[Web-bot-auth] Re: WebBotAuth Direction

Rifaat Shekh-Yusef <rifaat.s.ietf@gmail.com> Wed, 20 May 2026 22:02 UTC

Return-Path: <rifaat.s.ietf@gmail.com>
X-Original-To: web-bot-auth@mail2.ietf.org
Delivered-To: web-bot-auth@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 41449F1F4F28 for <web-bot-auth@mail2.ietf.org>; Wed, 20 May 2026 15:02:48 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1779314568; bh=F4+y2LBabTbHlII19DdnsbSYnT+JEWmRqsYHjcqmpBQ=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=OeLa8xBdKRenCNYlmtd30qnRGjBOZ5C5DKqz6cY1Vxl5edSh/VKFGnPwFrT/b6N8D b552+vVmbmoM9e1Bu3LJ9VZSlftDkbVEBBBUKnDJOJjqFDjsnKCpiSeRYXG4DpY+Mj +Ksd/WARG4mK1DvBUDFkpoH4vsWA0REEHWFAOA5M=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id aQHtZ-hxlIgz for <web-bot-auth@mail2.ietf.org>; Wed, 20 May 2026 15:02:46 -0700 (PDT)
Received: from mail-lf1-x130.google.com (mail-lf1-x130.google.com [IPv6:2a00:1450:4864:20::130]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 4AA75F1F4D8A for <web-bot-auth@ietf.org>; Wed, 20 May 2026 15:02:00 -0700 (PDT)
Received: by mail-lf1-x130.google.com with SMTP id 2adb3069b0e04-5a884815606so6407359e87.0 for <web-bot-auth@ietf.org>; Wed, 20 May 2026 15:02:00 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1779314519; cv=none; d=google.com; s=arc-20240605; b=ktzrLl8Q9MBFoltsQeAVPPijOvqoZkLzFPcf/Z2fC/+rami28idjhX7rKIAJ4hIlB3 YvY0Uez4JvE+JahndZ0kzYvIzssG/JUBKH0o3EZARTh6/WldQZgd06nGtOpfpZ+3CW1Y TP/p8xVEWIwrQfqc4qSnkrue4JCEpZC/m0/bTqsj2bsii5wOK6t1LT9TTn77zLYk7e7a S9Y9WMh4KAk+doTFjp4xSS0q6dlzQG6N+gRhSHxz/iSGup44D/z2giAOisuLmCBW5ZXD 9Ig82bOP3MeiKB7deHthWkPaYIOgf9qpC6dMJw0BGU9R4QBlHv/MIFIrMWuT/2s5YXpQ QJPw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=F4+y2LBabTbHlII19DdnsbSYnT+JEWmRqsYHjcqmpBQ=; fh=nfDHEI6CuHc9QACEiFZs65+Qg8a83YKG8FILB/NS4b8=; b=W2sup6F00L9/EO63aBAc7j0kcHfdYMuJVBL4uPdeane5AruWBixF7JqUnEGsnCZcw1 O++g6nN16FSWgWYxFELsYC2hLPzF0aJDzd4OS7UfGkgHBWV6TOO0CB6I0aQJgQZQ+6mc 4m7zqhUCdUYtWvSh/oZHPvH4ylYSfCXkNl75tKczx1azLSwprwZZq+QHpi4tVs5xCBNp E7072svq9zXTOwCRMv1gLPyIEkPOQ1AL3796EzRjd9b5NWYIkoZVgM4/kM+e1sSof8NK csRJJ/UHg99oJZ1+36bS/e+UVqFm3f7WY1snAB/3A5j/BnyGAxliVhyBPQgCL6Ptjl4G hpFg==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1779314519; x=1779919319; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=F4+y2LBabTbHlII19DdnsbSYnT+JEWmRqsYHjcqmpBQ=; b=qi6HY8NRXiLP87fbUbliCUq5OPIEV3rM0h4Z6lqMBNS0BVXgSB2HxtZHnKdOlr9tFE bZ5oc2rpxifig2epLsGvXjGMQp5KKIJedLpC4MuN7gV2g9O/rFJacOJECtBD1vccqsAQ 01l2uPPkGA2hxDWHFfX9IsEAynRUV9EY/LmEwIYmjqfjMJ/I+6laGSEp/AmOJ6iUQUIx Roz+/EwaQaLiwg1UMA5MQfPxx/2A60j6OCmhP96LKRTWl7xjQlfJ3E6KuSKV1ymrwUaH fmc2gF5KdvKkWv4ItXlWsmi3Rmc7rysNpZ2jgADAF0vW06o6NiJOt4qSEa7EPKPYev4u A+Xg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779314519; x=1779919319; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=F4+y2LBabTbHlII19DdnsbSYnT+JEWmRqsYHjcqmpBQ=; b=PyssYN8pkRv6Gl0wu8pZw7i9UDAAJmSr84pNH0eAfP4yUAFgaANSnrhtcB3wT2qPDe YtL28Cpi62cAlKSpjYcwI3nT/gaeQoquRCtFDibhnxPzUnQY27fQhKng6jDvO2S19LjD 5eBssM6EKvY6/oiAUbSB0eG688n/sv4rOXm0pkhAIXqAeA47JpzbP49B2NfeeTOG3+pj XZIZfGU8MkYab717XNjF0trK9tCCK9yOZET1q+HLWqAu31vwS+zrO9Zm9k19NSdpoth0 kDX1rZRRXq+HyxKVO88pNM0KDmf0LyZ2kQRDWm+PjWO8rAML9raOXoEkvwFYmvcRjRvS Kufw==
