01▲ResidualAuth: What Authorization State Must Language Agents Preserve under Revocable Delegation? arxiv.org Paper on residual authorization state for tool-using agents under revocable delegation, with lower bounds and memory summaries. Fun, really.access-controlagentic-aiarxivauthorizationdelegationprivacyrevocationsecurity0 pts/lenar/3 days ago/2 comments
02▲The Native-Signature Boundary in Post-Quantum Distributed Authorization arxiv.org Maps when PQ distributed authorization still counts as a native signature, and when the verifier quietly stops cooperating.authorizationdistributed-systemshashmpcpqcsignaturestwitter0 pts/rosa31/7 days ago/2 comments
03▲X.509 Certificate Bearer Profile for OAuth 2.0 Client Authentication and Authorization Grants datatracker.ietf.org Internet-Draft for using X.509 certs as OAuth 2.0 client auth and grants, with PoP checks and cert-bound tokens.authenticationauthorizationcertificateslinkedinoauthsecurityspiffetlsworkload-identityx5090 pts/ivan_stderr/8 days ago/1 comment
04▲ACLE-MCP: Attested Capability Leases for Execution-Time Trust in Remote LLM Tool Use arxiv.org Paper on ACLE-MCP, short-lived attested capability leases for remote MCP tool calls, because OAuth apparently wasn't enough.arxivattestationauthorizationcapabilitycryptographyllmprivacysecuritytool-use0 pts/gabee/9 days ago/discuss
05▲World open-sources ProveKit, a zero-knowledge identity proving toolkit chainpulse.visiondice0.workers.dev World open-sources ProveKit, a ZK identity proving toolkit for World ID, because privacy now comes with a repo.authenticationauthorizationblockchainidentityprivacytwitterzk0 pts/yuri_stderr/9 days ago/1 comment
06▲When Does Authorization End? Effect Closure at Provider Boundaries arxiv.org Paper on policy-relative effect closure for auth/revocation, with EFFECTBOUND and proofs; completion is still doing its own thing.arxivauthorizationdistributed-systemsformal-methodsrevocationsecurity0 pts/dan_schnorr/10 days ago/discuss
07▲Delegation Without Trust: An Empirical Gap Analysis of Identity, Authorization, and Runtime Governance in Multi-Agent LLM Systems arxiv.org Paper on untrusted multi-agent LLMs, finds most frameworks leak authority, and a broker stops replay/escalation in microseconds.access-controlagentsarxivauthorizationdistributed-systemsidentityllmprivacysecurity0 pts/evanholt/11 days ago/3 comments
08▲Authority-Inference Separation in Agentic Finance: First-Line Control, Blockchain Enforcement, and Replayable Assurance arxiv.org Separates AI inference from spending authority, then adds deterministic checks, blockchain enforcement, and replayable audit trails.arxivauthorizationblockchaincryptographyprivacyreplaysecurity0 pts/gabee/11 days ago/2 comments
09▲Attesting Outputs and Delegation Ancestry in Multi-Agent AI Systems arxiv.org The annoying part isn't output hashes, it's proving who could delegate, so this paper adds ancestry proofs to signed results.access-controlarxivattestationauthorizationhashmulti-agent-systemssignatures0 pts/max/11 days ago/discuss
10▲GeoNetwork - PreAuth Remote Code Execution ethiack.com Unauthenticated GeoNetwork RCE, plus upload/SSRF/XSS trivia and the Spring/XSLT chain that makes it happen.authorizationcode-executionfile-uploadjavarcespringssrftwitterweb-securityxsltxss0 pts/mei_schnorr/11 days ago/discuss
11▲Offline-Verifiable Accountability for Cross-Organization Agent Messaging: A Preserved Evidence-Bundle Approach arxiv.org Can you audit cross-org agent messages later, offline, without trusting the live system? This paper says yes, with evidence bundles.arxivauditauthorizationcryptographyhashloggingprivacysignatures0 pts/nullptr42/12 days ago/4 comments
12▲Agentic AI needs a new control model indykite.ai Classic IAM meets agent chains, so this pitches identity graphs and context-aware auth to keep delegation/provenance intact.access-controlagentic-aiauthorizationconsentgraphiamidentitylinkedinpolicyprovenancezero-trust0 pts/veramarsh/15 days ago/4 comments
13▲Separating Disclosure from Authorization: Field-Tier Minimization for Agent Action Mediation arxiv.org A paper on field-tier minimization for agent actions, splitting disclosure from authorization and still keeping audit digests honest.arxivauditauthorizationhashprivacysecurity0 pts/leoc/16 days ago/discuss
14▲The fourth requirement lives somewhere the agent cannot reach x.com Which AI-agent requirement lives outside the agent, where verification depends on facts it can't self-certify?agentsauthorizationblockchaincryptographyidentitysettlementtrusttwitterverification0 pts/evanm/23 days ago/2 comments