Expert at nothing but curious about everything. Security and Privacy for @brave

Christchurch, NZ
Age based verification on the Web produces perverse incentives to track users and limit human rights. The web3 community should not make this the "solution" to compliance. ZKPs are great, but don't appear to be able to solve these fundamental issues. lists.w3.org/Archives/Public…
3
9
44
10,104
Kyle DH | pryvit.eth retweeted
Hester Peirce: mass KYC collection builds honeypots that get crypto holders phished, hacked, and physically attacked. Her answer: zero-knowledge proofs - verify without exposing anyone. Meanwhile, SDNY is retrying Roman Storm in April 2027 - on the theory that he committed a crime by NOT building one of those honeypots. The government's own expert, AnChain.AI's Philip Werlau, told the jury Tornado Cash needed a "user registry": a list of authorized users, with logins "like Gmail, Spotify." On cross he admitted it "could have collected personal identifying information." When the defense asked whether hackers target exactly such databases, prosecutors objected. Sustained. The jury never heard the answer. Surveillance is privacy. Free Roman Storm. Study the case. Read the docket. See for yourself how bad this precedent is. Make some noise. This case is a threat to every developer and every user who values privacy. The more people know, the harder it is to get away with.
JUST IN: 🇺🇸 SEC Commissioner Hester Peirce calls to end mass KYC data collection, warning it puts crypto holders at risk of phishing and physical attacks. Pierce says the current KYC/AML system creates massive databases of sensitive information that can be hacked, leaked, or exploited. She's pushing for zero-knowledge proofs (ZK proofs) that could verify users meet regulatory requirements without exposing their personal information.
15
64
320
18,394
Kyle DH | pryvit.eth retweeted
A few months ago a collaborator and I built a tool which allows hiding encrypted texts inside of LLM texts to avoid censorship or message scanning and for creative misuse of public platforms for encrypted private communication. You can try it here: garfieldnaruto.com
9
11
61
3,017
RT @TaylorLorenz: When kids are banned from mainstream social media spaces online, they don’t stop socializing they just turn to less regul…
30
4
Kyle DH | pryvit.eth retweeted
Cypherpunk Congress speaker spotlight: Staff Cryptographic Security Engineer @PryvitKyle from @brave He has worked in leading privacy-focused browser Brave for five years. Focused on cryptographic security engineering. Kyle extensively contributed to the design and development of standards in the decentralised identity space (W3C, IETF & now EIPs). Deep thinker on subjects of privacy, the future of browsing, symbiotic relations between technology and humans, cryptography, and on-chain scalability. 4,000 people celebrate privacy here: congress.web3privacy.info
2
2
12
508
Kyle DH | pryvit.eth retweeted
207
4,403
66,325
1,599,212
Top tier shitpost when it makes the news
For the love of God, just let me shitpost in peace.
7
331
Kyle DH | pryvit.eth retweeted
A counter disinformation centre is the last thing any democratic country needs, especially Britain. Trump has barred major news outlets from the White House and launched Trump TV. Britain is taking a different approach by proposing preferential treatment for government-approved news. Both give governments influence over which news people see. If people believe an outlet receives preferential treatment because the government approves of its reporting, they may lose trust in its editorial independence. In June, the British government proposed mandating social media platforms to prioritise trusted news providers, including the BBC, through greater prominence in feeds and search results. It cited misinformation and disinformation as justification. The BBC is now led by Matt Brittin, Google’s former president for Europe, the Middle East and Africa. Every media outlet has editorial biases and makes mistakes. The BBC admitted that Panorama combined separate parts of Trump’s Jan 2021 speech in a way that falsely suggested he had called for violent action. 2 senior executives resigned, and the BBC apologised. Misinformation can be an honest mistake, an outdated finding or a claim later disproved by new evidence. Journalists make mistakes. Scientists revise conclusions. Even institutions considered trustworthy publish corrections. Disinformation involves deliberate deception. By the government’s classification, tech companies would have to deprioritise the BBC for spreading disinformation or face criticism. But that criticism could also be deprioritised. Once government policy favours approved sources, mistakes by independent journalists can become grounds for reducing their visibility or digital exile. The BBC’s reporting on Burnham’s new centre repeats the government’s warnings about Russian disinformation and AI without examining who decides what information is false, who can challenge those decisions or how the centre will be independently audited. The BBC is also among the organisations that would benefit from the proposal to prioritise approved news. Tech companies already prohibit coordinated deception, fake accounts and manipulation under their own terms. If they’re now going to enforce those policies more aggressively at the government’s request, what has changed? Why weren’t they enforcing them adequately before, and what are they receiving in return for closer cooperation with government? Burnham cites bots as a foreign interference threat. Identifying their operators would require tech companies to verify their identities and link them to their accounts. The announcement doesn’t mandate this, but the media should examine the surveillance capabilities it could enable. Combined with preferential news distribution, the new centre could give governments Cambridge Analytica-style capabilities, justified in the name of protecting freedom and democracy. Britain’s proposal gives authoritarian regimes justification to prioritise state-approved news and suppress opposition without banning it. Unlike Britain, they may conceal these instructions, leaving citizens unaware that their governments control which news and political views appear in their feeds. Journalists could lose visibility without knowing their reporting has been deprioritised. Unless government instructions and platform decisions are disclosed, neither journalists nor their audiences can establish when news distribution has been influenced by political intervention. My drafts folder is already full, but I’ll publish a technical investigation connecting these proposals to the capabilities they enable, using evidence anyone can understand. I’ll share it here, but follow my free Substack for the full investigation. My aim is to give journalists, researchers, policymakers and civil liberties groups the technical analysis needed to understand what legislation makes possible, beyond what governments say it is intended to achieve.
