Authentic Web workshop - Report
Authentic Web Summary
The Authentic Web mini-workshop series began in March 2025 with an introduction to a questionnaire based on Technological Approaches to Improving Credibility Assessment on the Web. The program committee solicited submissions from the community asking presenters to use a questionnaire as framework for presentation. Each session was 60-90 minutes, with at least 20 minutes reserved for questions. Presentations were recorded. Discussion was not recorded. Workshop sessions spanned nine months. Minutes are available.
Presentations of new and existing models
C2PA
C2PA is a Transparency mechanism, enabling creators and publishers to show how images and media content has been created, from capture through editing to publication, via a series of signed assertions. It can also be considered a Reputation System because it makes the provenance chain visible to the user. At the IPTC Webinar (Sep 2025), we learned that C2PA is becoming even more widespread, The camera on the newest Pixel phones provides C2PA data, and LinkedIn can share content credentials about the images in posts.
What can W3C do?
- work towards getting C2PA, IPTC and other trust lists supported by the Web Platform, ideally similar to the HTTP "padlock" icon in the location bar
- Help work towards a standardised API that covers how C2PA signals can be exposed as part of the Web Platform
- Help in evangelising C2PA work and the benefits of signing content
- Understanding any reservations around the specifications and policies, specifically from a Web Platform perspective
Trustnet
Trustnet lets people identify a list of people and other entities that they trust (facilitators), and then tells them which websites and articles their network thinks are credible. Facilitators record their credibility assessment on any URL (a Transparency mechanism). When a user visits a URL or encounters it in a feed, tools fetch and aggregate any assessments for that URL made by facilitators the user trusts. Based on the aggregation, the tool presents an aggregate credibility assessment in place as the user views the article or news feed, offering an Inspection System.
What can W3C do?
- Help Trustnet create a standard/API and/or socialize it
trust.txt
Trust.txt enables publishers to list information in their root domain that identifies relationships. Examples of relationships include member, belongTo, controlledBy, and social. These can be viewed as plain text or via a web extension, enabling small publishers, such as local news outlets to declare claims without complicated infrastructure.
What can W3C do?
- Standardize existing browser extensions Update threat model/security model
Originator Profile
Originator Profile Framework provides content provenance, alongside verifiable profile information that is the origin of the content, the Originator Profile. The profile information is validated and provided by multiple third parties, composed into an Originator Profile. Since the presentation, OP has published a draft architecture document that goes into greater detail, including information about Content Attestations. The framework is designed to be extensible and adaptable to various use cases and can be used for different types of media, including text fragments and other media within a web page.
What can W3C do?
- W3C is a potential home for architecture (as is IETF)
- Create CG
- Threat model
Dokie.li
Dokie.li is an open source platform on which credibility assessment is performed by individuals or communities using dokieli's indicators, rather than dokieli itself. It enables users to annotate content or fact check information by clicking a button that pulls in other annotations as well as open data.
What can W3C do?
- A standardised Credibility Assessment Data Model
- Development of an Argumentation Data Model
- Development or extension of Web Annotation motivations
- An authentication mechanism better suited to browser extensions that supports user-controlled identity
Next Steps and Goals of further workshops
It is unlikely that W3C will solve fake news or be able to detect deep fakes. However, there is a lot of interest in the tools that are being developed and in creating a multi-pronged approach that aids users in assessing what is "real". None of the tools proposed are focused on detection; rather on helping users make informed choices on their own. These can be applied not just in the context of news and social media but also to assess whether a product review was written by a human or a bot, whether an ebook is the one being sold by the publisher or a pirated version. Some of these tools could be applied to create a facilitator list for a peer review group.
- Create robust use cases (showing intersection of different tools)
- Understand what can be standardized/W3C’s role in standards
- Assess where proposals overlap / potential to work together (C2PA/OP?)
- Document robust threat model
- Work with browsers/implementers to understand appetite for proposals