[Webkit-unassigned] [Bug 204111] [WebAuthn] User Verification (UV) option present on a CTAP2 authenticatorMakeCredential while the authenticator has not advertised support for it

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Fri Jan 3 12:03:42 PST 2020


login Llama <loginllama at gmail.com> changed:

           What    |Removed                     |Added
                 CC|                            |loginllama at gmail.com

--- Comment #1 from login Llama <loginllama at gmail.com> ---
It seems bug (198408) has landed in iOS 13.3.1 and for desktop.

Good but that makes this bug much worse.  

Now almost no CTAP 2 keys are working, unless they support builtin UV. 

I have tested that and they work. 

There are some authenticators that for whatever reason don't properly check like some of the early Yubico 5ci with software 5.2.3.  All of the shipping ones with 5.2.4 fail to work with Safari because of this bug.  I tested other CTAP 2 authenticators and they also don't work almost certainly for the same reason.

So basically all CTAP2 authenticators without built in UV are currently broken.

You are receiving this mail because:
You are the assignee for the bug.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.webkit.org/pipermail/webkit-unassigned/attachments/20200103/5e093dc5/attachment.htm>

More information about the webkit-unassigned mailing list