Re: [Webauthn-reg-review] Request to add payment extension to WebAuthn Registry

Giridhar Mandyam <mandyam@qti.qualcomm.com> Tue, 15 August 2023 20:03 UTC

Return-Path: <mandyam@qti.qualcomm.com>
X-Original-To: webauthn-reg-review@ietfa.amsl.com
Delivered-To: webauthn-reg-review@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 32E1DC151551 for <webauthn-reg-review@ietfa.amsl.com>; Tue, 15 Aug 2023 13:03:37 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.006
X-Spam-Level:
X-Spam-Status: No, score=-2.006 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=qualcomm.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id A7IAKn-Nuw4k for <webauthn-reg-review@ietfa.amsl.com>; Tue, 15 Aug 2023 13:03:32 -0700 (PDT)
Received: from mx0a-0031df01.pphosted.com (mx0a-0031df01.pphosted.com [205.220.168.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CCB70C151088 for <webauthn-reg-review@ietf.org>; Tue, 15 Aug 2023 13:03:32 -0700 (PDT)
Received: from pps.filterd (m0279862.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.17.1.19/8.17.1.19) with ESMTP id 37FIuqqV019841; Tue, 15 Aug 2023 20:03:16 GMT
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h=from : to : cc : subject : date : message-id : references : in-reply-to : content-type : content-transfer-encoding : mime-version; s=qcppdkim1; bh=PudBM/ohIi1iT3AmfDU0UDFiV66L/Zzuj3+bz5D94K0=; b=T716LPcJnTgtVe/SaWXSWWg4GyhqYpiWQ6G5RJNBwvU+j/mu+zFrWw80u+WH2opbdvEX Odu4PFgCpWLdebi8g1JT0z9sGDS70SIK3CsO7ATzOoWMM0xZoHXj37zk46g78TMlIoFi QlNQxyCXOal6vYnrQGLBEYjlh/2NmhIe23oX3pRkN32Fa2TiwDxalFc0pjVFQg7V39L6 CkT4pwxiNOQw33rjk3jDO9hTLvaH0zBqGzTnNEX1zEXp/ijhc/kErxnotbERvLIg/3x9 52JgsHrduKbmnmMRQbl2ihSBFGrMmi2jnNlQb7WmiA5Vo6uqaAoJr53Sig4Z32Rfgz76 uQ==
Received: from nam12-mw2-obe.outbound.protection.outlook.com (mail-mw2nam12lp2047.outbound.protection.outlook.com [104.47.66.47]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 3sfqp1jmad-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Tue, 15 Aug 2023 20:03:16 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=bKj8sx6zLLy2sM7GNE/CvrUMzfUWZkb/kJyzFWNIGQXSiGJhbpKqAy060UfM0kGxqGGlXtTxtA0hW1e91p2S9brZp0CjnQ4CuaomJunhhvC52gXu5Fk3tEvDw8WJmHiGHjIKI2K1G6cpIWv5j99iuYRX8R3lVY+RcYxSbYKqjDinyI8zt09oCgR6PhlcSjbFcg6gkRVy5/4F2vJk2ICC2KZG97/Sj7zmCpKFZkddZupJkrgxyRrMq+IrS6keB2iVmVET5zYgoi642uYcQBULL59dh1OsujNahbtwDd2lWVEC6juJs0x3+xz5Ia68KHGE/l9XZmbIF3a7t+ICFzfgrQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=PudBM/ohIi1iT3AmfDU0UDFiV66L/Zzuj3+bz5D94K0=; b=FtWTrH8xzQZmpn3lqruf1IEL4XQpH/WXJ2Lhc1F3vGzMy9Am6aqTQ/AhNoCrcCtSMtdNYwGhkp1K8kRy4qFsGb6c38qaLtVs0syJFUjOBxcthpSpGH2rnSr4sA73DXZTaUG/VkEDz6a2x8QAN7PQrQl60fTMZZiZBauBmLATGTcGPl7VSVRtosxAOuWQoP9NgoQYYDZS+nX4TOET/vefdBbKI026JZl67Xk9jJTlGYq5Dzi27DeGX8eMmc0ziJlD5yDsQRmFERzUKfSEhUtAxjat0xOqpZ4F9m5NnbsFs0/Te5+JJR7j3X8QLZzChJRWSJMG8M7omI+R6VCkxzC1Jw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=qti.qualcomm.com; dmarc=pass action=none header.from=qti.qualcomm.com; dkim=pass header.d=qti.qualcomm.com; arc=none
