
My illustration entitled: “The Cypherpunkist’s Litmus Test” – I place different technologies—AI, digital currency, social platforms, biometrics and brain–computer interfaces—into a luminous testing apparatus. Each emerges marked either EMPOWERS THE INDIVIDUAL or CONCENTRATES POWER.
Eight years ago today, I formalized Cypherpunkism as a philosophy of Digital Sovereignty: the principle that technological progress should strengthen the authority of the individual rather than create irreversible concentrations of power over him.
Since then, digital technology has become more intimate, comprehensive and indispensable. Smartphones accompany us throughout the day. Social platforms organize relationships and public speech. Cloud services store personal and professional histories. Algorithms classify behaviour. Connected devices collect information from homes, bodies and physical environments.
Most technologies are introduced through the language of utility. They promise speed, convenience, personalization, security or efficiency. These benefits may be genuine, but they do not reveal the complete nature of the system.
A technology can be useful while concentrating extraordinary authority. It can be free of charge while extracting personal information. It can be decentralized in name while depending upon a handful of administrators, developers or gateways. It can offer privacy settings while retaining the power to observe, profile and exclude its users.
The proper question is therefore not simply:
What can the technology do?
We must also ask:
Who does the technology empower?
This is the Cypherpunkist Test.
A Test of Power, Not Branding
The Cypherpunkist Test does not judge a technology by the political language surrounding it. Terms such as open, decentralized, private, secure and user-controlled are claims to be examined, not conclusions to be accepted.
A system may publish source code while concentrating control over its servers. It may use cryptography while keeping every user’s keys. It may distribute a ledger while directing most participation through centralized gateways. It may offer an export button while providing data that cannot be used anywhere else.
The test concerns actual capabilities and dependencies.
Who can read the information? Who holds the keys? Who grants permission? Who can change the rules? Who can revoke access? Can consent be withdrawn? Can the individual leave without losing his identity, records, relationships and possessions?
The answers reveal the system’s real constitution.
The First Question: Who Is the Principal Beneficiary?
Every technology should begin with a clear account of whose interests it is designed to serve.
A service may benefit its users while also benefiting advertisers, investors, governments, developers or commercial partners. Multiple beneficiaries are not inherently illegitimate. The problem arises when the interests of the user are invoked publicly while the architecture is designed primarily to increase the power of someone else.
A platform may claim to connect people while engineering greater dependence upon itself. A security system may claim to protect users while increasing institutional surveillance. A personalized service may improve recommendations while constructing a detailed behavioural profile that the individual cannot inspect or control.
The first part of the test therefore asks:
- Who receives the principal benefit?
- Who assumes the principal risk?
- Who gains new knowledge or authority?
- Does the individual become more capable, or merely more manageable?
A technology should not be described as empowering merely because it gives the user additional functions. It must be examined for the power relationship created alongside those functions.
The Second Question: Who Defines the Identity?
Digital systems increasingly require individuals to exist through accounts, identifiers and institutional records.
Who creates the identity? Must it be connected to a legal name? Can a person use separate identities for separate contexts? Can the institution alter, suspend or erase the record? Can the identity be used outside the original service?
An identity controlled entirely by one provider is a form of dependency. The person may be the subject represented by the account, yet the institution remains the authority deciding whether that representation is valid.
Identification may be necessary in some contexts. A binding financial contract, government service or regulated professional activity may require stronger evidence of identity than an ordinary discussion forum. Cypherpunkism does not demand anonymity everywhere.
It demands proportionality.
A system should request only the degree of identity necessary for the relationship. It should not convert a limited need for verification into permanent visibility across every activity.
The Third Question: What Information Is Collected?
A system’s power begins not only with the information a user deliberately supplies, but also with the records generated around his activity.
What does the system collect? Does it record location, contacts, searches, purchases, browsing behaviour, device identifiers or patterns of communication? Is every category necessary for the service? How long is it retained? Can separate records be combined?
As explained in “Metadata Is Power,” protecting the contents of communication is insufficient when surrounding records can expose identities, relationships, routines and movements.
The strongest protection against misuse of unnecessary information is not to collect it.
A sovereignty-enhancing system minimizes collection, separates contexts, limits retention and processes information locally where practical. A sovereignty-reducing system collects broadly, retains indefinitely and treats every observable behaviour as a resource available for future exploitation.
The Fourth Question: Who Can Read and Use the Data?
Collection does not reveal the complete architecture of information. We must also identify every party capable of obtaining access.
Can employees examine the records? Are they disclosed to commercial partners? Can advertisers use them to target behaviour? Can governments obtain them through legal demands? Are backups protected? Can information collected for one purpose later be applied to another?
A privacy policy may promise limited use while the technical system preserves extensive access. The test should therefore examine both policy and architecture.
Information protected by effective end-to-end encryption places a stronger boundary between participants and the intermediary. Information encrypted only between the device and a company server remains accessible to the company after arrival. Both systems may advertise “encryption,” but they create different distributions of power.
The essential question is not whether encryption appears somewhere in the system.
It is whether the parties who do not need the information remain technically capable of reading it.
The Fifth Question: Who Holds the Keys?
Cryptographic keys determine who can decrypt information, authorize transactions, prove control and sign digital actions.
If an institution holds every key, the institution retains ultimate authority. It may authorize actions, deny access, surrender information or change the conditions under which the user is recognized.
If the individual controls the relevant key, authority moves closer to the person. The system can verify a cryptographic proof without requiring a central administrator to approve every action.
Individual control also creates responsibility. Keys can be lost, stolen or used carelessly. Some users may choose custodial assistance because they cannot manage security alone. A humane system should therefore permit different custody arrangements without disguising dependence as sovereignty.
The test asks:
- Who generates the key?
- Who stores it?
- Can the provider copy or recover it?
- Can access be revoked without the individual’s authorization?
- Can the individual choose independent custody?
Control of the key is not the whole of Digital Sovereignty, but it frequently reveals where practical authority resides.
The Sixth Question: Who Grants Permission?
A digital system may give the user a capability or merely grant temporary permission to use a capability controlled by someone else.
The difference may remain invisible while the relationship is cooperative. It becomes apparent when the user and operator disagree.
Can the individual publish without prior approval? Can a transaction be refused? Can software be installed from another source? Can one application communicate with a competing service? Can access to a purchased object be withdrawn?
Permissions can be legitimate. Administrators must protect systems from abuse, secure sensitive records and enforce rules necessary for cooperation. The Cypherpunkist Test does not require the elimination of governance.
It asks whether permission is limited to a necessary function or has become a universal mechanism of control.
When every important action depends upon the approval of one authority, the user possesses access without sovereignty.
The Seventh Question: Who Can Change the Rules?
Every technological system has rules. The political question is who possesses the authority to change them.
Can an operator modify the terms without meaningful notice? Can a software update introduce new collection or restrictions? Are changes publicly documented? Can independent implementations reject them? Do users have any method of voice, review or refusal?
Centralized control can make necessary updates faster. Security vulnerabilities can be repaired, harmful behaviour can be addressed and technical improvements can be distributed efficiently. But the same update mechanism can also expand surveillance, remove functionality or redefine ownership.
As argued in “The Architecture of Power,” control over software rules is a form of political authority. A programmer or platform operator may regulate the activities of millions without passing a law or holding public office.
A sovereignty-enhancing system makes consequential rules visible and limits unilateral change. A sovereignty-reducing system permits one party to rewrite the conditions of participation while everyone else must accept the change or lose access.
The Eighth Question: Where Is Power Concentrated?
The word “decentralized” should never be accepted without identifying what has actually been distributed.
A system may distribute data while centralizing software development. It may distribute computation while relying upon one website or company for access. It may permit anyone to operate a node while most users depend upon a small number of gateways. It may publish open-source code while one organization controls the dominant implementation.
The test must examine every layer:
- Who controls the servers?
- Who controls the software?
- Who controls the naming or discovery system?
- Who controls access to users?
