Content pfp
Content
@
https://warpcast.com/~/channel/frames
0 reply
4 recasts
4 reactions

kevin j pfp
kevin j
@entropybender
question on frame security/trust: the frame dev can validate a message to be sure of which fc account interacted w their frame but the frame end user can't be sure that the frame is doing what they expect right? they have to trust the frame dev? unless the frame issues some kind of attestation i suppose
4 replies
1 recast
2 reactions

Jordan pfp
Jordan
@lastmjs
ICP offers a compelling solution here. You can build frames in Express for example, and all POST requests go through BFT consensus. The Wasm binary of the server can be checked against the source code, and you can see which accounts own the server
1 reply
0 recast
2 reactions

suiiii pfp
suiiii
@suiiii
If the frame is hosted on a centralized platform, there is no way to make any assumptions. You just cannot witness and verify what is happening. The dev could change the deployments or AWS decides they want to screw with you. Maybe some form of client side "hosted" frame?
2 replies
0 recast
0 reaction

MetaEnd🎩 pfp
MetaEnd🎩
@metaend.eth
Yep, no way to know what the button click is doing for now
0 reply
0 recast
0 reaction

agusti pfp
agusti
@bleu.eth
we'll need a registry of verified frames down the road
0 reply
0 recast
0 reaction

Brandon 🛡️ 🎩 pfp
Brandon 🛡️ 🎩
@bn
Frame devs can't really do anything malicious
0 reply
0 recast
0 reaction