Skip to content

Forbid authenticator data from containing cleartext PRF outputs#2372

Open
emlun wants to merge 1 commit intomainfrom
issue-2359-prf-authenticator-outputs
Open

Forbid authenticator data from containing cleartext PRF outputs#2372
emlun wants to merge 1 commit intomainfrom
issue-2359-prf-authenticator-outputs

Conversation

@emlun
Copy link
Member

@emlun emlun commented Dec 10, 2025

Closes #2359.

The following tasks have been completed:

  • [ ] Modified Web platform tests (link) N/A - abstract requirement

Implementation commitment:

Documentation and checks

  • Affects privacy
  • Affects security
  • [ ] Updated explainer (link) N/A - abstract requirement

Preview | Diff

Copy link
Contributor

@arnar arnar left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks great to me, thank you!

Copy link
Contributor

@zacknewman zacknewman left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@nadalin nadalin added this to the L4 WD02 Milestone milestone Dec 18, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Forbid authenticator data from containing plaintext PRF outputs

6 participants