{"abstract": "   A human-authorization receipt proves an enrolled key produced a user-\n   verified signature over a digest that commits to an exact action.  It\n   does not prove the signing surface DISPLAYED that action honestly.\n   If a signing interface shows a benign summary while committing a\n   different action, the resulting receipt is laundered authority:\n   cryptographically valid and semantically false, which is worse than\n   no receipt at all.  This is the presentation attack, and it is the\n   deepest unsolved problem in authorization evidence, because a\n   signature cannot attest to pixels.  This document narrows the gap\n   with two additive, offline-checkable pieces that touch no existing\n   receipt format: a DETERMINISTIC RENDERER, a pure function from the\n   canonical action to a byte-identical human-readable rendering, so a\n   verifier RE-DERIVES the rendering from the signed bytes and rejects a\n   claimed rendering that does not match; and a DISPLAY ATTESTATION, a\n   signed claim by the signing client binding the rendering it showed to\n   the action it committed.  Neither eliminates the presentation attack\n   (nothing purely digital can), but together they let a verifier check\n   the claimed rendering against the signed action under relying-party-\n   selected client trust inputs.  They make the residual risk explicit\n   rather than hidden.\n", "ad": null, "expires": "2027-03-16T15:06:51Z", "external_url": "", "group": "/api/v1/group/group/1027/", "id": 157708, "intended_std_level": null, "keywords": "[]", "name": "draft-schrock-ep-presentation-binding", "note": "", "notify": "", "pages": 7, "resource_uri": "/api/v1/doc/document/draft-schrock-ep-presentation-binding/", "rev": "01", "rfc": null, "rfc_number": null, "shepherd": null, "states": ["/api/v1/doc/state/1/", "/api/v1/doc/state/150/"], "std_level": null, "stream": null, "submissions": ["/api/v1/submit/submission/165534/", "/api/v1/submit/submission/168936/"], "tags": [], "time": "2026-09-12T15:06:51Z", "title": "Binding Deterministic Rendering and Display Attestations to Human-Authorization Receipts", "type": "/api/v1/name/doctypename/draft/", "uploaded_filename": "", "words": null}