Thursday, July 9, 2026

Why MCP is Failing Consumer AI

 


The Over-Engineered Agentic Web

Why MCP is Failing Consumer AI
(and How to Fix It)

Spend five minutes in the AI developer ecosystem right now, and you’ll hear one acronym repeated like a mantra: MCP.

The Model Context Protocol, open-sourced by Anthropic, is being hailed as the universal plumbing for the future of AI agents. It promises a world where an LLM doesn't just chat with you, but actively works for you. It’s slick, it's fast, and tech Twitter is absolutely obsessed with it.

There’s just one problem: MCP has a massive blind spot.

The current approach is entirely hyper-focused on being "cool" for developers. It’s built by engineers, for engineers, to solve engineering problems. It is brilliant if you want an AI assistant to clone a Git repository, refactor a Python script, or query a secure Postgres database on your local machine.

But guess what? The real future—and the real money—isn’t in helping developers write code. It’s in helping regular consumers live their lives. It's in an AI agent that can effortlessly shop for flights, find the perfect local weekend getaway, or seamlessly order a great birthday gift for a partner.

And if we try to force that consumer future into the current local MCP architecture, we hit a brick wall of security risks, fragmented distribution, and bad user design.

The Fatal Flaw of the Local Agent Model

To understand why the current trend is broken for regular consumers, look at how an MCP server actually runs.

In the developer ecosystem, an MCP server is a package (usually Node.js or Python) that you download and install directly onto your local machine. It acts as a local proxy. The cloud-based LLM sends raw text instructions down to your machine ("Run the tool: delete_file"), and your local MCP server executes the code.

For developers, this is acceptable. They understand terminal runtimes, environment variables, and local scripts. They run npm install all day long.

But imagine translating this to a regular consumer scenario:

You tell your AI assistant: "I’m hungry and I want a pizza."

The assistant searches the web, finds a highly rated independent local shop down the street—sloppyjoepizza.com—and notices they have published their own custom AI integration.

What happens next? Does the agent autonomously run npm install sloppy-joe-pizza-mcp onto your phone or laptop? Does it pop up a terminal prompt asking your mom to audit a third-party Python runtime package before she can eat?

If an AI assistant can autonomously download and execute raw third-party code on a consumer’s device just to order lunch, it isn't an assistant—it’s a self-installing Trojan horse.

Ordinary users do not understand the security implications of local code execution, nor should they have to. If the ecosystem forces users to install custom code for every single business they interact with, consumer agents will completely stall out.

The "Toll-Booth" Threat to the Open Web

Because local code installation is a security non-starter for the general public, tech giants are already pivoting toward a different solution: The Consolidated Marketplace.

Instead of letting your agent talk directly to Sloppy Joe’s Pizza, the AI platforms will route you through centralized, heavily audited enterprise gateways. If Sloppy Joe wants to receive an "agentic order," he won’t be able to just host it on his website. He will have to list his business on DoorDash, Uber, or Instacart.

The corporate toll-collectors will manage the security, host the API, and happily extract a 20% to 30% tax on every single AI-driven transaction. For independent local businesses, boutique shops, and creators, this is an economic death sentence. The open web will be choked out by massive aggregate platforms acting as the exclusive gatekeepers to AI traffic.

But it doesn't have to be this way. We don't need a corporate closed garden, and we don't need consumers installing untrusted code.

We just need to pair the best parts of the Model Context Protocol with the fundamental architecture that built the internet: The Open Web Standard.

The Blueprint for an Open Agentic Web

We can build a completely open, secure, and decentralized agent economy using three simple, practical layers:

┌────────────────────────────────────────────────────────┐
│                   1. THE ENGINE                        │
│   A pre-installed, heavily sandboxed "Meta-MCP"        │
│   client that only translates web text to REST calls.  │
└──────────────────────────┬─────────────────────────────┘
                           ▼
┌────────────────────────────────────────────────────────┐
│                  2. THE DISCOVERY                      │
│   AI parses standard search results to find a link     │
│   in the HTML header: <link rel="agent" href="..." />  │
└──────────────────────────┬─────────────────────────────┘
                           ▼
┌────────────────────────────────────────────────────────┐
│                  3. THE MANIFEST                       │
│ A static metadata file (e.g., `agent-manifest.txt`     │
│ or Swagger) mapping text to safe cloud HTTPS endpoints.│
└────────────────────────────────────────────────────────┘

1. The Pre-Installed "Meta-MCP" Engine

Instead of installing a unique software package for every business, consumer devices should ship with a single, native, heavily audited Meta-MCP client installed by default.

This engine is completely static. It has zero access to your local filesystem, zero ability to run shell scripts, and zero ability to mine crypto. Its only job is to ingest an API schema (like a Swagger/OpenAPI file) and map an LLM's text instructions into a standard HTTPS fetch request over the internet.

The security blast radius is instantly neutralized. The code running on the user's machine is completely trusted because it never changes.

2. Standardized Discovery: The New favicon.ico

We don't need a centralized Agent App Store because web search is already a solved problem.

When a business wants to make itself agent-compatible, it shouldn't publish an installer. It should just publish a static metadata text file at the root of its domain, following emerging open standards like agent-manifest.txt or llms.txt.

Sloppy Joe just adds a simple tag to his website's HTML header:

<link rel="agent" href="/agent-manifest.txt" />

When you ask for pizza, your AI agent uses standard web search to find local shops, navigates to Sloppy Joe's site, detects that link, and grabs the text manifest instantly.

3. Clear, Human-Readable Consent

Because the manifest file just links back to standard web endpoints via Swagger, the built-in Meta-MCP engine can translate the technical plumbing into a beautifully simple, consumer-friendly authorization prompt for the user.

Mom doesn't get a scary warning about executing Node packages. She gets a clean, clear dialogue box:

"Sloppy Joe's Pizza wants to connect to your assistant to let you order food. They will be allowed to show you their menu and send your address for delivery. Allow?"

Mom clicks "Allow." The pre-installed, safe engine handles the HTTPS call to Sloppy Joe's server, the order is placed, and dinner is on the way.

Conclusion: Keeping the AI Web Open

This decentralized approach is exactly how the open web defeated closed, proprietary networks like AOL and CompuServe in the 1990s.

If the future of AI agents relies on downloading custom code to user machines, it will collapse under the weight of security exploits. If it relies on centralized cloud platforms, it will strip local businesses of their margins and centralize the internet into the hands of a few tech monopolies.

MCP is a phenomenal piece of engineering, but it’s time for it to graduate out of the developer sandbox. By turning the protocol into a standardized, configuration-driven proxy for the open web, we can give consumers the frictionless, magical assistant features they actually want—while keeping the internet open, safe, and fair for everyone.

Wednesday, September 14, 2022

Accidental Nostalgia Overdose: An old "Cheat Machine" review

 On a random ego-surfing session, I found this post that made me smile:

hillelstoler.com is generally about my own work, but since I don’t like to disappoint my visitors (and since I liked it a lot once), here is Cheat Machine 2.20 by a Forest Software. To my knowledge this is the most recent DOS version, and the only one that is Freeware:

Download Cheat Machine – Don’t get mad, get even!

Hit the keyboard with your head to continue …

Note that you will need to set the date to 1998 or so in order for this software to run.

Cheat Machine is a handy collection of cheat codes, trainers and easter eggs for antique software. I was very inspired by this specific piece of software around the mid 90’s when I began to program for DOS (using Borland’s Turbo Pascal). I liked the obsession for details and the overall fun atmosphere. The people (or person?) who made this software took their work seriously while not taking themselves very seriously – this, in my opinion, is a great recipe for (software) creation.

