IRC log of webauthn on 2023-11-29

Timestamps are in UTC.

20:05:22 [plh]
Topic: Next week meeting
20:05:30 [plh]
Tony: I can't make it next week...
20:06:04 [plh]
... we'll cancel unless someone speaks up now
20:06:23 [plh]
(none heard))
20:07:29 [plh]
Topic: Web Identity Credential Working Group Charter
20:07:41 [plh]
Tim: it's essentially the FedCM API WG.
20:07:56 [jfontana]
20:08:08 [plh]
--> Web Identity Credential Working Group Charter
20:10:23 [plh]
Tony: +1 to list WebAuthn as a depencency
20:11:26 [soba]
20:11:50 [steele]
is anyone scribing?
20:12:14 [steele]
I'll scribe
20:12:23 [steele]
no problem!
20:12:28 [jfontana_]
20:12:38 [plh]
20:12:57 [steele]
Meeting: WebAuthn Weekly
20:13:02 [steele]
Chair: Tony Nadalin
20:14:00 [plh]
20:14:05 [steele]
Discussion around Web Identity Working Group Charter before pull requests
20:14:11 [steele]
TOPIC: Pull Requests
20:14:17 [steele]
20:14:39 [selfissued]
20:14:41 [selfissued]
20:14:42 [steele]
AGL: Want to discuss with Nina Satragno, John Bradley & Tim Cappalli to review
20:15:48 [steele]
present+ ShaneWeeden,JasonCai,TimCappalli,AGL,TonyNadalin,PLH,AnderAberg,JaiminBhatt,DavidTurner
20:15:57 [steele]
present+ JohnPascoe
20:16:14 [steele]
present+ JohnSchanck
20:16:34 [steele]
Discussion of
20:16:40 [steele]
Shane making editorial change
20:16:55 [steele]
Tim Cappalli approved, ready to merge
20:17:57 [steele]
20:18:03 [steele]
Matthew on PTO this week
20:18:23 [steele]
Ready to Merge
20:18:59 [steele]
Nick Steele to merge
20:19:57 [steele]
20:20:29 [steele]
20:20:48 [steele]
Not been merged, ready for merge
20:20:55 [steele]
Nick Steele merging
20:21:47 [steele]
20:21:52 [steele]
Still pending
20:22:03 [steele]
20:22:14 [steele]
20:22:23 [steele]
20:22:29 [steele]
Tim: we're still waiting for a response
20:23:05 [steele]
20:23:16 [steele]
Tim: I need to add the privacy statement, will add before next call.
20:23:37 [steele]
TOPIC: Issues
20:23:53 [steele]
20:24:06 [steele]
Shane: this has been closed
20:24:22 [steele]
20:24:26 [steele]
Emlun not present to discuss
20:24:49 [steele]
20:25:12 [steele]
AGL: this would be resolved by #1999
20:25:20 [steele]
Matt not present
20:25:48 [steele]
20:25:59 [steele]
AGL: Nina will be present in 2 weeks to discuss
20:26:09 [steele]
20:28:09 [steele]
Shane: Our security model does not extend to a man in the browser model
20:28:21 [steele]
ACTION: Nick steele to relay this message and close #1965
20:28:28 [steele]
20:28:56 [steele]
AGL: This is in the CTAP spec, we could point to this if there's a recently published CTAP spec
20:29:24 [steele]
Tony: Do you want to respond?
20:29:30 [steele]
AGL: I can address in 2 weeks
20:29:34 [steele]
Issue to remain open
20:29:36 [steele]
20:30:10 [steele]
Tim: this issue was brought up the other day on Stack Overflow
20:30:24 [steele]
Tim: I think we should close this issue
20:30:44 [steele]
AGL: this could cause UI breakage
20:30:56 [steele]
Action: Tim Cappalli to draft response
20:32:40 [steele]
Discussion around requests for getOrCreate methd
20:33:07 [steele]
AGL: if hordes of developers are calling for it, Google would consider it
20:33:28 [steele]
MikeJones: becomes an issue when you have a multitude of accounts for an RP
20:35:29 [steele]
20:36:03 [steele]
Tim: I don't think this is appropriate for WebAuthn
20:36:11 [steele]
Shane agrees, this is out of scope
20:37:02 [steele]
JohnBradley: I disagree with tim that this is a security key issue, I think this is fundamentally different than sharing a hardware key. This is a FIDO issue
20:37:41 [steele]
Shane: we should get Emlun's opinion on this
20:38:06 [steele]
...he has some proposed chaanges to the wording
20:38:09 [steele]
20:38:11 [steele]
20:38:26 [steele]
Emlun to address
20:39:08 [steele]
Tim: I know that there was an issue in bikeshed regarding indenting? Has this been addressed?
