Notes

Who gets to sign the leader?

An open decision from my lockstep prototype.

In my private lockstep prototype I implemented regional, trusted hosts that sign elected leaders. They can refuse to sign for participants that cause problems.

The catch: my experiment with a fully distributed system now needs a trusted authority again.

The alternative is to hand that role to community-run servers. But then I'm back to the question of how to deal with malicious operators.

Neither option is finished; stability and security are still open. The code isn't public.