IRC log of webauthn on 2021-03-03
Timestamps are in UTC.
- 18:54:33 [RRSAgent]
- RRSAgent has joined #webauthn
- 18:54:33 [RRSAgent]
- logging to https://www.w3.org/2021/03/03-webauthn-irc
- 18:54:35 [Zakim]
- RRSAgent, make logs Public
- 18:54:36 [Zakim]
- Meeting: Web Authentication WG
- 18:54:38 [wseltzer]
- Agenda: https://lists.w3.org/Archives/Public/public-webauthn/2021Mar/0004.html
- 19:58:00 [jfontana]
- jfontana has joined #webauthn
- 19:59:46 [jfontana]
- sounds like a warning :-)
- 19:59:56 [jfontana]
- present+
- 20:00:09 [nsteele]
- nsteele has joined #webauthn
- 20:00:18 [wseltzer]
- s/sounds like a warning :-)//
- 20:00:25 [nsteele]
- present+
- 20:00:27 [dveditz]
- dveditz has joined #webauthn
- 20:01:18 [wseltzer]
- present+
- 20:02:21 [selfissued]
- selfissued has joined #webauthn
- 20:02:25 [nina]
- nina has joined #webauthn
- 20:02:49 [selfissued]
- present+
- 20:03:50 [dveditz]
- present+
- 20:05:30 [jeffh]
- present+
- 20:05:50 [jfontana]
- Tony: does L2 supersede or does L1 stay around
- 20:05:55 [jfontana]
- agl: yes.
- 20:06:04 [elundberg]
- elundberg has joined #webauthn
- 20:06:08 [jfontana]
- tony: supersede means depricate
- 20:06:36 [wseltzer]
- present+ agl, Nadalin, akshaykumar, davidturner, jeffh, johnbradley, dveditz, elundberg, matthewmiller, nina, raerivera, sbweeden, timcappalli
- 20:07:05 [jfontana]
- agl: there are no users for the extensions, L1
- 20:07:13 [jfontana]
- selfissue: we should deprecate
- 20:07:25 [jfontana]
- ...normal part of process.
- 20:07:41 [wseltzer]
- q+
- 20:07:50 [jfontana]
- tony: we don't change the L1 spec, we don't have a pointer
- 20:08:02 [wseltzer]
- PROPOSED: L2 Supersedes L1
- 20:08:16 [wseltzer]
- RESOLVED: L2 Supersedes L1
- 20:08:27 [jfontana]
- ...so we want to go supersede.
- 20:08:44 [wseltzer]
- q-
- 20:08:46 [jfontana]
- wendy: the patent policies for L1 remain in place.
- 20:09:05 [jfontana]
- bradley: reference in IANA registry.
- 20:09:15 [jfontana]
- tony: nothing left for CR
- 20:09:27 [jfontana]
- ... some open issues for L3,
- 20:09:38 [jfontana]
- ... I have not finished the charter.
- 20:09:45 [jfontana]
- ...a draft will be posted.
- 20:10:18 [jfontana]
- ...we are not merging any pull requests, just sorting out what we have.
- 20:11:17 [matthewmiller]
- matthewmiller has joined #webauthn
- 20:11:58 [jfontana]
- ...https://github.com/w3c/webauthn/pulls/1232
- 20:12:34 [jfontana]
- https://github.com/w3c/webauthn/pull/1232
- 20:14:26 [jfontana]
- elundberg: if we do this, we should keep in the RP updates
- 20:14:55 [jfontana]
- selfissue: for this to work you would have to update all Web authn clients to do this
- 20:15:02 [jfontana]
- agl: agents and servers, yes
- 20:15:08 [jfontana]
- selfissue: close and say will not do
- 20:15:19 [jfontana]
- agl: needs more explaining, justification
- 20:15:32 [jfontana]
- tony: nick will you do this and close it?
- 20:15:36 [jericks]
- jericks has joined #webauthn
- 20:15:37 [jfontana]
- nickS: yes
- 20:16:02 [jfontana]
- nickS: I don't know if Rolf has any interest in taking this on
- 20:16:14 [jfontana]
- tony: he can re-open if he wants.
- 20:16:38 [jfontana]
- https://github.com/w3c/webauthn/pull/1425
- 20:16:48 [jfontana]
- elundberg: no updates right now.
- 20:18:02 [jfontana]
- https://github.com/w3c/webauthn/pull/1576
- 20:18:10 [jfontana]
- jeffH: still interested
- 20:18:32 [jfontana]
- https://github.com/w3c/webauthn/issue/1570
- 20:18:53 [jfontana]
- tony: talking about payments in general.
- 20:19:33 [jfontana]
- URL correction: https://github.com/w3c/webauthn/issues/1570
- 20:19:54 [jfontana]
- https://github.com/w3c/webauthn/issues/1569
- 20:20:26 [jfontana]
- agl: we have a whole series of issues on github. boil down to re-auth does not work
- 20:20:46 [jfontana]
- tony: shold re-auth be in level 3
- 20:21:00 [jfontana]
- agl: it does not work, but might want to address in L3
- 20:21:16 [jfontana]
- tony: can we get a generic issue on this one.
- 20:21:26 [jfontana]
- jeffH: we could add something to the charter.
- 20:21:32 [wseltzer]
- present+ davidwaite, jericks
- 20:21:43 [jfontana]
- ...a blanket issue to cover all of them
- 20:21:58 [jfontana]
- bradley: we support re-auth, it is about improving or streamlining
- 20:22:18 [jfontana]
- agl: it's a bad UX
- 20:22:43 [jfontana]
- https://github.com/w3c/webauthn/issues/1568
- 20:23:41 [jfontana]
- akshay: we need #1569 #1567 #1559 all of these
- 20:24:19 [jfontana]
- bradley; need to look at #554. what to do now that token binding is dead
- 20:24:26 [jfontana]
- #1554
- 20:24:32 [jfontana]
- https://github.com/w3c/webauthn/issues/1554
- 20:25:40 [jfontana]
- JeffH: HSTS was a patch, we are defaulting to secure connections
- 20:26:30 [jfontana]
- https://github.com/w3c/webauthn/issues/1546
- 20:26:41 [jfontana]
- agl: multiple keys, yes, interested
- 20:26:54 [jfontana]
- selfissue: MSFT supports as well
- 20:27:03 [jfontana]
- ... could be used for recovery or migration
- 20:27:18 [jfontana]
- tony: non modal UI
- 20:27:22 [jfontana]
- jeffH: yes.
- 20:28:01 [jfontana]
- https://github.com/w3c/webauthn/issues/1462
- 20:28:15 [jfontana]
- tony: does anyone not support going ahead with this
- 20:28:18 [jfontana]
- silence
- 20:29:45 [jfontana]
- https://github.com/w3c/webauthn/issues/1381
- 20:30:26 [jfontana]
- mattM: I guess I can take this one.
- 20:30:31 [jfontana]
- ...sure
- 20:30:46 [jfontana]
- NickS: will help coordinate.
- 20:31:58 [jfontana]
- https://github.com/w3c/webauthn/issues/969
- 20:32:33 [jfontana]
- tony: this was a google one originally
- 20:33:04 [jfontana]
- shane: thought platform authenticators are device bound
- 20:33:11 [jfontana]
- agl: I think we can close this.
- 20:33:23 [jfontana]
- tony: agl can you close
- 20:33:39 [jfontana]
- https://github.com/w3c/webauthn/issues/465
- 20:33:50 [jfontana]
- jeffH: close it
- 20:34:30 [jfontana]
- ..clear out PR and issue
- 20:34:44 [jfontana]
- tony: this covers all the major enhancements we want to do.
- 20:34:48 [jfontana]
- ...anything else.
- 20:34:56 [jfontana]
- bradley: https://github.com/w3c/webauthn/issues/1446
- 20:35:06 [jfontana]
- ...don't think it needs to be in charter.
- 20:35:32 [jfontana]
- ...a new version of CTAP will catch up to it.
- 20:43:40 [jfontana]
- selfissues: fine for charter to include new algorithm work and it does not get done.
- 20:43:46 [jfontana]
- agl: should not happen by charter
- 20:44:04 [jfontana]
- tony: what do we say in charter; additional curves
- 20:44:42 [jfontana]
- bradley: additional work on algorithm agility
- 20:44:59 [jfontana]
- tony: this is all I have.
- 20:46:37 [jfontana]
- tony: should we pause until PR is done
- 20:46:47 [jfontana]
- ...take next week off and meet the following.
- 20:47:03 [jfontana]
- ...so meet again on the 17th
- 20:47:11 [jfontana]
- ...?
- 20:47:16 [jfontana]
- ...concerns?
- 20:47:47 [jfontana]
- ...skips the 10th and meet on the 17th
- 20:47:57 [jfontana]
- jeffH: sounds fine as proposed.
- 20:48:13 [jfontana]
- tony: adjourn
- 20:49:04 [jfontana]
- rrsagent, make logs public
- 20:49:12 [jfontana]
- rrsagent, draft minutes
- 20:49:12 [RRSAgent]
- I have made the request to generate https://www.w3.org/2021/03/03-webauthn-minutes.html jfontana
- 20:49:28 [jfontana]
- chairs: Nadalin, Fontana
- 20:49:42 [jfontana]
- Zakim, list attendees
- 20:49:42 [Zakim]
- As of this point the attendees have been jfontana, nsteele, wseltzer, selfissued, dveditz, jeffh, agl, Nadalin, akshaykumar, davidturner, johnbradley, elundberg, matthewmiller,
- 20:49:45 [Zakim]
- ... nina, raerivera, sbweeden, timcappalli, davidwaite, jericks
- 20:50:16 [jfontana]
- web page updated with minutes
- 20:50:25 [jfontana]
- Zakim, bye
- 20:50:25 [Zakim]
- leaving. As of this point the attendees have been jfontana, nsteele, wseltzer, selfissued, dveditz, jeffh, agl, Nadalin, akshaykumar, davidturner, johnbradley, elundberg,
- 20:50:25 [Zakim]
- Zakim has left #webauthn
- 20:50:33 [jfontana]
- rrsagent, bye
- 20:50:33 [RRSAgent]
- I see no action items