Notes on Internet Privacy

Posts and research from the URnetwork team and community.

RSS

Five Deadlines. Eight Days. One Internet That Will Not Be the Same.

Tomorrow, Russia orders its largest companies to block customers who use a VPN. On Monday, FISA Section 702 sunsets in Washington — though the surveillance it authorizes will not actually pause. On Wednesday of next week, China Telecom SIM cards stop supporting international roaming. This month, the United Kingdom's Ofcom publishes final guidance on "technology notices" that will compel platforms to scan encrypted content. And twenty days from today, the European Union reopens trilogue negotiations on the regulation that replaces Chat Control. Five mechanisms, three continents, eight days. The architecture they target is the same.

The line tomorrow

On the evening of March 30, 2026, Maksut Shadaev — head of Russia's Ministry of Digital Development — convened a private meeting with representatives from more than twenty of the country's largest internet companies. Sberbank was there. So were Yandex, VK, Wildberries, Ozon, Avito, X5 Group, Gazprom-Media, and Mail.ru. The ministry's message was explicit. By April 15, the participating companies were to implement technical measures that blocked users connecting through virtual private networks. The ministry would provide the list of VPN IP ranges. The companies would do the blocking at the service layer.

Failure to comply had two specific consequences. The first was removal from the "white list" — the registry of services that remain accessible during mobile internet restrictions. The second was the withdrawal of IT tax benefits, a set of preferential rates that make domestic technology operations commercially viable in Russia. For each of the twenty-plus companies present, the cost of non-compliance was not a fine. It was the end of the business model.

Tomorrow is April 15. The line is now hours away.

The scale of what crosses that line is easy to undercount. Pavel Durov, the founder of Telegram, confirmed on April 4 that sixty-five million Russians were using his platform every day through VPN tunnels — more than fifty million of them sending messages every day. This is not a niche population of activists and journalists. It is the daily communications substrate of roughly half of Russian internet users, routed around the Kremlin's filtering apparatus through a payment relationship with a commercial VPN provider that the state now intends to cut.

The Kremlin is not unaware of the scale. On February 19, Dmitry Peskov, the press secretary to President Vladimir Putin, was asked in a public briefing whether the presidential press service used a VPN to access Telegram. Peskov confirmed that it did.

This is the baseline fact that every story this week rests on. The officials who built the enforcement architecture do not use it against themselves.


Five deadlines

The Russian deadline arrives first, but it does not arrive alone. Four others follow within the same eight-day window.

On Monday, April 20, at midnight, Section 702 of the Foreign Intelligence Surveillance Act sunsets in the United States. Congress returned from recess today, and House leadership has signaled a vote this week. The Trump administration — through White House adviser Stephen Miller and CIA Director John Ratcliffe — is pushing for an 18-month clean reauthorization, invoking the ongoing US-Iran war as justification. The Congressional Progressive Caucus, ninety-eight House Democrats, has formally opposed any reauthorization without substantial reform. The Congressional Black Caucus has endorsed the clean extension.

On Wednesday, April 22, a leaked text message from China Telecom informs subscribers that their SIM cards will no longer support international roaming services — calls, messaging, or mobile data. The only way to restore those functions will be to replace the SIM card. Two weeks earlier, on April 8, a separate leaked notice from Shaanxi Telecom ordered internet service providers under its jurisdiction to halt all outbound connections to any external network, citing the elimination of "any form of circumvention business." The Ministry of Industry and Information Technology held a meeting on "strengthening management of unauthorized internet connections via dedicated cross-border data lines."

This month, the United Kingdom's Ofcom is due to publish final guidance on the Online Safety Act's "technology notices" regime — the legal mechanism that allows the regulator to compel online services to deploy specific technologies to detect child sexual abuse and terrorism content. The notices apply to encrypted services. The word "backdoor" appears nowhere in the Act. The operative word is "inspection."

