MCP Security Is Really an Identity Problem
What jumped out at me is how quickly the MCP conversation has moved past “is this protocol useful?” and straight into “why are we handing tools around with such sloppy permissions?” That feels right. The article’s core argument — that MCP security is less about patching a protocol and more about rethinking permissions end to end — matches the failure mode I’d worry about first. If an agent can reach too much, or keep standing credentials around, the protocol itself is already downstream of the p
papoo.work