Pact: Anonymous Credentials for the Web
hacks.mozilla.org
hacks.mozilla.org
i’m not sure what they mean about agents, however. would this mean a human generates legitimate traffic, and that goodwill can then be utilised by a browser agent? and will it be possible to host your own Moderator?
I feel like this is explained in the article:
> AI agents acting on behalf of a user slot into the same flow. An agent can carry its user’s Credentials, in which case the user remains accountable for how the agent behaves. Sites would not need to grant any more access than they would to the user themselves. Alternatively, the operator of an agent can run its own Anchor and vouch for its agents the way other Anchors vouch for human users. Sites retain control over which Anchors they accept, so they can choose how to treat agent traffic without needing a separate detection mechanism.
So there are 2 things that could happen, depending on how the agent works.
1: An Anchor gives the user Credentials, with personhood verified by e.g. the user's phone number. The agent can then use that to act like a normal user.
2: The operator of the Agent (OpenAI, Google, etc.) acts as the Anchor themselves. That Anchor gives the agent its own separate Credentials, maybe with personhood verified by the user's paid subscription or something. This approach would allow Moderators to block agents, if they wanted.
> and will it be possible to host your own Moderator?
Yes. They say that the website itself can be the Moderator > In the common case the site itself plays the Moderator role, so there’s no new entity or trust boundary.
Shorter post: https://blog.mozilla.org/en/privacy-security/keeping-the-web...
Reticulum uses a proof of work "stamp" as a user side defense against not like behavior.
Make a simple form protocol for things like posting comments. Maybe based on OpenAPI?
Solderpunk (Gemini creator) was correct that HTML and JS were both problems, but he didn’t foresee that the legacy TCP/IP client/server model could become a liability. The Gemini format is great, but the TOFU-based security layer is awkward and unnecessary with a proper overlay network that provides encryption and cryptographic IDs instead of domains. It’s also better not to expose your server IP these days.
Sincerely, I wish them the best of luck!