Thread · 3 tweets · 12 Nov 2022

Replying to @TheRealRevK and @KeirStitt, @neil_neilzone

That is indeed a good question 😁 A key concern I have is that you can harden a protocol against all kinds of problems but it is essentially impossible to protect against the user agent.
The classic example is: you can make the web as private as you want, there's still the Chrome Sync backdoor where Google tricks people into handing over their entire browsing history. So what motivates me is: could we attach constraints to a protocol to impose fiduciary UAs?
It's not the only path there, just one option I was wondering about. Another is to tie revenue streams to this, but that too is hard.