If I understand correctly, your device will have to contact its manufacturer everytime you visit a site requiring the token ?
And they say it's "privacy preserving" and "open standard", WTF ?
What if I want to change the OS of my device ?
I should "rejoice" ?!
I guess I prefer CAPTCHAs...
These GAFAM/Cloudflare IETF drafts are literal nightmares, hope it won't pass through.