
My illustration entitled: “The Three Gates of Authority” – I stand before three gateways representing different approaches to governance: no authority, legitimate limited authority, and coercive total control. I chose the transparent central gate, where authority is constrained by due process, proportionality and public accountability.
A philosophy of freedom must be capable of explaining the limits of freedom.
Cypherpunkism defends privacy, cryptography, decentralization, individual control, open knowledge, open architecture, freedom to build and Digital Sovereignty. These principles are necessary because digital civilization has given governments, corporations and technological platforms unprecedented capacities to observe, classify, influence and exclude individuals.
Yet no serious philosophy can stop at the declaration that individuals should be free. People live among other people. Technologies created to protect one person can be used to harm another. Privacy can shelter the innocent, but it can also conceal abuse. Anonymity can protect dissidents, but it can also protect fraudsters. Decentralized systems can resist censorship, but they can also leave victims without anyone capable of correcting an injustice.
Recognizing these tensions does not refute Cypherpunkism. It completes it.
The purpose of Cypherpunkism is not to eliminate every form of authority. It is to prevent authority from becoming arbitrary, unlimited or technologically irreversible. The individual should remain sovereign, but sovereignty does not include a right to destroy the equal sovereignty of others.
Freedom Is Presumptive, Not Absolute
Cypherpunkism begins with a presumption in favor of individual freedom. People should generally be free to communicate privately, use encryption, publish software, control their identities, hold their own cryptographic keys and participate in decentralized networks without seeking prior permission.
This presumption matters because institutions possess structural advantages over individuals. Governments can compel. Corporations can exclude. Platforms can change rules across entire populations. Databases can preserve information long after the purpose for collecting it has expired. A system that requires individuals to justify every private action reverses the proper relationship between person and institution.
Nevertheless, a presumption is not an absolute. Freedom may be limited when its exercise creates a sufficiently serious and demonstrable violation of another person’s rights.
John Stuart Mill’s harm principle, developed in On Liberty, argued that coercive power over an individual is justified principally to prevent harm to others. Cypherpunkism inherits part of this liberal intuition but must adapt it to technological systems in which harm can be distributed, automated, concealed or amplified across networks.
Digital harm is not limited to physical injury. It can include theft, fraud, coercion, unauthorized access, malicious impersonation, non-consensual exposure of intimate information, destruction of another person’s digital property or the use of automated systems to deny fundamental rights without recourse.
At the same time, disagreement, offense, unconventional belief and resistance to authority are not automatically harms. If discomfort alone were sufficient to justify technological control, almost any dissent could be classified as dangerous.
The burden must therefore remain upon the authority proposing a restriction. It must identify the harm, establish a credible connection between the conduct and that harm, and demonstrate why less intrusive measures would be inadequate.
The Limiting Principle of Cypherpunkism
Digital freedom should be presumed. A restriction becomes legitimate only when it is directed toward preventing demonstrable harm or protecting the equal sovereignty of others, and when the restriction is necessary, limited, transparent, proportionate, contestable and subject to meaningful review or exit.
Each condition is essential.
- Necessary: The restriction must address a real problem that cannot reasonably be managed through a less intrusive method.
- Limited: The authority must be confined by purpose, scope, duration and the categories of people or information it may affect.
- Transparent: The existence, legal basis and general operation of the authority must be publicly intelligible.
- Proportionate: The intrusion imposed must not exceed the seriousness and probability of the harm being prevented.
- Contestable: Affected people must possess a practical means of challenging errors, abuse or unlawful decisions.
- Reviewable: Independent institutions must be able to examine the use of power and impose consequences when it is misused.
- Subject to review or exit: No digital authority should become permanent merely because it has been embedded in infrastructure.
These conditions distinguish legitimate authority from domination. They also distinguish Cypherpunkism from digital absolutism.
Privacy and Investigation
Privacy is a condition of autonomy. It enables people to think, communicate, associate and develop their identities without constant observation. Article 12 of the Universal Declaration of Human Rights protects individuals against arbitrary interference with privacy, family, home and correspondence.
The word “arbitrary” is important. It recognizes that privacy is fundamental while leaving room for carefully justified interference under lawful conditions. A society may investigate violence, fraud, exploitation and other serious violations of rights. The existence of legitimate investigation, however, does not justify treating every person as a permanent suspect.
Mass surveillance reverses the presumption of freedom. It collects information about entire populations in the hope that some portion may later become useful. Instead of directing investigative power toward identified conduct, it turns ordinary life into a continuously searchable archive.
Cypherpunkism rejects this model. Investigation should be targeted, based upon evidence, authorized through procedures independent of the investigator and restricted to information relevant to the alleged harm. Access should expire. Its use should be recorded. Improper surveillance should create a right to remedy.
