-
Notifications
You must be signed in to change notification settings - Fork 234
Open
Labels
privacy-trackerGroup bringing to attention of Privacy, or tracked by the Privacy Group but not needing response.Group bringing to attention of Privacy, or tracked by the Privacy Group but not needing response.type:editorial
Description
Is user verification discouraged
intended to be used for relying parties to signal a preference for less user interaction? Does user verification provide a certain backstop of privacy protection for users to be sure they know what they're authenticating and to whom?
My understanding (thanks @timcappalli) is that this doesn't enable the abuse of silent info gathering. The spec might make that explicit, or note that UAs have the unaffected obligation to explain the operation to users even if the RP doesn't prefer that a user verification step is completed.
Metadata
Metadata
Assignees
Labels
privacy-trackerGroup bringing to attention of Privacy, or tracked by the Privacy Group but not needing response.Group bringing to attention of Privacy, or tracked by the Privacy Group but not needing response.type:editorial