The article does not say it’s storing the authenticator data (in the format the webauthn spec specifies), it says it’s storing (most of) the fields in cbor. So it’s using the webauthn reference for logical purposes (the names and types of fields) not physical (the encoding).