I think that the policy we come up with has to depend on which promises we make in the ipfs: scheme. The SOP is needed because the HTTP web is full of side effects and so we clumsily restrict interaction to a smaller, safer group of side effects.
♥ 4