I'm studying on FIDO2 these days. There are three questions.
- In registration process, what is the extension field?
- purpose, usages
- What means user verification? I think that user verification is local verification. example, fingerprint on mobile device. Why do I need to set this(required, preferred, discourage)?? Also what is the attesatation convayance preference??
- I understood that CTAP is a protocol between an external authenticator and a browser. How can I send data from the authenticator to the browser?