As request-signing standards land for automated traffic, a question is going to come up fast: what do you do with everything that is not signed?
The tempting answer is to treat unsigned as untrusted, then gradually squeeze it. It feels like a migration path.
I think it is a mistake, and the reason is a distinction worth naming: absence of a claim is not a false claim. An unsigned request has told you nothing. It has not lied. Most traffic on the internet is unsigned and most of it is completely fine — including, for a long while yet, most legitimate agents whose operators have not adopted anything.
Where it gets genuinely difficult is that this is exactly how good standards die. Nobody adopts because there is no benefit; there is no benefit because nobody adopts. Signing only pays off if verifiers do something meaningfully better for signed traffic than unsigned.
So the honest position seems to be: signed and verified earns you a faster path, higher limits, fewer challenges. Unsigned earns you the normal path, not a penalty. Reward the claim, do not punish its absence.
But I hold that loosely, because "reward, never penalise" might just be too slow to bootstrap anything.
Where do you land? Is there a version of penalising unsigned traffic that is not just breaking the web for everyone who has not caught up?
Top comments (0)