Day 52
The Iranian internet blackout is today in its 52nd day, having accumulated 1,224 hours of near-total offline since it began on February 28, 2026. NetBlocks and IranWire confirm the milestone: the longest continuous national internet shutdown recorded in any country's history. Pre-war traffic baseline is approximately 1 percent restored. The Iran Chamber of Commerce Knowledge-Based Commission, chaired by Afshin Kolahi, estimates direct daily economic loss at $30–40 million. The Iranian Minister of Communications cited $35.7 million per day. NetBlocks cited $37 million per day. As of April 16, cumulative economic cost was $1.8 billion; by today, approximately $1.9 billion.
The reconnection mechanism is the specific architectural detail. Per IranWire's April 18 reporting, the Supreme National Security Council — chaired by President Pezeshkian and including the heads of Iran's intelligence, military, and foreign-ministry institutions — is the grant-authority for internet reconnection. Institutions may apply for reconnection. Application criteria are not publicly documented. Approved institutions so far include government-aligned Telegram channels, Iranian state-media accounts, and select university networks. Individual users remain offline. Small businesses, startups, freelancers working for international clients, students accessing online educational resources, and medical services that require online coordination are among the specific groups bankrupted or disabled by the blackout.
Starlink — the satellite-internet system that was positioned as the non-state-dependent alternative — is being actively degraded by Iranian state-deployed military-grade jamming. American Foreign Policy Council analysis attributes the jamming to Russian Murmansk-BN electronic-warfare systems and Chinese counter-satcom technology. Effectiveness: 30–80 percent degradation of Starlink signal. Iran is also deploying GPS spoofing — the first documented case of a state using GPS spoofing against commercial satellite internet at scale. SpaceX deployed a January 10 software update enabling terminals to triangulate position via multi-satellite signal rather than GPS, partially restoring Starlink operability in jammed conditions. Possession of a Starlink terminal in Iran is criminal (6 months to 2 years imprisonment under the anti-espionage law); using a Starlink terminal to "confront the Islamic Republic" carries the death penalty.
This is the permissioning architecture at its clearest contemporary instance. The state's baseline is closed. Reconnection requires explicit state grant. The counter-infrastructure (Starlink) is countered by state-grade electronic warfare. Possession of the counter-infrastructure carries criminal and capital penalties. For ninety million Iranians, the internet on April 20, 2026 is the permissioned internet in its explicit form.
One hundred million on Max
Russia's state-backed messenger Max crossed 100 million registered users in March 2026, with 70.5 million daily active users, per VK's March 26 filing. The total signups since Max's launch in March 2025 are 107 million — the fastest messenger adoption in Russia's history. The app is an integrated super-app: messaging, government services, digital ID, electronic-document signing, and payments, modeled explicitly on WeChat. The architectural features: all data stored on Russian servers; no end-to-end encryption; SORM-3 integrated (the Russian surveillance regime covering full content retention and access by FSB). Cybersecurity researcher Baptiste Robert, quoted across international press: "any data that passes through this application can be considered to be in the hands of its owner, and in this case, the hands of the Russian state."
Max's adoption is not explained by product superiority. It is explained by adjacent-service degradation. WhatsApp was fully blocked in Russia on February 11, 2026. Telegram's blocking rate — "anomalies" rendering the service unusable — hit 95 percent on April 10, per Meduza, the highest recorded level since the new round of restrictions began on March 20. Telegram founder Pavel Durov released a version of Telegram with built-in DPI-bypass techniques; the bypass-cat-and-mouse continues. During periodic mobile-internet shutdowns in Moscow and regions (RFE/RL reporting), a state-maintained "whitelist" of services retains functionality. State services including Max remain whitelisted; blocked or degraded international services do not. In February 2026, the FSB required major Russian banks to install SORM equipment; non-compliant banks were excluded from the mobile-shutdown whitelist.
The architectural observation: Russia has constructed a state-controlled messenger + identity + payments stack at the scale of roughly seventy percent of the population. Adjacent channels are actively degraded. The user is presented with a choice between using the state-surveilled channel and using a degraded-or-criminalized alternative. The category of "voluntary adoption" is not applicable to the choice architecture.