20:39:12 [steele]
AGL: I've seen them
20:39:21 [steele]
Tim: next time I see them I'll try to remove them
20:39:24 [steele]
20:40:15 [steele]
Arnar assigned, still pending a reviewer. Tim to assign MatthewMiller who had opinions on the topic
20:40:21 [steele]
20:40:47 [steele]
20:41:04 [steele]
Tim bumping issue with Ackshay
20:41:46 [steele]
AGL: There is some amount of consternation happening because this introduces latency. Some RPs find this a problem. Idea of having a challenge callback is making an emergence again. We're still discussing
20:41:57 [steele]
Tony: would it align with this issue?
20:42:01 [steele]
AGL: maybe not directly
20:42:33 [steele]
20:43:07 [steele]
AGL: At some point we might want to decide to ignore or remove legacy issues
20:43:16 [steele]
Tony: Nina has responded
20:43:26 [steele]
AGL: waiting to put energy behind this
20:43:35 [steele]
Tony: is this something that folks want to do?
20:43:53 [steele]
... it's at risk, although unsure if people have time and capacity
20:43:59 [steele]
... can also leave undecided
20:44:38 [steele]
AGL: no objections, haven't heard about it in feedback, the utility is small. I wouldn't prioritize it for L3
20:44:42 [steele]
20:45:13 [steele]
AGL: When Arnar returns in two weeks you can bug him about this
20:45:32 [steele]
Tony assigns Arnar to the issue, the wily fellow
20:45:45 [steele]
20:45:56 [steele]
Tony: this is just a process and editorial change
20:46:01 [steele]
20:47:19 [steele]
John: we might want to just say that the type changes when we talk to CTAP2
20:47:26 [steele]
AGL okay with this
20:47:43 [steele]
ACTION: John Bradley to write a PR for issue #1795
20:47:52 [steele]
20:47:56 [steele]
Waiting for Nina
20:48:16 [steele]
AGL: issue not wrong, will bother Nina about it
20:48:21 [steele]
Tony: issue is at risk
20:48:28 [steele]
AGL will follow up with Nina
20:50:23 [steele]
20:50:30 [steele]
Action: Nick Steele to close
20:51:18 [steele]
20:51:44 [steele]
This issue is primordial but still valid
20:52:27 [steele]
Tony: I'll ping Ian Jacobs
20:52:46 [steele]
issue to remain open, a relic of the old world
20:53:01 [selfissued]
20:53:43 [steele]
MikeJones: For one thing, we have a reference to large per credential blobs that I am unable to find in the CTAP2 spec. Did that occur? was it deleted?
20:54:10 [steele]
AGL: At the webauthn layer we have largblob, at CTAP this gets abstracted down into a different format
20:55:05 [steele]
Mike Jones posts a note from the issue to chat: NOTE: In order to interoperate, user agents storing large blobs on authenticators using [FIDO-CTAP] are expected to use the provisions detailed in that specification for storing large, per-credential blobs.
20:55:30 [selfissued]
20:55:51 [steele]
Adam Langley points to RD (review draft)
20:56:04 [steele]
David Turner: That's the 2.0 version, Mike, not 2.1
20:56:26 [steele]
From David Turner,
20:56:33 [plh]
--> 10.1.5. Large blob storage extension (largeBlob)
20:56:37 [selfissued]
20:57:08 [steele]
AGL posts to 2.1 draft
20:57:39 [steele]
Mike Jones should have what he needs now to make a PR regarding largeblob
20:57:55 [steele]
MikeJones: there's also a different link to responses
20:58:51 [steele]
MikeJones: I need to fix the CTAP references, will sort out other issues async
20:59:21 [steele]
We will cancel next two weeks of meetings as discussed, resume in two weeks
20:59:58 [steele]
21:00:00 [steele]
21:06:36 [steele]
21:41:32 [steele]
21:49:59 [steele]
21:51:02 [steele_]
23:44:17 [Zakim]