- Who controls the authoritative record?
- Who can stop the system from operating?
Decentralization is a check on power only when it removes an unnecessary point of control or requires independent parties to cooperate. Multiplying machines without distributing authority creates redundancy, not necessarily decentralization.
The Ninth Question: Can the System Be Understood and Challenged?
Digital authority becomes especially dangerous when its operation is hidden from the people affected by it.
Can users understand what information is collected and why? Can qualified researchers inspect important aspects of the technology? Are decisions explained? Can errors be corrected? Is there a person or institution responsible for reviewing contested outcomes?
Transparency alone is insufficient. A company may publish an extensive policy that few people can understand. Source code may be available while the deployed system differs from the published version. An algorithm may be described generally while the individual cannot discover why a particular decision was made.
Transparency becomes meaningful when it supports action: informed choice, independent verification, correction, appeal or the construction of an alternative.
The European Union’s General Data Protection Regulation, applicable since May 2018, reflects several related principles, including data protection by design and default, rights of access and erasure, data portability and safeguards concerning certain automated decisions.
Law can establish important protections, but systems should also embody those protections technologically. A legal right that cannot be exercised through the architecture may remain too distant from ordinary users.
The Tenth Question: Can Consent Be Withdrawn?
Consent is often treated as a single event. A person selects a box, installs an application or accepts a policy, and the institution treats that decision as continuing authorization for everything that follows.
But digital relationships change. New features are added. Companies merge. Information is combined with new databases. Purposes expand. A decision made years earlier cannot automatically justify every future use.
The test asks whether consent is specific, understandable and reversible.
Can the person stop a category of collection without abandoning an unrelated essential function? Can previously granted access be revoked? Will future processing cease? Are consequences of refusal proportionate, or is the individual punished by losing services that do not genuinely require the disputed information?
Consent without the ability to withdraw is not continuing consent. It is a permanent transfer of authority disguised as a past choice.
The Eleventh Question: Can the Individual Leave?
As developed in “The Right to Exit in Digital Civilization,” participation is not genuinely voluntary when leaving requires the abandonment of identity, information, relationships, reputation, records or digital possessions.
The test therefore examines more than whether an account can be closed.
Can information be exported completely and in a usable format? Can another service interpret it? Can relationships continue across providers? Can legitimately acquired possessions survive departure? Can unnecessary retained records be deleted? Can essential information be recovered if the provider fails?
Portability allows the individual to take information away. Interoperability allows relationships and functions to continue across institutional boundaries. Recoverability protects against the disappearance or hostility of the provider.
A cancellation button without these supporting conditions may terminate access without ending dependence.
The Twelfth Question: Who Is Accountable When Harm Occurs?
A system that distributes functions should not distribute responsibility until responsibility disappears.
Who is responsible when information is exposed, an account is wrongly suspended, software causes foreseeable harm or an automated decision cannot be explained? Can the affected person identify an accountable party? Is there a method of remedy, correction or compensation?
The updated ACM Code of Ethics and Professional Conduct, released in 2018, emphasizes that computing professionals should contribute to society, avoid harm, respect privacy, honor confidentiality and design systems that are robustly and usably secure.
These responsibilities are especially important because technical experts often possess knowledge and control unavailable to ordinary users. Expertise should not become immunity from accountability.
As stated in “The Rights and Responsibilities of the Cypherpunkist,” sovereignty grants an individual authority over himself, not unrestricted authority over other people. Technologies that increase individual freedom must still respect the privacy, consent, security and legitimate rights of everyone affected.
Interpreting the Results
The Cypherpunkist Test should not be reduced to a superficial numerical score. Not every question has equal importance, and a severe failure cannot always be cancelled by several minor strengths.
A service may offer excellent portability while conducting pervasive surveillance. A decentralized network may resist censorship while exposing sensitive information permanently. An encrypted application may protect message contents while collecting extensive metadata. Open-source software may remain dependent upon one centralized identity provider.
The test therefore produces three broad judgments.
