19:04:09 RRSAgent has joined #webauthn 19:04:13 logging to https://www.w3.org/2024/02/28-webauthn-irc 19:05:39 Chair: Tony 19:05:55 Meeting: Web Authentication Working Group 19:06:10 AGL: FIDO SPWG Are finishing up their requirements document, no progress on caching yet 19:06:11 Agenda: https://lists.w3.org/Archives/Public/public-webauthn/2024Feb/0084.html 19:06:18 Scribe: steele 19:07:35 TOPIC: Pull Requests 19:07:36 https://github.com/w3c/webauthn/pull/1953 & https://github.com/w3c/webauthn/pull/1954 19:07:44 Skipping until David Waite is present 19:07:58 https://github.com/w3c/webauthn/pull/1951 19:08:27 Pascoe: Waiting for further approvals 19:08:43 Nina has approved, AGL cedes his approval to Nina 19:09:53 present+ Nina,PLH,TimC,AGL,Emil,Tony,Shane,JohnPascoe,JohnBradley,MikeJones,Lachlan,Simone,Schanck,Anders 19:10:07 https://github.com/w3c/webauthn/pull/2020 19:10:19 Christiaan is currently OoO for the next two weeks 19:11:57 AGL: I'd potentially like to move this out of L3, depending on where we want to cut off L3 commmitments 19:12:07 Tony: Willing to put this at at-risk 19:12:20 David Turner to reach out to Rolf 19:12:22 https://github.com/w3c/webauthn/pull/2026 19:13:08 present+ DavidTurner 19:15:02 selfissued has joined #webauthn 19:15:05 present+ 19:15:46 Shane: if there's text change required then we should hold off, but otherwise we should contact Monty and ask him which path to pick 19:16:00 ACTION: David Turner to reach out to Monty 19:16:11 TOPIC: Issues 19:16:28 https://github.com/w3c/webauthn/issues/2026 19:20:23 ACTION: AGL Volunteers to respond 19:20:30 https://github.com/w3c/webauthn/issues/2024 19:20:43 Emil not on call 19:20:44 https://github.com/w3c/webauthn/issues/2023 19:21:15 Rolf to attend next week 19:21:50 Tim: I did create an additional Issue to reflect the alternative to this: https://github.com/w3c/webauthn/issues/2034 19:22:21 https://github.com/w3c/webauthn/issues/2034 discussion 19:23:36 Anders: would this allow for tracking? You could potentially fingerprint users 19:24:00 AGL: Multiple RPs can poentially see the delta between auth being performed 19:24:21 Matthew: All this occurs after ceremony 19:24:46 Discussion around rounding time of response to prevent direct fingerprinting of times 19:25:34 Shane: This could be a storm in a teacup a bit, unsure of what this marker could be used to achieve 19:25:49 Anders: I want to consider the privacy concerns of it 19:26:06 Discussion around possibly rounding the time delta 19:26:48 Nina: You might want to have some noise added to it, but you'd want to make sure RPs can't request multiple assertions for the purpose of tracking 19:32:46 Matthew: What about having the RP provide an acceptable timeframe and the authenticator responds with a boolean? 19:32:55 Tim: essentially what Rolf is proposing 19:33:29 Shane: leaning towards Nina's idea of adding noise 19:33:46 Anders agrees 19:33:52 Zakim has joined #webauthn 19:35:39 AGL drops link in chat https://lbarman.ch/blog/padme/ 19:35:52 AGL: This has some concepts relevant to the discussion 19:36:22 Discussion around rounding and/or adding noise to response 19:37:17 present+ Khaled 19:38:59 Tim to iterate on the request with feedback from discussions 19:39:08 Going back to Pull Request https://github.com/w3c/webauthn/pull/2026 now that Emil is bac 19:39:14 AGL: I am ok with this 19:39:59 oops I meant https://github.com/w3c/webauthn/pull/2017 19:40:35 Emil: APhillips current wording regarding Unicode encoding would be a breaking change 19:40:43 ...planning to push back on that 19:43:00 Emil: This pull request has kind of grown to encompass two things though, what Adam addressed and this other issue 19:43:10 https://github.com/w3c/webauthn/issues/2022 19:43:25 Rolf will be joining March 6th to discuss 19:43:42 https://github.com/w3c/webauthn/issues/2016 19:44:28 Emil: Pull Request has opened today for this https://github.com/w3c/webauthn/pull/2031 19:45:34 https://github.com/w3c/webauthn/issues/2028 19:45:55 Emil: The person that opened this is happy to close after the solution offered in #2029 19:46:15 https://github.com/w3c/webauthn/pull/2029 19:46:27 AGL and Shane say it should be merged 19:46:30 it is done 19:47:21 https://github.com/w3c/webauthn/issues/1859 19:47:28 Matt: I have no progress on this 19:47:47 https://github.com/w3c/webauthn/issues/1856 19:47:53 Ackshay not present to discuss 19:48:28 https://github.com/w3c/webauthn/issues/1797 19:48:47 Emil: This is not very high priority, should ask John B if this is still relevant 19:49:16 Emil: Mike Jones can you have a look? 19:49:24 Mike agrees to review 19:49:40 TOPIC: General Issues and Discussion 19:50:04 Emil wishes to discuss https://github.com/w3c/webauthn/issues/2024 19:51:32 Emil wishes to close 2024 if there are no differing opinions 19:51:42 none 19:52:17 Matt: Did get confirmation of F2F plans? Are we doing this in April on the 19th? 19:52:57 AGL: Meant to ask Christiaan but he is away. The event is in our system but unprocessed. I suspect we'll be able to host but it's not confirmed 19:53:27 Suspected to host near IIW still within the Mountain View area (near the museum) 19:56:40 End meeting 19:56:50 Zakim, list participants 19:56:50 As of this point the attendees have been Khaled 19:57:03 present+ Nina,PLH,TimC,AGL,Emil,Tony,Shane,JohnPascoe,JohnBradley,MikeJones,Lachlan,Simone,Schanck,Anders 19:57:19 present+ Nina,DavidTurner 19:57:34 Zakim, list participants 19:57:34 As of this point the attendees have been Khaled, Nina, PLH, TimC, AGL, Emil, Tony, Shane, JohnPascoe, JohnBradley, MikeJones, Lachlan, Simone, Schanck, Anders, DavidTurner 19:57:56 RRSAgent, make logs public 19:58:01 RRSAgent, generate minutes 19:58:02 I have made the request to generate https://www.w3.org/2024/02/28-webauthn-minutes.html steele 19:58:11 Zakim, bye 19:58:11 leaving. As of this point the attendees have been Khaled, Nina, PLH, TimC, AGL, Emil, Tony, Shane, JohnPascoe, JohnBradley, MikeJones, Lachlan, Simone, Schanck, Anders, 19:58:11 Zakim has left #webauthn 19:58:14 ... DavidTurner 19:58:17 RRSAgent, bye 19:58:17 I see 2 open action items saved in https://www.w3.org/2024/02/28-webauthn-actions.rdf : 19:58:17 ACTION: David Turner to reach out to Monty [1] 19:58:17 recorded in https://www.w3.org/2024/02/28-webauthn-irc#T19-16-00 19:58:17 ACTION: AGL Volunteers to respond [2] 19:58:17 recorded in https://www.w3.org/2024/02/28-webauthn-irc#T19-20-23