Against Digital Absolutism: Why Cypherpunkism Is Not Anti-State or Anti-Corporation

My illustration entitled: “The Shield Against Absolutism” – I raise a luminous shield between citizens and two corrupted manifestations of power: an all-seeing surveillance state and an exploitative corporate monopoly. Behind them, their legitimate counterparts — public service and ethical enterprise — help build an open digital society.


Cypherpunkism is sometimes interpreted as a philosophy of opposition: opposition to governments, corporations, centralized institutions, regulation and every structure capable of exercising authority. This interpretation mistakes a criticism of concentrated power for a rejection of organization itself.

Cypherpunkism is not anti-state. It is not anti-corporation. It does not demand that every institution be abolished, every database distributed or every decision transferred to an anonymous network. It recognizes that governments can protect rights, companies can organize productive cooperation and centralized systems can perform necessary functions efficiently.

Its objection is more precise. No institution should acquire unlimited technological authority merely because that authority is convenient, profitable or administratively efficient.

The question is not whether governments and corporations should possess power. The question is what power they may legitimately possess, under what conditions they may exercise it and what protections remain available to the individual when that power is abused.

Cypherpunkism is not a philosophy against institutions. It is a philosophy against unaccountable technological domination.

The Error of Digital Absolutism

Digital absolutism begins when one principle is elevated above every competing value. The state declares that security justifies universal surveillance. A corporation declares that consent to its terms justifies unlimited collection. A decentralist declares that distribution is always preferable to coordination. A privacy absolutist declares that no social obligation can ever justify investigation or accountability.

Each position takes a legitimate concern and removes its limits. Security matters, but security without restraint can become control. Innovation matters, but innovation without responsibility can externalize harm. Privacy matters, but privacy does not transform fraud, coercion or violence into protected conduct. Decentralization matters, but a decentralized system can still reproduce exploitation, opacity and concentrated influence.

Cypherpunkism rejects this style of reasoning. It does not begin with the assumption that one category of actor is always virtuous and another is always dangerous. It examines the architecture of power itself.

Who collects the information? Who controls the keys? Who defines the identity? Who changes the rules? Who can exclude a participant? Who can observe without being observed? Who can appeal a decision, withdraw consent or leave without surrendering identity, property and relationships?

These questions apply to states, corporations, decentralized networks, nonprofit organizations and communities alike. A system does not become sovereign merely by calling itself public, private or decentralized.

Government Can Protect Freedom

The state is capable of extraordinary intrusion because it possesses coercive authority. It can investigate, compel, prohibit, seize and punish. When combined with digital infrastructure, these powers can extend across communications, financial activity, location, identity and association.

That danger is real, but it does not follow that government itself has no legitimate function. Governments establish legal rights, enforce contracts, investigate serious crimes, protect vulnerable people, maintain public infrastructure and create institutions through which power can be challenged.

The same state that threatens privacy may also prohibit unlawful surveillance. The same legal system that compels information may require a warrant, test evidence and provide a remedy for abuse. Public authority can restrain private power when a company deceives consumers, exposes personal information, discriminates through automated decisions or makes participation dependent upon unfair conditions.

The relevant distinction is therefore not between government and freedom. It is between limited government and unlimited government; between authority constrained by rights and authority converted into permanent technological access.

Cypherpunkism opposes the presumption that the state should possess universal visibility. A government may have legitimate reasons to investigate a particular person or event, but particular suspicion does not justify indiscriminate observation of an entire population. The existence of crime does not establish a general duty for every citizen to make every communication, movement and relationship permanently accessible.

The Universal Declaration of Human Rights and the International Covenant on Civil and Political Rights recognize privacy while permitting lawful restrictions under defined conditions. This is not an absolute rejection of authority. It is an insistence that authority must be justified and bounded.

Corporations Can Create Human Value

Corporations are also instruments. They allow people to coordinate knowledge, capital, labor and risk across projects that individuals might be unable to undertake alone. Companies can build useful technologies, expand access to communication, develop security tools and transform research into services available to millions.

Cypherpunkism does not oppose commerce, profit or organizational scale as such. Its concern arises when the commercial relationship becomes a structure of dependency in which the company knows everything about the user while the user knows almost nothing about the company’s system.

