You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Just a quick question on WebAuthn. My impression has always
been that the private key of a generated credential should never
leave the Authenticator.
But a casual read of w3c.github.io/webauthn/
doesn't give me any such language. There's "user deletes the
credential from the device" under Decommissioning, implicating that
the credential can only be on one device, but I fail to find anything
explicit on this topic. Am I missing something or am I mistaken about
credential export and import?
My brief answer:
Yes, that's the baseline posture.
Though, it is modulo some form of secure credentials migration/backup/recovery means, which we have not figured out yet and is a work in early progress. e.g. see issue #931
Yes, the spec is arguably missing something in terms of describing this and perhaps pointing to appropriate FIDO material.
The text was updated successfully, but these errors were encountered:
A reader asks:
My brief answer:
Yes, that's the baseline posture.
Though, it is modulo some form of secure credentials migration/backup/recovery means, which we have not figured out yet and is a work in early progress. e.g. see issue #931
Yes, the spec is arguably missing something in terms of describing this and perhaps pointing to appropriate FIDO material.
The text was updated successfully, but these errors were encountered: