Hi IAWG - for increased clarity about Thursday's call...
We have been analysing the NIST 800-63 Supplement on Syncable Authenticators in order to address it correctly in our assessment criteria.

Last time IAWG discussed this, we had questions about how syncable passkeys work at a moderate technical level, and the roles and responsibilities of the parties involved.

This is not a "presentation" from Tim, Dean and Alexei - it's a chance for us all to ask questions and think about how the NIST supplement is written versus how syncable passkeys might be implemented, and how assessors can inspect implementations to ensure conformance.

Jimmy has circulated his initial thoughts and criteria on this supplement - your homework is to read through and prepare to discuss. 

We'll get a quick overview of how the passkeys ecosystem is designed to get some context, then I hope we'll get into the documents and assessability topics.

We will skip most of the normal agenda and get into the main discussion quickly.

thanks for your advance work on this!
andrew.

————————
Andrew Hughes CISM 
m +1 250.888.9474
AndrewHughes3000@gmail.com 



On Tue, Aug 6, 2024 at 4:30 AM Amanda Gay <amanda@kantarainitiative.org> wrote:
Dear IAWG Members:
Please join us this Thursday, at 12 Noon ET for the next IAWG meeting.

The proposed agenda and Zoom details are below.  Please also keep an eye out for an email from Jimmy containing a first attempt at rolling the supplement into Kantara criteria!

Date and Time

DRAFT 08.08.2024

  1. Administration:

  • Roll call, determination of quorum. 

  • Minutes approval 

  • Kantara Updates

  • Assurance Updates

  1. IAWG Actions/Reminders/Updates:

    • Proposed Meeting Cadence for June/Extended Summer*

      • August 8 (Passkey Presentations), August 22

      • *If rev.4 is released, this cadence will be updated 

  2. ISO 17065 Discussion Items

  3. Group Discussion:  

    • Passkey Presentations

      • Tim Capalli, Okta

      • Dean Saxe, Beyond Identity

      • Alexei Czeskis, ID.me

  4. Any Other Business


--
Amanda Gay | Administrative Coordinator
 

Twitter:    @KantaraNews

LinkedIn:  @KantaraInitiative

_______________________________________________
A Community Group mailing list of KantaraInitiative.org
WG-IDAssurance mailing list -- wg-idassurance@kantarainitiative.org
To unsubscribe send an email to staff@kantarainitiative.org
List archives --  https://mailman.kantarainitiative.org/hyperkitty/list/wg-idassurance@kantarainitiative.org/
______
Group wiki -- https://kantara.atlassian.net/wiki/spaces/WG-IDAssurance