The Rights and Responsibilities of the Cypherpunkist

My illustration entitled: “The Cypherpunkist’s Shield and Key” – Herbert carries a luminous shield protecting individual rights while holding a cryptographic key that must be used responsibly. The shield displays privacy, free expression and self-sovereignty; the key projects secure tools for citizens while refusing access to harmful systems.


Cypherpunkism begins with the conviction that individuals should possess meaningful authority over their digital lives. Privacy, cryptography, decentralization, open knowledge and individual control are not merely technical preferences. They are instruments through which human freedom can be preserved in a society increasingly governed by networks, databases and software.

Yet a philosophy of sovereignty cannot speak only about rights.

The power to communicate privately, control cryptographic keys, publish information and build systems independent of centralized authority also creates obligations. Privacy can protect the vulnerable, but it can also conceal misconduct. Anonymity can defend dissent, but it can also be used to avoid responsibility. Decentralization can restrain institutional power, but it can also make harmful activity more difficult to correct.

Cypherpunkism must confront these tensions directly.

A Cypherpunkist is not someone who believes that every restriction is tyranny, every institution is illegitimate or every technically possible action is morally justified. A Cypherpunkist defends the individual against unnecessary technological domination while recognizing that every individual lives among others who possess the same claim to sovereignty.

The governing principle is therefore:

Digital Sovereignty grants the individual authority over himself, not unrestricted authority over other people.


From Technological Power to Moral Responsibility

The historical Cypherpunks understood that code could alter the balance of power between individuals and institutions. Strong cryptography could protect communication. Anonymous systems could make identification more difficult. Peer-to-peer networks could reduce dependence upon central intermediaries. Open-source software could allow technical rules to be inspected and modified.

These developments expanded what individuals could do without institutional permission. That expansion was politically important because freedom that depends entirely upon the approval of a powerful intermediary remains fragile.

But a capability is not automatically a justification.

The ability to obtain private information does not create a right to publish it. The ability to act anonymously does not make fraud legitimate. The ability to preserve information permanently does not remove another person’s interest in privacy. The possession of a cryptographic key does not excuse actions authorized with that key.

Technology changes what is possible. Ethics determines what should be done with that possibility.

Cypherpunkism therefore joins technological freedom with personal responsibility. It resists unnecessary authority from above while demanding restraint from every person who acquires power through code.


The Rights of the Cypherpunkist

The rights of the Cypherpunkist are not privileges reserved for programmers, cryptographers or political activists. They express rights that should belong to every person participating in digital civilization.

1. The Right to Privacy

Every individual should possess the ability to establish meaningful boundaries around personal information, communication, identity and association.

Privacy is not merely secrecy. It is the capacity to determine which parts of oneself are revealed, to whom they are revealed and under what conditions. A person does not surrender this claim merely because communication occurs through a computer, activity creates metadata or participation requires interaction with an institution.

Governments and companies may possess legitimate reasons to collect particular information. But collection should be necessary, proportionate and directed toward a defined purpose. The existence of technical capacity does not create an unlimited entitlement to observe.

As established in “Privacy Is Sovereignty,” privacy protects the boundary within which individual judgment, association and development can occur without continuous external supervision.

2. The Right to Use Strong Cryptography

Individuals should be free to use strong encryption to protect lawful communications, information and digital possessions.

Cryptography gives practical force to privacy. It transforms a request not to access information into a technical boundary against unauthorized access. It protects ordinary users from criminals, commercial exploitation, intrusive surveillance and the consequences of insecure databases.

This right should not depend upon whether a person can prove an immediate need for secrecy. Envelopes are not reserved for criminals, locks are not evidence of wrongdoing and encryption should not create a presumption of guilt.

The United Nations Special Rapporteur on freedom of expression recognized in 2015 that encryption and anonymity enable people to exercise privacy and freedom of expression in the digital age. Restrictions upon these technologies must therefore satisfy the principles of legality, necessity, proportionality and legitimate purpose.

A vulnerability deliberately created for one authority does not remain available only to that authority. Weakening security for everyone in order to gain access to particular communications may expose entire populations to abuse. Targeted investigation should not become a justification for universal insecurity.

3. The Right to Control Personal Keys and Credentials

Where practical, individuals should be able to control the cryptographic keys and credentials that authorize access to their information, communications and digital possessions.

An account controlled entirely by another institution provides conditional access, not complete digital authority. The institution may change its policies, suspend access, disclose records or cease operating. Control of the relevant key gives the individual a more direct form of technological authority.

