As request-signing standards land for automated traffic, a question is going to come up fast: what do you do with everything that is not signed? The tempting answer is to treat unsigned as untrusted, then gradually squeeze it. It feels like a migration path.
Source: [Dev.to](https://dev.to/layercall/we-treat-a-missing-signature-as-suspicious-should-we-819)