Thread · 3 tweets · 11 Jan 2023

Replying to @lidelOrg and @BrendanEich, @dietrich, @boscolochris, @darrello, @csuwildcat, @gordonbrander, @brave, @shivan_kaul, @fmarier

Absolutely, but what would normally fall under "third-party" threats is the ability to identify (probabilistically enough) the person who triggered a load so as to track their behaviour. So the threat is the same for all IPFS loads you don't already have.
That's different from HTTP where the threat will differ based on which domain is top-level. For mixed content, so long as you verify what you load (and there are no credentials over IPFS), then loading ipfs: in an https: context should always be safe?
And same with ipns: assuming that you verify that it was signed correctly too. I could be wrong (I haven't looked through the full mixed content threat model) but this is pretty neat.