Cloudflare enlists Chrome, Firefox, Edge to kill CAPTCHAs with cryptographic tokens
Cloudflare, in collaboration with Chrome, Firefox, and Edge, is developing PACT (Private Access Control Tokens), a protocol to replace CAPTCHAs with anonymous cryptographic tokens based on IETF RFC 9576-9578. The project aims to allow sites to verify human users without CAPTCHAs, using tokens from issuers that already trust the user, but raises concerns about a two-tiered internet and who controls token issuance.
Key Takeaways
- PACT builds on IETF RFC 9576-9578 (Privacy Pass, published June 2024) and extends Apple's Private Access Tokens, which launched in iOS 16 and macOS Ventura in 2022 and attested device validity rather than human presence
- Cloudflare, Google Chrome, Mozilla Firefox, Microsoft Edge, and Shopify are co-developing the protocol with plans to submit it for formal standardization
- The protocol also covers authorized AI agents, distinguishing them from malicious crawlers — relevant because bots now exceed 57% of global web traffic per Cloudflare Radar data from June 2026
- PACT does not address browser fingerprinting, IP tracking, or other surveillance vectors; it only removes the CAPTCHA layer
- Mozilla published a detailed architecture proposal on June 23, 2026 describing Anchors, Moderators, and stateful Credentials, with drafts being prepared ahead of IETF 126 in Vienna
Why It Matters
PACT targets a real and worsening problem: with bot traffic now exceeding 57% of global web requests per Cloudflare CEO Matthew Prince's June 3, 2026 announcement, sites are layering on increasingly invasive verification that degrades user experience and privacy. For CDN and streaming infrastructure operators, PACT could reduce friction at access points while cutting reliance on fingerprinting-based bot detection. The concern is structural: if Cloudflare — already the bouncer for a massive portion of the internet — controls token issuance, it creates a de facto two-tier web where non-tokenized traffic is suspect by default. Watch whether the IETF dispatches the related MoLE (Moderation of unLinkable Endorsements) draft at IETF 126 in Vienna, which will signal whether standardization is months or years away.
Additional Context
The PACT announcement lands against a backdrop of a milestone in internet traffic composition. Cloudflare CEO Matthew Prince disclosed on June 3, 2026 that bots had overtaken human traffic for the first time, with 57.4% of HTTP requests to HTML content now automated (per NBC News, June 4, 2026; Search Engine Land, June 5, 2026). Prince had predicted the crossover for late 2027, but agentic AI accelerated it by roughly 18 months. Forbes (June 4, 2026) reported that HUMAN Security's 2026 State of AI Traffic report found agentic AI traffic grew 8,000% over 2025, while Thales's 2026 Bad Bot Report recorded a 12.5x year-over-year surge in AI-driven bot attacks. Apple deployed Private Access Tokens (PATs) in iOS 16 and macOS Ventura in 2022 (per The Verge, June 20, 2022), using Privacy Pass with device attestation via the Secure Enclave, with Cloudflare and Fastly serving as production issuers. Mozilla, however, published a critical analysis in December 2023 arguing that Apple's PAT model ties web access to hardware from a small set of vendors and that Privacy Pass on the open web poses unresolved non-technical hazards around equity of access and centralization. Standardization work is already underway. The W3C Antifraud Community Group hosted a PACT workshop at Cloudflare's London office on May 4–6, 2026, with participants from Cloudflare, Chrome, and Mozilla. Per a May 14, 2026 email to the IETF web-bot-auth mailing list by Dennis Jackson, participants began sketching a design called MoLE (Moderation of unLinkable Endorsements), built on Anonymous Credit Tokens rather than conventional Privacy Pass. Mozilla followed with a detailed technical blog post on June 23, 2026 describing a system of Anchors (issuers of Endorsements), Moderators (rate-limiting verifiers), and stateful Credentials — an architecture explicitly designed to avoid the device-lock-in problem of Apple's PATs. Drafts are being prepared ahead of IETF 126 in Vienna, where a side meeting will discuss where to dispatch the work.
Read full article at korben.info
Get this in your inbox → Subscribe
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source