Digital Sovereignty: A Formal Definition

The Individual’s Authority Within Technological Civilization


My illustration entitled: “The Sovereign Digital Fortress” – I stand at the entrance of a magnificent futuristic fortress protected by cryptographic walls. Inside are a person’s identity, communications, financial assets and personal data.


The word sovereignty traditionally describes a form of supreme authority. Political sovereignty concerns the authority of states over territory, law and institutions. Personal sovereignty concerns the individual’s authority over his own body, conscience, choices and private life.

Digital civilization creates another domain in which sovereignty must be considered.

Human identity is increasingly represented through databases. Communication passes through privately and publicly operated networks. Personal memories are stored on remote servers. Financial activity is recorded electronically. Access to knowledge, employment, relationships and public participation increasingly depends upon accounts, devices and technological platforms.

These systems do not merely serve the individual. They also exercise power over him.

They can determine whether he may participate, what he must reveal, which identity he must use, what he may possess, whom he may contact and whether he can leave without losing the accumulated record of his digital life.

In Cypherpunkism: A Philosophy of Digital Sovereignty, published on 10 October 2010, I introduced Digital Sovereignty as the unifying objective of a wider philosophy built upon privacy, cryptography, decentralization, open knowledge and individual control.

The Cypherpunkist Manifesto subsequently declared that neither government nor corporation should become the unquestioned sovereign of digital existence. The Eight Principles of Cypherpunkism placed Digital Sovereignty as the final principle toward which the other seven converge.

This article performs a more precise task.

It provides a formal definition of Digital Sovereignty, identifies its domains and establishes the minimum conditions required for individual authority to become meaningful rather than merely symbolic.


The Formal Definition

Digital Sovereignty is the condition in which an individual retains sufficient, meaningful and practically enforceable authority over his digital identity, information, communications, cryptographic credentials, digital possessions and participation in technological systems—so that cooperation does not become domination, convenience does not become irreversible dependency and technological participation does not require the unnecessary surrender of human autonomy.

Every element of this definition is necessary.

A Condition

Digital Sovereignty is not merely an intention, promise or political slogan. It is a condition produced by the combined operation of law, technological architecture, institutional practice and individual capability.

A company may promise that users control their information while retaining the technical ability to access, transfer or permanently withhold it. A government may formally recognize privacy while constructing systems of indiscriminate surveillance. A platform may describe participation as voluntary when leaving would mean losing identity, relationships, records and access to essential services.

The real condition matters more than the declared intention.

The Individual

The primary subject of Digital Sovereignty is the human individual.

Governments increasingly use the term digital sovereignty to describe national control over data, communications infrastructure, computer networks or technological industries. States may possess legitimate interests in protecting infrastructure and reducing dependency upon foreign powers.

But state digital sovereignty and individual Digital Sovereignty are not automatically the same.

A state may become technologically independent from foreign governments while making its own citizens more dependent upon centralized domestic authority. A national database may increase the sovereignty of the state while diminishing the sovereignty of the individuals represented within it.

Cypherpunkism therefore begins with the individual. Institutions should be evaluated according to whether they preserve or unnecessarily diminish the person’s meaningful sphere of authority.

Retains

The word “retains” recognizes that technological participation frequently requires cooperation. Individuals must share information, use infrastructure and accept rules when entering legitimate relationships.

Digital Sovereignty does not require the individual to control every machine, network or institution. It requires that participation does not transfer more authority than the relationship genuinely requires.

A person may disclose an address for delivery without surrendering permanent control over his movements. He may provide identity to enter a contract without agreeing to universal identification across unrelated activities. He may entrust information to a service without abandoning every future claim concerning its use.

Sovereignty can accommodate limited delegation. It cannot survive unlimited surrender.

Sufficient Authority

Digital Sovereignty is not absolute authority. No individual possesses unlimited freedom to use technology in ways that defraud, coerce or directly harm others.

The individual must nevertheless retain authority sufficient to preserve genuine agency. He must possess more than a ceremonial choice between accepting every institutional demand and withdrawing from digital society entirely.

Sufficient authority means that the person can make consequential decisions concerning disclosure, identity, access, security, possession, participation and exit.

Meaningful Authority

Authority is meaningful when it can be understood and exercised in practice.

A person does not meaningfully consent to data collection he cannot understand. He does not meaningfully control an account when the operator may revoke it arbitrarily. He does not possess a meaningful right to leave when departure requires abandoning his information, relationships and digital property.

A theoretical right that cannot be exercised is not sufficient.

Practically Enforceable Authority

Digital Sovereignty must be supported by mechanisms capable of protecting it.

Some mechanisms are legal: privacy rights, contracts, due process, limits on surveillance and remedies for misuse. Others are institutional: independent oversight, transparent policies and accountable governance. Others are technical: encryption, cryptographic authentication, open protocols, local storage, interoperability and distributed architecture.

None is sufficient alone.

A legal right without secure architecture may be violated secretly. A technical protection without legal recognition may be prohibited or circumvented through coercion. A decentralized system without usable tools may provide theoretical freedom inaccessible to ordinary people.

Digital Sovereignty exists most strongly when legal, institutional and technological protections reinforce one another.


Digital Sovereignty Is Not Absolute Independence

Sovereignty can be misunderstood as complete independence from every external authority. That is not the meaning intended here.

Human beings live within societies. They rely upon shared infrastructure, form organizations, enter contracts and accept responsibilities toward others. Digital participation necessarily involves relationships among users, developers, service providers, governments and network operators.

Digital Sovereignty does not mean:

  • that every person must operate his own servers;
  • that every communication must be anonymous;
  • that every system must be decentralized;
  • that governments possess no legitimate authority;
  • that corporations should cease providing digital services;
  • that contracts and community rules are inherently illegitimate;
  • or that individuals may use technology without responsibility for harm.

It means that dependence should remain limited, visible and contestable.

The individual may depend upon technology without becoming technologically subordinate. He may cooperate with institutions without granting them unlimited authority. He may delegate particular functions without surrendering the whole of his digital identity.

Digital Sovereignty is not the absence of relationships. It is the preservation of human agency within those relationships.


The Seven Domains of Digital Sovereignty

Digital Sovereignty operates across several interconnected domains. Control in one domain cannot fully compensate for domination in another.

Domain Sovereign Question Primary Risk Necessary Protection
Information Who may collect, retain, combine and disclose information about the individual? Surveillance, profiling and unrestricted secondary use Privacy, data minimization, purpose limitation and security
Identity Who defines, verifies and controls the digital person? Universal tracking, exclusion and institutional identity ownership Contextual identity, selective disclosure and user control
Communication Who can read, block, record or map human communication? Interception, censorship and exposure of associations Encryption, metadata protection and open communication protocols
Money and Digital Possessions Who can authorize, freeze, transfer or confiscate digital value? Conditional ownership and total intermediary dependence Clear property rights, cryptographic control and proportionate legal process
Infrastructure Who controls the networks and services required for participation? Monopoly, censorship and unavoidable dependency Interoperability, open standards, competition and decentralization where justified
Computation Who controls the devices and software through which the individual acts? Remote restriction, hidden execution and loss of user authority Device control, inspectability, secure software and freedom to build
Cognition Who may access or influence technology interacting closely with human thought and perception? Manipulation and future technological intrusion into the mind Cognitive privacy, informed consent and direct human authority

I. Information Sovereignty

Information Sovereignty concerns the individual’s authority over information that describes him.

In Privacy Is Sovereignty, I defined privacy as sovereignty over disclosure: the ability to establish boundaries around what is revealed, to whom and under what circumstances.

This authority must extend beyond isolated facts. Digital systems can collect fragments from different areas of life and combine them into a detailed profile. One location, purchase or contact may reveal little. Thousands of connected records can reconstruct identity, habits, associations and beliefs.

Metadata Is Power demonstrated that even when communication content remains protected, records concerning identities, locations, timing and relationships can reveal the structure of human life.

Information Sovereignty therefore requires meaningful limits upon:

  • collection;
  • retention;
  • aggregation;
  • linkage;
  • analysis;
  • disclosure;
  • and secondary use.

It also requires the ability, where appropriate, to access, correct, retrieve and challenge information used to make decisions about the individual.

The central principle is:

Information concerning a person should not become an unrestricted institutional asset merely because technology made its collection possible.


II. Identity Sovereignty

Digital identity determines how a person is recognized by technological systems.

An identity may consist of a legal name, account, password, cryptographic key, telephone number, email address, customer record or pseudonym. Increasingly, identity is not merely a description of the individual. It is also a mechanism of permission.

The institution controlling the authoritative identity record may determine whether the person can communicate, work, transact, travel or access information.

Identity Sovereignty does not mean that individuals may falsely assume identities in order to commit fraud. It means that identification should remain proportionate to the legitimate requirements of an interaction.

A person should not need to disclose his complete legal identity when a service requires only proof of authorization, membership or age. Nor should every context of life be connected to one permanent identifier.

Human beings possess contextual identities. A person may be a parent, employee, patient, customer, voter, writer and member of a religious community. Combining every context into one universal record gives whoever controls that record extraordinary power.

Identity Sovereignty therefore favors selective disclosure, contextual identity and pseudonymity where complete identification is unnecessary.

The individual should be able to prove what an interaction legitimately requires without automatically revealing everything else.


III. Communication Sovereignty

Communication Sovereignty concerns the ability to speak, correspond, publish and associate without unnecessary observation or permission.

Private communication has traditionally been protected through physical boundaries: sealed letters, closed rooms and confidential meetings. When communication becomes electronic, those boundaries must be recreated technologically.

Cryptography Is Applied Freedom established that encryption can transform confidentiality from a promise into a technical capability. Correctly implemented cryptography can limit access to the holders of appropriate keys regardless of the power of an unauthorized observer.

But communication sovereignty requires more than encrypted content. It also concerns metadata, censorship, network access and the ability to choose among communication providers.

A person does not possess communication sovereignty when:

  • every message is automatically readable by an intermediary;
  • every association is permanently mapped;
  • one operator can silence him without review;
  • one identity must be exposed in every context;
  • or no meaningful alternative channel exists.

Communication Sovereignty does not guarantee that every statement will be lawful or accepted. It requires that the infrastructure of communication does not place unrestricted prior power in the hands of one institution.


IV. Monetary Sovereignty and Digital Possession

Digital systems are changing the meaning of possession.

In the physical world, possession often involves direct control. A person holds cash, stores an object or controls a key to a room. In digital systems, something described as belonging to the user may remain under the technical control of an intermediary.

An account balance may depend upon the institution maintaining the ledger. A digital purchase may disappear if a service closes. An account may appear personal while the operator retains the power to revoke access. A file may be called yours while existing only on another party’s server.

Cryptographic keys introduce another model of authority. A person controlling the appropriate key can authorize an action recognized by a network without requiring an intermediary to act on his behalf.

Bitcoin remains an early and experimental example. Its 2008 proposal asked whether electronic value could be transferred through a peer-to-peer network without relying upon one financial institution to maintain the authoritative transaction history.

Its future remains uncertain, but its architectural question is important:

Can digital possession be constituted through direct cryptographic authority rather than existing only as permission recorded by an intermediary?

Monetary Sovereignty does not require the rejection of banks, laws or financial institutions. It requires scrutiny of who controls the ledger, who may authorize transactions, under what conditions assets may be frozen and whether the individual possesses any direct form of authority.


V. Infrastructure Sovereignty

Digital freedom depends upon infrastructure.

A person may formally possess the right to communicate, publish or transact, yet be unable to exercise it if every practical channel is controlled by one gatekeeper.

Infrastructure Sovereignty concerns the distribution of power across networks, platforms, protocols, servers and access providers.

Centralization is not automatically illegitimate. Centralized systems can offer efficiency, coordination, security, recovery and ease of use. The relevant question is not whether a centre exists, but how much authority that centre possesses.

A centralized system becomes a threat to Digital Sovereignty when it creates an unavoidable point of surveillance, censorship, exclusion or failure.

Decentralization can reduce this danger by distributing functions among multiple participants. Open standards can allow competing implementations. Interoperability can permit users to change providers without abandoning the wider network.

Infrastructure Sovereignty therefore requires alternatives.

A person who cannot practically leave a system remains subject to whoever controls it, even when participation is described as voluntary.


VI. Computational Sovereignty

The individual increasingly experiences the digital world through devices and software he may not meaningfully control.

A computer may belong physically to the user while its software remains capable of restricting installation, reporting activity or receiving remote commands from another institution. A service may perform computation on remote servers whose operation cannot be examined. An application may request authority far beyond what its stated function requires.

Computational Sovereignty concerns the individual’s practical authority over the machines and software acting on his behalf.

It includes the ability to:

  • choose and secure devices;
  • understand important software permissions;
  • install legitimate alternatives;
  • protect information through cryptography;
  • inspect open implementations where possible;
  • and prevent unnecessary remote control.

Not every user must become a programmer. Specialization is unavoidable, and people will continue relying upon experts. But dependence upon expertise should not become blind submission to systems that cannot be questioned, audited or replaced.

This is why Open Knowledge, Open Architecture and Freedom to Build are essential principles of Cypherpunkism.


VII. Cognitive Sovereignty

Today, Digital Sovereignty primarily concerns computers, telephones, networks, databases and electronic transactions. Technology may not remain outside the individual.

Computers have moved from rooms to desks, from desks to laps and from laptops into pockets. Increasingly, computing will be worn upon the body. Future interfaces may interact more closely with human senses, biological signals and the nervous system.

If technology eventually acquires the capacity to record, interpret or influence neural activity, the boundary of Digital Sovereignty will extend toward cognition.

Questions that currently concern data may then concern thought.

Who can access neural information? Can cognitive signals be stored or transmitted? May an institution require access as a condition of employment, insurance or participation? Who controls the software mediating between a human nervous system and an external machine?

These technologies remain developing and uncertain. Yet the governing principle can already be stated:

The closer technology approaches the human mind, the stronger the protections for individual sovereignty must become.

The mind must never become merely another peripheral controlled by an external administrator.


The Seven Minimum Conditions

A system cannot be described as digitally sovereign merely because it includes one privacy or security feature. Meaningful Digital Sovereignty requires seven minimum conditions.

1. Agency

The individual must possess consequential choices rather than merely formal permission to accept predetermined conditions.

2. Informational Boundaries

The individual must retain meaningful influence over what information is collected, disclosed, combined and retained.

3. Security and Cryptographic Protection

Sensitive information, communications and credentials must be protected against unauthorized access through appropriate security and cryptography.

4. Control

The individual must possess practical authority over relevant accounts, keys, identity credentials, information and digital possessions.

5. Intelligibility

Important rules, permissions and consequences must be understandable. Authority hidden inside incomprehensible architecture cannot be meaningfully evaluated.

6. Portability and Exit

The individual must be able, where reasonably possible, to retrieve information, change providers or leave without losing the essential substance of his digital life.

7. Contestability

Decisions affecting identity, access, property or participation must not become permanently unchallengeable. There must be a method of correcting error, questioning authority or obtaining meaningful review.

These conditions will vary by context. A medical database, social network, banking system and anonymous communication protocol will require different balances and safeguards.

But if agency, boundaries, security, control, intelligibility, exit and contestability are all absent, Digital Sovereignty does not exist.


>My illustration “The Sovereign Digital Fortress” work-in-progress – Governments and corporations remain outside, unable to enter without permission. Represents: The individual retaining authority over every part of their digital existence.


Digital Sovereignty Is More Than Privacy

Privacy and Digital Sovereignty are closely connected, but they are not identical.

Privacy concerns the boundaries surrounding information, identity, communication and association. Digital Sovereignty includes privacy while extending beyond it.

A system may protect information from public disclosure while still allowing one institution to revoke the user’s account arbitrarily. The system may be private but not sovereign.

A person may communicate through encryption while lacking control over the device on which the message is created. The content may be protected while the wider relationship remains dependent.

A decentralized network may resist censorship while exposing every transaction publicly. The network may distribute authority while providing insufficient privacy.

Digital Sovereignty therefore requires the principles of Cypherpunkism to operate together.

Privacy establishes the boundary. Cryptography protects it. Decentralization constrains concentrated power. Individual Control identifies the rightful authority. Open Knowledge creates understanding. Open Architecture preserves alternatives. Freedom to Build allows better systems to emerge.

Digital Sovereignty is the condition they collectively seek to establish.


Digital Sovereignty Is More Than Security

Security asks whether a system is protected against unauthorized interference. Sovereignty also asks who possesses legitimate authority within the system.

A prison may be highly secure. A surveillance database may be protected by strong encryption. An authoritarian identity system may resist intrusion. None becomes sovereign for the individual merely because it is secure.

Security protects an existing distribution of power. Digital Sovereignty evaluates whether that distribution of power is legitimate.

We must therefore ask not only:

Is the system secure?

We must also ask:

Whose authority does the security protect?

Security serving only the institution may make institutional control stronger. Sovereign security must also protect the person from unnecessary institutional power.


Digital Sovereignty Is More Than Ownership

Ownership provides one important form of control, but digital relationships cannot always be reduced to property.

Personal information may concern several people. A communication belongs morally to its participants even if one party possesses the technical ability to publish it. A platform may own its servers while users retain legitimate claims concerning their identities and records.

Digital Sovereignty asks a broader question than who legally owns a database or device. It asks what authority each party should possess within the relationship.

A corporation may own its infrastructure without acquiring moral entitlement to exploit every fact passing through it. A government may operate an identity system without becoming the owner of the identities it administers. A user may control a cryptographic key without gaining the right to use it to harm others.

Ownership, access, control, responsibility and sovereignty overlap, but they remain distinct concepts.


Digital Sovereignty Is a Spectrum

Technological systems rarely produce complete sovereignty or complete domination. Digital Sovereignty exists along a spectrum.

Nominal Sovereignty

The system claims that users possess control, but essential decisions remain entirely with the operator.

Delegated Sovereignty

The individual voluntarily entrusts particular functions to an institution while retaining understandable rights and alternatives.

Conditional Sovereignty

The individual possesses control only while an intermediary continues granting access or honoring its present policies.

Substantive Sovereignty

The individual possesses practical, enforceable and portable authority supported by law, architecture and meaningful alternatives.

Delegation does not necessarily diminish sovereignty if it is informed, limited and reversible. Dependency becomes domination when the individual can neither understand nor challenge the authority exercised over him.


The Digital Sovereignty Test

A technological system can be examined through twelve questions:

  1. Identity: Who defines and controls the user’s identity?
  2. Collection: What information is collected, and is every category necessary?
  3. Disclosure: Can the individual influence what is revealed and to whom?
  4. Security: Who can access sensitive information and communications?
  5. Keys: Who controls the cryptographic credentials authorizing important actions?
  6. Rules: Who can change the system’s rules?
  7. Exclusion: Who can deny access or remove the individual?
  8. Possession: Does the individual control digital property, or merely receive conditional access?
  9. Knowledge: Can users or independent experts understand and examine important aspects of the system?
  10. Portability: Can the individual retrieve information and move to another provider?
  11. Challenge: Can errors and adverse decisions be meaningfully contested?
  12. Exit: Can the individual leave without abandoning identity, relationships, records and possessions?

No system will answer every question perfectly. Different technologies face different requirements and risks.

But the pattern of answers reveals the system’s underlying constitution.

If every answer points toward one institution, the user may possess access without sovereignty. If authority is limited, intelligible, distributed and contestable, the individual possesses a stronger position.


Rights and Responsibilities

Digital Sovereignty creates rights, but it also creates responsibilities.

The individual should possess the right to protect private information, use strong cryptography, control personal credentials, question unnecessary surveillance and build legitimate alternatives.

He must also respect the privacy and sovereignty of others.

Control of a key does not eliminate responsibility for the action it authorizes. The ability to publish information does not create ownership of another person’s private life. Privacy does not transform fraud, coercion or violence into legitimate conduct.

A digitally sovereign individual should:

  • protect entrusted information;
  • secure important credentials;
  • respect contextual boundaries;
  • avoid surrendering another person’s information carelessly;
  • understand the systems he uses where reasonably possible;
  • distinguish privacy from impunity;
  • and accept responsibility for actions performed under his control.

Sovereignty without responsibility becomes domination over others. Responsibility without sovereignty becomes submission.

Digital civilization requires both.


A Declaration of Digital Sovereignty

I am a human being before I am a user, account, customer, identifier or entry in a database.

My participation in digital society does not erase my claim to privacy, dignity and individual agency.

I have the right to establish meaningful boundaries around my digital life.

I have the right to communicate privately.

I have the right to use strong cryptography.

I have the right to control my cryptographic keys and credentials where practical.

I have the right to know what information is collected about me and why.

I have the right to question how my information is combined, retained and used.

I have the right to use different identities in different contexts where complete legal identification is unnecessary.

I have the right to access knowledge and understand the systems upon which I depend.

I have the right to build and use legitimate alternatives.

I have the right to retrieve my information and leave a technological system where reasonably possible.

I have the right to challenge decisions affecting my identity, access and digital possessions.

I have the right to participate in technological civilization without surrendering the whole of myself to those who operate it.

And with these rights comes responsibility.

I must respect the privacy of others.

I must protect the credentials entrusted to me.

I must remain accountable for the actions I authorize.

I must distinguish individual freedom from the freedom to harm.

I must question power even when it claims to act for my convenience.

I must remember that technology is a tool and the human being is its purpose.


Digital Sovereignty Belongs to the Individual

Digital Sovereignty is the governing objective of Cypherpunkism.

It does not demand that human beings withdraw from institutions. It demands that institutions do not absorb the individual’s entire sphere of authority.

It does not oppose technological progress. It asks whom that progress empowers.

It does not reject cooperation. It requires that cooperation remain compatible with human agency.

It does not promise perfect independence. It establishes a minimum condition beneath which technological participation becomes subordination.

That minimum condition consists of meaningful agency, informational boundaries, security, control, intelligibility, portability, exit and the ability to challenge power.

The future will bring technologies more powerful and intimate than those we use today. Networks will become more essential. Databases will become more comprehensive. Devices will move closer to the body. Systems will acquire greater ability to identify, predict and influence human behaviour.

The more powerful technology becomes, the more precisely we must define the authority of the person living through it.

Digital Sovereignty is the condition in which technology expands human capability without transferring unnecessary or absolute authority over the individual to the institutions operating it.

Privacy establishes the boundary.

Cryptography protects it.

Decentralization constrains concentrated power.

Open knowledge makes sovereignty intelligible.

Open architecture preserves alternatives.

Freedom to build makes alternatives possible.

Individual control places authority in the hands of the person.

Digital Sovereignty belongs to the individual.


References and Foundational Influences

  1. United Nations. Universal Declaration of Human Rights, Article 12. 1948. Available online.
  2. United Nations. International Covenant on Civil and Political Rights, Article 17. Adopted December 16, 1966; entered into force March 23, 1976. Available online.
  3. Westin, Alan F. Privacy and Freedom. Atheneum, 1967.
  4. Diffie, Whitfield, and Martin E. Hellman. “New Directions in Cryptography.” IEEE Transactions on Information Theory, Vol. 22, No. 6, 1976, pp. 644–654. DOI: 10.1109/TIT.1976.1055638.
  5. Organisation for Economic Co-operation and Development. Guidelines on the Protection of Privacy and Transborder Flows of Personal Data. 1980. Available online.
  6. Chaum, David. “Security Without Identification: Transaction Systems to Make Big Brother Obsolete.” Communications of the ACM, Vol. 28, No. 10, 1985, pp. 1030–1044. Available online.
  7. Stallman, Richard. The GNU Manifesto. 1985. Available online.
  8. May, Timothy C. The Crypto Anarchist Manifesto. Written in 1988 and circulated electronically to the Cypherpunks mailing list in 1992. Available online.
  9. Hughes, Eric. A Cypherpunk’s Manifesto. March 9, 1993. Available online.
  10. Lessig, Lawrence. Code and Other Laws of Cyberspace. Basic Books, 1999. Publication information.
  11. Nakamoto, Satoshi. “Bitcoin: A Peer-to-Peer Electronic Cash System.” 2008. Available online.
  12. Cavoukian, Ann. Privacy by Design: The 7 Foundational Principles. Information and Privacy Commissioner of Ontario, 2009. Available online.
  13. Nissenbaum, Helen. Privacy in Context: Technology, Policy, and the Integrity of Social Life. Stanford University Press, 2010. Publication information.
  14. Federal Trade Commission. Protecting Consumer Privacy in an Era of Rapid Change: Recommendations for Businesses and Policymakers. March 2012. Available online.
  15. La Rue, Frank. “Report of the Special Rapporteur on the Promotion and Protection of the Right to Freedom of Opinion and Expression.” United Nations Human Rights Council, A/HRC/23/40, April 17, 2013. Available online.
  16. de Montjoye, Yves-Alexandre, César A. Hidalgo, Michel Verleysen and Vincent D. Blondel. “Unique in the Crowd: The Privacy Bounds of Human Mobility.” Scientific Reports, Vol. 3, Article 1376, March 25, 2013. DOI: 10.1038/srep01376.
  17. Sim, Herbert R. “Cypherpunkism: A Philosophy of Digital Sovereignty.” October 10, 2010. Available online.
  18. Sim, Herbert R. “The Cypherpunkist Manifesto.” November 22, 2010. Available online.
  19. Sim, Herbert R. “The Eight Principles of Cypherpunkism.” October 10, 2011. Available online.
  20. Sim, Herbert R. “What Makes Cypherpunkism a Philosophy?” December 5, 2011. Available online.
  21. Sim, Herbert R. “Cypherpunk, Crypto-Anarchism and Cypherpunkism: The Essential Differences.” September 15, 2012. Available online.
  22. Sim, Herbert R. “Privacy Is Sovereignty.” March 9, 2013. Available online.
  23. Sim, Herbert R. “Cryptography Is Applied Freedom.” June 17, 2013. Available online.
  24. Sim, Herbert R. “Metadata Is Power.” July 25, 2013. Available online.