Question for the #security people, and apologies if I am using the wrong terms: let's say that we want to "liberate" a service that started charging outrageous prices for their API, but that API is mostly public data. Assume a large number of downloaders who do not (necessarily) trust each other but are willing to share any data they can verify to be legitimate.
Shouldn't there be a way via HTTPS to prove that any given response was generated by the server?