Skip to content

Adjustments to BBK requirements #293

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 3 commits into
base: main
Choose a base branch
from
Open

Adjustments to BBK requirements #293

wants to merge 3 commits into from

Conversation

ianbjacobs
Copy link
Collaborator

Based on recent conversations:

  • Clarify that a BBK should not be usable outside of the device where it was originally bound.
  • Make explicit the implication that if a passkey is deleted then any associated BBK should also be deleted.

@ianbjacobs ianbjacobs requested a review from stephenmcgruer May 6, 2025 18:10
@Goosth
Copy link
Collaborator

Goosth commented May 7, 2025

Do we need to link BBK's to a specific passkey? I feel it raises a number of other questions:

  • What does this mean if a Passkey is used on a different device and removed there?
  • What about a new passkey being issued, since the browser/RP could not detect the previous Passkey anymore (cookie was deleted).
    It would be great to leave open the option of having a BBK in the future which we only want to use that as a possession factor without the direct link to Passkeys. So basically the BBK would work more along the principles of Server Side Cookies with CHIPS.

@stephenmcgruer stephenmcgruer requested a review from pejic May 7, 2025 16:30
@ianbjacobs ianbjacobs changed the title Small adjustments to BBK requirements Adjustments to BBK requirements May 12, 2025
@ianbjacobs
Copy link
Collaborator Author

I have updated this pull request following the 8 May 2025 WPWG meeting.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants