Earlier quoted context omitted.
It's more like "provenance" of content. I broadcast my accountability of "myblog.com/posts/...", but would disavow "myblog.com/posts/.../#comments" There's some ways of like "nofollow", but nothing systematic, and no "protocol" for disavowing paths, uploads, or fragments. Back in the slashdot days, I thought of "blogs are the stationary of the internet", a way to more authoritatively declare that the content was your…
Again I think we're talking about different things. > We just haven't had the benefit or forcing function which encourages a solution to "that stuff over there is less trusted than my stuff over here". No the problem is we can't let people say "that stuff is someone elses fault" when it is their own fault. Scammers will claim subdomains are actually just not them and are other bad actors, and you're back to loads of…
The other way of looking at it might be similar to "DMARC-4-HTTP", ie: sign Content-Length, Content-Sig with a public/private key and if you include `SELECT comments FROM evil` then that "taints" your key.
It gets back to netlify that index.html would be signed by netlify.gpg, but haxor.netlify.com would be signed by not_netlify.gpg
...we can call it "web of trust 2.0" :-P
Appreciate the honest discussion!