@kaniini There will always be a trust assertion indeed.
But it's important to recognize where the trust assertion shifts with ocaps; the identity of the peer within the *ocap component* is not checked at the time of receipt. However, through allowing for revocation and accountability, we have a mechanism that composes with the ocap stuff to reason about identity (but we do not make a "value judgement" in the ocap infrastructure, we leave tools so our users can do that)