Not every user will choose self-custody, and many will require assistance securing complicated credentials. Cypherpunkism does not demand one model for every person. It demands that convenience should not eliminate the possibility of meaningful individual control.

4. The Right to Communicate Anonymously or Pseudonymously

People should not be required to attach their complete legal identity to every expression, association or ordinary act of communication.

Anonymity and pseudonymity can protect whistleblowers, journalists, political dissidents, minority groups, victims of abuse and people discussing sensitive personal matters. They also preserve the freedom to explore ideas without every thought becoming a permanent component of one public identity.

This right does not mean that identity can never be required. Certain contracts, regulated activities, judicial proceedings and relationships of trust may legitimately depend upon identification. The principle is that identification should correspond to a genuine need rather than becoming the automatic price of digital participation.

5. The Right to Open Knowledge

Individuals should be able to study, discuss and understand the technologies governing their lives.

Cryptography, network architecture and computer security should not remain the exclusive knowledge of governments, corporations or a narrow technical elite. A society cannot be digitally sovereign when most of its members are prohibited from understanding the systems upon which they depend.

This includes the freedom to publish legitimate research, examine protocols, inspect open-source code and teach others how technological systems work. Security based entirely upon public ignorance is fragile. Genuine security should survive informed examination.

6. The Right to Build

The Cypherpunkist should be free to create and distribute lawful privacy-enhancing, cryptographic, peer-to-peer and decentralized technologies.

Freedom cannot depend entirely upon tools supplied by the same authorities whose power those tools may need to constrain. If communication is insecure, people must be free to develop encryption. If a platform imposes unnecessary surveillance, people must be free to construct an alternative. If an essential network contains a single point of failure, people must be free to experiment with distributed architecture.

The freedom to build also includes the freedom to fork, modify and independently implement open systems where their licences permit it. Without the possibility of alternatives, criticism leaves the underlying structure of power unchanged.

7. The Right to Transparency, Due Process and Challenge

When a technological system makes consequential decisions about identity, access, speech or property, the affected person should possess a meaningful ability to understand and challenge those decisions.

Secret rules, unexplained exclusions and irreversible automated judgments create authority without accountability. A user should know when access has been restricted, which rule was applied and whether an error can be corrected, except where limited confidentiality is genuinely necessary to protect an investigation or another person.

Technological efficiency must not eliminate due process. The speed with which software can impose a decision makes safeguards more important, not less.

8. The Right to Portability and Exit

Individuals should be able to retrieve their information and leave a digital system without abandoning everything accumulated within it.

Consent is weakened when departure means losing identity, communications, relationships, records, reputation or digital possessions. Interoperability, usable export formats and independent alternatives strengthen the individual’s ability to refuse unacceptable changes.

A person who cannot realistically leave remains subject to the operator even when participation is described as voluntary.


The Responsibilities of the Cypherpunkist

Rights protect the individual against domination. Responsibilities prevent the individual from becoming a source of domination over others.

1. Respect the Privacy of Others

A Cypherpunkist who demands privacy for himself must recognize the same boundary around other people.

Private messages should not be exposed casually. Personal photographs, identifying records, medical information and confidential conversations should not be published merely because someone has obtained technical access to them.

Information about one person often contains information about others. A contact list reveals relationships. A photograph may identify bystanders. A genetic record may reveal facts about relatives. Protecting personal data therefore includes considering the people indirectly represented within it.

Privacy cannot become a one-directional demand in which the individual conceals himself while treating everyone else as an open database.

2. Protect Entrusted Information

When another person entrusts information to us, we acquire a duty of care.

This means using appropriate security, limiting unnecessary copies, controlling access and deleting information when its legitimate purpose has ended. It also means resisting the temptation to collect data merely because storage is inexpensive or future analysis may make it valuable.

Data minimization is not only an institutional responsibility. Individuals, developers and community administrators should avoid building archives of other people’s lives without necessity.

3. Secure the Keys Under Your Control

Control of a cryptographic key creates both authority and responsibility.

A person who chooses self-custody must take reasonable measures to protect important credentials, preserve necessary backups and avoid exposing others who depend upon those credentials. A developer or administrator entrusted with user keys bears an even greater obligation because one failure may affect an entire community.

Cryptographic control should not be romanticized as effortless independence. Losing a key, exposing a key or signing an action without understanding it can produce serious consequences. Sovereignty requires competence, preparation and care.

4. Distinguish Privacy from Impunity

Privacy protects the person from unnecessary observation. Impunity exempts a person from responsibility for harm. They are not the same.

