Metadata spec for CodeAccuracyDescriptor.maxRetries defines 0 in an incompatible way with CTAP

33 views
Skip to first unread message

zack

unread,
5:37 AM (2 hours ago) 5:37 AM
to FIDO Dev (fido-dev)

> Maximum number of false attempts before the authenticator will block this method (at least for some time). 0 means it will never block.

This defines 0 as basically "infinity"; however [CTAP 2.3](https://fidoalliance.org/specs/fido-v2.3-ps-20260226/fido-client-to-authenticator-protocol-v2.3-ps-20260226.html#pinretries) does not set a lower bound for this value (i.e., it allows an authenticator to set pinRetries to 0). Such authenticators are incapable of conforming to the Metadata Statement spec since their use of 0 would not agree with the defined meaning of 0.

Perhaps this is the reason there exists FIDO 2 authenticators that have been certified by the FIDO Alliance where their corresponding MetadataBLOBPayloadEntry in the blob downloaded from https://mds.fidoalliance.org/ defines maxRetries as 0 despite this violating CTAP which sets a maximum possible value of 8.

Carsten Lange

unread,
6:10 AM (1 hour ago) 6:10 AM
to zack, FIDO Dev (fido-dev)
In Jure

--
You received this message because you are subscribed to the Google Groups "FIDO Dev (fido-dev)" group.
To unsubscribe from this group and stop receiving emails from it, send an email to fido-dev+u...@fidoalliance.org.
To view this discussion visit https://groups.google.com/a/fidoalliance.org/d/msgid/fido-dev/7ef03ac7-7b54-41dd-aa18-4713a69debf7n%40fidoalliance.org.
Reply all
Reply to author
Forward
0 new messages