On Monday, May 4 — twenty days from now — the European Union resumes trilogue negotiations on the Child Sexual Abuse Regulation, the permanent replacement for Chat Control 1.0, which expired on April 3 after an eighty-three-vote defeat in the European Parliament on March 26. The Danish Council presidency is driving a negotiating mandate that introduces mandatory age verification across in-scope services. The fourth trilogue round is scheduled for May 11.

Five deadlines. Three continents. Eight days.

The coincidence is not a coincidence. The five mechanisms are not the same. But they converge on the same architectural target.


What the mechanisms share

Each of the five deadlines applies pressure at a different point in the communications stack. It is useful to lay them out side by side:

  • Russia, April 15: compelled compliance at the service provider layer. Twenty-plus companies block customers with active VPN sessions or lose their regulatory standing.
  • United States, April 20: compelled acquisition at the carrier and platform layer, authorized by a statute that sunsets on paper but whose FISC certification for 2025-2026 persists through the spring regardless of what Congress does.
  • China, April 22: compelled severance at the physical network layer. Telecom carriers withdraw the international connectivity that sat under the content-level firewall.
  • United Kingdom, April: compelled detection at the application layer. Technology notices require encrypted services to deploy content-detection systems or face enforcement action.
  • European Union, May 4: compelled identity at the access layer. Age verification regimes require users to attest identity before accessing in-scope platforms.

The points of compulsion differ. The point of leverage does not.

Every one of these five mechanisms works because there is a provider to compel. Russia compels Sberbank. The US compels AT&T, Verizon, and T-Mobile through Section 702 certifications. China compels China Telecom, China Mobile, and China Unicom. The UK compels Apple, WhatsApp, and Meta. The EU compels the in-scope services enumerated in the CSA Regulation. The architecture that has a provider has a lever. The provider has a legal presence in the jurisdiction, a revenue stream contingent on regulatory goodwill, and a compliance team whose job is to translate government demands into technical implementations. None of these enforcement actions would be possible without centralized, corporate, identifiable intermediaries who can be served with legal process and pressured with commercial consequences.

This is the structural observation that links the five deadlines. It is also the observation that makes the solution visible.


Russia's ratchet

The April 15 deadline is the leading edge of a two-month escalation that has already reshaped the technical environment for ordinary Russian internet users.

On April 1, Apple's mobile-phone-bill payment route for Apple ID top-ups was terminated for Russian accounts. This closed one of the last remaining paths by which Russian users could pay for international digital subscriptions — including commercial VPN services — after Western card networks withdrew in 2022. On the same day, Russian mobile operators began enforcing a fifteen-gigabyte monthly cap on international traffic. The cap does not explicitly target VPN use. It does not need to. Tunneled traffic to endpoints outside Russia is, by definition, international.

On April 3, major Russian banks experienced a widespread outage. The Moscow Times reported losses of approximately $12.5 million per day in Moscow alone. Telegram founder Pavel Durov attributed the crash to the interaction between the new deep-packet-inspection enforcement and legitimate banking traffic. The government's DPI layer could not reliably distinguish a banking session from a VPN tunnel, so it broke both.

On April 10, Roskomnadzor — Russia's media and communications regulator — banned GlobalCheck, the most widely used service for tracking which VPN providers still functioned in Russia. The ban is meta-censorship: the suppression of information about the censorship itself.

Running alongside the VPN enforcement is the state's affirmative push for Max — the Russian-developed messenger positioned as the domestic replacement for foreign platforms. A presidential decree signed by Putin in June 2025 made Max the national messenger. A State Duma law passed in December 2025 requires apartment building managers outside Moscow to communicate with residents through Max. The Ministry of Digital Development has discussed migrating bank SMS notifications to Max in pilot programs at Sberbank and VTB. Schools are being encouraged to adopt Max for parent-teacher communication. The Japan Times called Max "the unencrypted super-app being forced on citizens."

The architecture is bidirectional. VPN enforcement raises the cost of non-compliant communication. Max adoption lowers the cost of compliant communication. A household that migrates its apartment-committee chat, its banking alerts, and its school communications to Max has materially less daily need for international routing, materially less exposure to the VPN friction regime, and materially less reason to maintain the Telegram channel that was becoming more expensive to reach anyway. The friction ratchet does not need to catch every user. It needs to catch the marginal user every month.

Wildberries, Ozon, and VkusVill — three of Russia's largest domestic retail platforms — began implementing VPN blocks on their customer-facing services during the first week of April, ahead of the formal deadline. The commercial calculation behind the early compliance is straightforward. The white-list designation is not optional. The tax benefits are not optional. The choice is between losing the fraction of customers who use a VPN and losing the regulatory environment that makes the business viable at all.

This is what the enforcement architecture looks like from the provider's side. The Kremlin does not need to identify every VPN user. It needs to identify VPN traffic fingerprints and delegate the blocking to twenty companies that cannot afford to refuse.


The American theater

In Washington, the fight is framed differently. The surveillance at issue is not platform-layer blocking of VPN users. It is the compelled acquisition of communications content from US telecommunications providers under Section 702 of the Foreign Intelligence Surveillance Act.

Section 702 permits the National Security Agency, with compelled assistance from US providers, to acquire the content of communications from non-US persons reasonably believed to be located outside the United States. The law has been reauthorized in 2012, 2017, 2018, and — most recently — in April 2024, when Congress passed the Reforming Intelligence and Securing America Act. The April 20, 2026 sunset is the next cliff.

On March 23, a bipartisan group introduced the Government Surveillance Reform Act of 2026 (S.4082). Its Senate sponsors are Ron Wyden (D-OR) and Mike Lee (R-UT), with cosponsors including Cynthia Lummis (R-WY) and Elizabeth Warren (D-MA). The House companion is led by Zoe Lofgren (D-CA) and Warren Davidson (R-OH). The bill would require warrants for FBI searches of Section 702 data on US persons, close the data broker loophole through which federal agencies purchase commercial location and communications metadata, and add transparency to the secret FISA Court.

Ninety-eight House Democrats — the full Congressional Progressive Caucus — have formally opposed any clean reauthorization of 702 without these reforms. The Congressional Black Caucus has publicly supported the clean 18-month extension. The Trump administration, through Stephen Miller and CIA Director John Ratcliffe, is invoking the ongoing US-Iran war to argue that any lapse in authority would produce intelligence blind spots.

The coverage this week will treat the vote as the pivot. That framing is almost entirely wrong.

The real mechanism that determines whether 702 surveillance continues is not the statutory sunset. It is the annual certification issued by the Foreign Intelligence Surveillance Court — a classified order that specifies the categories of foreign intelligence that may be acquired under the program. The FISC's 2025 certification, issued in the spring of 2025, runs through the spring of 2026. It authorizes ongoing acquisition from communications already flowing through the compelled-assistance infrastructure at US providers. The Department of Justice has taken the position, in prior sunset standoffs, that existing acquisitions under a valid certification continue through the period of the certification even if the underlying statutory authority has lapsed.

The practical consequence is that if Section 702 "expires" at midnight on April 20 and no bill is passed, the NSA does not turn off the collection. The FISC certification does not terminate. The existing targeting decisions remain in force. The FBI does not lose the ability to query the 702 corpus — the ability that produced 7,413 warrantless queries of Americans' data in the most recent ODNI transparency report. The compelled assistance at AT&T, Verizon, T-Mobile, Google, Microsoft, Meta, and the other designated providers continues.

What would change is narrow. New targeting decisions outside the scope of the 2025 certification would face legal uncertainty. Provider counsel would have to evaluate each new directive against the possibility that the authority had lapsed. Congress would face pressure — real, but not operational — to act before the FISC's 2026 certification is due.

This is not a reason to treat the vote as unimportant. Reforms matter. The data broker loophole is real. Warrant requirements for US-person queries matter. But the vote is not the cliff. The cliff is the architecture: a compelled-assistance regime that operates under a classified court order, at providers whose commercial viability depends on maintaining the regulatory relationship that the compulsion is part of.

