IETF Web Bot Auth Leaves Human Verification Unsolved, Developer Proposes Fix
The IETF Web Bot Auth working group has published a charter draft that deliberately excludes end-user authentication from its scope, focusing only on identifying which AI agent is making a request. While services like Cloudflare and AWS can cryptographically confirm a request originates from a known bot such as ChatGPT, they cannot confirm a consenting human is behind it. A developer has proposed a lightweight alternative using a signed HTTP header called X-Trust, which carries a behavioural trust score derived from browser signals like keystroke timing and scroll patterns. The score updates during a session and lets the receiving server decide how to respond, without forcing CAPTCHAs or identity checks. The developer acknowledges the system is not fraud-proof and flags unresolved concerns about whether the scoring model may disadvantage users with motor impairments.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in