One set of technologies that might get us closer, though, is allowing offline signing of websites. This would mean you could trust the public key for a webapp once, and then run that webapp from any domain that serves it correctly. Any data sent or received by users of the webapp (like comments or likes or bids, etc.) would have to be signed by the keys of individual users, meaning a malicious server could only filter messages you send and receive, but not spoof them. For persistence of data across sessions, and synchronisation between the mirrors, the back-end data store could be a web-API database accessed over Tor by the servers hosting these mirrors of the web app.