The Architecture of Power: A Cypherpunkist Theory of Technology

My illustration entitled: “Rebuilding the Architecture of Power” – I use a glowing cryptographic hammer to dismantle a centralized technological fortress. Around me, citizens rebuild its components into an open decentralized network protected by encryption and transparent protocols.


Technology is commonly evaluated by what it enables us to do.

Does it make communication faster? Does it reduce costs? Does it increase convenience? Does it connect more people, process more information or solve a problem that could not previously be solved?

These are important questions, but they are incomplete.

Every technological system also establishes a relationship between those who use it, those who operate it and those who possess the authority to alter it. Its databases determine what can be remembered. Its interfaces determine what users can see. Its permissions determine what they may do. Its protocols determine how participants interact. Its cryptographic keys determine who can authorize actions. Its software determines which rules are automatically enforced.

A technology therefore does more than perform a function.

It distributes power.

This essay develops a Cypherpunkist theory of that distribution. Its central proposition is:

Technology should be evaluated not only by what it does, but by the structure of authority it creates.

I call this structure the architecture of power.


Technology Is Never Merely a Tool

A hammer does not normally record who holds it, require permission before striking a nail or report each use to its manufacturer. Most digital technologies are different.

A digital service may identify its user, record his actions, preserve those records indefinitely, compare them with other databases and condition future access upon rules that he cannot inspect or negotiate. The service provider may change those rules remotely. It may suspend an account, restrict a transaction, remove information or alter the interface through which the user perceives the system.

These powers are not accidental additions to the technology. They arise from its design.

When participation requires an account, the system creates an identity relationship. When activity is logged, it creates an informational relationship. When access can be revoked, it creates a relationship of dependency. When only one party can modify the rules, it creates a hierarchy. When users cannot retrieve their information or communicate through another provider, it creates captivity.

The political character of a digital system therefore exists even when no politician designed it and no law explicitly describes it.

Its architecture governs.


Code Is Political Architecture

Lawrence Lessig famously argued that “code is law.” His essential insight was that software and hardware can regulate behaviour by determining what is possible inside a technological environment.

Law generally tells people what they are permitted to do and establishes consequences for disobedience. Code can go further: it can make disobedience technically impossible.

A law may prohibit unauthorized access to a record. An access-control system can refuse to display it. A contract may prohibit copying. Software can attempt to prevent copying. A government may order censorship. A centralized platform can remove disputed information from every account under its control.

Architecture does not merely advise. It permits, refuses, records, filters and executes.

The programmer consequently occupies a position that earlier political theory did not fully anticipate. A programmer may create rules governing millions of people without holding public office. A database administrator may possess practical powers of observation exceeding those of many historical governments. A platform operator may determine who can speak, transact or participate within an environment that has become socially indispensable.

This does not mean that programmers or technology companies are inherently hostile to freedom. It means that technical decisions must be recognized as decisions about power.

A field marked “required” can become compulsory identification. A default setting can become mass disclosure. A centralized log can become an archive of human behaviour. A proprietary format can become dependence upon one vendor. A remotely revocable account can turn apparent ownership into conditional access.

These decisions may appear small when considered individually. At scale, they can constitute the unwritten constitution of digital life.


The Seven Locations of Technological Power

To understand a technological system, we must identify where authority resides. That authority can be examined across seven connected locations.

1. The Database

The database determines what the system remembers.

Who decides which information is collected? How long is it retained? Can separate records be connected? Can an individual inspect, correct or delete information concerning himself? Can the operator combine the database with records obtained elsewhere?

A database is not simply a storage mechanism. It is an institutional memory. The more comprehensive, identifiable and permanent that memory becomes, the greater the power of whoever can search it.

As I argued in “Metadata Is Power,” even records that do not reveal the contents of communications can expose relationships, locations, routines and patterns of association. The architecture of collection therefore determines how visible the individual becomes to the institution.

2. The Interface

The interface determines how the system presents reality and which choices appear available.

An interface can make privacy easy or bury it beneath layers of settings. It can distinguish clearly between consent and refusal, or use confusion to obtain agreement. It can display every available option or conceal alternatives that do not serve the operator’s interests.

Interfaces exercise a quiet form of power because most users experience the system only through what the interface permits them to see. The underlying software may technically support many possibilities while the visible design channels behaviour toward only a few.

A free choice that cannot be found, understood or exercised is not meaningful control.

3. The Permission System

Permissions determine who may act.

Who may publish? Who may transfer value? Who may create an account? Who may access a document? Who may connect a new application? Who may remove another participant?

Permission is sometimes necessary. Hospitals must restrict access to medical records. Banks must protect accounts. Administrators must prevent abuse. The existence of permissions is not itself evidence of domination.

The political question is whether permission is limited to a legitimate purpose or becomes a universal point of control.

When every action requires approval from one authority, participation exists at that authority’s discretion. The user may be capable of acting, yet remain unable to act without institutional consent.

4. The Cryptographic Key

The key determines who can authorize, decrypt, sign or prove.

If an institution possesses every key, the institution ultimately controls every protected action. It may act on the user’s behalf, deny the user access or surrender the information to another party. The user possesses an account, but not necessarily authority.

When the individual controls the relevant key, the relationship changes. Authorization no longer depends exclusively upon recognition by a central database. It can arise from cryptographic proof.

This is why cryptography is more than a security feature. It can relocate authority.

Encryption places the decision to reveal information in the hands of those possessing the decryption key. Digital signatures allow authorization to be demonstrated without requiring every act to originate from a central administrator. In Bitcoin, private keys and a peer-to-peer ledger provide a model of digital value whose transfer does not require a conventional financial intermediary to maintain the sole authoritative record.

The crucial question is therefore not merely whether a system uses cryptography.

Who controls the keys?

5. The Protocol

A protocol determines the terms upon which different participants and systems can communicate.

Open protocols can permit independent implementations, competing services and communication across institutional boundaries. Closed protocols can confine participants to one operator’s environment.

Email demonstrates the political significance of interoperability. People using different providers can exchange messages because participation does not depend upon everyone joining one company’s database. The protocol connects separate systems while permitting multiple operators to exist.

By contrast, a closed communication platform may require both parties to accept the authority of the same provider. Their identities, relationships and conversations then become dependent upon a single institutional center.

Interoperability is therefore not merely a matter of convenience. It limits the ability of one operator to transform network participation into permanent dependency.

6. The Rule-Making Process

Every digital system has rules, but systems differ in who may change them.

Can one company alter the rules without the consent of users? Are changes publicly documented? Can independent implementations reject them? Does the system contain a process for review? Can participants continue using an earlier version, or must they accept every modification to retain access?

A centralized update mechanism can be useful. It allows security vulnerabilities to be repaired quickly and improvements to be deployed widely. But the same mechanism may also add surveillance, remove functionality or redefine what the user is permitted to do.

Power over updates is power over the future character of the system.

7. The Infrastructure

Infrastructure determines whether the system can continue to exist without a particular operator, server or jurisdiction.

Can one authority switch it off? Does the failure of one data center disable every participant? Can a domain name, payment processor or hosting provider become a point of censorship? Can users operate their own nodes or servers? Can information be reconstructed from independent copies?

Central infrastructure can provide speed, coordination and consistent maintenance. It can also create a single point at which observation, exclusion or coercion becomes possible.

Distributed architecture does not abolish power, but it can divide power among parties that must cooperate rather than placing it completely in one set of hands.


Capability and Permission

A central distinction within the architecture of power is the difference between possessing a capability and receiving permission.

When I possess a capability, I can perform an action through tools under my control. When I possess permission, another party allows me to perform it through a system under its control.

A person holding a cryptographic key possesses the capability to authorize a signature. A person whose account depends upon a central server possesses permission to request that the server authorize an action.

The experiences may appear identical while the system is functioning normally. The difference becomes visible when interests conflict.

Permission can be withdrawn. Capability must be technically defeated.

Cypherpunkism does not require every human relationship to be transformed into unilateral capability. Cooperation frequently requires institutions, shared rules and trusted administration. But where fundamental privacy, identity, communication or possession is concerned, the individual should not be reduced unnecessarily to a petitioner.

Digital Sovereignty grows when essential freedoms exist as capabilities rather than revocable favors.


Four Asymmetries of Digital Power

Technological domination often emerges through asymmetry: one party can do something to another that the second party cannot meaningfully understand, resist or reverse.

Visibility asymmetry exists when an institution can observe the user while the user cannot observe the institution. The operator can examine behaviour, internal records and automated decisions, while the individual sees only the final interface.

Knowledge asymmetry exists when rules are hidden or too obscure for outsiders to evaluate. The user must trust claims about security, privacy and fairness without access to the code, protocol or decision process.

Control asymmetry exists when one party can alter permissions, revoke access or change rules unilaterally. The user remains bound by decisions in which he has no meaningful participation.

Exit asymmetry exists when an operator can remove a user easily, but the user cannot leave without losing information, identity, relationships, reputation or possessions accumulated inside the system.

No complex institution can eliminate every asymmetry. Expertise, administration and coordination will always create differences in knowledge and authority. The objective is not perfect equality between every participant.

The objective is to prevent ordinary participation from requiring unconditional submission to powers that are invisible, unlimited and impossible to challenge.


Centralization Is Not the Enemy; Unaccountable Concentration Is

A Cypherpunkist theory of technology must avoid the simplistic claim that every centralized system is oppressive and every decentralized system is liberating.

Centralization can provide efficiency, coherent responsibility, rapid maintenance and accessible support. A hospital should be able to coordinate patient care. A company should be able to secure its internal network. An online service may legitimately remove malicious activity from infrastructure it operates.

Decentralized systems also have limitations. They may be difficult to govern, slow to change, wasteful in their duplication, vulnerable to domination by technically sophisticated participants or incapable of reversing serious mistakes. Decentralization may distribute authority without distributing knowledge, wealth or practical influence.

The relevant question is not whether a center exists.

It is whether the center possesses more power than its legitimate function requires.

A centralized system becomes dangerous when its authority is comprehensive, hidden, permanent, non-portable and immune to challenge. A decentralized system becomes dangerous when its apparent lack of leadership conceals concentrated control over software development, computing resources, gateways or information.

Architecture must therefore be evaluated by its real distribution of power, not by the language used to market it.


Open Architecture and the Freedom to Build

A system cannot be meaningfully challenged when no one outside its controlling institution can understand or reproduce its essential functions.

Open architecture allows protocols, interfaces and important rules to be examined. Open-source software allows code to be studied, modified and independently implemented. Open standards allow separate systems to communicate. Accessible technical knowledge permits a wider public to understand the infrastructure upon which it depends.

Openness does not guarantee freedom. Published source code may remain incomprehensible to most people. An open protocol may still develop centralized gateways. A public repository may be governed by a small group. Transparency without the ability to act can become observation without power.

For this reason, open knowledge must be joined by the freedom to build.

People must be able to create alternative clients, operate independent servers, improve cryptographic tools and develop systems whose existence does not depend upon approval from the authority they are intended to constrain.

The old Cypherpunk instruction that “Cypherpunks write code” remains politically significant because it recognizes that criticism alone does not redistribute technological power.

An alternative must be possible.


The Questions Every Technology Should Answer

Before accepting a technological system as neutral infrastructure, we should ask:

  • What information does the system collect, and what could be inferred from it?
  • Who can inspect that information?
  • Who possesses the cryptographic keys?
  • Who defines the user’s identity?
  • Who grants or refuses permission to act?
  • Who can change the rules?
  • Who can remove a participant or revoke access?
  • Can independent systems interoperate with it?
  • Can the individual retrieve his information in a useful form?
  • Can errors and abuses of authority be challenged?
  • Can the system survive the failure or hostility of one controlling institution?
  • Can the individual leave without abandoning his identity, relationships, records or possessions?

The answers reveal the system’s underlying constitution.

If every answer points toward a single institution, then the system concentrates technological sovereignty. If authority is distributed, limited, visible, portable and contestable, the system gives the individual a stronger position.


My illustration “Rebuilding the Architecture of Power” – work-in-progress – The art represents: Cypherpunkism transforming technological power through construction, not merely criticism.


The Architecture of Digital Sovereignty

Digital Sovereignty is the condition in which individuals retain meaningful authority over their identities, information, communications, credentials, digital possessions and participation in technological systems.

That sovereignty cannot be created by one feature alone.

Encryption without control of the keys may protect data while preserving institutional dependency. Decentralization without privacy may distribute a permanent record of human activity. Open-source code without interoperability may expose the rules while leaving users trapped inside one network. Portability without usable alternatives may offer a theoretical exit that few people can exercise.

A sovereign architecture instead combines several properties.

It minimizes unnecessary collection. It protects sensitive information cryptographically. It gives individuals meaningful control over important credentials. It makes consequential rules intelligible. It permits independent implementation where practical. It avoids unnecessary single points of control. It allows errors and abuses to be challenged. It preserves the possibility of leaving.

Such an architecture does not eliminate institutions. It defines their authority.

Governments, companies, communities and technical administrators may continue to perform necessary functions. But their powers should be proportionate to those functions rather than silently extending across the whole of a person’s digital existence.