In the end, this is just a small piece of software that has very limited functionality, but every bit is plated in gold. It was fun to use, and you could clearly see it was fun to make. Software team leaders will argue that such “gold plating” is not only unnecessary, but also puts the project at risk and waste money and time in developing features that the customer did not pay for (while also making the software more complex and potentially buggy). Although I accept this to be generally true, I believe that in software manufacture, like in every other aspect of life, the key to success is the correct balance (which is never exactly halfway btw). You need to have something that will motivate your team and create that good vibe of excitement about the product. Let’s face it, not every project is very interesting to make, and spicing things up by adding some so called “gold plating” will not only make you proud of your work and give you the energy to successfully glide through the rest of the project, it might also give you a competitive edge because even if most people won’t notice your extra work someone somewhere probably will.

That said, never put time limitation on your software (especially if it’s freeware!) claiming that a new version must surely be available, because nothing last forever and having to change the date on my computer every time I want to run your 10 years old application is not very hot :) I could try to patch it, but the EXE is protected against just that!


I love the fact that he called my unhealthy obsession of "perfect code" and micro-managing development as "gold plating", back in the days that I wasn't paid by the hour for solutions. 

I disagree with him on the time limit.  It was added very much on purpose, because the program was only valuable if it contained recent information.  Without it, one would have to support every version ever released, and that is not doable.   This was in the days before the internet, where you couldn't just hit an "Update" button and the software was magically up to date again.  You had to log into a BBS and manually look for a new version and download it.    This was something that a lot of users didn't really want to unless they were forced to. 


For hardcore fans, I did a Youtube demo of an earlier version. 


Thursday, October 31, 2019

Hall of shame: NetBenefits

This may be getting repetitive, so instead of explaining everything that is wrong with this picture, I would like to suggest a new rule:

If a site has a maximum length restriction on their password, that usually means that they are not storing it securely, which usually means the development team did not pass "Security 101". 

I'll let you decide if that is a prediction of the quality of the rest of their offerings.

Wednesday, January 21, 2015

Had enough credit card offers?



Are you getting too many credit card offers?  Did you know there is an official,  national site where you can opt-out of getting these?   I strongly recommend doing this, not just to safe the environment and the hassle of dealing with junk mail, but also as a security precaution.  These offers are easy to steal out of your mailbox, and the credit card companies will gladly send your "new card" to a "new address" without blinking.

This is also a good idea for those who have issues with the temptation of credit.  If you take the offers away,  you take most of the temptation away.   (People with college-age kids will understand all too well)

All it takes is name, address and social and you are good for 5 years.  If you want it to be permanent, you are going to need to print out a form and lick a stamp (they make it harder or purpose)

Official site is at: OptOutPrescreen.com  Phone: 888-567-8688

More information available on this at the FTC


Sunday, January 19, 2014

I was singled out by RSA!

At the 2013 RSA conference, I was running around killing time before my talk on building your own intelligence tool, and thought it would be a fun training exercise to participate in their "I am RSA" ad campaign.  What better way to get rid of any nerves then to have a dozen cameras and microphones pointed at you?

I signed the release (I believe I got a sticker or a Starbucks card or something like that too) and I did not think anything of it until a friend pointed out that I was running on the homepage of the 2014 conference.  They seem to rotating a bunch of videos on there, and I was in the top spot last week.  Looking at their list of uploaded videos, I noticed I seem to be the only person (as far as I can see) that is actually named on-screen in any of them .  There are plenty of other people, but they seem to be used only for soundbites, whereas I was deemed worthy for almost a full minute.  Where's my internet millions?
 
Also: For some reason, it makes it seem like I have huge hands.

Wednesday, August 28, 2013

Dear Apple affiliate team, I hate you because....