A platform may record identities, messages, searches, purchases, locations and social relationships. It may determine what the individual can see, say, buy or build. It may alter the rules unilaterally, suspend access without meaningful explanation and make departure costly by retaining the individual’s data, audience, reputation or digital possessions.

Calling such a relationship voluntary does not resolve the problem. Consent is weakened when a service is socially indispensable, its practices are incomprehensible, alternatives are unavailable or leaving requires the destruction of one’s digital life.

A corporation exercises legitimate technological authority when it supplies a valuable service under intelligible and limited conditions. Its authority becomes harder to justify when data gathered for one purpose is silently converted into surveillance, behavioral manipulation or control over unrelated aspects of life.

The United Nations Guiding Principles on Business and Human Rights make clear that respect for human rights is not exclusively a governmental obligation. Businesses also bear responsibilities to avoid causing or contributing to harm and to provide or cooperate in appropriate remedies.

Authority Is Not the Same as Domination

Authority is the recognized capacity to make or enforce a decision within a defined domain. Domination occurs when that capacity becomes arbitrary, inescapable or effectively unlimited.

A hospital may need authority over access to medical records, but it does not require permission to sell a patient’s complete history for unrelated purposes. A bank may need to authenticate an account holder, but authentication does not automatically justify permanent observation of every aspect of that person’s life. A platform may moderate conduct within its service, but moderation does not require secret rules, unexplained punishment or the confiscation of a user’s data and identity.

Legitimate authority is specific. Domination expands by inference: because an institution may do one necessary thing, it assumes the right to do everything technically possible.

Digital technology makes this expansion unusually easy. Information collected once can be retained indefinitely, combined with other databases and reused for purposes never presented to the person from whom it was obtained. A permission created to address an exceptional danger can become an ordinary capability. A temporary identification measure can develop into permanent infrastructure.

For this reason, legal assurances alone are insufficient. The architecture should also limit power. Data minimization, encryption, selective disclosure, access controls, deletion, interoperability and independent auditing can turn abstract restraints into operational boundaries.

A Doctrine of Justified Technological Authority

Cypherpunkism evaluates institutional power through a doctrine of justified technological authority. Authority is legitimate when it satisfies six conditions: it must be necessary, limited, transparent, proportionate, contestable and subject to meaningful review or exit.

1. Necessary

An institution should exercise technological power only when that power serves a legitimate function that cannot reasonably be achieved through a less intrusive arrangement.

Collecting information because it may someday be useful is not necessity. Requiring universal identification because some transactions involve risk is not necessity. Creating a permanent vulnerability in encryption because investigators may occasionally seek access is not necessity.

Necessity requires the institution to identify the problem, explain why the proposed capability addresses it and demonstrate why less invasive alternatives are insufficient.

2. Limited

Legitimate power must possess boundaries. Its purpose, duration, scope and authorized users should be defined. Information collected for one purpose should not automatically become available for every other purpose.

Limits should exist in both policy and design. Retention periods should be enforced. Access should be compartmentalized. Cryptographic keys should not be concentrated unnecessarily. Exceptional permissions should expire instead of quietly becoming permanent.

A promise of restraint is valuable. An architecture that prevents unrestrained access is stronger.

3. Transparent

People should be able to understand what authority exists and how it is exercised. Transparency does not require the publication of every security secret or personal record. It requires intelligible rules, disclosed purposes, visible procedures and sufficient information for independent evaluation.

Secret power cannot be meaningfully consented to or challenged. If a system profiles users, shares their information, ranks their speech or makes consequential automated decisions, the existence and governing logic of those functions should not be hidden behind technical complexity.

4. Proportionate

The intrusion imposed by a technological measure must be proportionate to the harm it is intended to prevent or the interest it is intended to protect.

A serious, particularized threat may justify carefully supervised investigation. It does not necessarily justify the routine collection of an entire population’s communications. Preventing account fraud may justify authentication. It does not necessarily justify constructing a permanent behavioral dossier.

Proportionality requires attention not only to immediate effects but also to cumulative power. Many individually modest collections can combine into an extraordinarily intimate map of a person’s life.

