20:04:52 RRSAgent has joined #webauthn 20:04:57 logging to https://www.w3.org/2023/11/29-webauthn-irc 20:05:22 Topic: Next week meeting 20:05:30 Tony: I can't make it next week... 20:06:04 ... we'll cancel unless someone speaks up now 20:06:23 (none heard)) 20:07:29 Topic: Web Identity Credential Working Group Charter 20:07:41 Tim: it's essentially the FedCM API WG. 20:07:56 jfontana has joined #webauthn 20:08:08 --> https://github.com/w3c/strategy/issues/427 Web Identity Credential Working Group Charter 20:10:23 Tony: +1 to list WebAuthn as a depencency 20:11:26 soba has joined #webauthn 20:11:50 is anyone scribing? 20:12:14 I'll scribe 20:12:23 no problem! 20:12:28 jfontana_ has joined #webauthn 20:12:38 Agenda: https://lists.w3.org/Archives/Public/public-webauthn/2023Nov/0145.html 20:12:57 Meeting: WebAuthn Weekly 20:13:02 Chair: Tony Nadalin 20:14:00 rrsagent, generate minutes 20:14:01 I have made the request to generate https://www.w3.org/2023/11/29-webauthn-minutes.html plh 20:14:05 Discussion around Web Identity Working Group Charter before pull requests 20:14:11 TOPIC: Pull Requests 20:14:17 Discussing https://github.com/w3c/webauthn/pull/2001 20:14:39 selfissued has joined #webauthn 20:14:41 present+ 20:14:42 AGL: Want to discuss with Nina Satragno, John Bradley & Tim Cappalli to review 20:15:48 present+ ShaneWeeden,JasonCai,TimCappalli,AGL,TonyNadalin,PLH,AnderAberg,JaiminBhatt,DavidTurner 20:15:57 present+ JohnPascoe 20:16:14 present+ JohnSchanck 20:16:34 Discussion of https://github.com/w3c/webauthn/pulls 20:16:40 Shane making editorial change 20:16:55 Tim Cappalli approved, ready to merge 20:17:57 https://github.com/w3c/webauthn/pull/1992 20:18:03 Matthew on PTO this week 20:18:23 Ready to Merge 20:18:59 Nick Steele to merge 20:19:57 https://github.com/w3c/webauthn/pull/1998 20:20:29 https://github.com/w3c/webauthn/pull/1988 20:20:48 Not been merged, ready for merge 20:20:55 Nick Steele merging 20:21:47 https://github.com/w3c/webauthn/pull/1972 20:21:52 Still pending 20:22:03 https://github.com/w3c/webauthn/pull/1945 20:22:14 Closed 20:22:23 https://github.com/w3c/webauthn/pull/1926 20:22:29 Tim: we're still waiting for a response 20:23:05 https://github.com/w3c/webauthn/pull/1923 20:23:16 Tim: I need to add the privacy statement, will add before next call. 20:23:37 TOPIC: Issues 20:23:53 https://github.com/w3c/webauthn/issues/1998 20:24:06 Shane: this has been closed 20:24:22 https://github.com/w3c/webauthn/issues/1994 20:24:26 Emlun not present to discuss 20:24:49 https://github.com/w3c/webauthn/issues/1987 20:25:12 AGL: this would be resolved by #1999 20:25:20 Matt not present 20:25:48 https://github.com/w3c/webauthn/issues/1967 20:25:59 AGL: Nina will be present in 2 weeks to discuss 20:26:09 https://github.com/w3c/webauthn/issues/1965 20:28:09 Shane: Our security model does not extend to a man in the browser model 20:28:21 ACTION: Nick steele to relay this message and close #1965 20:28:28 https://github.com/w3c/webauthn/issues/1964 20:28:56 AGL: This is in the CTAP spec, we could point to this if there's a recently published CTAP spec 20:29:24 Tony: Do you want to respond? 20:29:30 AGL: I can address in 2 weeks 20:29:34 Issue to remain open 20:29:36 https://github.com/w3c/webauthn/issues/1942 20:30:10 Tim: this issue was brought up the other day on Stack Overflow 20:30:24 Tim: I think we should close this issue 20:30:44 AGL: this could cause UI breakage 20:30:56 Action: Tim Cappalli to draft response 20:32:40 Discussion around requests for getOrCreate methd 20:33:07 AGL: if hordes of developers are calling for it, Google would consider it 20:33:28 MikeJones: becomes an issue when you have a multitude of accounts for an RP 20:35:29 https://github.com/w3c/webauthn/issues/1921 20:36:03 Tim: I don't think this is appropriate for WebAuthn 20:36:11 Shane agrees, this is out of scope 20:37:02 JohnBradley: I disagree with tim that this is a security key issue, I think this is fundamentally different than sharing a hardware key. This is a FIDO issue 20:37:41 Shane: we should get Emlun's opinion on this 20:38:06 ...he has some proposed chaanges to the wording 20:38:09 https://github.com/w3c/webauthn/issues/1912 20:38:11 https://github.com/w3c/webauthn/issues/1913 20:38:26 Emlun to address 20:39:08 Tim: I know that there was an issue in bikeshed regarding indenting? Has this been addressed? 