Report-out from breakouts
● Identification != authentication. Getting the world to understand the difference.
○ Separation of concerns: authentication and attribute-provisioning ceremonies
● Privacy. Needs more discussion of privacy concerns and considerations
○ Privacy by design
● Identity assurance. How do you get to trusting the issuer or assurer? Moving
from technology to service
● Want browser/device to know who I am and be my agent in revealing that
● Bridging WebAuthn and OAuth
● RPs have a rich choice of federation, and user-access to those
○ Also data storage
● Coexistence, not choosing between paradigms. Discovery, registration,
resolution.