5. Contestable

A person affected by a consequential technological decision should have a meaningful opportunity to question it. There should be a comprehensible reason, an identifiable decision-maker and a procedure capable of correcting error.

An appeal mechanism is not meaningful if it merely repeats the original automated judgment. Contestability requires the possibility of reconsideration by someone or something capable of reaching a different conclusion.

This principle applies whether the decision concerns governmental suspicion, access to a financial account, removal from a platform, denial of a service or the classification of an individual by an algorithm.

6. Subject to Review or Exit

Power requires an external boundary. For public authority, this may include judicial review, legislative oversight, independent regulators, public scrutiny and constitutional rights. For private services, it may include audits, liability, consumer protection, competition, portability and interoperability.

When review cannot adequately restrain an institution, the individual must retain a meaningful right to exit. Departure should not require the unnecessary loss of identity, records, relationships, reputation or digital property.

Review and exit are complementary. Review allows a person to challenge power from within a system. Exit prevents the system from becoming the only place in which digital life is possible.

These Conditions Must Be Cumulative

The six conditions cannot be treated as a menu from which an institution selects the most convenient item. Transparent surveillance remains surveillance. A contestable power may still be grossly disproportionate. A limited power may have no legitimate necessity. A service that offers formal exit may make departure practically impossible.

Justification must be considered as a whole. The greater the power, the stronger the safeguards required. Authority over an entertainment preference does not demand the same scrutiny as authority over identity, movement, communication, money or access to essential services.

This produces a graduated rather than absolutist theory. Cypherpunkism does not answer every institutional question with prohibition. It asks whether the power being claimed is justified by its purpose, constrained by its architecture and accountable to the people subjected to it.

Encryption and the Limits of Institutional Access

The debate over encryption demonstrates the difference between rejecting authority and limiting it. Cypherpunkism does not deny that governments investigate serious crimes or that companies must respond to valid legal processes concerning information they actually possess.

It rejects the conclusion that these functions entitle an institution to universal cryptographic access.

An exceptional-access mechanism does not recognize the moral purpose of each person attempting to use it. It creates a technical capability. Once created, that capability may be discovered, copied, expanded or abused by governments, criminals, insiders and foreign adversaries.

Strong encryption therefore limits everyone, including institutions acting for legitimate purposes. That limitation is not necessarily a defect. Constitutional and technical systems often protect freedom by making certain actions difficult even for actors who claim benevolent intentions.

The 2015 report of the United Nations Special Rapporteur on freedom of expression recognized encryption and anonymity as technologies that enable individuals to exercise rights. Similarly, the Internet Engineering Task Force declared pervasive monitoring an attack requiring technical mitigation in RFC 7258.

This does not make investigation illegitimate. It means investigation must adapt to a world in which the security of everyone cannot safely depend upon a universal means of secret entry.


My illustration entitled: “The Shield Against Absolutism” work-in-progress. The art represents: the true opponent of Cypherpunkism is absolutism, regardless of whether it comes from government or business.


Regulation Can Either Restrain or Consolidate Power

Cypherpunkism is not categorically opposed to regulation. Rules can protect privacy, require security, prohibit deception and provide remedies unavailable to isolated individuals. The European Union’s General Data Protection Regulation, applicable since 2018, reflects principles such as purpose limitation, data minimization, access, correction and erasure.

Yet regulation should be judged by its architecture and effects, not only by its declared objective. Compliance burdens can unintentionally strengthen the largest organizations if only they possess the resources to satisfy them. Identification requirements can exclude vulnerable people. Mandatory retention can transform service providers into surveillance infrastructure. Licensing can prevent independent developers from creating alternatives.

Good regulation constrains domination while preserving the freedom to build. It establishes protections without making the regulated incumbents the permanent gatekeepers of technological life.

Decentralization Is a Check, Not a Commandment

Cypherpunkism values decentralization because concentrated systems create concentrated opportunities for censorship, surveillance and exclusion. But decentralization is a means, not an object of worship.