20:39:12 AGL: I've seen them 20:39:21 Tim: next time I see them I'll try to remove them 20:39:24 https://github.com/w3c/webauthn/issues/1888 20:40:15 Arnar assigned, still pending a reviewer. Tim to assign MatthewMiller who had opinions on the topic 20:40:21 https://github.com/w3c/webauthn/issues/1859 20:40:47 https://github.com/w3c/webauthn/issues/1856 20:41:04 Tim bumping issue with Ackshay 20:41:46 AGL: There is some amount of consternation happening because this introduces latency. Some RPs find this a problem. Idea of having a challenge callback is making an emergence again. We're still discussing 20:41:57 Tony: would it align with this issue? 20:42:01 AGL: maybe not directly 20:42:33 https://github.com/w3c/webauthn/issues/1854 20:43:07 AGL: At some point we might want to decide to ignore or remove legacy issues 20:43:16 Tony: Nina has responded 20:43:26 AGL: waiting to put energy behind this 20:43:35 Tony: is this something that folks want to do? 20:43:53 ... it's at risk, although unsure if people have time and capacity 20:43:59 ... can also leave undecided 20:44:38 AGL: no objections, haven't heard about it in feedback, the utility is small. I wouldn't prioritize it for L3 20:44:42 https://github.com/w3c/webauthn/issues/1819 20:45:13 AGL: When Arnar returns in two weeks you can bug him about this 20:45:32 Tony assigns Arnar to the issue, the wily fellow 20:45:45 https://github.com/w3c/webauthn/issues/1797 20:45:56 Tony: this is just a process and editorial change 20:46:01 https://github.com/w3c/webauthn/issues/1795 20:47:19 John: we might want to just say that the type changes when we talk to CTAP2 20:47:26 AGL okay with this 20:47:43 ACTION: John Bradley to write a PR for issue #1795 20:47:52 https://github.com/w3c/webauthn/issues/1748 20:47:56 Waiting for Nina 20:48:16 AGL: issue not wrong, will bother Nina about it 20:48:21 Tony: issue is at risk 20:48:28 AGL will follow up with Nina 20:50:23 https://github.com/w3c/webauthn/issues/1743 20:50:30 Action: Nick Steele to close 20:51:18 https://github.com/w3c/webauthn/issues/1667 20:51:44 This issue is primordial but still valid 20:52:27 Tony: I'll ping Ian Jacobs 20:52:46 issue to remain open, a relic of the old world 20:53:01 https://github.com/w3c/webauthn/issues/1635 20:53:43 MikeJones: For one thing, we have a reference to large per credential blobs that I am unable to find in the CTAP2 spec. Did that occur? was it deleted? 20:54:10 AGL: At the webauthn layer we have largblob, at CTAP this gets abstracted down into a different format 20:55:05 Mike Jones posts a note from the issue to chat: NOTE: In order to interoperate, user agents storing large blobs on authenticators using [FIDO-CTAP] are expected to use the provisions detailed in that specification for storing large, per-credential blobs. 20:55:30 https://fidoalliance.org/specs/fido-v2.0-ps-20190130/fido-client-to-authenticator-protocol-v2.0-ps-20190130.html#large-blob 20:55:51 Adam Langley points to RD (review draft) https://fidoalliance.org/specs/fido-v2.1-rd-20201208/fido-client-to-authenticator-protocol-v2.1-rd-20201208.html#authenticatorLargeBlobs 20:56:04 David Turner: That's the 2.0 version, Mike, not 2.1 20:56:26 From David Turner, https://fidoalliance.org/specs/fido-v2.1-ps-20210615/fido-client-to-authenticator-protocol-v2.1-ps-errata-20220621.html#conformance 20:56:33 --> https://w3c.github.io/webauthn/#sctn-large-blob-extension 10.1.5. Large blob storage extension (largeBlob) 20:56:37 https://fidoalliance.org/specs/fido-v2.1-ps-20210615/fido-client-to-authenticator-protocol-v2.1-ps-20210615.html 20:57:08 AGL posts to 2.1 draft https://fidoalliance.org/specs/fido-v2.1-ps-20210615/fido-client-to-authenticator-protocol-v2.1-ps-errata-20220621.html#authenticatorLargeBlobs 20:57:39 Mike Jones should have what he needs now to make a PR regarding largeblob 20:57:55 MikeJones: there's also a different link to responses 20:58:51 MikeJones: I need to fix the CTAP references, will sort out other issues async 20:59:21 We will cancel next two weeks of meetings as discussed, resume in two weeks 20:59:24 rrsagent, generate minutes 20:59:25 I have made the request to generate https://www.w3.org/2023/11/29-webauthn-minutes.html plh 20:59:58 adjourn 21:00:00 RRSAgent, make logs public 21:06:36 steele has joined #webauthn 21:41:32 steele has joined #webauthn 21:49:59 steele has joined #webauthn 21:51:02 steele_ has joined #webauthn 23:44:17 Zakim has left #webauthn