The existence of crime does not grant the state ownership of everyone’s communications. Nor does the existence of governmental abuse make every investigation illegitimate. The correct distinction is not between privacy and security. It is between accountable investigation and indiscriminate access.
Encryption and Lawful Authority
Strong encryption creates a difficult limit for authority: information may exist, and an investigator may possess a legitimate reason to seek it, while the technological system remains incapable of producing readable content without the user’s key.
Governments sometimes respond by proposing exceptional-access mechanisms, key escrow or other methods through which encrypted information could be recovered. The difficulty is architectural. A mechanism capable of bypassing encryption for a legitimate authority is also a mechanism that can be discovered, stolen, expanded or abused.
A universal backdoor does not remain morally confined to legitimate cases. It becomes a structural weakness affecting journalists, businesses, public officials, activists, families and critical infrastructure. The intended investigator is not the only party capable of exploiting it.
Cypherpunkism therefore rejects the deliberate weakening of general-purpose encryption. This does not place individuals beyond law. Authorities may use targeted investigation, conventional evidence, financial records, witness testimony, endpoint forensics and other lawful methods subject to due process. What they should not possess is a permanent master capability over the private communications of an entire population.
Cryptography limits the methods available to authority. That limitation is not necessarily a failure of justice. Constitutional rights and due-process protections also limit investigative power because unlimited efficiency would be incompatible with a free society.
Anonymity and Accountability
Anonymity protects people who cannot speak safely under their legal identities. A dissident living under an authoritarian government, a whistleblower exposing corruption, a victim seeking assistance and a person exploring a stigmatized idea may all require separation between speech and civil identity.
Anonymous and pseudonymous participation also allows ideas to be judged without automatically importing the speaker’s wealth, nationality, race, social status or institutional position.
Yet anonymity can reduce the personal cost of harassment, fraud and coordinated abuse. Someone may create repeated identities, cause harm and disappear before victims can obtain redress.
The solution cannot be mandatory universal identification. Requiring every person to disclose a government identity before speaking, reading or participating would create an infrastructure of permanent traceability. It would eliminate legitimate anonymity in order to make some forms of misconduct easier to investigate.
Accountability should instead be connected to conduct and context. Reading public information requires less identification than assuming control of another person’s assets. A private conversation requires less verification than signing a high-value commercial agreement. The greater the potential harm created by an action, the stronger the legitimate demand for evidence of authority, responsibility or available remedy.
Pseudonymous reputation, deposits, multisignature authorization, selective disclosure, rate limits and verifiable credentials can create accountability without exposing a complete civil identity in every interaction. As argued in Self-Sovereign Identity: Proving Without Revealing, a person should be able to prove what is necessary without surrendering everything else.
The principle is proportional identity: reveal no more identity than the interaction genuinely requires.
Decentralization and Consumer Protection
Decentralization can resist censorship, distribute operational risk and reduce dependence upon a single institution. It can create systems that continue functioning even when one operator fails or attempts to exercise arbitrary control.
But eliminating a central administrator may also eliminate the party whom a user can contact when something goes wrong.
A decentralized financial protocol may continue operating exactly as written after a user makes a catastrophic mistake. A self-custodied key can protect property from institutional seizure while leaving no recovery mechanism if the key is lost. A decentralized marketplace may resist political censorship while providing little protection against fraudulent sellers.
These risks do not prove that centralized control is preferable. They demonstrate that decentralization must be accompanied by institutions and tools appropriate to human vulnerability.
Voluntary multisignature arrangements, social recovery, time-delayed transactions, spending limits, independent audits, insurance and user-selected guardians can provide protection without granting one institution unconditional control. Different users should be able to select different balances between independence and assistance.
As explained in Decentralization Is a Check on Power, decentralization is not a command that every function must be distributed. It is a method for preventing unnecessary concentrations of authority.
A centralized service may be legitimate when users choose it knowingly, its powers are limited, its obligations are enforceable and meaningful alternatives remain available. The danger begins when convenience becomes dependency and dependency becomes unaccountable government by infrastructure.
Immutability and the Right to Correction
Immutable records can protect history against censorship and manipulation. When no single authority can secretly rewrite a ledger, participants gain confidence that established rules and transactions will not be altered for political or commercial convenience.
Immutability can also conflict with the ability to correct false, unlawful or dangerously exposed information. Personal information may be entered without consent. A record may falsely accuse someone. A private key or confidential document may be published maliciously. Information concerning a child may remain accessible long after its original context has disappeared.
A philosophy of digital sovereignty cannot defend one individual’s power to publish while ignoring another individual’s interest in privacy, correction and remedy.
The answer is not to give a central administrator secret power to rewrite every ledger. Systems should instead minimize the personal information placed permanently on-chain. Sensitive material can remain off-chain while the ledger stores proofs, commitments or references. Corrections can be appended transparently rather than silently replacing history. Access-controlled layers may be used when permanent public disclosure is unnecessary.
Immutability should protect integrity, not transform every mistake into an eternal sentence.
Censorship Resistance and Moderation
Censorship-resistant systems protect unpopular speech from institutions capable of silencing it. This is especially important when political authorities control communications infrastructure or when private platforms dominate access to public discussion.
But no person possesses a right to force every community, publisher or private service to distribute every message. Freedom of expression includes the freedom to establish communities with defined purposes and rules.
The Cypherpunkist concern is not that moderation exists. It is whether moderation becomes invisible, arbitrary and unavoidable.
Legitimate moderation should be governed by intelligible rules, applied consistently and accompanied by notice and appeal where consequences are significant. Users should be able to leave, preserve their lawful content, move their relationships and participate through alternative services or protocols.
At the protocol level, censorship resistance may remain strong while applications and communities construct different filters above it. This layered model permits collective self-government without granting one platform authority over the entire network.
A free network need not be a network without boundaries. It should be a network in which no single boundary becomes compulsory for everyone.
Open Knowledge and Dangerous Capabilities
Open knowledge distributes power. Public research allows independent verification, education and innovation. Open-source code allows people to inspect the technologies upon which they depend rather than trusting assurances from institutions.
Yet information can sometimes provide an immediate operational capability to cause serious harm. Publishing a defensive discovery is different from releasing active credentials, intimate personal records or instructions tailored to exploit systems before their users can protect themselves.
Cypherpunkism should not interpret open knowledge as an obligation to publish every detail immediately and without context. Responsible disclosure can temporarily limit access to a vulnerability while affected systems are repaired. Personal data can remain private even when the methods used to protect it are open. Dangerous operational details may require staged publication without converting broad scientific knowledge into permanent institutional secrecy.
The presumption should remain in favor of openness because secrecy can conceal incompetence, abuse and monopoly. Any restriction must be specific, temporary and justified by a credible risk of harm. “Security” must not become a word used to prevent scrutiny indefinitely.
Open knowledge is a means of distributing human capability. It must be practiced with responsibility toward the people that capability can affect.
Self-Custody and Human Vulnerability
Cypherpunkism values self-custody because possession of one’s own cryptographic keys can convert ownership from an institutional promise into a directly exercisable power.
But individuals differ in technical ability, health, age and personal circumstances. Some people will prefer direct custody. Others may need assistance. Children and adults with impaired decision-making capacity may require guardians or fiduciaries. A philosophy of individual sovereignty must take these realities seriously.
Assistance becomes legitimate when it serves the individual rather than appropriating the individual’s authority. A guardian’s power should be limited to the person’s interests, monitored for abuse, regularly reviewed and reduced when the person becomes capable of exercising greater control.
The objective is not to force every person into identical technical independence. It is to prevent vulnerability from becoming a justification for permanent domination.
Emergency Powers and the Ratchet of Control
Emergencies may justify temporary measures that would be excessive under normal conditions. A serious cyberattack, immediate threat to life or failure of essential infrastructure may require rapid coordination and restricted access.
The danger is that emergency authority rarely disappears by itself. Databases remain. Surveillance capabilities acquire new purposes. Temporary identity requirements become ordinary conditions of participation. Institutions learn to describe recurring problems as permanent emergencies.
Emergency powers must therefore contain expiration dates, defined purposes, independent oversight and procedures for deleting information collected under exceptional conditions. Renewal should require new evidence rather than occur automatically.
A crisis may alter what is proportionate. It should not abolish the requirement of proportionality.
Rights Require Responsibilities
The rights and responsibilities of the Cypherpunkist are inseparable. The right to privacy entails a responsibility to respect the privacy of others. The right to hold one’s keys entails a responsibility to secure them. The freedom to publish code entails a responsibility to consider foreseeable harm. The right to resist arbitrary authority does not provide permission to become an arbitrary authority over someone else.
A person should not demand privacy while exposing another person’s intimate information. A developer should not describe a system as decentralized while secretly retaining administrative control. A platform should not promise self-custody while possessing the power to confiscate users’ assets. A government should not invoke public safety while concealing the scope of its surveillance.
Responsibility is not obedience to power. It is recognition that individual freedom exists within a community of equally sovereign people.

My illustration “The Three Gates of Authority” work-in-progress. The art represents that Cypherpunkism need not reject all authority—it distinguishes legitimate, limited governance from both lawless disorder and oppressive control.
A Doctrine of Legitimate Digital Authority
Authority is legitimate when it protects the conditions under which freedom can be exercised by everyone. It becomes illegitimate when it treats its own convenience, permanence or expansion as an end in itself.
Legitimate digital authority possesses several defining characteristics:
- Its purpose is publicly defined.
- Its powers are no broader than that purpose requires.
- Its decisions can be explained and challenged.
- Its surveillance is targeted rather than indiscriminate.
- Its rules apply consistently, including to those exercising authority.
- Its errors can be corrected.
- Its abuses produce meaningful consequences.
- Its exceptional powers expire.
- Its users retain portability or a meaningful right to exit.
- Its architecture does not make temporary authority technologically permanent.
These conditions apply to governments, corporations, platforms, decentralized organizations and protocol communities. Decentralized authority can become abusive. Private authority can become coercive. Democratic authority can exceed its lawful purpose. No institutional label guarantees legitimacy.
The correct question remains the one posed by The Cypherpunkist Test: who does the technology empower?
Ten Questions at the Boundary of Freedom
When a digital freedom conflicts with a claim of harm, the following questions should guide judgment:
- What specific harm is alleged?
- Whose rights are directly affected?
- Is the harm demonstrated, probable or merely speculative?
- Is the conduct itself harmful, or is it only unpopular or offensive?
- What is the least intrusive effective response?
- Will the proposed response affect innocent people who are not involved?
- Who authorizes, operates and reviews the restriction?
- Can the affected person challenge the decision and obtain a remedy?
- Will the authority expire when the stated danger ends?
- Does the solution protect equal sovereignty, or create a larger and more permanent concentration of power?
These questions cannot eliminate every disagreement. They can prevent vague claims of safety from automatically defeating freedom and prevent vague claims of liberty from automatically excusing harm.
The Limit of Every Principle Is Equal Sovereignty
The principles of Cypherpunkism constrain one another.
Privacy protects the individual, but it does not authorize the violation of another person’s privacy. Open knowledge distributes power, but it does not convert another person’s intimate data into public property. Decentralization restrains concentrated authority, but it does not eliminate the need for responsibility. Individual control protects autonomy, but it does not include control over other individuals without their consent.
Digital Sovereignty is therefore not technological isolation or personal omnipotence. It is meaningful authority over one’s own identity, information, communications, digital possessions and participation in technological systems, exercised within a world of other sovereign persons.
The boundary of my sovereignty is not the convenience of the state, the business model of a corporation or the preference of a majority. Its principled boundary is the equal sovereignty of another human being.
Conclusion: Freedom Without Impunity, Authority Without Domination
Cypherpunkism rejects the false choice between unrestricted technological freedom and total institutional control.
Freedom without responsibility can become impunity. Authority without limits can become domination. Privacy without respect for others can become concealment of abuse. Accountability without privacy can become universal surveillance.
A mature philosophy must preserve both sides of this tension. Individuals require technological power sufficient to resist arbitrary institutions. Society requires legitimate means of preventing demonstrable harm and protecting the equal rights of others. Neither objective should be allowed to consume the other.
Cypherpunkism therefore defends a presumption of digital freedom while recognizing narrowly bounded, proportionate and contestable authority. It opposes universal backdoors without opposing due process. It protects anonymity without denying responsibility. It values decentralization without pretending that vulnerable users never need assistance. It supports open knowledge without abandoning ethical judgment.
The purpose is not a world without authority. It is a world in which authority must continuously justify itself—and in which no government, corporation, platform, protocol or individual possesses an unrestricted right to rule the digital lives of others.
Privacy is sovereignty. Cryptography is applied freedom. Decentralization is a check on power. Code is political architecture. Responsibility protects equal sovereignty. Legitimate authority must remain limited. Digital sovereignty belongs to the individual.
References
- Herbert R. Sim, Cypherpunkism.
- Herbert R. Sim, Cypherpunkism: A Philosophy of Digital Sovereignty.
- Herbert R. Sim, The Eight Principles of Cypherpunkism.
- Herbert R. Sim, The Rights and Responsibilities of the Cypherpunkist.
- Herbert R. Sim, Against Digital Absolutism: Why Cypherpunkism Is Not Anti-State or Anti-Corporation.
- Herbert R. Sim, The Cypherpunkist Test: Who Does the Technology Empower?.
- Herbert R. Sim, Decentralization Is a Check on Power.
- Herbert R. Sim, The Right to Exit in Digital Civilization.
- John Stuart Mill, On Liberty, 1859.
- United Nations, Universal Declaration of Human Rights, 1948.
- United Nations, International Covenant on Civil and Political Rights, 1966.
- United Nations Human Rights Committee, General Comment No. 16: The Right to Privacy, 1988.
- Electronic Frontier Foundation and partner organizations, International Principles on the Application of Human Rights to Communications Surveillance, 2014.