A private communication remains subject to moral responsibility. An anonymous act can still be fraudulent, coercive or destructive. Encryption does not transform theft into ownership, deception into consent or harassment into legitimate expression.

The Cypherpunkist may defend a person’s right to use encryption without defending everything that person might do with it. The legitimacy of a tool and the legitimacy of an action performed through that tool are separate questions.

5. Reject Fraud, Coercion and Unauthorized Intrusion

The ability to enter a system does not establish a right to enter it. The ability to manipulate a protocol does not justify deceiving its participants. The ability to conceal one’s identity does not justify impersonating another person.

Cypherpunkism defends freedom from centralized domination; it does not authorize individuals to dominate through fraud, threats, malicious software or unauthorized control over another person’s devices and information.

Freedom to build must remain compatible with the freedom and security of those affected by what is built.

6. Build for Security and Privacy

Developers who understand digital risks have a responsibility not to impose avoidable insecurity upon users who may not recognize those risks.

Privacy should be considered during design rather than added after extensive collection has already occurred. Sensitive data should be minimized. Security claims should be honest. Known limitations should be disclosed responsibly. Systems should not present central custody as self-sovereignty or describe nominal distribution as meaningful decentralization.

A tool that promises liberation while exposing its users to foreseeable harm has failed both technically and ethically.

7. Make Knowledge Understandable

Open knowledge is weakened when information is technically available but practically inaccessible.

Those with expertise should explain important risks in language ordinary users can understand. Interfaces should communicate the consequences of decisions. Documentation should identify what a system collects, who controls it and what happens if credentials are lost.

Expertise should expand the agency of others rather than becoming another instrument of dependency.

8. Accept Responsibility for Consequences

The Cypherpunk tradition emphasizes building rather than waiting for permission. That creative independence does not remove responsibility for foreseeable consequences.

Builders should consider how a technology may be abused, who may be placed at risk and whether authority has merely been transferred from a visible institution to an invisible group of developers, administrators or technically powerful participants.

Not every harmful use can be predicted or prevented. A builder cannot be held morally responsible for every action performed with a general-purpose tool. But neither should technological neutrality become an excuse to ignore obvious dangers created by design choices.

Freedom to build includes the responsibility to think seriously about what is being built.


Privacy and Legitimate Investigation

The most difficult conflict concerns the relationship between privacy and investigation.

Societies possess legitimate interests in investigating violence, fraud, exploitation and other serious harms. Victims have rights as well. A philosophy concerned only with the privacy of the accused, while ignoring the liberty and safety of those harmed, would be incomplete.

But the existence of crime does not justify treating every person as a permanent suspect. Universal monitoring, indiscriminate retention and deliberately weakened encryption impose costs upon entire populations. They create infrastructures of power that may be redirected toward political opponents, journalists, minorities or ordinary citizens.

The proper distinction is between targeted accountability and generalized surveillance.

Legitimate investigative power should be established by clear law, directed toward a defined purpose, necessary to that purpose, proportionate to the suspected harm, limited in scope and duration, and subject to independent authorization and meaningful review.

Cypherpunkism does not require the elimination of investigation. It requires that exceptional access to particular information should not become unrestricted access to everyone’s digital life.


Anonymity and Accountability

Anonymity is often criticized because an anonymous person may evade reputational or legal consequences. That risk is real, but compulsory identification creates its own dangers.

When every opinion is permanently attached to a legal identity, people living under political repression may be unable to speak. Victims may be unable to seek help. Employees may be unable to expose misconduct. Individuals may be unable to explore unpopular beliefs without fear that one statement will follow them indefinitely.

Accountability does not always require universal identification. Communities can establish rules, moderation systems, reputational mechanisms and proofs of membership without demanding that every participant reveal a complete civil identity to every other participant.

Different contexts require different degrees of identification. A public discussion, private purchase, medical consultation and binding financial contract do not create identical needs.

The Cypherpunkist principle should be:

Require only the identity necessary for the relationship, and do not convert limited identification into universal visibility.


My illustration “The Cypherpunkist’s Shield and Key” – work-in-progress. The art represents: Cypherpunkists must defend freedom while exercising technological power carefully.


The Responsibilities of Institutions

Responsibility does not belong only to individuals. Governments and corporations possess greater resources, wider access and the ability to affect entire populations. Their responsibilities increase with their power.

Governments should protect lawful access to encryption and should not normalize indiscriminate surveillance. Investigatory powers should remain constrained by legality, necessity, proportionality, oversight and due process.