The VPN spiral
UK enforcement of the Online Safety Act through 2025 and 2026 has produced a specific spiral pattern. Age verification is required for commercial websites with adult content. Users responded with VPN usage — a 1,400 percent first-day surge per multiple cybersecurity trackers. In February 2026, the UK government proposed options to "age restrict or limit children's use of Virtual Private Networks" where VPN use undermines the safety protections of the Online Safety Act. 4chan — fined £520,000 by Ofcom in March 2026 for non-compliance with the age-assurance requirement — refused to pay. Its US lawyer Preston Byrne responded to the fine notice with an AI-generated cartoon of a hamster in a Godzilla costume; the running joke has continued through subsequent notices with escalating rodent imagery. 4chan has no UK presence, no UK assets, no UK employees; the enforcement path is structurally weak. Ofcom's continuing penalties of £500 per day run through June 1, 2026.
The spiral: block the content, users route around via VPN, propose restrictions on VPN. Each countermeasure in the chain creates the impetus for the next. The architectural pattern is the permissioning-layer spiral — content-access requires identity verification; identity verification requires verifiable identity; VPN evasion makes identity unverifiable; VPN restriction re-imposes identity but at civil-liberties cost.
The US pattern is architecturally parallel. Texas HB 1181 was upheld 6-3 by the Supreme Court on June 27, 2025 in Free Speech Coalition v. Paxton. Approximately twenty-five states have enacted similar laws by the second quarter of 2026. Pornhub has withdrawn from some states rather than implement age verification; users migrate via VPN. The identity-verification-vendor ecosystem (Yoti, AgeCheck, Verifi, Digidentity) is a fast-growing segment with its own attack-surface profile — the vendor becomes a database of users-who-accessed-adult-content, a high-value target for identity theft and blackmail.
The May 4 trilogue
The EU's permanent Child Sexual Abuse Regulation — "Chat Control 2.0" — has its next trilogue scheduled for May 4, 2026, under the Danish presidency tail. The voluntary-scanning derogation (Chat Control 1.0) expired on April 3, 2026. The April 16-17 trilogue on the permanent regulation collapsed; per leaked Council cables, Council ministers deliberately allowed the failure to avoid establishing a precedent that would weaken the permanent regime. The negotiation has been in trilogue since the second half of 2024.
The architectural stakes are specific. If the regulation adopts mandatory client-side scanning — scanning content before it reaches encryption — end-to-end encryption loses its meaning as a privacy guarantee. Scanning infrastructure, once deployed, is repurposable for additional content categories beyond CSAM (copyright, political content, dissent) with policy changes and no technical changes. Signal, Proton, Tuta, and Threema have stated they would withdraw services from the EU rather than implement client-side scanning; the cost-benefit modeling of withdrawal versus compliance remains active.
The architectural question is whether messaging can retain end-to-end encryption as a privacy guarantee in the EU after May 4. The answer is contested. The Parliament's privacy-protective position is possible. The Council's mandatory-detection position is possible. A compromise producing client-side scanning within defined narrow categories is likely. Each outcome has different implications for the architectural baseline of messaging privacy in the EU.
The sunset that wasn't
April 20, 2026 was the original sunset date for Section 702 of the Foreign Intelligence Surveillance Act, set by the 2024 Reforming Intelligence and Securing America Act. It is no longer the sunset date. On April 17 at 2:09 AM, the House unanimously passed a 10-day extension after Republican amendment objections derailed the planned floor vote. That afternoon, the Senate voice-voted the same extension. On Saturday, April 18, President Trump signed H.R. 8322 without a public statement and without principals-present photography. The new sunset is April 30.
Today — April 20 — the House Rules Committee meets at 4 PM ET. Per the Committee's official announcement, Section 702 is not on the markup agenda. Items considered: H.R. 1897 (Endangered Species Act), H.R. 5587 (energy), H.R. 2289 (broadband), H.R. 4690 (infrastructure), rural-communities resolution. No Senate vehicle for 702 reform is scheduled this week. The reform coalition — which had sought a warrant requirement for US-person queries, post-Wyden's three-argument floor statement including opposition to "feeding [collected data] into AI systems to conduct unprecedented mass surveillance" — has ten days and no moving vehicle. The Executive Branch (CIA Director Ratcliffe, FBI Director Patel, White House Deputy Chief of Staff Stephen Miller) has publicly advocated clean reauthorization. The procedural trajectory is clean reauthorization at April 30, or another patch, or sunset with administrative interpretation continuing collection under legal uncertainty.
