[webauthn] §6.1.1. Signature Counter Considerations does not explicitly mention constant-zero case (#1734)

emlun has just created a new issue for https://github.com/w3c/webauthn:

== §6.1.1. Signature Counter Considerations does not explicitly mention constant-zero case ==
Currently, [§6.1.1. Signature Counter Considerations](https://www.w3.org/TR/webauthn/#sctn-sign-counter) doesn't implicitly mention what authenticators should do if they do not implement a signature counter. This is only implicitly described by how RPs validate the signature count.

The expected behaviour is explicitly specified in [§6.3.3. The authenticatorGetAssertion Operation](https://www.w3.org/TR/webauthn/#sctn-op-get-assertion), but it's confusing that we summarize everything else about the signature counter in §6.1.1 but not the constant-zero case.

Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1734 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Friday, 27 May 2022 14:49:54 UTC