-
Notifications
You must be signed in to change notification settings - Fork 49
Open
Description
Spec: Gap between BBK requirements and specification
The BBK requirements document describes BBKs as having a strict 1-1 relationship with a tuple of (Browser instance, passkey, device). Currently the SPC specification does not describe how the tuple is formed or how the relationship is enforced.
- The Browser Bound Key Stores description "owned by the user agent" is ambiguous, and does not describe how a BBK is bound to a browser instance, additionally it does not prevent the user agent from holding many such stores.
- The binding process describes how a BBK may be associated with a passkey, but does not enforce an exclusive association (One BBK could be bound to many passkeys following this description)
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels