need to resolve that before #1621
… leave this alone for now.
… then revist #1670

revisit

https://github.com/w3c/webauthn/pull/1668

zridouh: describes PR

elundberg: I will also look. JeffH also

https://github.com/w3c/webauthn/pull/1664

tony: is this ready

agl: potentially. has been changing with comments

jeffH: looked good to me

tony: give it two more weeks?

agl: wait on this one a bit.

agl: can we land in the next two weeks

jeffH: plausible

agl: I will work on this.

agl: american case law say these are different so we should make the change.

https://github.com/w3c/webauthn/pull/1621

agl: : should a self attestation be return when preference was none

agl: i think answer here is a special case.

agl: if you have a mac, say, there is not a whole lot of questions to what it is.
… what we have in the spec seems correct.

shane: think this is chrome bug, lets go with spec

elundberg: want to ignore issue now and land PR first

https://github.com/w3c/webauthn/pull/1576

jeffH: still in works

https://github.com/w3c/webauthn/pull/1425

eluncberg: nothing new.

https://github.com/w3c/webauthn/issues/1671

akshay: linked with cross origin authentication

agl: this is a whole can of worms from chrome view
… I want to highlight other interests in the space that makes moving complicated.

MMiller: this is only for discovery, it is not authentication
… doesn't change security properties

agl: I will talk about this with others in W3C and see how things go
… point Tim is this direction

https://github.com/w3c/webauthn/issues/1676

correction

https://github.com/w3c/webauthn/issues/1667

akshay: this is still in development.

Missing some of the participants in this discussion.

akshay: I need to work with all security keys, so I need more time, so keep this open.

https://github.com/w3c/webauthn/issues/1639

tonuy: no comments. do we close

jeffH: I suggest we close it.

jeffH: OK

tony: close

https://github.com/w3c/webauthn/issues/1637

agl: ridouh discussion is part of this, needs a review

tony: will track and see what happens

https://github.com/w3c/webauthn/issues/1612

tony: elundberg close?

elundberg: yes

tony: no objections

jeffH: we should triage this into current milestone.

tony: any other issues to bring up?

tony: not hearing anything. Any other items to discuss?

tony: adjourn

attendees: A. Langley, M. Miller, JeffH, z. ridouh, D. Turner, E.Lundberg, Aksay,

Minutes manually created (not a transcript), formatted by scribe.perl version 136 (Thu May 27 13:50:24 2021 UTC).

Diagnostics

No scribenick or scribe found. Guessed: jfontana

Maybe present: agl, akshay, attendees, eluncberg, jeffH, MMiller, shane, tonuy, tony, zridouh