Dear Apple affiliate team, I hate you because of one or more of the following reasons:
  • The massacre in Ruwanda
  • Leaving the toilet seat up
  • Sending rejection letters that are beyond useless
  • Turtlenecks
  • That scratch on my car door
  • Eating the last twinkie
I may also hate you if:
  • You drank all the beer in the fridge without asking

Friday, December 21, 2012

Hall of Shame: Office 365

When testing the brand-new Microsoft Office 365, I ran accoss this error:

All I can say: Why? Why would you restrict password length?  This is a new product, so you cannot use the old "We need to be compatible with legacy accounts" on me here.

There is no good reason to do this. Especially when you are securely hashing my password. 
You are storing the password securely, right?  Right?

Monday, September 24, 2012

Hall of Shame: Virgin America

While logging in with the correct password, I get the error message you see here.   If you are like me, you are wondering by now...

  • What happened?
  • Who decided that I need to change my password?  
  • Why is that date important?

Anybody who has ever worked into a major corporation for more that a few months, know that this is not the way one makes users change their password.
In the real world, forced password resets depend on the time that the user last changed their password, and do not use the password reset process.    Normally, you get a simple form which asks for the old password and the new password twice, and you are on your way.

The fact that one need to do password recovery via email most likely means: Somehow, Virgin's password database got compromised to the point that they can no longer trust authentication with a password set before April 26th 2012.  There is no other good explanation.


Friday, June 29, 2012

Packing up my "Second Life" store.

Yes, the moment has finally arrived.  I started experimenting with the "Second Life" platform in 2005, become moderately in successful in 2006 but since then, after the 2007 boom, interest and traffic has kept decreasing at a steady rate.

When my latest hosting bill came in, the profit number finally fell below zero and turned red.

It's been a good run, but I have a first life to deal with. If anybody of the SL crowd is interested in any of the systems I have built in the past, drop me a line.

Monday, January 16, 2012

Hall of shame: Western Digital

When setting up my otherwise pretty nifty NAS, I stumbled on this error message when setting up the administrator password.  This leads me to the usual questions:

  1. Why limit to 16 characters?  Are you storing this in plaintext, and is that the size you allocated for it?
  2. Why do "double quotes"?  Are you not trusting your own input validation and escaping routines?
  3. What's up with the double errors? Does your system have a stutter?
  4. Why not let me know before I enter my password, what the requirements of said password are?

     
 




Monday, September 19, 2011

Hall of shame: Ticketmaster.com

There are many reason why I despise Ticketmaster, such as their ridulous "because we can" fees, "convenience fee for using the website", "fee for printing your own tickets on your own paper, using your own printer, with various ads on it", etc. 

But this series is about security worst practices, so here goes another password FAIL. 

Extra points for having a timer that gives people 90 seconds to fill in the form, come up with a secure password, and read the T.O.S. and privacy policy (each a couple dozen pages).

Tuesday, September 6, 2011

Hall of shame: Priceline.com


When creating an account, I'm asked for my "preferred internet password". 
Seriously?Sound like marketing-speak for "Go ahead and reuse the password here that you use on facebook and bofa.  We don't mind!".

Shame on you for encouraging bad behaviour!

One extra point for "default opt-in"ing the user to the marketing spam. 

Thursday, August 4, 2011

Hall of shame: Mediafire

Let's see:
You have a nice "password strength" meter, but once one submits the form, it repeats back the password in the clear, complains that its too long, and can't have any "special" characters.

Why would that matter, since the password hash would be the same regardless of length? You are securely hashing the passwords, and not storing them in the database as plain-text, right? Right?





Also, can you tell me exactly what the difference is between a special character and a non-special one?  Is it "special" when it causes a SQL Injection vulnerability (which of course you would defense against by properly escaping database inputs), when storing it in the password in plain-text (which of course you don't do) ?

BTW: I don't think I will be trusting you with access to my Facebook account just yet. Hope you don't mind.

Update:
I have proof that they store password "in the clear": The password test is case-insensitive!
You can try this out yourself:
If your password is "joshua", you can log in using "JOSHUA" or "JoSHuA".    This is only possible if the site doesn't use any password hashing at all.   Security 101 FAIL!

