Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Adding Section 1.1. #21

Open
wants to merge 1 commit into
base: master
Choose a base branch
from
Open

Conversation

maxhata
Copy link

@maxhata maxhata commented Oct 31, 2020

#3
New section 1.1 describes the unique issue of platform authenticators, user lock-out.
Addressing this issue in the beginning part of the document makes it easier to describe different scenarios of platform and roaming authenticators, e.g., why some models are called "convenient", or "phishing resistant", despite the fact that all the models use FIDO.
This section explains that the strongest reason why passwords are kept alive along with FIDO for the "convenient" model is to avoid user-lock out that will cause frictions of account recovery.

A new section 1.1 describes the unique of platform authenticator, user lock-out.
Addressing this issue in the beginning part of the document makes it easier to describe different scenarios of
platform and roaming authenticators, e.g., why some model is called "convenient", or "phising resistant".
16. This limitation may be solved if CTAP is implemented on the platform
authenticators. CTAP will enable platform authenticators to securely connect
to other devices via local transports like BLE and enable bootstrapping the
device. No off-the-shelf solution is available at the time of writing.
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we want to include this in "how-to-fido"? Sounds like more of a TWG discussion than guidance for FIDO RPs?

Platform authenticators have a unique issue which needs to be carefully considered when designing the flows and operations.

**Issue:** Platform authenticators cannot be connected to and used with other devices. Namely, they cannot bootstrap other devices [16].

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Perhaps start with a short recap of the difference between platform and roaming authenticators? Or if we just want to focus on the issue of lockout perhaps we can change the "Overview" section to "FIDO2 Usecases", and then add a 1.1 "Special considerations for Platform Authenticators"? In the future perhaps we can add 1.2 "Special considerations for Roaming Authenticators"?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants