[webauthn] Bad instructions in Android SafetyNet attestation validation steps

sbweeden has just created a new issue for https://github.com/w3c/webauthn:

== Bad instructions in Android SafetyNet attestation validation steps ==
In section 8.5 (https://www.w3.org/TR/webauthn/#android-safetynet-attestation) there are validation instructions for the Android SafetyNet Attestation Statement Format.

One of these states:

"Verify that the nonce in the response is identical to the concatenation of authenticatorData and clientDataHash."

This is actually wrong. The nonce actually seems to be: 
b64encode(sha256(authenticatorData + clientDataHash));

Please confirm with the Google team first, but that seems to be the needed check to me.

Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1018 using your GitHub account

Received on Saturday, 28 July 2018 06:31:56 UTC