It's crazy that, after all our experience with this, we're implementing another protocol that doesn't have any auth built in.
You'd think the last 30+ years of regret and hacky attempt to add auth to email and http (as just the top two to come to mind) hadn't happened.