The debate is performative because the infrastructure is not debatable. The surveillance does not pause for the vote.


China's cut

If Russia's approach is to dismantle through the commercial compliance mechanism and America's is to operate through compelled assistance at the carrier layer, China's April 22 action is the endgame.

The progression has been visible for a decade. In the 2000s, Chinese internet policy focused on content filtering — blocking specific URLs, sensitive keywords, and platform categories at the Great Firewall. In the 2010s, the focus shifted to deep packet inspection — classifying traffic by type and blocking traffic patterns consistent with VPN or proxy use. In the early 2020s, Chinese policy added throttling — degrading the performance of circumvention tools to the point of practical unusability without formally blocking them. In 2026, the policy shifts again.

The April 22 action removes international roaming from China Telecom SIM cards. The April 8 Shaanxi Telecom notice orders carriers to halt outbound connections entirely. The Ministry of Industry and Information Technology meeting on "unauthorized internet connections via dedicated cross-border data lines" signals that the enforcement extends beyond individual users to the private dedicated lines that foreign companies use to connect Chinese offices to international headquarters.

This is not filtering. It is not throttling. It is severance.

For foreign companies operating in China — automakers, consulting firms, technology providers, financial services — the dedicated cross-border lines are the operational backbone. The internal email system, the ERP integration, the customer support routing, the video conferencing to headquarters: all of it rides on these dedicated circuits. Hong Kong, which has served as the operational gateway for decades, is being explicitly named in the severance orders. Macau is too. Taiwan, predictably, is at the top of the list.

What China is doing is moving from censorship-of-content to censorship-of-connectivity. The firewall is no longer the policy instrument. The physical cable is.

The escalation tells Beijing's domestic audience that the cost of foreign internet access is rising. It tells the foreign business community that the comfort of operating through the gateway is ending. And it tells every other jurisdiction with a state-level appetite for information control that the extreme end of the curve is technically achievable. China is not running a thought experiment. It is running a pilot.


Britain's inspection

The United Kingdom's mechanism is the subtlest of the five. In a sequence of policy documents that accelerated through 2024 and 2025, the British government has shifted the debate over encrypted communications from "backdoor" to "inspection."

The word "backdoor" lost the political argument. It carries connotations of covert access, unpatchable vulnerabilities, and cryptographer consensus against. The argument ran aground on the Swedish Armed Forces statement that a backdoor "cannot be fulfilled without introducing vulnerabilities and backdoors that could be exploited by third parties."

"Inspection" is different. Under the Online Safety Act, Ofcom has the authority to issue "technology notices" to in-scope services — notices that compel the deployment of "accredited technology" to detect child sexual abuse material or terrorism content. The technologies are specified in separate guidance. The compliance requirement is absolute. The phrase "end-to-end encryption" does not appear in the Act.

This month, Ofcom is due to publish final guidance on the technology notices regime. Once the guidance is in force, the regulator has the mechanism to compel any in-scope service — including encrypted messengers — to deploy client-side scanning systems that perform detection before a message is encrypted. The argument that this does not "break encryption" is technically accurate and substantively misleading. The message is scanned before it is encrypted, so the transport-layer encryption remains mathematically sound. The message is also scanned.

The Apple precedent is visible in parallel. Last February, Apple withdrew Advanced Data Protection from UK users after the Home Office issued a secret Technical Capability Notice under the Investigatory Powers Act. In September 2025, the Home Office issued a second Technical Capability Notice, this time demanding backdoor access to encrypted iCloud backups specifically. Privacy International, Liberty, and two individual claimants filed a challenge at the Investigatory Powers Tribunal. The seven-day hearing has been scheduled for early 2026. The tribunal directed the UK government to agree on "assumed facts" with Apple that could be heard in open session, rather than entirely in secret.

The UK is not running the same playbook as China. It is running a different playbook toward a convergent outcome. The content-scanning regime does not require the state to pull the cable. It requires only that the legal framework produce enough compliance risk that platforms deploy the detection systems on their own.


Europe's age gate

Twenty days from now, the European Union's trilogue negotiations on Chat Control 2.0 — the Child Sexual Abuse Regulation — resume under the Danish Council presidency.

The political context is singular. On March 26, 2026, the European Parliament killed Chat Control 1.0 — the temporary ePrivacy derogation that had given Google, Meta, Microsoft, and TikTok a legal basis to voluntarily scan private messages for child sexual abuse material — by a margin of eighty-three votes. The tally was 311 against extension, 228 in favor, 92 abstentions. Members of the European People's Party had attempted to force a re-vote and route the decision through fisheries ministers. Patrick Breyer, the German Pirate Party MEP who led the opposition for four years, called the result "a historic day that brings tears of joy."

Chat Control 2.0 is the permanent replacement. The 1.0 fight centered on whether private messages could be scanned without user consent. The 2.0 fight has shifted. The Council position — which has the backing of the Danish presidency — still includes mass scanning, but the new battleground is mandatory age verification across in-scope services.

Tuta, the German encrypted email provider, summarized the shift in a public analysis last month: Chat Control 2.0 no longer forces platforms to break end-to-end encryption, but it does require age verification that would effectively end anonymous online communication in Europe. If implemented as proposed, any in-scope service — including messengers, social platforms, and content services — would be required to verify the age of every user before permitting access to functionality used by minors. In practice, age verification at scale requires identity verification. Identity verification requires a state or bank-linked attestation. The attestation is logged.

This is how anonymity dies in Europe. Not by banning it. By requiring the opposite every time a user opens an app.

The May 4 trilogue is the political deal-making round. May 11 is the fourth technical trilogue. June 29 is the final political round. The target for a deal is July.


The pattern

Set the five mechanisms against each other and the common architecture becomes visible.

Russia's platform-layer VPN block depends on twenty identifiable commercial providers with tax-benefit incentives to comply. China's physical severance depends on three state-controlled carriers whose dedicated cross-border lines are the operational backbone for foreign business operations. America's Section 702 compulsion depends on a handful of US telecommunications and internet companies whose commercial viability requires a regulatory relationship with the federal government. Britain's inspection regime depends on platforms whose legal presence in the UK produces compliance risk sufficient to deploy client-side scanning. Europe's age verification depends on platforms that depend on EU market access.

In every case, the mechanism works because the communications architecture has a centralized intermediary that can be compelled. Remove the intermediary, and the mechanism has nothing to compel. Remove the compliance relationship, and the enforcement has no instrument. Remove the commercial incentive that keeps the intermediary at the table, and the lever loses its grip.

The defense that is sufficient against one of these mechanisms is not sufficient against the others. End-to-end encryption protects against content inspection at the server layer. It does not protect against client-side scanning. It does not protect against age-verification regimes. It does not protect against VPN blocking at the platform layer. It does not protect against physical severance of the international line. Each of the five mechanisms has been chosen by its state, in part, because it does not depend on breaking encryption — it depends on compelling the provider that encryption runs on top of.

The common defense is architectural. A communications system in which there is no provider to compel — no single company with a commercial relationship to the state, no single server to be served with a Technical Capability Notice, no single cable to be severed, no single platform to be ordered to verify ages — cannot be dismantled by the mechanisms being deployed this week. The compelled-assistance model assumes a party to compel. The architectural defense is to not be a party.

This is not a theoretical observation. Onion-routed traffic, peer-to-peer relays, mesh transport, and decentralized VPN protocols that do not converge on enumerable commercial endpoints are technically available today. They are not yet deployed at the scale necessary to absorb the displacement that will follow the April 15 Russian enforcement, the April 22 Chinese severance, or the eventual deployment of UK technology notices. Their absence, at the mass scale, is why the Kremlin can sever the daily communications of sixty-five million of its own citizens by sending a letter to twenty companies.


What the week ends with

The five deadlines will not all resolve by April 22.

The Russian enforcement will begin tomorrow, grind through the month, and produce a steady migration of persistent users toward obfuscated protocols, decentralized VPN alternatives, and peer-to-peer relays. Thirty-five million Russians will continue to circumvent. Thirty million more will comply. The ratchet will continue.

The FISA vote may or may not pass this week. If it does, the surveillance continues unchanged. If it does not, the FISC certification continues through spring, the existing acquisitions continue, and the political pressure on Congress builds into the summer. Either way, the structural question — whether Americans' communications can be acquired without a warrant through commercial data broker purchases, whether the FBI must obtain a warrant before querying the 702 corpus for a US person — remains unsettled.

The Chinese SIM severance will take effect on April 22 as announced unless the leaked notice is walked back. Foreign companies operating in China are already stockpiling alternative connectivity options. Hong Kong's role as the gateway is being reassessed. Taiwan is already separated.

The UK Ofcom guidance, when it arrives, will become the legal basis for technology notices that will be issued to platforms through 2026 and 2027. The first notices will not be publicly announced. They will appear as quietly as the Apple Technical Capability Notice did — a classified order with a non-disclosure obligation attached.

The Chat Control 2.0 negotiations may or may not produce a political deal in May or June. The age verification mandate remains the dominant concern of the civil society coalitions that killed 1.0. The 2026 European legislative year will be dominated by this fight.

These five stories converge this week. They do not resolve this week. What they resolve is the question of whether the architecture of the internet, as built, can be pulled apart by states that have the commercial and legal leverage to compel the intermediaries. The answer, for this week, in these five jurisdictions, is yes.

The next question is whether an architecture exists that cannot be pulled apart the same way. The answer, at scale, is: not yet. The work of building it — peer-to-peer, mesh-routed, decentralized, without a provider to compel or a cable to cut — is the work that has to happen before the next five deadlines arrive.

There will be more deadlines.


References (9 sources)

References

Sources: Meduza, "RBC: Russia asks major online platforms to block users with active VPNs by April 15" (April 2, 2026); Meduza, "Russia's internet regulator bans site that tracks which VPNs still work in the country" (April 10, 2026); Meduza, "Telegram founder says 65 million Russians use app daily via VPN despite blocking attempts" (April 4, 2026); Moscow Times, "As Kremlin Cuts Off the Internet, VPNs Become a Way of Life" (April 3, 2026); bne IntelliNews, "Russia orders major websites to block VPN traffic from April 15"; Kremlin press briefing, Dmitry Peskov (February 19, 2026); CNN Politics, "US intel officials scramble to keep surveillance law running amid Iran war tensions" (April 13, 2026); Washington Post, "Fate of powerful surveillance program unclear as renewal deadline looms" (April 11, 2026); Congress.gov, S.4082 Government Surveillance Reform Act of 2026; Wyden.senate.gov section-by-section summary of S.4082; Vision Times, "China's Telecom Crackdown May Block All Overseas Internet Access, Leaked Notice Suggests" (April 11, 2026); Ofcom, "Ofcom's approach to implementing the Online Safety Act" roadmap; Privacy International, "PI Apple TCN Challenge" (2025-2026); Apple Support, "Apple can no longer offer Advanced Data Protection in the United Kingdom to new users" (February 21, 2025); Computer Weekly, "Home Office issues new backdoor order over Apple encryption" (September 2025); Patrick Breyer, "End of Chat Control: EU Parliament Stops Mass Surveillance in Voting Thriller" (March 26, 2026); Electronic Frontier Foundation, "EU Parliament Blocks Mass-Scanning of Our Chats — What's Next" (April 2026); Tuta, "Huge Victory: Chat Control no longer forces us to break encryption! But: It now wants age verification" (March 2026); Access Now and KeepItOn coalition, "Rising repression meets global resistance: Internet shutdowns in 2025" (March 2026); Japan Times, "Russia's Max: The unencrypted super-app being forced on citizens" (March 24, 2026); Carnegie Endowment for International Peace, "Why Did Messaging App Telegram Fall From Grace in Russia?" (March 2026); Brennan Center for Justice, Section 702 2026 Resource Page; State of Surveillance, "Wyden-Lee Reform Bill: What the Government Surveillance Reform Act Would Change" (2026); NPR, "Why Congress is fighting over a central tool of American surveillance" (April 14, 2026).

Further Discussion

Five Deadlines. Same Fault Line.

Russia orders Sberbank to block VPN users tomorrow. The United States debates whether to sunset Section 702 on Monday — even though the FISA Court's 2025 certification will keep the surveillance running regardless of what Congress does. China cuts international roaming on China Telecom SIMs the following Wednesday. The United Kingdom's Ofcom publishes its final technology notice guidance this month, giving the regulator the authority to compel platforms to scan encrypted content. Twenty days from today, the European Union reopens Chat Control 2.0 negotiations with mandatory age verification on the table. Five mechanisms. Three continents. Eight days. The words differ. The architecture is identical. Every one of these enforcement actions works because there is a provider to compel. Russia compels Sberbank, Yandex, VK, Wildberries, Ozon, and the rest of the twenty-plus companies on its white list. The US compels AT&T, Verizon, T-Mobile, Google, Microsoft, and Meta through FISC certifications and Technical Assistance Orders. China compels its three state-controlled carriers. The UK compels Apple under the Investigatory Powers Act. The EU compels in-scope platforms through the Digital Services Act. In every case, the government reaches the citizen by reaching the intermediary. The intermediary has a commercial relationship with the state. The state has a lever. The lever is the compliance relationship. The compliance relationship is the architecture. The mechanism that works against all five is not stronger encryption. End-to-end encryption does not protect against client-side scanning. It does not protect against age verification. It does not protect against VPN blocking at the platform layer. It does not protect against the international cable being cut. The mechanism that works is an architecture with no intermediary to compel — peer-to-peer, mesh-routed, decentralized, without a corporate entity whose tax position or market access can be made contingent on compliance. Remove the party. Remove the lever. That is the only defense. Five governments, in eight days, are about to demonstrate why.

Peskov Uses a VPN. So Does Every Official Who Built the Blocks.

On February 19, 2026, Dmitry Peskov — the press secretary to Vladimir Putin — was asked in a public briefing whether the presidential press service used a VPN to access Telegram given Russia's restrictions on the platform. Peskov confirmed that it did. The same week, Russia's Ministry of Digital Development was finalizing the enforcement order that, on April 15, will force twenty of the country's largest companies to block VPN users or lose their tax benefits. This is not hypocrisy. It is design. Every one of the five architectures deploying this week follows the same pattern. The officials building them are exempt from them. The US intelligence community operates under Section 702 and uses encrypted communications for classified work. The Chinese Ministry of Industry and Information Technology operates dedicated cross-border lines and runs international communications that the April 22 severance will remove from the rest of the country. The UK Home Office uses encrypted messaging services that the Online Safety Act technology notices will require platforms to scan. The European Commission operates its own secure communications infrastructure and mandates age verification it would never accept applied to its own officials. Every surveillance architecture has a threat model and a user model. The threat model is the population. The user model is the state. The architecture is designed so that the population cannot evade the monitoring while the state can. This is why the Swedish Armed Forces opposed their own government's encryption backdoor bill — they understood that an architecture without exceptions would be applied to them too. This is why the Kremlin's press service continues to use the Telegram it is dismantling for everyone else. This is why the US intelligence agencies that brief on Salt Typhoon's compromise of 200 telecoms still rely on Signal for internal coordination. If encryption and unmonitored connectivity are essential for the officials who build the blocks, the blocks are not about safety. They are about who gets to be safe. The test of whether a communications architecture is real is whether it works when governments do not want it to. Five governments this week are answering that question in the negative. The only reply that survives contact with their enforcement is an architecture that does not depend on their cooperation. Not end-to-end encryption on a centralized platform. Decentralized transport that has no platform to compel in the first place.

Comics

#1Five Deadlines. Same Fault Line.
#2Peskov Uses a VPN. So Does Every Official Who Built the Blocks.