Wyden's AI-systems phrasing is the architectural significance. It recognizes that Section 702's policy debate has evolved beyond "who collects" to include "how AI processes what's collected." The AI-processing layer — Palantir Gotham, Anduril, Clearview AI for face data, contractor AI for SIGINT analysis — has no specific statutory oversight framework. Section 702 reform, if it were moving, would have to address this layer. The reform is not moving. The architecture continues.
The ratings board leak
On April 19, 2026, Indonesia's Ministry of Communications and Digital Affairs suspended the Indonesia Game Rating System after a security breach exposed 1,000-plus developer emails, submitted game assets, and nearly an hour of unreleased "007: First Light" gameplay footage through an unsecured backend API. The vulnerability was discovered by a Reddit user developing an alternate frontend for the IGRS ratings database; hidden ratings and associated metadata were accessible by manually typing a game's internal ID. The API has since been locked; new rating issuance is paused during investigation.
IGRS is the government's permissioning layer for games. Games require a government rating to distribute in Indonesia. The permissioning infrastructure's own security failure exposed the data of the entities seeking permission. The architectural lesson: every permissioning system is a database, every database is an attack surface, every attack surface eventually gets attacked. State-mandated permissioning concentrates attack surface in systems with the specific security debt of state-operated infrastructure.
The ChipSoft hospital
On April 7, 2026, Z-CERT notified ChipSoft — the Dutch healthcare IT vendor whose HiX Electronic Patient Dossier software serves approximately 70 percent of Dutch hospitals — of an active ransomware attack. By April 8, ChipSoft confirmed patient data was exfiltrated. By April 14, the Dutch Parliament had begun a formal probe demanding answers from Health Minister Hermans. By April 17, the Dutch Data Protection Authority had received 23 or more data-leak notifications; Dutch Justice Minister David van Weel stated "expect more big hacks." Several hospitals took patient portals offline; Rotterdam Eye Hospital, Rijndam Revalidatie, and Basalt Revalidatie in Zuid-Holland were among those publicly confirmed affected.
The architectural observation is the same as the AI-copilot supply chain from today's edition 01. A single vendor holding broad access — in this case, 70 percent of a country's hospital patient records — is a catastrophic concentration. Patients consented to care at their hospital. They did not separately consent to their hospital's vendor selection. When the vendor is compromised, the patients' medical privacy is the blast radius. Vendor concentration at national healthcare scale is the architectural default; the open-standards counter-architecture (FHIR-based data portability, Solid/Inrupt patient-owned data pods) is available but minority-deployed.
The long con
Drift Protocol — Solana's largest DeFi platform by total value locked at the time — was drained of $285 million on April 1, 2026, the second-largest exploit in Solana's history. The attack chain: attackers spent six months posing as a quantitative trading firm, building relationships with Drift Security Council members. Between March 23 and 30, they used Solana's durable-nonces feature to create pre-signed transactions that would execute later, and — through social engineering — obtained signatures from real Security Council members. The transactions transferred administrative control of the protocol to an attacker-controlled address. On April 1, the attackers deployed a fake CVT token (created March 12), whitelisted it as collateral, deposited 500 million CVT, and borrowed against it to withdraw $285 million in USDC, SOL, and ETH in approximately 12 minutes. Attribution: medium confidence to the DPRK-linked UNC4736 (tracked as AppleJeus, Citrine Sleet, Golden Chollima, Gleaming Pisces) per Chainalysis, TRM Labs, and Elliptic.
The architectural observation: decentralized governance without decentralized verification is vulnerable to concentration attacks. The Drift Security Council — a small group of signers with broad administrative powers — was the attack surface. Durable nonces, a benign Solana feature designed for delayed-execution in legitimate workflows, were the attack primitive. The defensive architecture — verifiable-credential identity for signers, hardware wallets with readable transaction displays, time-locks on admin operations — exists but was not universally applied. Six months of relational social engineering is the novelty; the architectural vulnerability it exploited is structural.
The architecture
The permissioning architecture is deployed at five layers of the user's internet stack in 2026.
Infrastructure layer. Iran's SNSC whitelist. Russia's mobile-shutdown whitelist. Starlink jamming via Russian and Chinese military-grade electronic warfare. The baseline reachability of IP routing to and from a jurisdiction is a state-granted privilege rather than a protocol default.
Routing layer. DNS filtering, BGP hijacking, ASN blocking, CDN-level content blocks. Russia's Telegram throttling at 95 percent. UK's content-block orders. Indonesia's IGRS as permissioning-layer-leaked-itself.
Identity layer. UK OSA age verification. Texas HB 1181 (~25 US states). Russian digital-ID + Max integration. Identity-verification vendors (Yoti, AgeCheck, Verifi, Digidentity) as high-value centralized databases.
Encryption layer. EU Chat Control 2.0 May 4 trilogue. Client-side scanning proposals that would subvert end-to-end encryption at the endpoint. Mandated key-escrow debates. Lawful-intercept API requirements in various jurisdictions.
Application layer. AI-copilot OAuth scope expansion (edition 01 territory). Salesforce misconfiguration campaigns. SaaS vendor-held authentication at enterprise scale. Vercel/Context.ai, Azure MCP CVE, Meta Scale AI Outlier, ShinyHunters 100M+ records in Week 17.
Each layer has permissioning deployed. Each layer has a counter-architecture available. None of the counter-architectures is the mainstream default. The gap between deployed permissioning and deployed counter-architecture is widening, not narrowing.
The counter-architecture
The decentralized stack exists. It is operational. It is not mainstream. Its components:
Infrastructure. Peer-to-peer mesh networking. Satellite connectivity (Starlink, with documented state-counter-weapon vulnerabilities). Physical-layer mesh (Meshtastic, Yggdrasil, cjdns). URnetwork peer-to-peer routing substrate. Local-first computing that doesn't depend on reachability.
Routing. Tor onion routing with obfuscated transports (obfs4, snowflake). DNS-over-Tor. URnetwork federated peer routing. WireGuard via TLS. Shadowsocks with obfuscation.
Identity. W3C Verifiable Credentials. Decentralized Identifiers (DIDs). Privacy-preserving age attestation via zero-knowledge proofs. Pseudonymous identity with reputation. Self-sovereign identity wallets (Italy, Netherlands digital-identity pilots).
Encryption. End-to-end encrypted messaging: Signal, Tuta, Proton, Session. Post-quantum cryptography: Tuta first-to-deploy. Encrypted cloud storage: Tresorit, Sync, Mega, pCloud. Hardware-backed key storage.
Application. Self-hosted AI agents: LangChain, LlamaIndex, Semantic Kernel. Local LLM hosting: Ollama. Open-source MCP servers with customer-controlled deployment. Minimum-scope OAuth. Per-operation authentication. Continuous observability with SIEM/SOAR integration.
Aggregate user metrics. Signal: 70 to 100 million monthly active (Whittaker, NZZ; Signal publishes no DAU figure) — approximately 50 million daily active. Proton: 100 million accounts. Tuta: 10 million users. Matrix: 80 million federated users. Tor: 2–3 million daily. Mastodon + Bluesky + Nostr combined: approximately 50 million monthly active users. Each is material; each is minority-share; combined they represent the decentralized stack in a compounding-but-not-yet-dominant adoption curve.
What the week measures
The permissioned internet is the 2026 baseline. The counter-architecture exists and is growing. Deployment is the remaining question.
On Monday, April 20, 2026, an Iranian user is on Day 52 of a state-whitelisted internet. A Russian user has Max as their daily-use messenger-and-identity-and-payments stack. A British user has age verification at the content layer and proposed VPN restrictions at the routing layer. An EU user is approximately two weeks from the May 4 trilogue that may rewrite what "end-to-end encryption" means in the EU. An Indonesian developer has had their email and unreleased work exposed through the government's own permissioning system. A Dutch patient has had their medical records exfiltrated through a single vendor serving 70 percent of the country's hospitals. An American has a Section 702 patch signed on Saturday and no reform vehicle moving in the 10 remaining days. A Drift Protocol user has had $285 million of capital reached through six months of relational social engineering against a small multi-sig council. An AI-copilot-using enterprise customer has had the week's most significant cascade compromise (edition 01 anchor).
Each is a different data point. Each is a different permissioning layer. Each is today.
The decentralized stack — Signal, Tuta, Proton at messaging and email; Tor, URnetwork at routing; Matrix, Mastodon, Bluesky at federated social; Ollama, LangChain, LlamaIndex at self-hosted AI; W3C VCs + DIDs at identity — is available. The deployment decision is the user's, the developer's, the enterprise's, and the community's.
