We are aware that proper security and authentication are core problems to solve for the idea to scale. However, it is also an open (research) question how to do this properly.
Currently we have per-webstrate access right, which means that if you give someone permission to write in one of your webstrates they can do anything with it, e.g. empty its body. It could be interesting if it would be possible to specify what operations you would permit from someone to a webstrate, e.g. "you can only add to this particular unordered list, and the added element must have following form".
Good ideas are welcome.