14:55:11 RRSAgent has joined #wpwg 14:55:16 logging to https://www.w3.org/2023/11/09-wpwg-irc 14:55:16 Zakim has joined #wpwg 14:55:21 Meeting: Web Payments Working Group 14:55:26 Agenda: https://github.com/w3c/webpayments/wiki/Agenda-20231109 14:55:28 Chair: Ian 14:55:30 Scribe: Ian 14:55:33 Regrets+ NickTR 14:55:36 present+ 14:58:48 tomasz has joined #wpwg 14:59:33 present+ Tomasz_Blachowicz 14:59:36 present+ Anne_Pouillard 14:59:45 present+ Jeff_Owenson 15:00:33 present+ Yannick_Seveant(FIME) 15:00:35 clinton has joined #wpwg 15:01:00 Anne has joined #wpwg 15:01:41 present+ Ryan_Watkins 15:01:49 present+ Clinton_Allen 15:01:54 present+ Steve_Cole 15:02:18 present+ Fahad_Saleem 15:02:26 present+ Stephen_McGruer 15:02:52 Topic: SPC Prioritization 15:03:09 present+ Arman_Aygen 15:03:24 Fahad has joined #wpwg 15:03:40 -> http://www.w3.org/2023/11/worldline-spc-priority.pdf Worldline reply to outreach 15:04:02 -> https://docs.google.com/spreadsheets/d/1VevF32NcbT7rxK3Bq1M97Ibzhm124Y7SUAFHM-uWC64/edit#gid=0 Spreadsheet 15:04:29 Steve_C has joined #wpwg 15:04:41 Bastien has joined #WPWG 15:04:44 present+ Bastien_Latge 15:04:59 (Anne presents the Worldline feedback) 15:05:21 Anne: The main requests relate to 3DS. 15:05:34 ...Issuer and network iconography are required in the ACS UI 15:05:39 present+ Doug_Fisher 15:05:51 present+ Sami_Tikkala 15:05:58 Anne: Recurring payments are important to us 15:06:16 ...non-payment use cases are also important. 15:06:55 ...but the most important request relates to receiving an attestation (relates to PSD2); we have to differentiate devices and understand their capabilities. 15:07:16 ...it's also very important that we see interoperability (e.g., Webkit implementation) 15:07:27 Anne: Also, the authenticator dialog should stop saying "Sign-in" 15:07:46 ...this conveys the wrong message to the user; but this is slightly less critical than others 15:08:01 Rolf has joined #wpwg 15:09:36 SameerT has joined #wpwg 15:09:42 present+ Sameer_Tare 15:09:42 present+ 15:10:02 [We walk through FIME prioritization reply from Jean-Luc] 15:10:56 present+ Rolf_Lindemann 15:12:24 smcgruer_[EST]: I wonder whether "roaming" in FIME feedback also implies "hybrid" 15:13:24 smcgruer_[EST]: Summary - other payments use cases, show RP origin, roaming, android native, some UX changes (bigger icon, fallback UX, issuer/network) 15:14:16 Sameer: We are close to finalizing our list from the 3DS WG 15:14:31 ...we are trying to put more structure into our feedback to include "blockers" from our perspective e 15:16:10 Rolf: Main feedback is to get additional browser support. 15:16:21 ...get the attestation stuff done (for PSD2) 15:16:26 ...support roaming authenticators 15:16:45 ...vanilla webauthn credentials for use by RP. 15:18:03 IJ: Stephen what's your vision related to this last point? I imagine usage in both top-level and cross-origin iframe. 15:18:25 Rolf: you can name Nok Nok in the spreadsheet 15:18:54 q+ 15:19:31 ack Anne 15:20:03 Anne: When we tried to classify the requests, it was not clear what userVerification=discouraged 15:20:31 smcgruer_[EST]: WebAuthn allows the caller to specify whether to verify the user (biometric) or only user presence check. 15:21:37 ...when userVerification is discouraged, e.g., the user might just click a button. This is sufficient for "user presence". The cryptogram result is of less value of course. But there's some interest in the for use cases that don't require as strong security. 15:22:02 ...but note that the authenticator can always choose to do userVerification anyway, and we know that Windows Hello always does userVerification. 15:22:23 present+ Gerhard_Oosthuizen 15:22:30 q+ 15:23:09 ack SameerT 15:23:32 SameerT: If the userVerification=discouraged and user verification IS performed, is the verification data in the assertion? 15:24:16 Rolf: The method won't be known, but the authenticator will indicate whether the user was verified in the response. 15:26:16 Topic: Updates 15:26:34 - MDN 15:27:26 https://github.com/mdn/content/pull/28705 15:29:44 - Conferences? 15:30:26 Rolf: +1 to this; lots of value. I don't have a list. But Money 20/20 a candidate 15:30:52 ...we could do something in Europe where multiple companies cooperate to spread the word. 15:31:03 ...I think this was a key to passkey success 15:31:27 ...good to have different kinds of stakeholders talking about this from various perspectives. 15:31:40 Steve: ETA transactions 15:32:35 Arman: US Payments Forum 15:33:14 - "How to SPC" 15:33:51 present+ Jean-Luc_di_Manno 15:34:09 IJ: What is status of How to FIDO? 15:34:52 Rolf: Really targeting engineers. I think the case of SPC, there will be a smaller number of implementers. Most of the people will be using 3rd party tools. For them we need a document on a different level. 15:35:05 ...mainly about educating merchants and issuers on the value of SPC. 15:35:22 ...but they typically don't implement it themselves. They get it through their 3DS SDKs 15:35:47 Sami: +1 15:36:01 Sameer: +1 15:37:39 JeanLuc has joined #WPWG 15:37:42 Doug: Merchant Risk Conf 15:38:09 Fahad has joined #wpwg 15:38:52 q+ 15:39:43 [We look at the poll results] 15:40:36 Jean-Luc: I would distinguish roaming and hybrid 15:41:00 q? 15:41:02 ack JeanLuc 15:41:28 Ian: I will add the data to the spreadsheet 15:41:43 smcgruer_[EST]: Thanks for all the feedback, this is great. We are looking at this and our investment of SPC. 15:41:58 ...all feedback (whether same or different than others) valued. 15:42:10 Topic: upcoming meetings 15:42:17 23 Nov: Canceled 15:42:17 7 Dec: Scheduled 15:42:17 21 Dec: Canceled 15:42:19 4 January 2024: Canceled 15:43:04 q+ 15:43:07 Topic: Any other business? 15:43:28 Jean-Luc: There is a lot of discussion on quantum computing. 15:43:46 ...is there any impact on SPC (or WebAuthN) regarding crypto agility? 15:44:04 smcgruer_[EST]: All the impact on SPC would also impact WebAuthn 15:44:19 +1 15:44:29 ...with WebAuthn you specify which crypto algorithms when you create the credential 15:45:31 IJ: Has this been discussed in WebAuthn? 15:45:38 Rolf: The algorithms are registered in IANA 15:45:49 ...we rely on other groups to give us algorithm identifiers. 15:47:25 [Adjourned until 7 Dec] 15:47:30 I have made the request to generate https://www.w3.org/2023/11/09-wpwg-minutes.html Ian 18:24:52 Zakim has left #wpwg 19:11:14 bkardell_ has joined #wpwg