Sovereignty-Enhancing Technology
A sovereignty-enhancing technology gives individuals meaningful capabilities, minimizes unnecessary collection, protects information, distributes critical authority, permits independent verification and preserves the ability to challenge or leave the system.
Conditionally Sovereign Technology
A conditionally sovereign technology provides genuine benefits and some individual control but retains important dependencies. It may be acceptable for particular purposes while requiring safeguards, reform or informed caution.
Sovereignty-Reducing Technology
A sovereignty-reducing technology makes participation dependent upon unnecessary identification, surveillance, centralized permission or irreversible institutional control. Its convenience increases the power of the system more than the authority of the person using it.
The purpose of these judgments is not to declare every imperfect technology illegitimate. It is to identify the direction in which power is moving.

My illustration “The Cypherpunkist’s Litmus Test” work-in-progress – The art represents: Technology is evaluated not by novelty, but by where control ultimately resides.
Applying the Test
Encrypted Messaging
A messaging service should be examined for more than the presence of encryption. Who controls the keys? Can the provider read messages? What metadata is retained? Must users reveal a telephone number or legal identity? Can independent clients connect? Can the operator remove users or change the protocol unilaterally?
End-to-end encryption may protect content while centralized account control and metadata collection preserve other forms of institutional power.
Social Platforms
A social platform may give individuals an audience while retaining control over identity, visibility, relationships and access. The test asks how content is ranked, what behaviour is recorded, whether advertising profiles can be inspected, how rules change and whether relationships can continue after departure.
The events surrounding Cambridge Analytica in 2018 demonstrated how information collected through social platforms could be transferred, combined and used for political profiling beyond what many users understood when they participated.
The lesson is not merely that one company or application behaved improperly. The deeper lesson concerns architecture: a centralized repository of identities, relationships and behaviour creates power that may be redirected toward purposes never anticipated by the people who produced the data.
Cloud Services
Cloud computing can provide reliable storage and convenient access, but it can also place documents, applications and professional history under one provider’s authority. The test asks whether information is encrypted, whether the provider controls decryption, whether usable backups can be created and whether the service can be replaced without disrupting essential work.
Connected Devices
A connected device should be examined for its ability to function without continuous contact with its manufacturer. Does it collect more information than its physical function requires? Can software be updated remotely? Can the company disable the device? Will it continue operating if the manufacturer ends support?
Ownership becomes questionable when an object purchased by the individual remains permanently dependent upon permission from a distant server.
Bitcoin and Decentralized Networks
Bitcoin demonstrates how cryptography and peer-to-peer architecture can distribute functions traditionally performed by a central financial intermediary. Individuals can control private keys and independently verify the ledger through software governed by public rules.
Yet the test must still examine practical concentration. Do users control their own keys or leave them with exchanges? Is mining power concentrated? Do a small number of services mediate access? Can ordinary participants understand the security responsibilities they assume?
No technology receives an exemption merely because its origins are Cypherpunk or its architecture is described as decentralized.
Convenience Is Not Sovereignty
Centralized services frequently succeed because they reduce complexity. They recover passwords, synchronize devices, moderate communities and provide support. Individual control may require additional knowledge and responsibility.
Cypherpunkism should not pretend that every person wishes to operate a server, inspect source code or manage cryptographic keys. A technology that only experts can use may provide theoretical sovereignty without making it widely accessible.
The objective is therefore not to abolish assistance. It is to prevent assistance from becoming unavoidable domination.
Users should be able to choose custody without being deceived about who controls the keys. They should be able to choose convenience without unknowingly accepting unlimited surveillance. They should be able to delegate functions without permanently surrendering the ability to withdraw that delegation.
The strongest system is not necessarily the one that forces every user into complete independence. It is the one that preserves meaningful options across different levels of technical ability.
The Complete Cypherpunkist Test
Before trusting a technology with an important part of human life, ask:
- Benefit: Who receives the principal benefit, and who bears the risk?
- Identity: Who defines, verifies and controls the user’s identity?
- Collection: What information and metadata are collected, and is each category necessary?
