







I'm seeing a lot of different people, coming from different angles, recognize that the Same-Origin Policy is insufficient for the kind of apps that we want to make now, and that we need something more fine-grained and more secure. Very interesting times!
Sep 1, 2025 at 5:11 PM
Evolving AltStore PAL
In April of last year, we launched AltStore PAL in the European Union as one of the first official alternative app marketplaces on iOS thanks to the Digital Markets Act. We launched with just 2 apps — my Nintendo emulator Delta and clipboard manager Clip — yet Apple immediately changed their App Store rules to allow emulators worldwide for the first time ever.
Alex Moore on Open Web Advocacy and Why "Innovation Doesn't Come from the Gatekeepers"
A new layer of security for certified Android devices
Starting in 2026 and in select countries first, Android apps must be registered to a verified developer in order to be installed.

Cross-Border Collaboration For Ip Protection.
Cross-Border Collaboration for IP ProtectionCross-border collaboration in IP protection occurs when multiple countries, corporations, or ins...

Origin Trials
Chrome origin trials allow developers to safely experiment with web platform features
It’s Official, Apple Kills Web Apps in the EU - Open Web Advocacy
If you ship a Web App in the EU and will be impacted by this, please sign our open letter to Tim Cook. It is critical that we gather as much evidence as possible to prevent Apple from breaking Web Apps in the EU.

The EU’s age verification app has a privacy problem — and it may be more than just a 'bug in an app'
It's an improvement compared to existing solutions, but security experts still aren't convinced

SLAP and FLOP: Apple's Lack of Full Site Isolation and iOS Browser Ban Puts Users at Risk - Open Web Advocacy
TL:DR; Yet again Apple’s ban on third-party browser engines weakens security rather than strengthens it.

A BlueSky thread by GrapheneOS on Skyview
We strongly oppose the Unified Attestation initiative and call for app developers supporting privacy, security and freedom on mobile to avoid it. Companies selling phones should not be deciding which operating systems people are allowed to use for apps. uattest.net
Claude is inheriting a centralized app-centric bias here (which existing OAuth profiles may share) To wind up in a decentralized world where all "my data" lives on "my PDS" -- regardless of how many atproto apps I authorize to store stuff there for me (see 🧵) -- we should invert that paradigm
Paul Rohr
TL/DR = yes, it's a subtle conceptual shift: - from app-centric (apps control identity/data, delegating access to you at signin) - to identity-centric (you control identity/data, delegating access to apps at signin) Really looking forward to how the team evolves the OAuth UX to address this! /END
Not even low-key, Access-Control-Allow-Origin: '*' everywhere is one of the best things that atproto has done. (I'm reasonably excited about this, in part because I've been waiting since shortly after it was proposed and first implemented. Here's a moan from 2010: x.com/blaine/status/13206867161?s=2…)
3) it still doesn't fully cover all use cases well or at all 4) bsky.app still didn't manage to implement OAuth at all Yes, we should all be moving to OAuth w/ scopes, that's the goal, but give people some slack, it's all still rather fresh, we'll get there… (yes, it's me, I'm those people)
The same-origin paradigm has unfortunately become a local maxima of the web. I'd argue the capture of the internet's search, social spaces, and data lock-in, as well as the lack of open protocols counter this capture can be directly attributed to building on top of the same-origin paradigm.
𝕮
Thinking about atproto as an identity and data *substrate* of the web. RSS couldn't go all the way because it built within the boundaries of the same-origin paradigm, just like the closed platforms that ended up enclosing most of the web.