Cloudflare, Google, Mozilla, and Microsoft are developing a mechanism to filter out web bots

The companies Cloudflare, Google, Mozilla, Microsoft, and Shopify have unveiled a collaborative project to develop and standardize the Private Access Control Tokens (PACT) protocol. This protocol allows for distinguishing real users and legitimate bots from junk traffic and uncontrolled AI bot activity while maintaining user privacy. It is claimed that the new protocol will enable the filtering of bot traffic on websites using anonymous tokens, eliminating the need for CAPTCHA, mandatory authentication, and tracking via cookies.

The idea is that services with a reasonable belief that a user is a real person—such as after successful authentication or anti-bot checks—will issue anonymous tokens to the user. Subsequently, the user's browser will be able to present these tokens to other sites as proof that the request is not automated. This approach will allow the use of validations already passed on one website for connections to other sites without additional checks. Meanwhile, the protocol is designed so that websites cannot use the tokens to identify users or recover browsing history.

The initiative was prompted by the increasing share of automated traffic from AI agents, crawlers, and scrapers that masquerade as requests from ordinary users, ignore rules from robots.txt, and create immense parasitic load on servers. Previously, Cloudflare proposed using the Web Bot Auth mechanism for bot authentication, which is based on appending a cryptographic signature to HTTP requests from bots to make access decisions based on verifiable data, rather than relying on an IP address or easily spoofable User-Agent field content.

Among the potential risks associated with the PACT protocol implementation is the concern that the mechanism designed for voluntary user confirmation could evolve into a mandatory access filter for websites, creating a barrier where programs, browsers, and users must prove that they deserve access.

The Electronic Frontier Foundation (EFF) has previously drawn attention to a similar issue in its critique of the Web Environment Integrity API and remote attestation. Such mechanisms allow website owners to block undesirable browsers, operating systems, and automation tools, framing it as a fight against fraud and malicious activity. EFF acknowledges that bot problems are real, but considers it unacceptable to address them by introducing new restrictions that infringe on the user's right to control their own computer.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster