Notes on Internet Privacy

Posts and research from the URnetwork team and community.

RSS

The Deadline You Did Not Vote For

Seven clocks are running this week in seven jurisdictions. The operators they tick against are real; the authorities setting them are real; the harms they produce are real. None of the users at the other end were asked. That is the missing consent at the center of every privacy and internet-freedom story of April 2026.

Saturday morning, seven cities

In Tehran, a Saturday morning in April 2026 begins with the question of whether this is the day the internet returns. Forty-nine days have passed since Iranian telecommunications carriers zero-routed the foreign-ASN backbone on February 28. NetBlocks confirmed the fiftieth day early this morning: 1,176 hours, the longest nationwide internet blackout ever recorded. A Tehran hardware importer last reached his Shenzhen supplier on the last day of February. A Sharif University medical researcher has not read a foreign-hosted journal in fifty days. An Iranian diaspora family in Hamburg has not video-called their grandmother. A Supreme National Security Council committee will meet next week to decide whether four additional businesses get added to the "pro internet" whitelist. None of the people waiting for that decision chose the committee.

In Moscow, a Saturday morning is a thirteen-day countdown. On May 1, a per-gigabyte tariff of 150 rubles — about $1.80 — takes effect on any international internet data routed through a Russian carrier above fifteen gigabytes a month. The tariff applies whether the traffic is roaming data, VPN-routed, or any other path through the licensed carrier layer. The Digital Development Ministry announced the scheme in March. A Moscow business traveler's email sync with a foreign cloud provider will begin to accrue charges when the counter crosses the threshold. An expatriate Russian's calls to family abroad are already throttled on Telegram and blocked on WhatsApp; the tariff adds the next layer. The ministry did not ask the users.

In Brussels, a Saturday morning sits between two trilogues. The third trilogue on Chat Control 2.0, the Child Sexual Abuse Regulation, concluded Thursday without agreement on whether client-side scanning should be mandated. The fourth trilogue is May 4. The political-deal target is July. Signal's president Meredith Whittaker has publicly stated that Signal will leave the EU market rather than implement client-side scanning. Tuta, Proton, and Threema have said the same. The European Council, the Parliament, and the Commission are the three parties in the room. The 450 million EU users whose messaging this regulation will govern are not.

In Washington, a Saturday morning is a twelve-day clock. The Senate confirmed Friday afternoon by voice vote, in well under thirty seconds, the House's 2:09 a.m. unanimous-consent extension of Section 702 of the Foreign Intelligence Surveillance Act until April 30. The clean eighteen-month reauthorization the White House wanted is dead. The warrant-requirement amendment the reform coalition wanted was out of order. The authority continues; the FBI continues to query the 702 database under RISAA administrative controls; the FISA Court's April 2025 counternarcotics certification continues to authorize fentanyl-supply-chain collection. No American whose communications are in the database voted on the patch.

In Rotterdam, a Saturday morning is a waiting pattern. ChipSoft, the Dutch electronic-health-record vendor whose HiX platform serves seventy-six percent of Dutch acute-care hospitals, confirmed on Wednesday, April 15, that patient records "could not be ruled out" as accessed in the ransomware intrusion that began April 7. Franciscus Gasthuis Rotterdam and Albert Schweitzer Ziekenhuis Dordrecht are among eleven hospitals that disconnected HiX from their networks. Basic-Fit, Europe's largest gym chain, disclosed April 13 that one million members across six EU countries had their names, email addresses, physical addresses, phone numbers, dates of birth, and bank account numbers stolen. No ransomware group has claimed responsibility for either intrusion. The 1.2 million Europeans whose data is now in the wrong hands did not choose the concentration that made the breach feasible.

In London, a Saturday morning is two days after Ofcom's April 16 deadline for children's-access assessments under the Online Safety Act. Ninety-plus services are under formal investigation. Approximately 1-in-7 UK adults completed an age-verification flow in the past twelve months — about six million verifications. Yoti, Persona, Verify, and a handful of smaller intermediaries now hold identity-document images for a substantial fraction of UK-resident adults. A UK Reddit user verified their age on Tuesday to see a sensitive subreddit; their passport image is retained on Persona's servers under a twelve-month retention policy. The user did not design the intermediary ecosystem.

In Sydney, a Saturday morning is four months into the statutory under-16 ban on major social-media platforms. Facebook, Instagram, Snapchat, TikTok, and YouTube are under formal investigation by eSafety Commissioner Julie Inman Grant. The March 20 compliance report documented systemic gaps: platforms encouraging underage users to "correct" age estimations via low-confidence methods; repeated retries allowed with the same verification method; face estimation inaccurate at the 16/17 boundary. Australian teens have migrated to Discord, Roblox, Telegram. The seventy-six percent of fourteen-to-fifteen-year-olds reporting they have circumvented age restrictions did not vote on the statute.

Seven cities. Seven clocks. None set by the users those clocks tick against.

The common structural property

The seven clocks operate across different policy domains, different jurisdictions, and different timescales. They share one structural property: in each case, an authority is pulling a lever against a commercial or governmental operator to produce an effect on a population of users, and the users have no standing in the lever-pulling.

Iranian carriers comply with Supreme National Security Council directives. The SNSC is the authority; the carriers are the operator; Iranian internet users are the affected population. The population does not elect or appeal the SNSC's decisions.

Russian cellular carriers implement the Digital Development Ministry's tariff. The ministry is the authority; the carriers are the operator; Russian citizens who require international data are the affected population. The population is neither consulted nor appealable.

The EU Council, Parliament, and Commission are the three-party trilogue authority; major platforms (Meta, Google, Microsoft, Snap) and E2EE platforms (Signal, Tuta, Proton, Threema) are the operators; 450 million EU users are the affected population.

The U.S. Congress and administration are the authority; American carriers, cloud providers, and email services are the operators; Americans whose communications transit that infrastructure are the affected population.

ChipSoft and its insurance carrier, the Dutch DPA, and the Dutch health sector are the nexus of authority; ChipSoft is the operator; eleven hospitals' patient populations are the affected group. Basic-Fit corporate, insurance, and DPAs in six countries are the authority nexus; Basic-Fit is the operator; one million members are the affected population.

Ofcom is the authority; platforms and verifier intermediaries are the operators; UK internet users are the affected population.

eSafety Commissioner Inman Grant is the authority; the five major platforms are the operators; every Australian internet user is the affected population — teens directly, adults indirectly through verification friction.

The shape of each is the same. The user is always the affected population. The user is never the authority. The user is, in each case, at whatever substrate the operator runs.

Why the authorities' interests do not reach user consent

It is possible to steelman each authority's position, and it is important to.

Iran's government is operating under wartime conditions following the February 28 U.S.-Israeli strikes on Natanz, Fordow, and Arak. The stated justification — counter-espionage, prevention of foreign coordination with domestic actors — is a legitimate state interest in general. The blackout's fifty-day duration and its transition to a permit regime make the necessity claim harder to accept at face value, but the authority is legitimate even if the exercise is disproportionate.

Russia's government has a coherent digital-sovereignty position. Reducing dependency on foreign platforms is defensible; consolidating government services in a single application has operational efficiency. The absence of encryption and the aggregation at state-controlled infrastructure are privacy harms, but the authority — elected, statutory, constitutional under the Russian framework — is legitimate.

The EU Council, Parliament, and Commission are democratically constituted. The Chat Control regulation addresses a serious and well-documented problem (child sexual abuse material online). The mechanism of detection orders is contested, but the underlying policy goal is legitimate and the policy process is democratic.

The U.S. Congress and administration have constitutional standing for national-security authorities. Section 702 addresses foreign-intelligence collection, a legitimate state function. The tension with Fourth Amendment protections is the core of the Wyden-Lee-Lummis-Warren reform coalition's argument, but the underlying authority is legitimate.

Dutch and EU data-protection frameworks, UK Ofcom, and Australian eSafety are democratically established regulators with defined statutory authorities. Their interventions are not arbitrary.

Yet in each case, the legitimate authority acts on an operator the user did not choose to accept as the operator of their communications, records, or traffic. The Dutch patient did not choose to have her records consolidated in ChipSoft. The UK Reddit user did not choose that Persona would hold an image of her passport for twelve months. The Australian teen did not choose that her age-verification attempt would be gated by the platform's chosen face-estimation vendor. The consent that the authority presumes runs through the operator, not through the user.

The authority is legitimate. The operator is legitimate. The consent chain from user to operator to authority is an architectural artifact, not a freely-given permission. That is what the week's deadlines expose.

What architecture would change the question

A user whose communications, records, identity, and traffic do not depend on a compellable commercial operator cannot be ordered around by an authority whose lever pulls on a compellable operator. The architectural alternative to the present pattern is the one that, candidate by candidate, week by week, each reform conversation implicitly points at without naming.

End-to-end cryptography with user-held keys. Signal's protocol is the commercial-scale example: keys generated on the user's device, content encrypted under those keys, the operator holding only ciphertext it cannot decrypt. Apple's Advanced Data Protection was a similar design for iCloud; the UK Technical Capability Notice under the Investigatory Powers Act specifically targets this architecture to force operator key-custody globally.

Peer-to-peer transport. Traffic routed across devices of peers rather than facilities of licensed carriers. WireGuard as a protocol, Tor's onion routing as a network, URnetwork's residential-node transport as a live peer-relay fabric, Briar and Session as mesh messaging substrates. Each is a partial answer to the same architectural question: can communications avoid the licensed-carrier chokepoint that Russia's tariff, Iran's blackout, China's filter, and CALEA-compliant U.S. telecommunications depend on?

Federated moderation and federated storage. Content moderation chosen by the user or by user-chosen moderators, distributed across a federation of smaller operators rather than concentrated at a single gatekeeping platform. Matrix federation, Bluesky's PDS model, Mastodon, federated Nextcloud instances. Each distributes the lever's reach: the authority can pull on one operator, but not on the whole substrate.

User-held identity via verifiable credentials. Cryptographic assertions held in a user-controlled wallet, selectively disclosed through zero-knowledge proofs that verify the attribute (over 16, over 18, licensed) without revealing the underlying document. The EU Digital Identity Wallet under eIDAS 2.0 is the leading regulatory path; academic research on zero-knowledge age proofs has matured since 2023.

Decentralized vendor architecture. Health records held by the patient or across multiple independently-operated custodians (the EU-funded InteropEHRate project; Dutch Nuts peer-to-peer patient-authentication). Consumer identity held per-service or across user wallets rather than concentrated at operator databases.

None of these, today, replaces the present architecture wholesale. Each shrinks the attack surface for the specific lever that targets it. Decentralization is a narrower claim than "solves everything." It is a claim about structural properties of specific substrates: a substrate that does not present a compellable center does not present a lever, and a lever that cannot be pulled cannot produce a deadline the user did not consent to.

What this week actually costs

The aggregate tally of harm across the seven cities this week:

  • Iran, Day 50: approximately $1.8 to $2 billion in direct and indirect economic loss; tens of thousands of businesses degraded or shuttered; 85 million citizens unable to reach the external internet.
  • Russia, May 1 countdown: approximately 30 million users between a state messenger without encryption, a VPN filter that broke the country's major banks when it activated, and a tariff that will price international data out of reach for business travelers, expatriates, and ethnic minorities with family abroad.
  • Brussels, May 4 countdown: 450 million EU users in uncertainty over whether their messaging applications will be compelled to scan private communications or will withdraw from the market.
  • Washington, April 30 countdown: an entire surveillance authority continuing unmodified for at least another twelve days, with no structural path to reform before the deadline.
  • Rotterdam, ongoing: patient data for a substantial fraction of Dutch acute-care patients possibly leaked; eleven hospitals running in manual workflows; one million gym members with stolen bank account numbers.
  • London, post-deadline: six million identity-document images aggregated at four intermediary operators, with no large-scale breach yet but a structural concentration that will, in probability, produce one.
  • Sydney, four months in: 22-42 percent reduction in under-16 accounts on mainstream platforms, with a corresponding migration to less-regulated alternatives; 76 percent of teens reporting circumvention.

Seven cities' worth of specific harm, produced by authorities whose legitimacy is not the issue, operating on operators who cannot refuse the levers, producing effects on users who had no standing in the lever-pulling.

The next clock

The next clock starts this weekend. The Brussels trilogue is May 4; the Russia tariff is May 1; the Washington Section 702 sunset is April 30; the London age-assurance investigations will produce enforcement decisions through the summer; the Sydney enforcement decisions are mid-2026; Iran's next SNSC whitelist meeting is in the coming week; Rotterdam's DPA report closes in May. Each is a deadline. Each was set by an authority that did not ask the user. Each will operate on an operator the user did not design.

The architecture that produces this pattern is the architecture each policy debate of the week takes as given. The architectural alternative — end-to-end cryptography, peer-to-peer transport, federated moderation, user-held identity, distributed vendor ecosystems — is available, partially deployed, growing, and not yet the mainstream. Tor's bridge usage is up forty-two percent year-over-year. WireGuard is the 94 percent standard in consumer VPNs. Signal has sixty million monthly active users. URnetwork's residential-node transport is up thirty-seven percent in 2026. Each metric is a step. None is the turn.

What the week's deadlines reveal is that the present architecture produces policy debates about which authority gets to pull which lever. The user is the object of the debate, not a party to it. Whether the user can be a party requires a different architecture. That architecture is the slow, quiet, underfunded work of a different stack — the one that, deadline by deadline, week by week, becomes harder to ignore.

The next clock starts Monday. The user in Tehran, the user in Moscow, the user in Brussels, the user in Washington, the user in Rotterdam, the user in London, the user in Sydney — each will wake to a countdown set somewhere else. None of them were at the table. The architecture is why.


References (7 sources)

Sources

  1. NetBlocks, Iran connectivity report, April 18, 2026, confirming Day 50 of shutdown.
  2. Free Malaysia Today, "Iran internet blackout now in its 50th day," April 18, 2026.
  3. Shabtabnews, "Iran's Internet Blackout Shows No Signs Of Ending," April 17, 2026.
  4. Bloomberg, "Iran Internet Blackout Eases Slightly as Businesses Face Economic Costs," April 14, 2026.
  5. Moscow Times, "Russian websites begin blocking VPN users as internet controls tighten," April 15, 2026.
  6. Techdirt, "Whoops: Russia's Attempt To Block VPNs Causes Major Banking Failure," April 13, 2026.
  7. Zona.media, "Russia's internet censorship in 2026: VPN crackdowns, mobile shutdowns, Telegram blocks and the state messenger Max," April 7, 2026.
  8. EFF, "EU Parliament Blocks Mass-Scanning of Our Chats — What's Next?" April 2026.
  9. State of Surveillance, "Chat Control Is Dead. Long Live Chat Control.," April 2026.
  10. Patrick Breyer, "Chat Control: The EU's CSAM scanner proposal," continuous updates through April 17, 2026.
  11. Roll Call, "Senate sends short-term surveillance reauthorization to Trump," April 17, 2026.
  12. Al Jazeera, "US Congress extends controversial surveillance power under FISA for 10 days," April 17, 2026.
  13. NPR, "Congress extends controversial surveillance powers for 10 days," April 17, 2026.
  14. S.4082, Government Surveillance Reform Act, introduced March 12, 2026.
  15. Congressional Progressive Caucus binding resolution, April 16, 2026.
  16. NL Times, "Hospital patient data may have leaked in Chipsoft hack, sources say," April 15, 2026.
  17. The Register, "Ransomware knocks Dutch healthcare software vendor offline," April 8, 2026.
  18. BleepingComputer, "European Gym giant Basic-Fit data breach affects 1 million members," April 13, 2026.
  19. SecurityWeek, "Europe's Largest Gym Chain Says Data Breach Impacts 1 Million Members," April 13, 2026.
  20. Ofcom, "Age checks to protect children online," April 2026 guidance; eSafety Commissioner compliance update, March 20, 2026.
  21. Meredith Whittaker, @mer__edith on X, April 15, 2026, on Signal escalation to Apple.
  22. Freedom of the Press Foundation, updated iOS Signal guidance, April 16, 2026.
  23. Aviatrix threat research center, April 2026 Salt Typhoon updates; Senate Commerce Committee hearing, December 2025.
  24. Silicon UK, "Government Issues New Order To Access Apple UK User Data."
  25. Computer Weekly, "Home Office 'back door' seeks world-wide access to Apple iCloud users' data."
  26. European Commission Supplementary Statement of Objections to Meta, April 15, 2026.
  27. Bloomberg, "EU Warns Meta on WhatsApp AI Rules, Citing Competition Concerns," April 15, 2026.
  28. Meta Engineering, "Post-Quantum Cryptography Migration at Meta: Framework, Lessons, and Takeaways," April 16, 2026.
  29. Quantum Insider, "Q-Day Just Got Closer: Three Papers in Three Months," March 31, 2026.
  30. Tor Project, Arti 2.2.0 release; Snowflake bridge statistics; Cure53 Tor VPN audit, early 2026.
  31. URnetwork documentation and 2026 growth reports.
  32. Wyden-Lee-Lummis-Warren joint statement on GSRA.
  33. eSafety Commissioner Inman Grant compliance report, March 20, 2026.
  34. Reports on verifiable-credential architectures: EU Digital Identity Wallet (eIDAS 2.0); W3C Verifiable Credentials specification.
  35. Open Rights Group commentary on UK Online Safety Act intermediary architecture.

This is edition 2026-04-18-01 of the URnetwork daily privacy and internet freedom journal. The companion hot-takes document and the associated images, meme comics, and short-form video are published alongside.

Further Discussion

Every Deadline Is Their Deadline

Seven clocks. Seven jurisdictions. Zero users at any table. This Saturday, April 18, Iran is on Day 50 of the longest nationwide internet blackout ever recorded — a Supreme National Security Council committee decides who gets "pro internet" access, one business at a time. Russia's Digital Development Ministry has the May 1 switch for a per-gigabyte tariff on international data: 150 rubles above 15 GB, applied at the carrier gateway. The European Council, Parliament, and Commission meet May 4 on Chat Control, with Signal, Tuta, Proton, and Threema publicly prepared to leave the EU market if client-side scanning is mandated. The U.S. Congress has twelve days until the April 30 Section 702 sunset; the administration wants a clean reauthorization, the reform coalition will block anything without a warrant amendment, and neither will have the votes before the deadline. ChipSoft cannot rule out that patient records from 76 percent of Dutch acute-care hospitals were accessed in the April 7 ransomware intrusion; Basic-Fit has admitted that bank account details for one million European gym members are in attackers' hands. UK Ofcom's April 16 children's-access-assessment deadline just closed; six million UK adults have verified their age through commercial intermediaries whose ID-image retention policies are the new privacy layer. Australia's under-16 social-media ban is under eSafety compliance review with decisions expected mid-2026; 76 percent of the affected teens report they have already circumvented it. Seven deadlines. Every one was set by an authority whose legitimacy is not the issue — the SNSC, the ministry, the Council, the Congress, the DPA, Ofcom, the Commissioner. Every one acts through an operator — a carrier, a platform, a vendor, a cloud provider, an intermediary. And every one produces its effect on a population of users whose consent was never solicited at any point in the chain. **Key stat:** Seven operative clocks running this weekend. Each set by a different authority. None by a user. **Urgency:** April 30 Section 702 + Russia tariff + ActiveMQ/SharePoint KEV. May 4 Chat Control. Each deadline arrives whether users want it or not.

Decentralization Is the Only Way Out

A user cannot be ordered about by an authority whose lever cannot reach them. This is not a slogan — it is an architectural observation. Section 702 works because American carriers are compellable. The Russian tariff works because Russian carriers bill for international traffic under licensing directives. Iran's blackout works because six phone calls from the ministry to the six licensed carriers zero-route the external backbone. Chat Control would work, if adopted, because platforms with operator-held infrastructure can be compelled to scan. The UK Technical Capability Notice against Apple works because Apple holds iCloud Standard keys. ChipSoft's ransomware reached 76 percent of Dutch acute-care hospitals because 76 percent of Dutch acute-care hospitals use ChipSoft. Every lever in every policy debate this week is against a specific operator. Every specific operator is the center of an architecture users did not choose. The alternative architecture is available, partially deployed, and specifically designed to make those levers less effective. End-to-end encryption with user-held keys (Signal's protocol; Apple's ADP before the UK killed it) removes the operator from the decryption chain. Peer-to-peer transport (WireGuard's cryptokey routing, Tor's onion routing, URnetwork's residential-node relay, Briar's mesh) removes the licensed carrier from the transit chain. Federated moderation (Matrix, Bluesky PDS, Mastodon) removes the single-platform gatekeeper from the moderation chain. User-held identity through verifiable credentials (W3C, EU Digital Identity Wallet under eIDAS 2.0) removes the intermediary from the identity chain. Federated vendor architecture (InteropEHRate for health records; Nuts for Dutch patient authentication) removes the single-vendor concentration from the breach chain. None of these solves everything. All of them shrink specific attack surfaces. Every policy debate this week was about how to control a lever. The question the debates do not ask — the architectural question — is whether a lever should exist at all. The decentralized stack is the honest answer. Tor bridges are up 42 percent year-over-year. WireGuard is the 94 percent standard in consumer VPN. Signal has 60 million monthly active users. URnetwork is up 37 percent in 2026. Each metric is a step. None is the turn. The turn begins when the user whose clock was set elsewhere starts choosing the substrate that does not present a clock. **Key stat:** Every deadline this week operates on a compellable operator. A user-controlled substrate does not present one. **Urgency:** The architecture question is available right now. The policy question keeps producing the next deadline.

Comics

#1Every Deadline Is Their Deadline
#2Decentralization Is the Only Way Out