...
3. Is it possible to implement software FIDO2 Authenticator, or does it have to be hardware based? Can it reside on the same device as the client (e.g. app in a browser that I'm authenticating against)? In this case, how will the Authenticator and the client communicate, when CTAPv2 protocol only specifies USB, NFC and Bluetooth?
...
Thank you very much. I have two follow-up questions regarding the software authenticator topic (1 and 2) and two more unrelated questions. I would appreciate help clarifying these:
In the WebPayment & WebAuthn Demo, Adam Powers wrote a comment: “CTAP is for external authenticators attached by USB, NFC, or BLE. This was an internal authenticator.”. In that case, how did the browser communicate with the internal authenticator? Or, more broadly, what are the possible options for such communication?
WebAuthn scenarios describe mobile phone as an authenticator (when authenticating against e.g. a laptop). Does it need to communicate via CTAP as well, being an external authenticator?
WebAuthn specification describes user-verifying platform authenticators. Why there is no notion about user-verifying roaming authenticators? Is such thing not possible
Adam Langley’s blog post mentions that “There are no CTAP2 devices on the market yet but their major distinguishing feature will be that they can be used as a 1st (and only) factor. I.e. they have enough internal storage that they can contain a username and so both provide an identity and authenticate it.”. Could anybody please explain how this works and what other scenario will it add to the existing scenarios already supported?
--
You received this message because you are subscribed to a topic in the Google Groups "FIDO Dev (fido-dev)" group.
To unsubscribe from this topic, visit https://groups.google.com/a/fidoalliance.org/d/topic/fido-dev/R0U51PU0Fzs/unsubscribe.
To unsubscribe from this group and all its topics, send an email to fido-dev+unsubscribe@fidoalliance.org.
To post to this group, send email to fido...@fidoalliance.org.
Visit this group at https://groups.google.com/a/fidoalliance.org/group/fido-dev/.
To view this discussion on the web visit https://groups.google.com/a/fidoalliance.org/d/msgid/fido-dev/2e2e85e5-cc0f-4066-ac43-2940f7ac6c87%40fidoalliance.org.
You received this message because you are subscribed to the Google Groups "FIDO Dev (fido-dev)" group.
To unsubscribe from this group and stop receiving emails from it, send an email to fido-dev+u...@fidoalliance.org.
To post to this group, send email to fido...@fidoalliance.org.
Visit this group at https://groups.google.com/a/fidoalliance.org/group/fido-dev/.
To view this discussion on the web visit https://groups.google.com/a/fidoalliance.org/d/msgid/fido-dev/CAN07uWVPWM8NDqvW8tBLyYDz0O_TsO-Ln2ums%3D8g0fdkxJjnzA%40mail.gmail.com.
To unsubscribe from this group and stop receiving emails from it, send an email to fido-dev+unsubscribe@fidoalliance.org.
To post to this group, send email to fido...@fidoalliance.org.
Visit this group at https://groups.google.com/a/fidoalliance.org/group/fido-dev/.
To view this discussion on the web visit https://groups.google.com/a/fidoalliance.org/d/msgid/fido-dev/CAN07uWVPWM8NDqvW8tBLyYDz0O_TsO-Ln2ums%3D8g0fdkxJjnzA%40mail.gmail.com.
To unsubscribe from this group and all its topics, send an email to fido-dev+u...@fidoalliance.org.
To post to this group, send email to fido...@fidoalliance.org.
Visit this group at https://groups.google.com/a/fidoalliance.org/group/fido-dev/.
To view this discussion on the web visit https://groups.google.com/a/fidoalliance.org/d/msgid/fido-dev/2e2e85e5-cc0f-4066-ac43-2940f7ac6c87%40fidoalliance.org.
--
You received this message because you are subscribed to the Google Groups "FIDO Dev (fido-dev)" group.
To unsubscribe from this group and stop receiving emails from it, send an email to fido-dev+u...@fidoalliance.org.