I expected something very different from this article based on the headline. Specifically, I completely disagree with the "leave it to industry standards" approach, as that doesn't help people understand what they should do, and more importantly, why. Request/response protocols (well, many things) really break down into 5 top-level categories (some sources will say the 6th is Audit): - Authentication - Authorization…
Given the inconsistent support for mutual-auth TLS, which along with its direct ancestors has existed for a decade and a half, what makes you think they'll be widespread and correct support for SAS?