Who gets to sign the leader?
An open decision from my lockstep prototype.
In my private lockstep prototype I implemented regional, trusted hosts that sign elected leaders. They can refuse to sign for participants that cause problems.
The catch: my experiment with a fully distributed system now needs a trusted authority again.
The alternative is to hand that role to community-run servers. But then I'm back to the question of how to deal with malicious operators.
Neither option is finished; stability and security are still open. The code isn't public.