X-Forwarded-Encrypted: i=1; AFNElJ9MB9q9+j3h38zwdtdUlBoqA0R8KaSbE6PVSJWgNynhAIjtUCb77FLlfaxkt52IeTooB7+OyXl6uMK3A4A=@ietf.org
X-Gm-Message-State: AOJu0YwokxdD+ztLYgcY/ze5kaaRd+g62CY8h7SSXCSDS/X3RcdBGr/b fci5ot0TNmcJejzPVLiW2TYaHZOnfGayXA9bvBvk8CdSlS9IGtKpEewpRHSn1ACTvAzBtfqSEQi h2FMKYoWX96HzVi/4VMiZcLUIzwHnU1I=
X-Gm-Gg: Acq92OGIbmk0mJyP28uui8bN0WnOQPdsGw58orJE8ioCN5i1pJWj7olxUU8AJanosQS CWHo0+5p5IfHJyt3u1GM+olVA5vqAO42ZJXJ5ulbCQf4WzMkDt4EnnmcQz3jJh72d1IfWM70zjG fO+N51BEh7r0TyMxao1b53nvNskc62d7ffMVv4KnjJUdUalmlXKbIDi7wTgc3+Cb9QuKumyJd/M RwWUo0sgXb2Tex0rWvkz99ehUbHBJ4tK3xV1eTy2NPQfElJkVaDvjMehlG4CDMiZ44mRJdiW5bI HeOGelr26tgnhC9eBmUpBXblZopn+otwfj3l1760Kin9j/IiZ75ZoTLU3PY7z9d8OL5chc61E8S xFooyDruuAchJ3uvSmSlf0+zHRg==
X-Received: by 2002:a19:5212:0:b0:5a7:46e6:74c4 with SMTP id 2adb3069b0e04-5aa2ba64ec3mr60953e87.9.1779314517768; Wed, 20 May 2026 15:01:57 -0700 (PDT)
MIME-Version: 1.0
References: <CADNypP_iOUp6K90V4a=WcDOhqpG5yUv+VXh_jOwtLhEJf7s4jA@mail.gmail.com> <4BC241F8-8E3E-4CAE-B381-A0017E4C27F6@mnot.net> <2B1B950A-9FE2-4037-B5F1-11D1B4F25571@skgo.org> <CAGJaBrD27ZUxXBP4z_q22w=08yRRs9ABMjcTTWsAwa6J4gP95g@mail.gmail.com> <CAMzqgozP8chRZHgjJGevYWDfP5C=Ewc8mZUDCeEreEmJGtvomg@mail.gmail.com> <CAP5QTG7=Z_b1vgmKd6+iQk-+QNfKhZM3_q8wV4FTHepsQhYRvQ@mail.gmail.com> <DBBPR01MB1065104F6FE6CD00A9A747C0195002@DBBPR01MB10651.eurprd01.prod.exchangelabs.com> <CACsn0cmLHM2jAw2M20ekGeQ+T68HuhuxHkexBcqde-3P_BWtFg@mail.gmail.com> <F4BD282F-7201-4C3A-97F9-6816EE5E512B@litzki-systems.com>
In-Reply-To: <F4BD282F-7201-4C3A-97F9-6816EE5E512B@litzki-systems.com>
From: Rifaat Shekh-Yusef <rifaat.s.ietf@gmail.com>
Date: Wed, 20 May 2026 18:01:44 -0400
X-Gm-Features: AVHnY4K-f7FB3JwCWF3hFHx4mS_20Upw5bJozk2U-OMM9F5C5oIH_45tQTf56q4
Message-ID: <CADNypP_xRtV-qgJ7D9kLYe_Lt9eQYrkO3jKiMkmjav1CasqSKA@mail.gmail.com>
To: info@litzki-systems.com
Content-Type: multipart/alternative; boundary="000000000000c6809b065246f19a"
Message-ID-Hash: S6PRZTZKBF7NGSLMWNQGR5SZYIBM767X
X-Message-ID-Hash: S6PRZTZKBF7NGSLMWNQGR5SZYIBM767X
X-MailFrom: rifaat.s.ietf@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Watson Ladd <watsonbladd@gmail.com>, Srecko Jovancevic <Srecko.Jovancevic@skgo.org>, Brent Zundel <brent.zundel@yubico.com>, Orie <orie@or13.io>, Sarah McKenna <sarah.mckenna=40sequentum.com@dmarc.ietf.org>, Mark Nottingham <mnot=40mnot.net@dmarc.ietf.org>, "web-bot-auth@ietf.org" <web-bot-auth@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Web-bot-auth] Re: WebBotAuth Direction
List-Id: Authentication of non-human users to human-oriented Web sites <web-bot-auth.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/web-bot-auth/gxkMGMC75Sm1LO9WPvZbPKYhNAc>
List-Archive: <https://mailarchive.ietf.org/arch/browse/web-bot-auth>
List-Help: <mailto:web-bot-auth-request@ietf.org?subject=help>
List-Owner: <mailto:web-bot-auth-owner@ietf.org>
List-Post: <mailto:web-bot-auth@ietf.org>
List-Subscribe: <mailto:web-bot-auth-join@ietf.org>
List-Unsubscribe: <mailto:web-bot-auth-leave@ietf.org>

Thank you all for providing your opinion on these options.
Based on the feedback we received from the WG, we believe that we have
rough consensus to go for *option #2* - Work on both, anonymous and bot
identity approaches, in parallel.

We believe that the next step is to start discussing the requirements
associated with each one of the approaches.
We ask the proponents of each approach to start a discussion on the mailing
about these requirements.

If needed, we would be happy to schedule another interim before Vienna.

Regards,
 Rifaat & David



On Wed, May 20, 2026 at 5:06 PM <info@litzki-systems.com> wrote:

> Hi Watson,
>
> The argument holds. A browser-wrapped bot is, at the transport layer,
> identical to a human browser. Behavioral heuristics cause collateral damage
> to legitimate users before they catch a sophisticated bot. That is a
> structural property of the open web, not an implementation gap.
>
> The same analysis points to where attestation does work: closed,
> cooperative ecosystems where it is a hard entry condition. The attack
> surface disappears by design. Protocol engineering delivers there.
>
> I submitted draft-litzki-sovp-00 to DISPATCH last week. It addresses one
> specific layer: verifying that a domain owner's signed machine-readable
> declaration remains intact between signing and agent ingestion. It operates
> before ingestion begins, orthogonal to agent identity (WIMSE) and source
> certification (draft-bondar-wca).
>
> The enterprise-ecosystem framing in this thread maps directly onto that
> layer.
>
> Draft: https://datatracker.ietf.org/doc/draft-litzki-sovp/
>
> Best regards
>
> *Thorsten Litzki*
> Inventor, Sovereign Validation Protocol
>
> *LITZKI SYSTEMS LLC*
> Web <https://litzki-systems.com/> // LinkedIn
> <https://www.linkedin.com/in/thorsten-litzki/>
>
>
>
> Am 19.05.2026 um 09:27 schrieb Watson Ladd <watsonbladd@gmail.com>:
>
> I think that argument proves too much. The issue is not that bot traffic
> doesn't look human. Rather it's that there are classes of interaction that
> are malicious, and until recently automation (which after all humans
> start!) was a proxy for that actual behavioral difference.
> _______________________________________________
> Web-bot-auth mailing list -- web-bot-auth@ietf.org
> To unsubscribe send an email to web-bot-auth-leave@ietf.org
>
>
>