Some functions benefit from central coordination. Emergency response, public records, common standards and large-scale infrastructure may require identifiable responsibility. A decentralized network may also suffer from hidden concentrations of wealth, technical expertise, hardware, governance or influence.

The correct question is not whether a system is perfectly decentralized. It is whether the distribution of power is appropriate to the consequences of control.

A centralized component may be acceptable when its authority is narrow, observable and replaceable. A distributed system may remain oppressive when ordinary participants cannot understand it, influence it or leave it. As argued in The Architecture of Power, technology must be evaluated according to the relationships of authority it creates, not merely the labels attached to its design.

Neither Public Nor Private Power Is Automatically Legitimate

Arguments about technology are often reduced to a choice between state and market. If government power is feared, corporate control is presented as freedom. If corporate power is feared, state control is presented as democracy.

This binary is inadequate. Public and private institutions can restrain one another, cooperate with one another or amplify one another’s authority.

A corporation may accumulate detailed personal information and later provide it to the state. A government may delegate identity, communication or public discourse to private platforms. A company may invoke governmental regulation to exclude smaller competitors. A state may depend upon proprietary systems that its own citizens cannot examine.

The combination can be more powerful than either institution alone. Data collected through commercial convenience may become an instrument of public surveillance, while governmental authority may entrench private technological monopolies.

Cypherpunkism therefore refuses to grant moral immunity based upon institutional category. A public database is not safe merely because it serves the state. A private platform is not voluntary merely because it is operated for profit. A decentralized protocol is not liberating merely because it lacks a formal headquarters.

Responsibilities Accompany Digital Freedom

Opposition to absolutism also applies to the individual. Digital Sovereignty is not a claim that personal freedom cancels responsibility toward other people.

A Cypherpunkist should protect the privacy of others, secure entrusted information, reject fraud and coercion, distinguish anonymity from impunity and accept responsibility for deliberate harm. The freedom to build does not remove the obligation to consider how a system may be abused or whom it may expose.

These responsibilities were developed in The Rights and Responsibilities of the Cypherpunkist. They matter here because a philosophy that limits institutional authority must also explain why individual power is not unlimited.

The standard remains consistent: power should be proportionate, accountable and bounded, whoever exercises it.

The Cypherpunkist Position

Cypherpunkism neither sanctifies nor demonizes the state. It neither sanctifies nor demonizes the corporation. Institutions should be judged according to what they can do to the individual, what prevents abuse and whether participation preserves meaningful agency.

A legitimate government protects rights without converting every citizen into a permanent suspect. A legitimate corporation creates value without converting every user into an extractable dataset. A legitimate digital system coordinates people without making their identities, possessions and relationships dependent upon an unchallengeable center.

The practical inquiry can be summarized through six questions:

  1. Is the authority necessary for a legitimate and defined purpose?
  2. Is its scope technically and legally limited?
  3. Can people understand how it operates?
  4. Is its intrusion proportionate to the interest being protected?
  5. Can affected individuals challenge its decisions?
  6. Is it subject to meaningful review or a genuine right to exit?

These questions extend the practical analysis introduced in The Cypherpunkist Test. They do not assume that all authority is oppression. They require authority to justify itself.

Conclusion: Cooperation Without Domination

Technological civilization requires cooperation. It requires institutions capable of maintaining infrastructure, developing complex systems, resolving disputes and responding to genuine threats. Cypherpunkism does not imagine that every person can or should live independently of these structures.

But cooperation must not become domination. Convenience must not become permanent dependency. Security must not become universal surveillance. Commercial consent must not become unlimited permission. Administrative efficiency must not eliminate the individual’s ability to understand, challenge or leave a system.

The purpose of privacy, cryptography, decentralization and open architecture is not to destroy every institution. It is to ensure that institutions remain compatible with human freedom.

Authority is legitimate when it is necessary, limited, transparent, proportionate, contestable and subject to meaningful review or exit.

That is the Cypherpunkist alternative to digital absolutism: neither a world without institutions nor a world governed by institutions without limits, but a technological order in which power must remain answerable to the individual.

Privacy is sovereignty.

Cryptography is applied freedom.

Decentralization is a check on power.

Code is political architecture.

Digital sovereignty belongs to the individual.


References