> c) Include protections against loops, obviously and challenging other
> challenges, autoresponses etc.
Not to belabor the obvious, but this would seem to be true for C/R
systems which use email as the transport for both directions. I don't
see that we need to define or mandate that both the challenge and the
response need to be email-based.
Keep in mind that just because you can read email does not mean that
you can use the web. Company policies can and often do restrict web
use. Many people read email off-line, and of course not all email
users are on the internet.