| Anderson, “Why Information Security Is Hard” (2001) | note | 2, 3, 6, 19–21 | checked |
| Thomas et al., “Trafficking Fraudulent Accounts” (2013) | note | 3, 9, 13, 15, 19, 20 | checked |
| Thomas et al., “The Abuse Sharing Economy” (2016) | note | 6, 7, 9, 10, 12, 13, 15 | checked |
| NIST AI RMF 1.0 (2023) | note | 6, 7, 11, 12, 15, 17, 19, 21 | checked |
| NIST Privacy Framework 1.0 (2020) | note | 5, 7, 9, 13, 17–19, 21 | checked |
| NIST SP 800-63-4 Digital Identity Guidelines (2025) | note | 4, 5, 7–9, 14, 15, 17, 18 | checked |
| IETF RFC 6598, Shared Address Space (2012) | note | 7, 9, 10, 13, 15, 16 | checked |
| IETF RFC 8981, IPv6 Temporary Addresses (2021) | note | 7, 9, 10, 13, 18 | checked |
| W3C WebDriver (2026 Working Draft) | note | 1, 4, 7, 8, 10, 11, 14 | checked |
| Google crawler verification guidance (2026 access) | note | 1, 4, 7, 8, 10, 18 | checked |