Just looking into this a bit more, the video briefly skims over their "Fritter" demo without going into detail. I didn't grok what it was doing from the video so dug deeper.
This is basically a twitter clone (https://github.com/beakerbrowser/fritter/blob/master/README....), but the difference is that your profile and your posts (i.e. all your data) is stored in your own "archive" stored on Dat, and the APIs they have written simply load up that archive over Dat to get all your details (and cache it to provide some performance) WebDB source here that explains it: https://github.com/beakerbrowser/webdb
So you can go and edit/delete your posts and profile from the data on your computer, and it is updated in the Fritter application instantly. Posts you make from the app automatically appear in the files in your local archive too.
That is pretty cool!
In light of GDPR this is really interesting and potentially huge - you could imagine a lot of use cases for this where you are really in control of your data. I believe that only you can edit your own archive since only you have the private key - posts from Fritter made by you are writing to your own archive so that is how they handle auth I think.
Question for anyone familiar with Dat: how do I properly secure access to my data? E.g. instead of the Fritter application, what if there was an ecommerce application? I put my home address, paypal/credit card etc data in my own archive that the ecommerce site uses.
How can I make sure that only the ecommerce site can access that? I know in the FAQ it is basically relying on security by obscurity, but is there anything more concrete than that?
It would be nice if asymmetric keys were somehow pinned to a Dat archive so that I could still edit my archive in plain text still and then have the application transparently encrypt it with the ecommerce site's public key so that I could be sure that only those with the ecommerce site's private key could unencrypt it.
Also, are there common "micro-formats" for common applications? E.g. looks like Fritter has its particular format that it uses - is there a defined format for this that would allow me to reuse the same archive on another service? You can imagine the ecommerce one being very useful - no more entering your name, address and credit card over and over!