IRC log of webauthn on 2023-12-13

Timestamps are in UTC.

20:03:34 [RRSAgent]
RRSAgent has joined #webauthn
20:03:39 [RRSAgent]
logging to https://www.w3.org/2023/12/13-webauthn-irc
20:03:39 [Zakim]
Zakim has joined #webauthn
20:03:50 [plh]
Meeting: Web Authentication
20:03:55 [plh]
Chair: Tony
20:04:05 [plh]
scribenick: jfontana
20:06:19 [plh]
agenda: https://lists.w3.org/Archives/Public/public-webauthn/2023Dec/0037.html
20:06:29 [jfontana]
we will meeton on the 20th
20:07:10 [jfontana]
tony: come back on the 3rd
20:09:49 [jfontana]
https://github.com/w3c/webauthn/pull/2005
20:10:12 [plh]
rrsagent, make logs world-visible
20:10:42 [jfontana]
https://github.com/w3c/webauthn/pull/2005
20:11:03 [jfontana]
shane: seems trivial
20:11:16 [jfontana]
MMmiller: I will approve.
20:11:28 [jfontana]
...merge
20:11:33 [jfontana]
https://github.com/w3c/webauthn/pull/2003
20:11:49 [jfontana]
emil: waiting review
20:12:13 [jfontana]
agl: i will approve in a few minutes.
20:12:23 [jfontana]
tony: no objections
20:12:28 [jfontana]
https://github.com/w3c/webauthn/pull/2001
20:12:44 [jfontana]
tony: that looks like it can go.
20:12:53 [jfontana]
mmliller: does that go to 1999?
20:13:33 [jfontana]
tony: merge 2001
20:13:42 [jfontana]
https://github.com/w3c/webauthn/pull/1990
20:14:06 [jfontana]
tony: no objections
20:14:14 [jfontana]
https://github.com/w3c/webauthn/pull/1997
20:14:20 [jfontana]
agl: needd to rev it
20:14:32 [jfontana]
https://github.com/w3c/webauthn/pull/1991
20:14:40 [jfontana]
agl: it is good to go
20:14:56 [jfontana]
tony" no objections?
20:15:00 [jfontana]
hearing none
20:15:13 [jfontana]
https://github.com/w3c/webauthn/pull/1972
20:15:43 [jfontana]
agl: 1997 in moot
20:16:23 [jfontana]
mmiller filled in 1997
20:16:30 [jfontana]
https://github.com/w3c/webauthn/pull/1926
20:16:51 [jfontana]
shane: waiting on tim and akshary
20:17:03 [jfontana]
https://github.com/w3c/webauthn/pull/1923
20:17:24 [jfontana]
tim: add privacy text. getting close to merge
20:17:43 [jfontana]
nina: take a look at it, emil also
20:20:12 [jfontana]
tony: you lthree took at it
20:20:18 [jfontana]
tony: go to issues.
20:20:56 [jfontana]
https://github.com/w3c/webauthn/issues/1994
20:22:04 [jfontana]
emil: lots of references, spell it out
20:22:14 [jfontana]
tony:s oething for level 3
20:22:25 [jfontana]
somethign for level 3
20:24:15 [jfontana]
arnar: cred man level change
20:24:28 [jfontana]
miller: from RP it looks straight forward
20:25:03 [jfontana]
...likes statelessness
20:25:18 [jfontana]
...wnat to take another look
20:25:39 [jfontana]
Arnar: new API
20:27:06 [jfontana]
...credential provider
20:28:08 [jfontana]
tony: may be some differences among providers.
20:28:24 [jfontana]
arnar: is user ID the critical part
20:28:28 [jfontana]
arndar: yes.
20:30:53 [jfontana]
bradley: should we allows Rps to delete creds?
20:31:45 [jfontana]
nina: why so dangerous, does it have bug, maybe we could do a different
20:32:52 [jfontana]
nina: i don't see reason not to support, should be able to do this
20:33:32 [jfontana]
arnar: these are recommendations; should specify
20:33:46 [jfontana]
tony: what do we need to do?
20:34:19 [jfontana]
arnar: things could happen, locks, etc. there will always be inconsistency
20:34:32 [jfontana]
mmiller: is this great for RP
20:34:40 [jfontana]
...?
20:35:15 [jfontana]
...there is abuse that could come thi sway
20:36:33 [jfontana]
mmiller: what about handing aoiut browser extentions
20:37:19 [jfontana]
nina: don't think we can do any cashing
20:37:55 [jfontana]
...cashing idea seems dangerous.
20:37:55 [plh]
s/cashing/caching/
20:40:51 [jfontana]
bradley: we would need to change CTAP, could be a credential command, but that is not possible
20:41:49 [jfontana]
...the one being deleted in not in the list, you don't know.
20:46:45 [jfontana]
tony: is this something that works for you
20:46:56 [jfontana]
shane: concept does, need to think it out
20:47:16 [jfontana]
...will it help or not - not certain
20:47:27 [jfontana]
tim: we would like to see this move forward"
20:47:36 [jfontana]
mmiller: same for us.
20:47:52 [jfontana]
tony: hearing a mixed reaction
20:48:03 [jfontana]
...beneficial or not?
20:48:29 [jfontana]
shane: i'm not on the negative side, agree with Tiim
20:49:35 [jfontana]
bradley: questions, what kind of re-auth? how will this be processed?
20:57:37 [jfontana]
tony: anyone aganst this.
20:57:49 [jfontana]
bradley: I want more answers.
20:58:24 [jfontana]
....it is in CTAP sepc
20:58:42 [jfontana]
...before 2.2 want to make some changes?
21:00:04 [jfontana]
arnar: tell people to go forward with pulls request, issues.
21:00:09 [jfontana]
...?
21:00:47 [jfontana]
nina: the cred man
21:01:28 [jfontana]
...I don't know what the value will be with this...
21:03:23 [jfontana]
rrsagent, make logs public
21:04:40 [jfontana]
rrsagent, draft minutes
21:04:42 [RRSAgent]
I have made the request to generate https://www.w3.org/2023/12/13-webauthn-minutes.html jfontana
21:05:42 [jfontana]
zakim, list attendees
21:05:42 [Zakim]
As of this point the attendees have been (no one)
21:07:28 [jfontana]
chairs: Nadalin, Fontana
21:21:13 [jfontana]
zakim, bye
21:21:13 [Zakim]
Zakim has left #webauthn
21:21:30 [jfontana]
rrsagent, bye
21:21:30 [RRSAgent]
I see no action items