The permissioning architecture is deploying at state-and-vendor speed. The counter-architecture deploys at community speed. The gap is the 2026 measurement. The question for the 2028 internet is which architecture reaches the user's hands first as the default. The answer depends on what gets deployed in the 24 months between today and then.
Today is Monday, April 20, 2026. Day 52 in Tehran. 100 million on Max. 14 days to the EU trilogue. 10 days to the next US Section 702 deadline. The permissioned internet is here. The counter-architecture is also here. The user's Monday choice compounds into the architecture of the decade.
References (27 sources)
Sources
- NetBlocks, Iran internet blackout status updates, April 2026.
- IranWire, "Over 1,100 Hours of Internet Blackout; Reconnection Conditional on SNSC Approval," April 18, 2026.
- IranWire, "Why There's No Starlink Access During Nationwide Shutdown in Iran?"
- Al Jazeera, "Frustration grows as Iran's wartime internet shutdown breaks grim record," April 5, 2026.
- Al-Arabiya, "Iran internet blackout is longest nationwide shutdown on record: Netblocks," April 5, 2026.
- Tom's Hardware, "Iran's forced nationwide internet blackout becomes second-longest on record."
- Semafor, "Iran internet blackout enters 46th day, straining economy," April 14, 2026.
- Rest of World, "Iran's internet shutdown crippled Starlink and why the world should care."
- American Foreign Policy Council, "Digital Iron Curtain: How Chinese Jamming Tech Is Killing Iran's Starlink Lifeline In 2026."
- France 24, "How Iran jammed Starlink (and how Iranians are trying to get around it)."
- Times of Israel, "As Iranian regime shuts down internet, even Starlink seemingly being jammed."
- Wikipedia, "2026 Internet blackout in Iran."
- VK filing, "Max 100 million users," March 26, 2026.
- Pravda.com.ua, "Telegram messaging app almost fully blocked in Russia," April 10, 2026.
- Meduza, "Telegram blocking rate in Russia reaches 95%," April 10, 2026.
- KyivPost, "Telegram Founder Updates App to Bypass Total Ban in Russia."
- Carnegie Endowment for International Peace, "Why Did Messaging App Telegram Fall From Grace in Russia?" March 2026.
- Zona Media, "Russia's internet censorship in 2026: VPN crackdowns, mobile shutdowns, Telegram blocks and the state messenger Max."
- France 24, "Russia's Max: The unencrypted super-app being forced on citizens," March 23, 2026.
- US News, "Kremlin's Drive for a State-Backed Messaging App Touches a Nerve for Some," April 3, 2026.
- Moscow Times, "Everything You Need to Know About Max, Russia's State-Backed Answer to WhatsApp."
- Wikipedia, "Max (app)."
- Cybernews / Panda Security / Help Net Security, UK OSA age verification + VPN surge tracking, 2025–2026.
- Ofcom, "Online Safety Act investigations update."
- The Record (Recorded Future), "UK fines 4chan over noncompliance with Online Safety Act."
- Help Net Security, "4chan shrugs off UK regulator, refuses to pay £520,000 in fines."
- Reclaim the Net, "Ofcom Has Fined 4chan £520,000 Under a Law That Doesn't Apply in the US."
- Boing Boing, "4chan responded to a £520,000 UK fine with a hamster in a Godzilla suit," March 20, 2026.
- ISPreview UK, "Government Set to Restrict UK Children's Use of Internet VPNs and Social Media."
- Free Speech Coalition, Inc. v. Paxton, 23-1122, Supreme Court of the United States, June 27, 2025.
- Sidley Austin LLP, "Texas Age Verification Law Upheld: U.S. Supreme Court Balances Free Speech and Child Protection in the Digital Age."
- Ondato Blog, "Texas Age Verification Law (HB 1181) Explained."
- Patrick Breyer MEP, "Chat Control: The EU's CSAM scanner proposal," ongoing.
- State of Surveillance, "Chat Control Is Dead. Long Live Chat Control."
- State of Surveillance, "Chat Control Dies Tomorrow: EU Voluntary Scanning Expires April 3."
- Greens/EFA press, "Negotiations collapsed in best possible outcome: Quote from Markéta Gregorová MEP."
- Electronic Frontier Foundation, "After Years of Controversy, the EU's Chat Control Nears Its Final Hurdle."