Companies should collect only information genuinely required for their services, secure what they retain, explain their practices honestly and resist unnecessary demands that would compromise every user. They should not treat personal information as ownerless material merely because technology makes it observable.

Developers should design systems in which privacy and security are normal conditions rather than privileges available only to expert users. Administrators should not possess more access than their responsibilities require. Institutions controlling essential platforms should provide meaningful methods of appeal, correction and exit.

The concentration of power creates a concentration of responsibility.


A Declaration of Cypherpunkist Rights

I possess the right to establish boundaries around my digital life.

I possess the right to protect lawful communications through strong cryptography.

I possess the right to communicate anonymously or pseudonymously where complete identification is unnecessary.

I possess the right to control my personal information, credentials and cryptographic keys where practical.

I possess the right to study, create, publish and use legitimate privacy-enhancing and decentralized technologies.

I possess the right to understand and challenge systems that make consequential decisions about my identity, access and digital possessions.

I possess the right to retrieve my information and leave a technological system without unnecessary obstruction.

I possess the right to participate in digital civilization without surrendering the whole of myself to the institutions operating it.


A Declaration of Cypherpunkist Responsibilities

I shall recognize in others the same sovereignty I claim for myself.

I shall respect the privacy of others and protect information entrusted to me.

I shall secure important keys and credentials under my control.

I shall distinguish privacy from impunity and anonymity from freedom to harm.

I shall reject fraud, coercion, unauthorized intrusion and the exploitation of those with less technical knowledge.

I shall seek to build systems that minimize unnecessary collection, surveillance and concentrated power.

I shall communicate technological risks honestly and make knowledge more accessible where possible.

I shall remain accountable for the choices I make and the actions I authorize.


Sovereignty Requires Responsibility

Digital Sovereignty does not place the individual beyond morality, law or society. It establishes that the individual should retain meaningful authority within them.

The sovereign individual remains responsible because other people are sovereign too. Their privacy matters. Their property matters. Their consent matters. Their security matters. Their freedom from coercion matters.

Cypherpunkism therefore rejects two opposing forms of absolutism.

It rejects institutional absolutism: the belief that governments or corporations should possess unrestricted authority over digital identity, information, communication and participation.

It also rejects individual absolutism: the belief that possession of technical power releases the individual from every obligation toward others.

A free digital civilization requires a more demanding principle. Institutions must exercise restraint, and individuals must exercise responsibility. Systems must limit unnecessary power, and users must respect the sovereignty of those around them.

Rights without responsibility can become domination.

Responsibility without rights can become submission.

Cypherpunkism requires both.

Protect your privacy.

Respect the privacy of others.

Control your keys.

Accept responsibility for what they authorize.

Challenge concentrated power.

Do not recreate that power over someone else.

Digital Sovereignty belongs to the individual.

And every sovereign individual remains responsible for how freedom is used.


References and Foundational Influences

  1. United Nations. Universal Declaration of Human Rights. Articles 12, 19 and 29, 1948.
  2. United Nations. International Covenant on Civil and Political Rights. Articles 17 and 19, adopted December 16, 1966.
  3. Stallman, Richard. The GNU Manifesto. 1985.
  4. Hughes, Eric. A Cypherpunk’s Manifesto. March 9, 1993.
  5. Lessig, Lawrence. Code and Other Laws of Cyberspace. Basic Books, 1999.
  6. United Nations. Guiding Principles on Business and Human Rights. 2011.
  7. Cooper, Alissa, Hannes Tschofenig, Bernard Aboba, Jon Peterson, John Morris, Marit Hansen and Rhoda Smith. “Privacy Considerations for Internet Protocols.” RFC 6973, July 2013.
  8. International Principles on the Application of Human Rights to Communications Surveillance. Necessary and Proportionate Principles. 2013.
  9. Kaye, David. “Report on Encryption, Anonymity and the Human Rights Framework.” United Nations Human Rights Council, A/HRC/29/32, May 22, 2015.
  10. Sim, Herbert R. “Cypherpunkism: A Philosophy of Digital Sovereignty.” October 10, 2010.
  11. Sim, Herbert R. “The Cypherpunkist Manifesto.” November 22, 2010.
  12. Sim, Herbert R. “Digital Sovereignty: A Formal Definition.” December 10, 2013.
  13. Sim, Herbert R. “The Architecture of Power: A Cypherpunkist Theory of Technology.” June 22, 2015.
  14. Sim, Herbert R. “Decentralization Is a Check on Power.” October 26, 2015.