As the distinction between malicious and beneficial bots becomes blurred due to increased AI traffic, Cloudflare proposes using cryptographic methods to authenticate bots. This approach includes HTTP message signatures and request mTLS to verify bot identity. These methods aim to replace outdated IP address validation, providing a reliable way for bots to declare their identity. Both mechanisms are explored, with the potential to integrate them into broader bot management and AI audit systems, aimed at enhancing both security and traffic control for websites.
Table of contents
Existing bot verification mechanisms are brokenIntroducing HTTP Message SignaturesExperimentation with request mTLSTwo approaches, one goalThe bigger picture1 Comment
Sort: