Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Discuss] Relationship between identity credentials, passkeys, and federation #25

Closed
timcappalli opened this issue Oct 5, 2023 · 2 comments
Assignees

Comments

@timcappalli
Copy link
Member

timcappalli commented Oct 5, 2023

Surfaced as a core discussion topic on the first call (2023-10-04).

Sub topics:

  • should identity credentials, passkeys, and federation be surfaced to users in the same UI?
  • sign in vs claims transfer
@OR13
Copy link
Contributor

OR13 commented Oct 5, 2023

I think people enjoy the feeling of safety, knowing their fingerprint is required to present a credential, because similar to imagining someone forging an ink signature, it feels safer to the user to know that their consent and fingerprint is required, as opposed to a threat actor stealing a password, or forging their ink signature.

In the mind of the user, the action is using their fingerprint to authorize something... they want to feel safe authorizing things, the UI need to convey safety, and control for both... Payment experience is the same... if my phone doesn't ask for my fingerprint to confirm a payment, I fear that anyone with my phone may spend my money... if my phone doesn't ask for my fingerprint when signing in, I feel that anyone can impersonate me.

@timcappalli
Copy link
Member Author

This has been discussed across many venues including calls, IIW, TPAC, Fed ID WG, and WebAuthn WG. The direct interaction between these experiences is driven by the user agent and/or app platforms.

Mixed usage at the CredMan level can be supported in the future: w3c/webappsec-credential-management#244 (comment)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants