[Openid-specs-ab] SIOP and webauthn
Mike Jones
Michael.Jones at microsoft.com
Sat Mar 11 20:25:36 UTC 2023
SIOP standardization was completed in 2014 https://openid.net/specs/openid-connect-core-1_0.html#SelfIssued. (The ideas for it were partially based on self-issued Information Cards, which used a public/private keypair held in a wallet for authentication.)
-- Mike
From: Openid-specs-ab <openid-specs-ab-bounces at lists.openid.net> On Behalf Of Sam Goto via Openid-specs-ab
Sent: Saturday, March 11, 2023 11:17 AM
To: Artifact Binding/Connect Working Group <openid-specs-ab at lists.openid.net>
Cc: Sam Goto <goto at google.com>
Subject: Re: [Openid-specs-ab] SIOP and webauthn
I don't recall the timelines precisely, but didn't we develop WebAuthn before SIOP?
I think i understand why SIOP was developed, if it was done after WebAuthn, because, IIRC, WebAuthn didn't have the cross platform syncing capabilities that it has today, but i do wonder where SIOP would fit today.
On Sat, Mar 11, 2023, 9:41 AM Tom Jones via Openid-specs-ab <openid-specs-ab at lists.openid.net<mailto:openid-specs-ab at lists.openid.net>> wrote:
Check out chapi
thx ..Tom (mobile)
On Sat, Mar 11, 2023, 2:45 AM Nikos Fotiou via Openid-specs-ab <openid-specs-ab at lists.openid.net<mailto:openid-specs-ab at lists.openid.net>> wrote:
Hi,
I have a question which is related to politics and standardization history.
I believe that SIOP (as defined in openid connect core) could have been used instead of WebAuthn. A combination of SIOP+ctap (rather than WebAuthn+ctap) would have more chances of getting adopted. So I was wondering how we came up with yet another API instead of adding support for SIOP to browsers. Did this ever occur as a possibility?
Best,
Nikos
--
Nikos Fotiou - https://www2.aueb.gr/users/fotiou/
Researcher - Mobile Multimedia Laboratory
Athens University of Economics and Business
https://mm.aueb.gr
_______________________________________________
Openid-specs-ab mailing list
Openid-specs-ab at lists.openid.net<mailto:Openid-specs-ab at lists.openid.net>
https://lists.openid.net/mailman/listinfo/openid-specs-ab
_______________________________________________
Openid-specs-ab mailing list
Openid-specs-ab at lists.openid.net<mailto:Openid-specs-ab at lists.openid.net>
https://lists.openid.net/mailman/listinfo/openid-specs-ab
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-ab/attachments/20230311/4686c35b/attachment.html>
More information about the Openid-specs-ab
mailing list