A possible difference between private access tokens and the web integrity proposal is the idea of “holdback” which means that for some reasons chosen at random it would fail to work, and any websites that use it would be forced to have alternative fallback mechanisms.
Why bother, then? This is for things like captchas and credit card risk scores. It’s useful to be able to know that some users are low risk (not a bot, not being phished) and then to have additional verification for others.
It’s listed under “open questions” but I think it would go a long way towards preserving an open web.
replies(1):