W3C

– DRAFT –
Web Authentication Working Group

28 February 2024

Attendees

Present
AGL, Anders, DavidTurner, Emil, JohnBradley, JohnPascoe, Khaled, Lachlan, MikeJones, Nina, PLH, Schanck, selfissued, Shane, Simone, TimC, Tony
Regrets
-
Chair
Tony
Scribe
steele

Meeting minutes

AGL: FIDO SPWG Are finishing up their requirements document, no progress on caching yet

Pull Requests

w3c/webauthn#1953 & w3c/webauthn#1954

Skipping until David Waite is present

w3c/webauthn#1951

Pascoe: Waiting for further approvals

Nina has approved, AGL cedes his approval to Nina

w3c/webauthn#2020

Christiaan is currently OoO for the next two weeks

AGL: I'd potentially like to move this out of L3, depending on where we want to cut off L3 commmitments

Tony: Willing to put this at at-risk

David Turner to reach out to Rolf

w3c/webauthn#2026

Shane: if there's text change required then we should hold off, but otherwise we should contact Monty and ask him which path to pick

ACTION: David Turner to reach out to Monty

Issues

w3c/webauthn#2026

ACTION: AGL Volunteers to respond

w3c/webauthn#2024

Emil not on call

w3c/webauthn#2023

Rolf to attend next week

Tim: I did create an additional Issue to reflect the alternative to this: w3c/webauthn#2034

w3c/webauthn#2034 discussion

Anders: would this allow for tracking? You could potentially fingerprint users

AGL: Multiple RPs can poentially see the delta between auth being performed

Matthew: All this occurs after ceremony

Discussion around rounding time of response to prevent direct fingerprinting of times

Shane: This could be a storm in a teacup a bit, unsure of what this marker could be used to achieve

Anders: I want to consider the privacy concerns of it

Discussion around possibly rounding the time delta

Nina: You might want to have some noise added to it, but you'd want to make sure RPs can't request multiple assertions for the purpose of tracking

Matthew: What about having the RP provide an acceptable timeframe and the authenticator responds with a boolean?

Tim: essentially what Rolf is proposing

Shane: leaning towards Nina's idea of adding noise

Anders agrees

AGL drops link in chat https://lbarman.ch/blog/padme/

AGL: This has some concepts relevant to the discussion

Discussion around rounding and/or adding noise to response

Tim to iterate on the request with feedback from discussions

Going back to Pull Request w3c/webauthn#2026 now that Emil is bac

AGL: I am ok with this

oops I meant w3c/webauthn#2017

Emil: APhillips current wording regarding Unicode encoding would be a breaking change
… planning to push back on that

Emil: This pull request has kind of grown to encompass two things though, what Adam addressed and this other issue

w3c/webauthn#2022

Rolf will be joining March 6th to discuss

w3c/webauthn#2016

Emil: Pull Request has opened today for this w3c/webauthn#2031

w3c/webauthn#2028

Emil: The person that opened this is happy to close after the solution offered in #2029

w3c/webauthn#2029

AGL and Shane say it should be merged

it is done

w3c/webauthn#1859

Matt: I have no progress on this

w3c/webauthn#1856

Ackshay not present to discuss

w3c/webauthn#1797

Emil: This is not very high priority, should ask John B if this is still relevant

Emil: Mike Jones can you have a look?

Mike agrees to review

General Issues and Discussion

Emil wishes to discuss w3c/webauthn#2024

Emil wishes to close 2024 if there are no differing opinions

none

Matt: Did get confirmation of F2F plans? Are we doing this in April on the 19th?

AGL: Meant to ask Christiaan but he is away. The event is in our system but unprocessed. I suspect we'll be able to host but it's not confirmed

Suspected to host near IIW still within the Mountain View area (near the museum)

End meeting

Summary of action items

  1. David Turner to reach out to Monty
  2. AGL Volunteers to respond
Minutes manually created (not a transcript), formatted by scribe.perl version 221 (Fri Jul 21 14:01:30 2023 UTC).

Diagnostics

Maybe present: Matt, Matthew, Pascoe, Tim

All speakers: AGL, Anders, Emil, Matt, Matthew, Nina, Pascoe, Shane, Tim, Tony

Active on IRC: plh, selfissued, steele