<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=33&amp;t=1608" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2014-11-18T08:22:09+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=33&amp;t=1608</id>
<entry>
<author><name><![CDATA[Tom]]></name></author>
<updated>2014-11-18T08:22:09+01:00</updated>
<published>2014-11-18T08:22:09+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1608&amp;p=6247#p6247</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1608&amp;p=6247#p6247"/>
<title type="html"><![CDATA[Re: Q:- U2F, is there validation the user pressed the button]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1608&amp;p=6247#p6247"><![CDATA[
check the code:<br /><!-- m --><a class="postlink" href="https://developers.yubico.com/python-u2flib-server/">https://developers.yubico.com/python-u2flib-server/</a><!-- m --><br /><br />touch is &quot;signed&quot; by the device.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2195">Tom</a> — Tue Nov 18, 2014 8:22 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Automatic]]></name></author>
<updated>2014-11-17T22:19:01+01:00</updated>
<published>2014-11-17T22:19:01+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1608&amp;p=6246#p6246</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1608&amp;p=6246#p6246"/>
<title type="html"><![CDATA[Q:- U2F, is there validation the user pressed the button?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1608&amp;p=6246#p6246"><![CDATA[
I just skimmed through the the fido-u2f specification searching for `user verification`, however, I couldn't find what I was after. On your <a href="http://demo.yubico.com/u2f.php" class="postlink">demo</a> site, there's a 'touch' argument. It's marked as 'true'.<br /><br />My question is:- Is that 'touch' value signed by the u2f device? Or is that just the browser telling the the site that it requested a touch? I ask because, obviously, if malware is on your machine, the site could request a touch, but the malware could easily swap it out before it reaches the key and mark it as not-touch, then, on the way back to the site, swap it back round to being 'touched' again.<br /><br />The reason why I don't think it is is because it's under the &quot;Authentication parameters&quot;, not &quot;Response data&quot;.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2500">Automatic</a> — Mon Nov 17, 2014 10:19 pm</p><hr />
]]></content>
</entry>
</feed>