[webauthn] Process to report non-compliant credentials (#1713)

Firstyear has just created a new issue for https://github.com/w3c/webauthn:

== Process to report non-compliant credentials ==
Hi all,

So far having implemented webauthn-rs, and developed a compatibility testing site, we have uncovered a number of non-compliant credentials (windows 11 + TPM in some cases sends a truncated aaguid, pixel 3a/4 do not send valid authenticator attestation response). 

There seems to be no good way to handle this situation, and no clear way to direct feedback to the various manufactures to report non-compliant credentials/devices. Is this a process that we can improve as part of this wg? 

Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1713 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Monday, 28 March 2022 22:44:37 UTC