You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Each authentication operation using the authenticator SHOULD require the input of the additional factor.
This seems somewhat at odds with a later statement in the section:
The unencrypted key and activation secret or biometric sample — and any biometric data derived from the biometric sample such as a probe produced through signal processing — SHALL be zeroized immediately after an authentication transaction has taken place.
If the latter statement is a SHALL, it seems like the earlier one would need to be a SHALL as well. It's possible that the activation factor is resent from the host endpoint being authenticated, and that the zeroization requirement doesn't apply there. But this should be clarified.
The text was updated successfully, but these errors were encountered:
-63B Section 5.1.9.1 says:
This seems somewhat at odds with a later statement in the section:
If the latter statement is a SHALL, it seems like the earlier one would need to be a SHALL as well. It's possible that the activation factor is resent from the host endpoint being authenticated, and that the zeroization requirement doesn't apply there. But this should be clarified.
The text was updated successfully, but these errors were encountered: