diff --git a/index.bs b/index.bs index 991a722f5..5318a4b9c 100644 --- a/index.bs +++ b/index.bs @@ -4097,7 +4097,7 @@ Additionally, each authenticator has an Authenticator Attestation GUID or A authenticator. The AAGUID MUST be chosen by its maker to be identical across all substantially identical authenticators made by that maker, and different (with high probability) from the AAGUIDs of all other types of authenticators. The AAGUID for a given type of authenticator SHOULD be randomly generated to ensure this. The [=[RP]=] MAY use the AAGUID to infer certain properties of the authenticator, such as certification level -and strength of key protection, using information from other sources. The [=RP=] MAY use the AAGUID to attempt to identify the maker of the authenticator +and strength of key protection, using information from other sources. The [=[RP]=] MAY use the AAGUID to attempt to identify the maker of the authenticator without performing [=attestation=], but would be unable to trust that inference unless [=attestation=] is performed. The primary function of the authenticator is to provide [=WebAuthn signatures=], which are bound to various contextual data. These