Architecture Before Crisis

The distribution of technological power is easiest to ignore when institutions are benevolent, systems operate normally and users’ interests remain aligned with those of the operator.

Architecture reveals its political significance during conflict.

What happens when a government demands information? What happens when a company changes ownership? What happens when an administrator becomes corrupt? What happens when a database is breached? What happens when a user is falsely accused? What happens when public opinion changes and yesterday’s ordinary behaviour becomes tomorrow’s object of suspicion?

A system designed around unlimited institutional access assumes that authority will remain trustworthy. A system designed around distributed authority assumes that trust has limits.

Cypherpunkism begins from the second assumption.

This is not because every institution is malicious. It is because institutions change, databases persist and powers created for exceptional circumstances have a tendency to become ordinary.

Freedom must therefore be considered before the crisis arrives. Privacy, portability, interoperability and cryptographic control cannot always be added after a system has centralized the identities, relationships and possessions of an entire population.


A Cypherpunkist Theory of Technology

Cypherpunkism is not a philosophy against technology. It is a philosophy concerned with whom technology empowers.

It rejects the belief that innovation can be evaluated independently of authority. A system that offers extraordinary convenience while establishing permanent surveillance has made a political choice. A platform that connects millions while reserving the power to exclude any participant has made a political choice. A digital possession that can be revoked remotely has made a political choice about the meaning of ownership.

The Cypherpunkist does not respond by rejecting every institution or demanding that every network become completely decentralized. He examines the architecture.

Where authority is necessary, he asks that it be limited. Where information is sensitive, he asks that it be protected. Where trust can be reduced through cryptographic proof, he asks that proof be considered. Where one point possesses excessive control, he asks whether authority can be distributed.

Where rules govern the public, he asks that those rules be open to examination. Where dependence becomes unavoidable, he asks for interoperability, portability and a meaningful ability to leave.

The objective is not a world without organization.

It is a world in which organization does not become absolute technological sovereignty over the individual.


Who Does the Architecture Empower?

The defining political question of a technological civilization will not be whether society uses technology. That question has already been answered.

The defining question will be who possesses authority through it.

Who sees and remembers? Who grants permission? Who controls the keys? Who writes the rules and changes them? Who can refuse, challenge or leave?

These are not secondary questions to be considered after a technology succeeds. They define what kind of success the technology represents.

A machine may be efficient while the relationship it creates is oppressive. A platform may be convenient while the dependency it creates is dangerous. A network may be innovative while its concentration of knowledge, identity and control makes its users increasingly powerless.

Technological progress should expand human capability without quietly transferring ultimate authority over human beings to the systems they use.

That requires more than good intentions.

It requires architecture.

Privacy establishes the boundary.

Cryptography protects the boundary.

Open knowledge makes power intelligible.

Open architecture makes power contestable.

Decentralization prevents authority from becoming absolute.

Individual control places meaningful authority in the hands of the person.

Code is political architecture.

And architecture is the distribution of power.


References and Foundational Influences

  1. Saltzer, Jerome H., David P. Reed and David D. Clark. “End-to-End Arguments in System Design.” ACM Transactions on Computer Systems, Vol. 2, No. 4, November 1984, pp. 277–288.
  2. Stallman, Richard. The GNU Manifesto. 1985.
  3. Hughes, Eric. A Cypherpunk’s Manifesto. March 9, 1993.
  4. Carpenter, Brian, ed. “Architectural Principles of the Internet.” RFC 1958, June 1996.
  5. Lessig, Lawrence. Code and Other Laws of Cyberspace. Basic Books, 1999.
  6. Kempf, James and Rob Austein. “The Rise of the Middle and the Future of End-to-End.” RFC 3724, March 2004.
  7. Lessig, Lawrence. Code: Version 2.0. Basic Books, 2006.
  8. Nakamoto, Satoshi. “Bitcoin: A Peer-to-Peer Electronic Cash System.” 2008.
  9. Cooper, Alissa, Hannes Tschofenig, Bernard Aboba, Jon Peterson, John Morris, Marit Hansen and Rhoda Smith. “Privacy Considerations for Internet Protocols.” RFC 6973, July 2013.
  10. Sim, Herbert R. “Cypherpunkism: A Philosophy of Digital Sovereignty.” October 10, 2010.
  11. Sim, Herbert R. “Metadata Is Power.” July 25, 2013.
  12. Sim, Herbert R. “Digital Sovereignty: A Formal Definition.” December 10, 2013.
  13. Sim, Herbert R. “A Genealogy of Cypherpunkism.” October 21, 2014.