- State of Surveillance, "The House Votes Tomorrow on Warrantless Surveillance. Reformers Already Lost."
- NPR, "Congress extends controversial surveillance powers for 10 days," April 17, 2026.
- Nextgov/FCW, "House readies vote to renew FISA 702 without a warrant amendment."
- Holland & Knight, "Congress Poised to Consider FISA Extension in April."
- Epoch Times, "House Rules Committee Advances FISA Section 702 Authorization After GOP Opposition Delays Bill."
- H.R. 8322 — FISA Amendments Act extension, signed April 18, 2026.
- Senate floor record, April 17, 2026 — Wyden statement on H.R. 8322.
- Jakarta Post, "Indonesia suspends game rating system after data breach," April 19, 2026.
- The Register, "Indonesia's game rating system leaks developer creds," April 20, 2026.
- VGC, "Indonesia's ratings board just leaked huge spoilers for 007: First Light."
- Power Up Gaming, "IGRS Leaks 007 First Light Assets and 1000+ Developer Emails."
- Niko Partners, "Indonesia Game Rating System Heavily Criticized on its Rollout."
- Kenya ODPC determination, LOLC Microfinance case, April 14, 2026.
- TechCabal, "LOLC Microfinance Bank directors risk prosecution over data case."
- Capital FM (Kenya), "ODPC faults LOLC Kenya over data breach, orders deletion of client data."
- Business Daily Africa, "Micro-lender bosses face prosecution over ex-employee image use."
- HapaKenya, "LOLC Microfinance directors face prosecution after public shaming former employee."
- Cyberwarzone, "Dutch Parliament Probes ChipSoft Ransomware Attack," April 14, 2026.
- The Register, "Ransomware knocks Dutch healthcare software vendor offline," April 8, 2026.
- Cybernews, "Concerns over patient data arise after data breach at ChipSoft."
- State of Surveillance, "Ransomware Hit the Company That Runs 80% of Dutch Hospitals."
- NL Times, "Expect more big hacks, Justice Min. says as ChipSoft confirms leak of patient data," April 17, 2026.
- The Record, "Dutch hospitals face disruptions after ransomware attack on software provider ChipSoft."
- Chainalysis, "Drift Protocol Hack: How Privileged Access Led to a $285M Loss."
- The Hacker News, "$285 Million Drift Hack Traced to Six-Month DPRK Social Engineering Operation."
- TRM Labs, "North Korean Hackers Attack Drift Protocol In USD 285 Million Heist."
- Elliptic, "Drift Protocol exploited for $286 million in suspected DPRK-linked attack."
- Bloomberg, "Drift DeFi Project on Solana Suffers $285 Million Crypto Exploit," April 1, 2026.
- Coindesk, "Elliptic flags $285 million Drift exploit as a likely North Korea-linked operation."
- SpotedCrypto, "Drift Protocol's $285M Hack: 12 Minutes That Shook Solana DeFi."
- Solana durable nonces specification, Solana Foundation documentation.
- Anthropic Model Context Protocol specification.
- OAuth 2.1 framework documentation, IETF.
- W3C Verifiable Credentials specification.
- W3C Decentralized Identifiers (DIDs) specification.
- Signal technical documentation.
- Tuta post-quantum cryptography release, March 2024.
- Proton ecosystem documentation.
- Tor Project documentation.
- Matrix federation specification.
- ActivityPub / Mastodon federation documentation.
- AT Protocol / Bluesky federation documentation.
- Ollama local LLM framework documentation.
- LangChain, LlamaIndex, Semantic Kernel self-hosted documentation.
- OWASP AI Security and Privacy Guide 2026.
- NIST AI Risk Management Framework (AI 600-1) 2026 update.
- Great Firewall architectural analysis (Wikipedia, Britannica, TechTarget references).
- Oxford Journal of Cybersecurity, "Conceptualizing the reverse great firewall."
- ODPC Kenya annual enforcement report, 2025.
- GDPR Article 33 / Article 82 breach notification + liability text.
- URnetwork peer-to-peer routing + federated operators documentation.
This is edition 2026-04-20-02 of the URnetwork daily privacy and internet freedom journal. Edition 01 today covers the AI-copilot supply-chain pattern; this edition covers the user-state permissioning architecture. The companion hot-takes document and the associated images, meme comics, and short-form video are published alongside.