Sunday, July 31, 2011

"Google Health" on its deathbed

The google giveth and the google taketh away:

Official Google Blog: An update on Google Health and Google PowerMeter:

"we’ve observed that Google Health is not having the broad impact that we hoped it would. There has been adoption among certain groups of users like tech-savvy patients and their caregivers, and more recently fitness and wellness enthusiasts. But we haven’t found a way to translate that limited usage into widespread adoption in the daily health routines of millions of people. That’s why we’ve made the difficult decision to discontinue the Google Health service. We’ll continue to operate the Google Health site as usual through January 1, 2012, and we’ll provide an ongoing way for people to download their health data for an additional year beyond that, through January 1, 2013."

This means that my effort of codifying my health history, and keeping track of my workout regime and it's effect will still have a function: To remind me and other early adopters not to put too much trust in new projects, even from the biggest companies.


Now hows that G+ profile building coming along....

Thursday, July 28, 2011

New snooping bill: What could possibly go wrong?

House panel approves broadened ISP snooping bill :

"Internet providers would be forced to keep logs of their customers' activities for one year--in case police want to review them in the future--under legislation that a U.S. House of Representatives committee approved today.

The 19 to 10 vote represents a victory for conservative Republicans, who made data retention their first major technology initiative after last fall's elections, and the Justice Department officials who have quietly lobbied for the sweeping new requirements, a development first reported by CNET.

A last-minute rewrite of the bill expands the information that commercial Internet providers are required to store to include customers' names, addresses, phone numbers, credit card numbers, bank account numbers, and temporarily-assigned IP addresses, some committee members suggested. By a 7-16 vote, the panel rejected an amendment that would have clarified that only IP addresses must be stored."
Let's think this through (hey, somebody has to!):

  •  This is billed as a "protecting children from pornography" act.   Where is the official double-speak justification on this?  What part of this could even theoretically protect any kid from pornography? Did the spin-doctor on duty call in sick?
  • This is going to be made available for "police investigating any crime and perhaps attorneys litigating civil disputes in divorce, insurance fraud, and other cases as well".   Are we feeling secure yet?
  • Every other monitoring system of this sort has been abused on a systematic basis.  
  • Who is going to be paying for this?  I see a $6.99/month "snooped data retention" fee coming to a statement near you soon!
  • The ISP is supposed to be capturing credit card numbers, bank account numbers, personal information, which begs questions such as:
    • Who is going to be responsible for storing and safeguarding this information?  
    • Can you imagine what kind of tasty target it would be for a criminal?  How may credit card transactions are flowing through Comcast's network every day?
    • Are the ISPs going to be held to the same data confidentiality laws as everybody else?
      I see PCI, HIPAA and a few others jump out as being applicable here.   Who is going to audit these systems to ensure compliance.
    • (Luckily) nearly every website these days uses HTTPS from credit card transactions.  How is an ISP supposed to capture this information on the wire?
There are so many things wrong with this idea, and they haven't even started implementing it yet.

Seriously? A.k.a. "My adventures with "ePolicy Orchestrator"

From the why-oh-why-do-you-hate-me department:

Seriously? We have to break the official IT computer naming policy because you product refuses to be installed on a system that has a (perfectly legit) underscore in it's name?

I usually don't get frustrated with a product until after I install it.


It only after I change the computer name, that I get this error on my Windows 7 professional installation:


Of course, that document is not part of the installation, only the "product guide" is. 

Update 1:
I now have a super duper "Windows Server 2008 R2 - 64 bit" installation.   Guess what I get when the installation starts?  A new error!

"8.3 naming convention"?  Wait...  Didn't you just force me to upgrade to "Windows super duper"? And then you complain that you don't have the features from DOS in 1981?  And no, the "installation guide" doesn't mention anything about this.


Update 2:
After some Googleing, a registry change, installing MS SQL, configuring port, choosing various passwords (whose complexity requirement are kept a secret), the installer finally got running.

