Not only do you need to obtain access to the server, you also need the private key of its operator. (Which should be kept offline for signing.) If they don't surrender the key, then you cannot compromise their visitors.
This can also be a mitigation for drive-by malware exploits and whatnot.
(I emailed this to LiberationTech last year, no one took any interest in the idea.)
The most secure way right now is to isloate your Tor browsing activities to a virtual machine which is only able to access the internet via Tor.
Create a VM to act as a middle node with 2 NICs, the first of which will connect to the internet and the second of which will connect to the other VM. Disable any unnecessary services, expose only Tor's proxy to the second NIC.
Create the other VM with 1 NIC in the virtual network with the Second NIC on the other VM.
This enforces Tor-only access for the second VM. Any activity must go over Tor or it may not access the internet.
Snapshot the VMs. Always restore the snapshots when beginning a new session.
Setting this up takes some time, but nearly guarantees an exploit cannot escape.
I also recommend disabling unnecessary services which may expose the host to attack (ie: file sharing and video and mouse acceleration) through the second VM. It may be more secure to use a low-level emulation (QEmu, VirtualBox or VMWare with hardware acceleration disabled) rather than a hypervisor-based VM solution for this.
If TOR and Namecoin hooked up, Namecoin could provide a list of page hashes for a given onion address. Better still, interrogate Namecoin's DNS system into TOR and then make Hidden Services accessible via human readable domain names.
Why?
I had assumed that everyone would be either on the 'net with their 'net computer or on tor with their tor computer.
Doing both with one computer obviously defeats the purpose, doesn't it?
...Also, the chances of breaking out of a VM into the host are non-zero. Just sayin'.
My draft specified TOFU; if a site was previously signed and no signature is attached, don't allow any JS. If the signature doesn't match the key cached in the browser, go full noscript.
Might need to disable inline JavaScript, though. And double-check that meta tags are only meaningful when located in their proper place in the head tag.
I don't like the HTTP header idea, 'cause it precludes static content unless you modify the web server. And I don't like external files which are automatically read by the browser because then you run into namespace problems. Keeping everything in the HTML document provides tidy isolation.
Or am I missing something?