Skip to content

user verification discouraged should consider privacy impact or UA advice #2323

@npdoty

Description

@npdoty

Is user verification discouraged intended to be used for relying parties to signal a preference for less user interaction? Does user verification provide a certain backstop of privacy protection for users to be sure they know what they're authenticating and to whom?

My understanding (thanks @timcappalli) is that this doesn't enable the abuse of silent info gathering. The spec might make that explicit, or note that UAs have the unaffected obligation to explain the operation to users even if the RP doesn't prefer that a user verification step is completed.

Metadata

Metadata

Assignees

No one assigned

    Labels

    privacy-trackerGroup bringing to attention of Privacy, or tracked by the Privacy Group but not needing response.type:editorial

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions