Notes on Internet Privacy

Posts and research from the URnetwork team and community.

RSS

Twenty Days, One Classified Opinion

Section 702 of the Foreign Intelligence Surveillance Act sunsets in twenty days. June 12, 2026. The Trump administration this week let the negotiated deadline pass without declassifying the Foreign Intelligence Surveillance Court's March 17, 2026 opinion documenting Federal Bureau of Investigation Section 702 query practices. Senator Ron Wyden — who negotiated the 15-day expedited declassification window on April 30 as the condition for the 45-day reauthorization extension — said Tuesday May 19, "Every member of Congress should keep this in mind when they consider Section 702 reauthorization legislation in the coming days... I'll have more to say about this next week." Next week begins Monday May 25 — two days from today. The Senate Intelligence Committee chair Tom Cotton has not commented publicly since May 15. The Director of National Intelligence has not declassified. The Department of Justice has not declassified. Senate Intelligence Vice Chair Mark Warner has not commented. The FISC opinion, surfaced by the New York Times April 9 reporting, found the recertification of Section 702 acceptable while raising significant concerns about how the FBI runs queries against the §702 corpus — what Brent Skorup writing in The American Prospect framed as the debate over whether all queries count or only queries returning U.S.-person information. The same week the declassification deadline lapsed without action, CISA suffered the disclosure of its own GitHub credential leak — six months of AWS GovCloud admin keys and plaintext database passwords public on the agency's Private-CISA repository, surfaced May 19 by TechCrunch — while three concurrent vendor zero-days under active exploitation landed across 96 hours: CVE-2026-20223 Cisco Secure Workload at CVSS 10.0; two Microsoft Defender for Endpoint elevation-of-privilege and denial-of-service flaws now in the federal active-exploitation catalog (CVE-2026-41091 + CVE-2026-45498); and Exchange Server CVE-2026-42897 in day 9 today with no permanent patch and a Federal Civilian Executive Branch remediation deadline 6 days away. The recipient-country layer is being built in parallel — Mexico CURP Biométrica at less than 10 percent registration with 38 days to the June 30 deadline for 127 million mobile lines, Iran at day 85 with the Internet Pro / commercial-VPN three-tier system charging the general public 12.5 times the rate of approved professionals for the same bandwidth, Russia's April 15 ISP VPN-detection mandate running at Yandex, VK, Sberbank, Gosuslugi with 22 of 30 popular Android apps monitoring VPN status at the application layer, Niger day 15 of the nine-international-media ban, Burkina Faso day 18 of the TV5 Monde permanent ban, Tanzania's Commission of Inquiry report on the 518 dead post-Oct-29-2025 election violence still withheld. Friday the Monero FCMP++ Trail of Bits engagement closed (audit pipeline) while five user-side primitives shipped the same week — Discord rolled out the DAVE end-to-end-encrypted voice/video protocol to all users May 19, Tor Browser 15.0.14 shipped May 19 with security updates, Bitcoin BIP352 silent payments adoption continues in Core 28.0+, Monero FCMP++ enters post-audit remediation, and the user-side primitive stack — open clients, open firmware, FIDO2 hardware authentication, censorship-resistant transports, privacy-preserving currencies, local-inference AI, federated identity, self-hosted services, mesh and satellite, post-quantum cryptographic agility — runs continuously on the audit-pipeline architecture. The §702 fight is structurally about whether the Senate can see the ruling on a program the executive will not show them. The structural answer is the architecture that does not require asking. Twenty days. One classified opinion. Wyden's "next week" arrives Monday.

The missed deadline

Friday, May 15, 2026, was day fifteen.

Day fifteen of a clock that started on April 30, 2026 — the day Senator Ron Wyden withdrew his hold on a 45-day Section 702 reauthorization extension by unanimous consent, on the condition that the Trump administration declassify the March 17, 2026 Foreign Intelligence Surveillance Court opinion within fifteen days. The window closed on Friday May 15-16. The opinion remains classified.

Senator Wyden, May 19, 2026:

"I expect that my colleagues — and the American public — will be alarmed by what the FISC found, when the opinion is declassified. "Every member of Congress should keep this in mind when they consider Section 702 reauthorization legislation in the coming days... "Following the most recent reauthorization, Sec. 702 was used to access more than 14,000 U.S. persons' communications without warrants — communications that included those of U.S. journalists, members of Congress, and grand jurors. The American people deserve to know that this Court has documented serious violations of the law by the FBI in conducting these queries. "I'll have more to say about this next week."

Today is Saturday, May 23, 2026. Next week begins Monday, May 25 — two days from now. The June 12 hard sunset is twenty days away.

The Director of National Intelligence has not declassified. The Department of Justice has not declassified. Senate Intelligence Committee Chair Tom Cotton (R-AR) has not commented publicly since the May 15-16 deadline. Senate Intelligence Vice Chair Mark Warner (D-VA) has not commented. The reauthorization debate is being held on a program whose recent court ruling Congress cannot see.

That is the lede of this piece. Everything else is the architectural context behind it.

What the court found

The FISC opinion at the center of the missed deadline was the standard annual recertification ruling on Section 702, dated March 17, 2026 and surfaced through New York Times reporting on April 9. The court approved the recertification of Section 702 — meaning the program continues to operate at the court's authorization — while flagging significant concerns about FBI query practices against the Section 702 corpus.

Brent Skorup, writing in The American Prospect on May 11, framed the conceptual scaffold: the debate is whether all FBI queries against the §702 database count toward §702 oversight numbers, or only queries that return information about U.S. persons. The distinction is load-bearing. The IC has historically reported query counts using the narrower definition. Civil-society reformers have argued the broader definition is the operative legal question. The FISC opinion, per Wyden's characterization, addresses exactly this — the conditions under which the FBI may query the §702 database for U.S.-person identifiers.

Wyden's May 19 statement names the specific reported pattern: more than fourteen thousand U.S.-person communications queried without warrants, including communications of U.S. journalists, members of Congress, and grand jurors. The number is sourced to filings that became visible during the prior reauthorization cycle. The pattern is what the March 17 opinion appears to address structurally.

What the public has been told: that the FISC raised concerns about how the FBI runs queries. What the public has not been told: what the court's ruling on that pattern actually says.

That is the substance of the declassification fight.

The deal

The April 29-30 deal that produced the missed deadline is itself the structural news.

Section 702 was set to expire April 15, 2026. The Senate negotiated a 45-day reauthorization extension to June 12 by unanimous consent. The price of Wyden's withdrawn hold — the condition that allowed UC passage — was a 15-day expedited declassification window on the March 17 FISC opinion. Senate Intelligence Chair Cotton (R-AR) and Vice Chair Warner (D-VA) wrote a joint letter to the Director of National Intelligence and the Attorney General on May 1 requesting declassification on the agreed timeline.

The deadline arrived May 15-16. The opinion remained classified. The administration did not signal a delay. It simply did not act.

The default response to this kind of missed deadline is to argue FISC opinions are routinely classified — which is true at the systemic level and irrelevant to this case. The declassification was the negotiated price of the extension. Default classification is not a defense of breaching a legislative commitment.

The cleaner reading is what Wyden put on the record May 19: the executive chose not to comply with the condition under which the Senate granted reauthorization. The Senate Intelligence Committee chair, Cotton, has not since defended the executive's choice. The silence is the structural rupture — bipartisan deal signed, executive ignored it, the chair of the relevant Senate committee will not say in public whether the deal still binds.

That is the architectural fact. The reauthorization debate continues over the next twenty days without the FISC's view of FBI query practices.

The skeptic's case

The §702 reauthorization debate has been running long enough that the strongest version of each side's argument is on the record. The piece must engage the strongest case for keeping §702 unchanged, or it reads as advocacy rather than analysis.

The strongest case rests on three claims.

One: Section 702 produces a substantial portion of the President's Daily Brief. The IC has historically described this share as approximately sixty percent — a number that has been reported, contested, and revised across reauthorization cycles, but whose order of magnitude is undisputed by the Senate Intelligence Committee in classified briefings. The argument: a program that produces this volume of intelligence cannot be impaired without operational cost.

Two: the queries-as-warrants critique conflates a query against a lawfully-collected database with a warrant for new collection. The IC's framing: §702 collection happens against foreign targets under court-approved certifications; queries are searches against already-collected lawful material. Requiring a warrant for U.S.-person queries against a lawful database creates a new layer of friction without correcting an underlying collection problem.

Three: even if the June 12 sunset passes without reauthorization, the §702 authorities transition through March 31, 2027 under the existing extension architecture. The political weight of letting §702 lapse is more performative than operational.

Each of these is the cleanest form of the case. Each has a response from the other side.

The response to the PDB share argument: the IC's reported share has shifted across cycles depending on which administration is making the case. The number is not auditable by Congress outside classified briefings; civil-society analysts have noted significant ambiguity in how the share is calculated. The argument from utility is not an argument against oversight reform.

The response to the queries-as-warrants framing: this is the exact question the FISC opinion addresses. The reformer position has been refined over multiple cycles: a probable-cause warrant for U.S.-person queries, not a probable-cause warrant for the §702 collection itself. The 2026 reform package in play is narrower than the "convert §702 to a domestic warrant regime" framing the IC has used in response. The FISC opinion is the operative document. Without declassification, the public cannot assess whether the IC's response engages what the court actually found.

The response to the transition clause argument: the transition clause is a procedural fact, not a defense of the missed declassification deadline. A clean sunset re-opens the architecture for debate; an extension on the executive's terms — without the negotiated declassification — closes it. The political weight of letting §702 lapse is the lever Wyden is reaching for in his "next week" timing.

Section 702's strongest defense rests on the production utility of the program. Section 702's strongest critique rests on the FISC having ruled, in a specific opinion, that FBI query practices are not compliant with the law. The reauthorization debate over the next twenty days will turn on which framing Congress can see — and the declassification is the gate.

The recipient-country column

While Washington debates whether the Senate can see one classified opinion, the recipient-country layer is being built at scale.

Iran — day 85. The Internet Pro / commercial-VPN three-tier architecture continues operational. Approved IRGC- and MCI-affiliated professionals receive whitelisted bandwidth at approximately €0.20 per gigabyte. The general public is forced to commercial VPN at approximately €75 per month — roughly 12.5 times the per-bandwidth rate. Sina Toosi at the Quincy Institute called the system "digital apartheid" in a May 12 analysis. Estimated cumulative economic loss exceeds $5.2 billion per Donya-ye Eghtesad. The white-internet whitelist tier — for accessing only domestic-state-approved services — remains operational at scale.

Mexico — 38 days to CURP Biométrica. Approximately 127 million mobile phone lines must register face / fingerprint / iris biometric CURP by June 30 or face suspension. Registration is below 10 percent total per Mexican journalist Ignacio Gómez Villaseñor reporting. Carrier-by-carrier: AT&T at 29 percent, Bait at 28 percent, Telcel at 19 percent, Movistar at 16 percent. Telcel lost 1.2 million line additions in Q1 2026 — a measurable user-pushback signal. A federal court overturned a previous suspension order on March 16. The constitutional challenge from Mexican civil society is in motion but has not produced a stay.

Russia — April 15 ISP VPN-detection mandate operational. Per Meduza and Roskomsvoboda reporting, the law is being enforced at major service providers: Yandex, VK, Sberbank, Gosuslugi, Ozon, Wildberries, Aviasales, and Russian Railways. Per the same outlets' May tracking, 22 of Russia's 30 most popular Android apps now monitor VPN status at the application layer. The May 1 mobile-VPN traffic surcharge was delayed, but the architectural infrastructure to enforce it is in place. The MAX state-controlled messaging app continues being pushed despite documented surveillance features.

Niger — day 15. The May 8 Observatoire Nationale de la Communication suspension of nine international media outlets — France 24, Radio France International, Agence France Presse, TV5 Monde, Jeune Afrique, Mediapart, LSI Africa, TF1 Info, and France Afrique Média — remains operative. Niger is the second-worst jailer of journalists in sub-Saharan Africa per the CPJ December 1, 2025 census.

Burkina Faso — day 18. The May 5 permanent ban on TV5 Monde remains in effect. RSF's May 6 report documented continued detentions including journalist Atiana Serge Oulon.

Pakistan — PECA wave continues. Pakistan Press Foundation tracks 233 incidents January 2025-April 2026. The April 29 Freedom Network report documented continued press freedom contraction.

Tanzania — Commission of Inquiry report withheld. The April 23 CoI report — 518 dead, including 502 civilians, 16 security personnel, 21 children, in post-October-29-2025 election violence — remains withheld from public release. X (Twitter) remains suspended in Tanzania.

The common architectural property across these regimes is intermediary-layer control. The state controls the carrier, the platform, the registry, the broadcaster, or the report. The user-side primitive stack — censorship-resistant transports, end-to-end encryption, mesh and satellite, privacy-preserving currencies, federated identity with selective disclosure — is the operational counter.

While Washington fights about whether a single FISC ruling can be declassified, the architecture this is part of is being deployed at scale.

The cyber-week column

The same week the §702 declassification deadline lapsed, the institutional credential-and-supply-chain layer logged compounding failures.

CVE-2026-20223 — Cisco Secure Workload — CVSS 10.0. Disclosed Thursday May 21. Cisco's perimeter-defense product, the centralized policy enforcement and segmentation platform widely deployed in federal civilian and enterprise networks. CVSS 10.0 is the maximum severity score. Out-of-band Cisco PSIRT advisory; emergency patch released same day.

Microsoft Defender for Endpoint twin zero-days — CVE-2026-41091 + CVE-2026-45498. Added to the CISA Known Exploited Vulnerabilities catalog Wednesday May 20. The security tool itself in the federal active-exploitation catalog — Elevation of Privilege and Denial of Service flaws disclosed alongside five legacy CVEs from 2008-2010. The Defender team rolled patches alongside the Cisco emergency.

Exchange OWA — CVE-2026-42897 — day 9 today, no permanent patch. Active exploitation since May 14. FCEB remediation deadline May 29 — six days from today. Microsoft has shipped automatic mitigation for customers with the Exchange EM Service enabled; manual mitigation steps for everyone else. The vendor patch cycle is trailing the regulator clock for the second consecutive week.

GitHub TeamPCP — 3,800 internal repositories exfiltrated — confirmed May 21. The vector: the Nx Console VS Code extension supply chain (TanStack → poisoned Nx Console) installed by a GitHub employee, accessing internal repositories at credentialed scale. Listed on a dark-web extortion market at $50,000. The most consequential SaaS-vendor supply chain compromise in 2026 to date by repository count.

Microsoft Fox Tempest takedown — May 19. The Digital Crimes Unit disrupted a signing-as-a-service criminal operation running approximately one year. More than 1,000 fraudulent code-signing certificates revoked at takedown. Customers paid $5,000-$9,000 per certificate. Operational connection to Rhysida and Vanilla Tempest ransomware affiliates.

Operation Saffron — May 19-20. A multi-country law-enforcement operation seized the First VPN service, 33 servers, and approximately 5,000 user accounts. Phobos ransomware-as-a-service connection. Sixteen-country coordination. The seizure is the second VPN-service takedown in 2026.

The architectural property: three concurrent CVSS ≥7.8 zero-days under active exploitation across two major vendors, plus a 3,800-repository SaaS supply chain compromise, plus two operations against criminal infrastructure, plus the CISA credential leak (next section), inside 96 hours. The vendor patching pipeline this publication has been documenting for the past week was failing at the median, the tail, and the current crisis simultaneously.

The CISA inversion

Tuesday May 19, TechCrunch — followed by Wired May 19-20 — reported that CISA's own Private-CISA repository on GitHub had been left publicly accessible for approximately six months with AWS GovCloud administrator credentials, plaintext database passwords, and other operational secrets in commit history.

The valid-credential window was approximately 48 hours from disclosure to remediation per CISA's own incident report. CISA staff rotated credentials and pulled the repository as soon as the exposure was confirmed. The 48-hour valid-credential window — between disclosure and full rotation — is what the agency's own Binding Operational Directive 22-01 requires of federal civilian operators.

The architectural rejoinder writes itself. The agency that publishes the Known Exploited Vulnerabilities catalog — the federal active-exploitation list that drives FCEB remediation across the executive branch — also failed at the credential-management discipline its own directives require of others. The failure is not malicious. The failure is structural: the same vendor patching pipeline that produces the 18-year tail at CVE-2008-4250 produces credential exposure inside the agency tasked with cleaning it up.

"Just trust the IC" — the strongest version of the §702 status-quo case — is the same week's parallel argument. The institutional trust that the §702 reauthorization debate is being asked to extend is the same institutional trust that produced the CISA credential leak, the GitHub TeamPCP breach via a GitHub-employee-installed extension, the 1-year Fox Tempest operational window, and the unpatched Exchange OWA active exploitation at day 9.

The structural answer is not to oppose every institution. The structural answer is to recognize that the institutions are running on the same vendor-pipeline architecture that fails at every timescale this week, and that the user-side primitive stack — what shipped the same week — is the operational alternative.

The protocol pipeline

Five user-side privacy primitives shipped or closed an audit cycle in the same week the institutional layer was failing.

Discord DAVE — May 19. End-to-end encryption rolled out to all Discord voice and video calls. The DAVE (Discord Audio/Video End-to-end) protocol was Trail of Bits-audited and IETF-standardized in spec — the protocol has been in preview for months; the May 19 announcement made it default-on across the platform. The architectural change is in the user-base count: Discord has approximately 200 million monthly active users. The shift to E2EE-by-default for one of the largest consumer voice/video platforms in the world is the largest single-week deployment of E2EE infrastructure to a non-niche user base since Signal's default-on adoption.

Tor Browser 15.0.14 — May 19. Standard cadence release with security updates. Tor Browser 15.0.13's emergency patch May 7 was the prior release; 15.0.14 hardens against follow-up vectors. Tor Project's continuous release cadence is itself the architectural example — open-source, public audit, donation-funded development, multi-actor verification.

Monero FCMP++ — Friday May 22. The 11-day Trail of Bits engagement on FCMP++ 1a/1b production integration closed. Second independent firm (after Veridise 2025) on the protocol that replaces the 16-decoy ring signature with a full-chain membership proof — approximately 150 million UTXO anonymity set, roughly 9.4 million-fold expansion. Report forthcoming 2-6 weeks. Mainnet hard fork target H2 2026, contingent on audit-clearance remediation.

Bitcoin BIP352 silent payments. Continues rolling out in Core 28.0+ deployments. The Spring 2026 series adoption metrics are in the standard rollout curve. The BIP324 v2 encrypted P2P protocol (default-on since Core 27.0) is now the majority of global Bitcoin peer-to-peer traffic.

Cashu / BOLT12 / Nostr DM. Cashu mints continue federating; BOLT12 offer-encoding adoption continues in Lightning Network; NIP-44 / NIP-17 / NIP-59 encrypted direct messaging on Nostr is now the default in Damus and Amethyst clients.

The pattern: five protocol-layer privacy primitives shipping in a 96-hour window through audit-driven open-source community governance, on a different architecture than the vendor patching pipeline. The protocol pipeline does not require institutional declassification to ship.

The policy overhang

The §702 sunset is not the only policy deadline shaping the architecture this quarter.

TAKE IT DOWN Act — day 5 today. FTC enforcement entered Day 5 today, May 23. Fifteen platforms named in May 11 warning letters remain in compliance posture; an additional twelve nudify-tool platforms received warning letters May 20. The 48-hour takedown duty for non-consensual intimate imagery, $53,088 civil penalty per violation. takeitdown.ftc.gov consumer reporting portal live since May 20. The civil-liberties critique from EFF, ACLU, CDT, R Street Institute, Free Speech Center remains structural: the takedown-duty primitive is now available statutorily for future scope expansion; end-to-end-encrypted platforms cannot structurally comply.

EU AI Act enforcement — 71 days to August 2. General-purpose AI provider obligations enforce August 2, 2026. The compliance posture across foundation-model deployers is fragmented — OpenAI / Anthropic / Google / Meta have published various transparency-documentation frames; Mistral and Alibaba have not yet published equivalent disclosures. The Commission's enforcement architecture is the next-quarter test.

EU "Going Dark" / ProtectEU. The summer 2026 legislative-proposal window opens within weeks. The November 2025 Council document obtained by Netzpolitik proposed one-year mandatory metadata retention for online services with VPN inclusion proposed by some member states. The Commission's stated 2030 objective: "lawful access to encrypted data." The architectural counter is the user-controlled overlay (URnetwork, Tor, V2Ray VLESS+Reality, Shadowsocks-2022, WireGuard) that does not appear in any public-service operator registry.

UK Online Safety Act enforcement. Ofcom enforcement actions continued through the May window — though the specific actions of the May 20-23 window are not the lead story today. The Act's interaction with end-to-end-encrypted platforms remains the unresolved architectural question.

Pakistan PECA + Tanzania CoI. Covered in the recipient-country column.

The cross-policy pattern: every major jurisdiction is layering intermediary-liable regulation on the same architectural surface that the user-side stack is making cryptographically unreachable. The §702 fight is the U.S. instance of the same architectural question.

The Saturday stack

Saturday news cycles are weighted differently. Patch tempos are weekday-heavy. Ransomware deployment is weekend-heavy — the asymmetric exploitation window between the end of Friday's patch tempo and the start of Monday's response cycle. The architectural property of the user-side primitive stack — open clients, open firmware, hardware authentication, censorship-resistant transports, privacy-preserving currencies, local-inference AI, federated identity, self-hosted services, mesh and satellite, post-quantum cryptographic agility — is that it does not depend on the weekday patch cadence. The audit-pipeline architecture ratifies upgrades on its own timescale.

This week, the stack shipped Discord DAVE default-on, Tor Browser 15.0.14, Monero FCMP++ audit close, Bitcoin BIP352 continued adoption, and Cashu / BOLT12 / Nostr NIP-44 federation expansion. The vendor pipeline shipped Cisco CVSS 10.0, Microsoft Defender twin zero-days into KEV, Exchange OWA day 9 no-patch, CISA credential leak with 48-hour valid-key window, GitHub TeamPCP 3,800 repos, Fox Tempest takedown, and Operation Saffron seizure.

The institutional layer ran failing this week. The user-side stack ran shipping this week.

Both pipelines run. The architecture is the choice.

The §702 reauthorization debate over the next twenty days will turn on whether the Senate can see one classified opinion that documents how the executive's institutional layer runs in practice. The structural answer to that question — whether the answer to "can we see the ruling" is yes or no — is the architecture that does not require asking. The user-side stack ships continuously through open-source community governance, audit-driven verification, donation-funded development. The institutional layer ships through vendor patching, classified rulings, executive prerogative.

Wyden, May 19: "Every member of Congress should keep this in mind when they consider Section 702 reauthorization legislation in the coming days."

Today is Saturday, May 23.

Wyden's "next week" arrives Monday.

Twenty days to June 12.

The Senate will see what the executive chooses to declassify.

The user-side stack ships regardless.


URnetwork is a peer-to-peer overlay for censorship-resistant transport. The February 19, 2026 MCP server release lets agentic clients establish VPN sessions over the peer-to-peer overlay, abstracting transport from the carrier layer. URnetwork does not appear in the public-service operator registry of any of the statutes named in this article.

https://ur.io

Further Discussion

The Missed Deadline

**Position.** Section 702 of the Foreign Intelligence Surveillance Act sunsets in twenty days. Friday May 15-16, 2026 was day fifteen — the close of the expedited declassification window Senator Ron Wyden negotiated on April 30 as the price of his withdrawn hold on the 45-day reauthorization extension. The Trump administration let the deadline pass without action. The Foreign Intelligence Surveillance Court's March 17, 2026 opinion documenting Federal Bureau of Investigation Section 702 query practices remains classified. The Director of National Intelligence has not declassified. The Department of Justice has not declassified. Senate Intelligence Committee Chair Tom Cotton has not commented publicly since the deadline. Senate Intelligence Vice Chair Mark Warner has not commented. Senator Wyden Tuesday May 19, 2026: "Every member of Congress should keep this in mind when they consider Section 702 reauthorization legislation in the coming days — I'll have more to say about this next week." Next week begins Monday May 25 — sixty hours from this hot take's publication. The reauthorization debate is being held on a program whose recent court ruling Congress cannot see. The opinion, per Wyden's characterization, addresses the FBI's pattern of more than 14,000 U.S.-person queries against the Section 702 corpus without warrants — including communications of U.S. journalists, members of Congress, and grand jurors. Brent Skorup's American Prospect framing captures the operative question: whether all FBI queries count toward Section 702 oversight numbers or only queries returning U.S.-person information. The FISC opinion is the operative document on that question. The deal Wyden negotiated had a 15-day declassification window. The deadline was missed. The chair of the relevant Senate committee — Cotton, of the administration's own party — has not said in public whether the deal still binds. The silence is the structural rupture. The June 12 sunset is twenty days away. The Senate will reauthorize without the court's view, or it will not. Either way, the structural answer is the architecture that does not require asking — the user-side primitive stack that ships through audit-driven open-source community governance, regardless of whether the Senate can see one classified opinion. **Headline candidates.** - The Missed Deadline · 20 Days to §702 Sunset - One Classified Opinion · Twenty Days to Sunset - The Declassification That Didn't Happen - A Court Found Violations · Congress Won't See the Ruling **Kicker.** Twenty days to June 12 sunset. Wyden's "next week" arrives Monday. The Senate will see what the executive chooses to declassify. The user-side stack ships regardless.

The Saturday Stack

**Position.** The same week the Section 702 declassification deadline lapsed without action, the institutional credential-and-supply-chain layer logged compounding failures at upper-bound tempo. Tuesday May 19 TechCrunch surfaced CISA's own GitHub credential leak — six months of AWS GovCloud admin keys and plaintext database passwords public on the agency's Private-CISA repository, 48-hour valid-credential window from disclosure to rotation, the same agency that publishes the Known Exploited Vulnerabilities catalog. Tuesday May 19 Microsoft disrupted Fox Tempest — a signing-as-a-service criminal operation running approximately one year, more than 1,000 fraudulent code-signing certificates revoked, customers paid $5,000-$9,000 per certificate, operational connection to Rhysida and Vanilla Tempest ransomware affiliates. May 19-20 Operation Saffron seized First VPN — 33 servers, ~5,000 accounts, Phobos ransomware connection, 16-country coordination. Wednesday May 20 CISA Known Exploited Vulnerabilities catalog added seven CVEs including the 18-year-old CVE-2008-4250 plus two Microsoft Defender zero-days. Thursday May 21 Cisco Secure Workload CVE-2026-20223 disclosed at CVSS 10.0 — maximum severity. Today, Saturday May 23, Exchange OWA CVE-2026-42897 is in day 9 of active exploitation with no permanent patch and a Federal Civilian Executive Branch remediation deadline 6 days away. May 20-21 GitHub confirmed 3,800 internal repositories exfiltrated through the Nx Console / TanStack supply-chain compromise installed by a GitHub employee — listed on dark-web extortion market at $50,000. Three concurrent CVSS ≥7.8 zero-days under active exploitation across two major vendors, plus a 3,800-repository supply chain compromise, plus two operations against criminal infrastructure, plus CISA credential exposure — inside 96 hours. The same week, five user-side privacy primitives shipped on the audit-pipeline architecture: Discord DAVE end-to-end encryption rolled out default-on to ~200 million monthly active users May 19; Tor Browser 15.0.14 May 19 with security updates; Monero FCMP++ Trail of Bits 11-day engagement closed Friday May 22 with 16-decoy → ~150M UTXO anonymity set (~9.4M× expansion); Bitcoin BIP352 silent payments continues rolling out in Core 28.0+; Cashu/BOLT12/Nostr NIP-44 federation expanding. The recipient-country layer deploys in parallel — Iran day 85 Internet Pro tier digital apartheid at 12.5× rate differential, Mexico CURP Biométrica at <10 percent registration with 38 days to deadline, Russia ISP VPN-detection operational with 22 of 30 popular Android apps monitoring at the application layer, Niger day 15, Burkina Faso day 18, Tanzania Commission of Inquiry report on 518 dead still withheld. The institutional layer ran failing this week. The user-side stack ran shipping this week. The §702 fight is structurally about whether the Senate can see one classified opinion documenting how the executive's institutional layer runs in practice. The structural answer is the architecture that does not require asking. The user-side primitive stack — open clients, open firmware, FIDO2 hardware authentication, censorship-resistant transports, privacy-preserving currencies, local-inference AI, federated identity with selective disclosure, self-hosted services, mesh and satellite, post-quantum cryptographic agility — runs continuously on the audit-pipeline architecture. Both pipelines run. The architecture is the choice. Saturday news cycles are weighted differently — patch tempos are weekday-heavy, adversary opportunism is weekend-heavy — and the audit-pipeline architecture ratifies upgrades on its own timescale, independent of the patch cadence. The institutional layer's failure mode this week was upper-bound. The user-side stack's shipping mode this week was operational. The §702 reauthorization debate over the next twenty days will turn on which architecture Congress trusts. The user-side stack runs regardless. **Headline candidates.** - The Saturday Stack · While Washington Argues, Five Privacy Primitives Shipped - Three Zero-Days, One Credential Leak, Five Privacy Primitives · 96 Hours - The Institutional Layer Failed This Week · The User-Side Stack Shipped - Both Pipelines Run · The Architecture Is The Choice **Kicker.** The institutional layer ran failing this week. The user-side stack ran shipping this week. The §702 debate over the next 20 days will turn on which architecture Congress trusts. The user-side stack runs regardless.

Comics

#1The Missed Deadline
#2The Saturday Stack