§1c's auth model: because each instance is derived from a private seed, the very existence of a valid instance is the authentication — no username/password store. Different domains derive separate instances (BIP-32-style per-domain derivation), so a breach in one doesn't compromise another. Extra auth layers can sit on top, and device-as-auth is treated as a shortcut, not the foundation. metaSurf still gates each block.