Received: from SJ0PR02MB8353.namprd02.prod.outlook.com (2603:10b6:a03:3e4::7) by PH0PR02MB9364.namprd02.prod.outlook.com (2603:10b6:510:287::20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6699.14; Tue, 15 Aug 2023 20:03:10 +0000
Received: from SJ0PR02MB8353.namprd02.prod.outlook.com ([fe80::d0b3:1a10:dd7f:c2ee]) by SJ0PR02MB8353.namprd02.prod.outlook.com ([fe80::d0b3:1a10:dd7f:c2ee%6]) with mapi id 15.20.6699.013; Tue, 15 Aug 2023 20:03:09 +0000
From: Giridhar Mandyam <mandyam@qti.qualcomm.com>
To: Ian Jacobs <ij@w3.org>, "michael_b_jones@hotmail.com" <michael_b_jones@hotmail.com>
CC: "webauthn-reg-review@ietf.org" <webauthn-reg-review@ietf.org>, Stephen McGruer <smcgruer@google.com>, Philippe Le Hégaret <plh@w3.org>
Thread-Topic: [Webauthn-reg-review] Request to add payment extension to WebAuthn Registry
Thread-Index: AQHZjL3oecRotg+LAEWy8vAMDU1k5q9niFfQgABHyICAAABG0IAAMkOAgAAGqXCAAAjxAIAAAeTugAGGkgCAIllDgIAyjJyAgA8MW6CABsfwAIAXx7MAgAAwvfA=
Date: Tue, 15 Aug 2023 20:03:09 +0000
Message-ID: <SJ0PR02MB8353A8B4884ABE1D1F386DCD8114A@SJ0PR02MB8353.namprd02.prod.outlook.com>
References: <3C072A37-E257-4915-808F-1313634FF9E7@w3.org> <SJ0PR02MB83532B5F557C73B00F62FC3F81409@SJ0PR02MB8353.namprd02.prod.outlook.com> <8B3FB6B1-A6C1-4AD3-B5E5-89C088185AEC@w3.org> <SJ0PR02MB83534413068CE1C9B4E976EC81409@SJ0PR02MB8353.namprd02.prod.outlook.com> <B3E2CD8D-9714-40C3-B3EA-1309A85BDB59@w3.org> <SJ0PR02MB8353DF6FFE1584C2B560D32A81409@SJ0PR02MB8353.namprd02.prod.outlook.com> <91F93224-BD6D-4566-AF4B-4D40D57436A8@w3.org> <SJ0PR02MB835344D3D5688BC50D4A822B81409@SJ0PR02MB8353.namprd02.prod.outlook.com> <B34A0B9D-FF17-4B7C-A017-C4ECA857EF88@w3.org> <38F5B4F5-BD99-44FA-A646-03AEEA012C8D@w3.org> <2442E340-BE6E-44DA-A123-2107A20DC9EA@w3.org> <SJ0PR02MB8353B04770B85C82BA4519328101A@SJ0PR02MB8353.namprd02.prod.outlook.com> <91F71F16-E748-4F07-99DC-68B6CA946627@w3.org> <02B1ECC6-7EF9-4467-8280-23067E53C826@w3.org>
In-Reply-To: <02B1ECC6-7EF9-4467-8280-23067E53C826@w3.org>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: SJ0PR02MB8353:EE_|PH0PR02MB9364:EE_
x-ms-office365-filtering-correlation-id: 63fa4a1a-33e1-4ee9-ace0-08db9dcaa615
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: TdE2QC9ERU0R8Tf8D+SX8K4Bi9B3NOlzrl8hwwyf8OJAZYs/+4xjJs2vlxNONnplFALjosOQ4fNJQHMgVn85qvGHszFihZD/fGnqn+fbbJFFlIDJiWdZbO91/MDo/g1dnub4AGDdtBBfAvgGz6JBwtYV/2WvlZN07sTxDhWNVnUdYtiZfpQKNsmH15Q7UgeSVMTyVhe4ldVCUG2eoOtRMYPUy5AVS+jM5LN8jHxwOSb9qmLi0Px+ssl24NDJ77LvMGpTHeZlld8Hruu5vZqVbs5a8NpOVkgPpHIdDTot0n51TI8ncsRKxsEY3cZfD5yaIMHwvf+FeYomt+kXMVMzMy8ylPDHMDwmSUN/u6OaF7aAvMsGuE94BmItwSo2etrel8wqOKVd6CLxbZ8EjXYRmKrfI5QgyO4od03nLS3saQuWea7ptNWtP/g4QpG7cZ2z49vP0zhycCb4aHU67OuOiSMYgRdACkNrwwE1nAe1322Q1aPOvxJXRs2eRKU4dBRGvC5jB9Ln5Jp4daBnafsceupq/q40+avBTuaYrWwlkeidwkLuwgMjekMgyGzHT6zckrUgl88CI5wjd+TsSA2V3mfowL3CBMPdLVNDc33QivU=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:SJ0PR02MB8353.namprd02.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230031)(376002)(366004)(136003)(346002)(39860400002)(396003)(451199024)(1800799009)(186009)(40140700001)(38070700005)(52536014)(41300700001)(6506007)(4326008)(2906002)(53546011)(122000001)(26005)(316002)(83380400001)(8676002)(8936002)(55016003)(7696005)(66574015)(71200400001)(478600001)(9686003)(54906003)(966005)(66446008)(110136005)(45080400002)(15650500001)(66556008)(5660300002)(66476007)(64756008)(66946007)(86362001)(33656002)(38100700002)(76116006); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: r1Vtbn+68caw+uYe6cDzyiWC/2Fmsps+UnlOwFEEuHO+VxB4tbK3Za8GzH0cGAugtqQSz03UlUDDMMjW7Y3Lp/oBfKStxO+Z2Z7ZFi4epkgxG9iKxo5t7vrMho0nHTfiGxM1ChsHlwZqJ5Se/ndE8JdZJ2QMy5GIW3hEW4Zx7079e4c1lmBby1+oEPBqNDjjg4BnrW6HFaaz9AwnzJhpEPAwczQB2xkWoDfwx9blApLq8gwSTanVI5q6y6xkNXKO+tv0Puuuo5u8GrKHw1yY+w0k2+AL5/YgYRLSpsUPSiCD/1MizAJYVAH1BxSY3umWEeSIZjeULj6gFCZ0x4EEf3Xlu3W0RnecP2y+YhcDRoHC0tGTo/hUTlmECZvCyJHjAHfEWQfrqiETyzFgJmsh3skCyc9eM+y4sZaar7EIqohAGUb4aL7eqhtBiFn+AKSQumLgbRTxdSOVIM3ttkPOtONZzUC5089+4m7sGeEST9qEHVC0gwI//OCPEVL6+gqzcar+wc3PL1UQE6uBngKo7rMuvDjgFakoOwVncly6D6TwNRVyPoerJKmhM04/B4zGw7SFiSEWErR/pnGQ6HafWvnYZe6BXBMbushjFD+YkfKyEnvbIZFXsaFAXP+3FtGaiJfd2j3nVbwRkh3IRgAB/vOYN4jFlj+Jhr4FxjiEQwVna4OB+8w4F3eNj08b0wbCheREv7kLZ3GE43pSWqZnSzAP4rJlY7veoJrEdn1RYAy9oqJGS8zvfabvYdSWuh5hKD7reA6+/a29CN+TsF/3XwwPwvTDqZwepKBj7+8Hl7rVxVV+rrLWTC4Tdbm49fBQr+MT1nLyKDc6a7Vtih9d2pczqiPCVQzR1c2/5Cz5vJU5C4IuOasqKV+sWGxK+XYXj3V5OvhneTHDQyStpKVLXrofQWPgLJY6N/ycv82/1VU3qEucD+V8WQu5nSPkXUzveMMKJro0n8xE4d5z+RbcS2przck0Ewe3vqrmoQpMAeYTUCbSoYsZIk6LErkSCA2SguYCCBu7ylNJL3jjEq1pSDZmceTe3vugkr+ywz4EgZRStvBMbYB6/79mOgV/m17EikgSjPjLjdEMd9YXCq8Qr9viU6T3Akw56ipQbgsMnQ3tVTCp0gy4WFZUUN6Ycp1oD88ehYQOUdrKldsT95XKK3u9StkQibzQsxrb4e8183uU7/bC75e09orN99VJv1F3MWBlafnDSHYaToERR9/Hztz9kmOaVLkm1FF6x5a+tH0kGQNDPqhb5EPEZmXsqU3dbG8JSQs2ClDLOMLjjw11/3gWayEsxsaXDZNrzYY6obNfSkvbqYNCsjj+CJQ+s8mw3hRbcuf1ncQu6LtKY0dX5VlBd6E6t3dCpfUpYdCdDGgk5QbefdvQECe3RgSocxGnZBfcxnAtQ/CsbpYwZ0HLVJtEphTP+TDWW/ATsvUiKQjutktRzvVTuTD7sdFCLSqJqkSRRs5QylmpxHJdUm9DGgSDAaxcC0RLjlrIU//yGZxkuZye3YMT4WIzSCunAuFRXvUwyFakj2XrchQJX2Q3QJ+GLswkTxHYHEdsnXPNuWpn+74gEaN6C5MZl8uBeTtB
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-AntiSpam-ExternalHop-MessageData-ChunkCount: 1
X-MS-Exchange-AntiSpam-ExternalHop-MessageData-0: PaQ6Kt+8wnoz20oejx4P5BRZp9U+vkiz698ywbZXiTadxXEhnEERXU/iPVVaMEiYs5FOwJOKkpK7A6xs4wF+F0dR8cuSSfbBtcPlBTdXz1Lkl74FA8vhc8jHtEtmFuEebOEWxxiC774eT5l4eqpD6nnSyt7PxDNCq9G+zNEtWD4K8r5L8dzHgAgjVHjsSymMj2fdlWSZPFVW0mrWqBU9FtgS/GQAHErPdP4/5VT0PjcmxrIO2etktWhsWZ/sE9hVyi+yZROeKGARbGXd4b1LhAllK39Kut1PKBh2zGNSmva5Dl5dmg33YcYCwLjf79IQtaPZP0VqnsHBmR2Cnk0CUghQgeuIgSGZRiCFzBIs7S9rStTOpc4RTnCuuipS9MkKGFKaPB66auyZVBAB2PZlheP7d6OkouleRi2WTvtbUAhiAnH/J2TNrdIpT6jPMyCoflEnnjQnoesbD3YwDoAycpT0rLbloPg7ni3cAgY6t4uSahJxQHsLTiFso+h/qDQDHnRePQUv9AsQGPpN7hlnUKTQq2gN8Zk+syaYzSfVJqLd5RAOGKa34RcSEPAE2zF6s64cq+J6jv4InjDQgDv8spxNJQidRw8Kk1e60VGKeVddZOw14Cjuty3JkSBoh7dbwqp9TBtdIBkUVmUGR28tJNhVK0LfBy8vjEN/CF/I3DLDtNmilCeZ8sEgQbVzT9KennaCDNY2/DemDON0xSbk/V6a0wrT5l5Z0ubB4UxNGHuAcmVofdRMs2/f7YV0ses9Ce/UXj7svX65xBhR7PtQtjFbLAggv7IWl1oQEmUlo6hbCitlVzo4LSO0IGciI72CKTrpIySFusQ5L2mSba7kxQ==
X-OriginatorOrg: qti.qualcomm.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: SJ0PR02MB8353.namprd02.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 63fa4a1a-33e1-4ee9-ace0-08db9dcaa615
X-MS-Exchange-CrossTenant-originalarrivaltime: 15 Aug 2023 20:03:09.8088 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 98e9ba89-e1a1-4e38-9007-8bdabc25de1d
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: 5mjWb6Mwg+rD+aAfJU6ajGF27+L7SKIMm+HgBhm24UwPCKseqwCz1/auUz+vwIqJ3CMg3nm41+75ukeOpj7N/+b84Mek7EgMW4eLhiL5up4=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PH0PR02MB9364
X-Proofpoint-GUID: mkY7PUbojfZPKD7-Him3N0OFmUwMbA4u
X-Proofpoint-ORIG-GUID: mkY7PUbojfZPKD7-Him3N0OFmUwMbA4u
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.267,Aquarius:18.0.957,Hydra:6.0.601,FMLib:17.11.176.26 definitions=2023-08-15_19,2023-08-15_02,2023-05-22_02
X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 suspectscore=0 adultscore=0 mlxlogscore=999 bulkscore=0 malwarescore=0 priorityscore=1501 impostorscore=0 mlxscore=0 phishscore=0 spamscore=0 lowpriorityscore=0 clxscore=1011 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2306200000 definitions=main-2308150181
Archived-At: <https://mailarchive.ietf.org/arch/msg/webauthn-reg-review/zuRLR0Qby7-aJsZ7yPjctRBTmo0>
Subject: Re: [Webauthn-reg-review] Request to add payment extension to WebAuthn Registry
X-BeenThere: webauthn-reg-review@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Registration requests should be sent to the mailing list described in \[draft-hodges-webauthn-registries, Section 17\]." <webauthn-reg-review.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/webauthn-reg-review>, <mailto:webauthn-reg-review-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/webauthn-reg-review/>
List-Post: <mailto:webauthn-reg-review@ietf.org>
List-Help: <mailto:webauthn-reg-review-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/webauthn-reg-review>, <mailto:webauthn-reg-review-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 15 Aug 2023 20:03:37 -0000