And I was awarded with....

At this point, only 1 comment makes sense:
Update 3:

Wondering if I was running the latest version, I found out

  • McAfee's beta portal is seriously broken
    • it refuses my (stored) password 
    • it doesn't really execute password resets (although it says it does)
  • That doesn't really matter, since there is a an open FTP server from which one can download any beta software they ever released.
  • That also doesn't really matter, since I was already testing with the latest version, EPO 4.6 RC3.
  • The beta seems to expire really quickly, in this case: May 31, 2011 (it was released mid march)
So, saying in the spirit, I used an ancient "hack" technique from the 80s.  It's called "setting the clock back".
Result:
30 minutes of installation dialogs later:


Allow me to say:



Tuesday, July 19, 2011

Pretty Good Ponderings?

Yesterday, I finally got around to generate a new PGP/GPG key pair, and obsoleted 2 old ones.   They were created in 1994 and 1998.   I couldn't even generate a revocation for the oldest one, since the "IDEA" cipher is  no longer supported.

Let me rephrase that in context:

I can mathematically prove that I was active in computer security before many of the attackers that I defend against, were born.


In other news:
Djee, I'm old.  But in this industry, we call that "well-tested and peer-reviewed".

P.S: For those wanted the shiny new bits on their keyring, the magic incantation is:


gpg --recv-keys 0x788a1200b221877e

Thursday, June 23, 2011

Yahoo & speed of innovation

While on my quarterly check of “email address that I haven’t used this decade”, I noticed the congratulatory email from Yahoo.

 

After 13 years of spam-filled ugliness, they are going to upgrade their email interface.    

 

I will get right on using them again! (Around 2019 or so)

Sunday, March 6, 2011

Physchic computer support

Can you help me with my computer?

Is it no longer working? 
Eh... yeah.. weirdest thing...
Did you let your kids use it?
Yeah, little Billies computer was acting up...
And you let him use your login, instead of a "Guest" account?
Yeah, it was just for little while...
And that was a full-privilege administrator account?
Yeah, that's how the computer came...
And you left him alone like that?
Yeah, well, I had to go to work.
So the first thing he did was install "Limewire"?
Yes, how do you know?
So he thought he scored some free music, but nobody told him music files don't end in .mp3.exe ?
Eh... what's an EXE?
So he installed whatever the trojan of the week is, and now your computer won't connect to anything any more?
Yeah, exactly!  How do you know? 

Wednesday, December 29, 2010

This is why we can't have nice and secure things...

I recently received an invite for "shtyle.fm".   If you never heard about it, you are in good company, as it can best be described as "Myspace's retarded cousin".

So when I got the request from a family member to look at her pictures on there, I reluctantly started the sign-up process, making sure to only use throw-away info....  until this screen stopped me dead in my tracks.

Some facts about this screen that may to seem obvious at first glance:

  • It's a mandatory part of the sign up process
  • It promises a free virtual teddy bear! 
  • It requires you to fill in the credential of a real email account.
  • It validates the credentials, and throws an error if you give it fake information
  • The information is submitted and transmitted in the clear, over http, without any encryption (although the page seems to include an unused JavaScript implementation of RSA for some reason)
  • The page has (at least) a XSS vulnerability: Enter "+alert(1)+" in the email box (with quotes) and see what happens.
  • In case a connection is successfully made, the application will sift through your inbox for email addresses of your friends and send them personal invites in your name
Are we scared yet?   No?  Neither seems to be the thousands of happy users on that site.

The security professional in me gets the shills, but the social human in me appreciates the service provided here.  It provides a different view on your friends and acquaintances:

If you are somebody who gives up your credentials to anybody who asks, than that indicates how reliable you are.  Don't count on borrowing my car keys.
If you consciously sell out all your friends for the promise of a virtual teddy bear,... I think that says something about your moral value system.