- Access: Who can read, combine, disclose or use the information?
- Keys: Who controls the cryptographic credentials authorizing important actions?
- Permission: Which actions require approval, and who can refuse them?
- Rules: Who can change the system’s rules, software or conditions of participation?
- Concentration: Where are the system’s single points of control and failure?
- Transparency: Can users and independent experts understand, verify and challenge the system?
- Consent: Can permission be refused or withdrawn without disproportionate punishment?
- Exit: Can the individual retrieve information, preserve legitimate possessions and move to an alternative?
- Accountability: Who is responsible when the system causes harm, and what remedy exists?
These questions can be applied to governments, corporations, blockchains, communications networks, financial systems, digital identities, cloud services, software platforms and connected devices.
They do not assume that centralized authority is always illegitimate or that decentralization is always sufficient. They identify who possesses power, whether that power is necessary and what limits prevent it from becoming absolute.
Who Does the Technology Empower?
The Cypherpunkist Test begins where ordinary product evaluation often ends.
A technology may work exactly as intended and still create a dangerous relationship. It may be secure against outside attackers while giving its operator unrestricted access. It may comply with written policies while making refusal practically impossible. It may expand what individuals can do while expanding institutional control even more.
The test therefore asks us to look beneath features, slogans and interfaces toward the architecture of authority.
Who knows?
Who decides?
Who controls?
Who can refuse?
Who can leave?
And who remains accountable?
If every answer points toward one government, corporation, platform or technical elite, the user may possess extraordinary convenience without Digital Sovereignty.
If authority is limited, distributed, understandable, contestable and recoverable by the individual, technology becomes an instrument of freedom.
Privacy is sovereignty.
Cryptography is applied freedom.
Decentralization is a check on power.
Code is political architecture.
Exit makes consent meaningful.
Do not judge technology only by the power it gives us.
Judge it by the power it gives over us.
Always ask: Who does the technology empower?
References and Foundational Influences
- United Nations. Universal Declaration of Human Rights. Articles 12 and 19, 1948.
- Saltzer, Jerome H., David P. Reed and David D. Clark. “End-to-End Arguments in System Design.” ACM Transactions on Computer Systems, Vol. 2, No. 4, November 1984, pp. 277–288.
- Hughes, Eric. A Cypherpunk’s Manifesto. March 9, 1993.
- Carpenter, Brian, ed. “Architectural Principles of the Internet.” RFC 1958, June 1996.
- Lessig, Lawrence. Code and Other Laws of Cyberspace. Basic Books, 1999.
- Cooper, Alissa, Hannes Tschofenig, Bernard Aboba, Jon Peterson, John Morris, Marit Hansen and Rhoda Smith. “Privacy Considerations for Internet Protocols.” RFC 6973, July 2013.
- Farrell, Stephen and Hannes Tschofenig. “Pervasive Monitoring Is an Attack.” RFC 7258, May 2014.
- Kaye, David. “Report on Encryption, Anonymity and the Human Rights Framework.” United Nations Human Rights Council, A/HRC/29/32, May 22, 2015.
- European Parliament and Council of the European Union. Regulation (EU) 2016/679, General Data Protection Regulation. April 27, 2016; applicable from May 25, 2018.
- Association for Computing Machinery. ACM Code of Ethics and Professional Conduct. Adopted June 22, 2018.
- Sim, Herbert R. “Cypherpunkism: A Philosophy of Digital Sovereignty.” October 10, 2010.
- Sim, Herbert R. “Digital Sovereignty: A Formal Definition.” December 10, 2013.
- Sim, Herbert R. “Metadata Is Power.” July 25, 2013.
- Sim, Herbert R. “The Architecture of Power: A Cypherpunkist Theory of Technology.” June 22, 2015.
- Sim, Herbert R. “Decentralization Is a Check on Power.” October 26, 2015.
- Sim, Herbert R. “The Rights and Responsibilities of the Cypherpunkist.” August 8, 2016.
- Sim, Herbert R. “The Right to Exit in Digital Civilization.” November 1, 2017.