Nothing from my end.  Awaiting Mike's review.

-Giri

-----Original Message-----
From: Ian Jacobs <ij@w3.org> 
Sent: Tuesday, August 15, 2023 10:08 AM
To: Giridhar Mandyam <mandyam@qti.qualcomm.com>; michael_b_jones@hotmail.com
Cc: webauthn-reg-review@ietf.org; Stephen McGruer <smcgruer@google.com>; Philippe Le Hégaret <plh@w3.org>
Subject: Re: [Webauthn-reg-review] Request to add payment extension to WebAuthn Registry

WARNING: This email originated from outside of Qualcomm. Please be wary of any links or attachments, and do not enable macros.

Hi Giridhar,

I wanted to let you know that we’ve merged the pull request, so the statement you referred to below no longer appears.

If there’s any other information you need to complete your evaluation, let me know. Thanks again!

Ian

> On Jul 31, 2023, at 8:59 AM, Ian Jacobs <ij@w3.org> wrote:
>
> Thanks Giridhar,
>
> I’ve proposed a pull request to remove the note:
> https://github.com/w3c/secure-payment-confirmation/pull/255
>
> Ian
>
>> On Jul 27, 2023, at 1:32 AM, Giridhar Mandyam <mandyam@qti.qualcomm.com> wrote:
>>
>> Hi Ian,
>>
>> Mike needs to sign off,  but I have reviewed this an am satisfied that the extension can be registered.
>>
>> Please consider removing the following in any future revision:
>>
>> "Note: Reading [webauthn-3] literally, these steps don’t work; extensions are injected at step 12 of [[Create]] and cannot really modify anything. However other extensions ignore that entirely and assume they can modify any part of any WebAuthn algorithm!"
>>
>> I don't think the above statement is an accurate reading of the WebAuthn spec, as the steps outlined in the Webauthn spec do not have to be executed in sequence.  This is because the cited section in Webauthn is for an internal method, which as per the ECMA description is left up to the implementation (https://tc39.es/ecma262/#sec-object-internal-methods-and-internal-slots).
>>
>> Mike,
>> Please provide your feedback.
>>
>> -Giri

--
Ian Jacobs <ij@w3.org>
https://www.w3.org/People/Jacobs/
Tel: +1 917 450 8783