W3C

– DRAFT –
Web Authentication WG

15 December 2021

Attendees

Present
elundberg, jeffh, jfontana, nsteele
Regrets
-
Chair
-
Scribe
jeffh

Meeting minutes

discussion of Akshay's concerns wrt the Secure Payment Confirmation SPC discussion, see this comment onwards: https://github.com/w3c/webauthn/issues/1667#issuecomment-993959019

Akshay and interested parties will join the WPWG's SPC-webauthn taskforce call in the future inorder to sort this out with SPC folks

Also in attendance, Wendy S., Adam L, Tim C., E. Lundberg, J. Bradley, Akshay K.

Emil: notes that there is sort of a potential de-anonymization attack with the proposed 3d party credentials
… will note these details in a comment on webauthn issue #1667

jbradley: how many "cred types" do we want to allow for at the CTAP layer ?

akshay: use a DWORD of bit flags

agl: "put it in large blob" ie an unecrypted portion of largeBlob. there's considerations with credprotect... ans: dont make payment credentials cred protect level 3

nick steele: he and Matt Miller are putting together material on developer considertations and will submit as an issue before the next meeting 12-Jan-2022

<wseltzer> [Next meeting Jan. 12]

Minutes manually created (not a transcript), formatted by scribe.perl version 185 (Thu Dec 2 18:51:55 2021 UTC).

Diagnostics

Succeeded: s/scribenick/scribenick:/

Maybe present: agl, akshay, Emil, jbradley