🚨 WATCH: Andy Burnham announces he will create a "National Centre for Information Defence" to combat foreign interference
2
9
52
1,567
Kyle DH | pryvit.eth retweeted
Micropayments also cause a disparity in access on the Web. Imagine if every time you wished to read a Wikipedia article you had to pay a penny. A person earning a minimum US wage then has access to far more information than the average Tanzanian. The effects compound then too.
2
2
4
370
Kyle DH | pryvit.eth retweeted
The day after she made this post, she was found dead Hsin-Ju was one of the nicest people I met and made this industry feel inclusive May you rest in peace @hsinju 💜
1/ gm. gm. Name is Hsin-Ju. I have a dark, kinda tragic personal announcement. I've decided I'd rather take $0 than accept a settlement that requires me to stay silent about what happened to me. I have since fired my lawyers at @sanfordheisler & will be releasing all the evidence from my time @hack_vc on Wed 8/26. INTRO: I've been in crypto for 9 years. Most recently I was a partner & head of platform @hack_vc which is a $600-700M crypto VC firm. Many of you may know me from my time as Head of Growth at @StellarOrg in 2017 (worked w/ the Mt. Gox founder), @Solana in 2018 (joined under ~10 ppl, but quit before my cliff), & @Fhenix in 2024. Or have attended one of my @DystopiaLabs ETH events (2019-now). Last year, I was forced to work through a serious medical emergency while at @Hack_VC due to threats by @alpackaP @dbulaevsky, saying that they would blacklist me from the space if I quit before finishing the hacksummit conference & side events that I was helping with during @kbwofficial. I was working 13-14hr days, 6 days a week, sleeping 0-4 hrs a night, and had documented Graves' disease, hyperthyroidism, and severe insomnia. I repeatedly asked to quit. Hack VC refused. This + other threats and intimidation went on for almost a month. The conditions got so bad I attempted suicide. The fucked up part is that, even after the suicide attempt, I told everyone at Hack VC (in writing) that I had no plans to sue. I was scared & extremely sick. I just wanted to leave. I told them that as long as there was no retaliation or badmouthing - I had no plans to sue. @Hack_VC chose to retaliate. After just 1 month after my near suicide, Hack VC mishandled my COBRA health insurance, refused to fix things, kept shooing me to customer support (when it's legally Hack VC's responsibility to fix this), and my insurance had issues and was not fixed for almost 4 MONTHS. Hack VC did not fix everything until I hired lawyers and had them force Hack VC to adhere to the law & fix my COBRA insurance issues. The sheer cruelty of an employer harming someone's health insurance almost immediately after they nearly committed suicide is extremely fucked up. And, even during the legal engagement, Hack VC continued to lie & attempt to harm me through their lawyers and other employees/partners (multi-million dollar carry & clawbacks can make even the nicest ppl willing to turn the other way or lie). @0xRodney @IsTheBaron @roshunpatel @Alex__Botte. Now. Almost an entire year of engagement & my near suicide anniversary coming up, our lawyers (mine & Hack VC's) have reached the point of preparing for private mediation and settlement. And...I realized that I just can't do it. I don't want money in exchange for silence. I'd rather speak. I fired my lawyers yesterday. In case it needs to be said, I did a good job at Hack VC. I was only there full time for 7 months; been part-time since 2021. I got a $50k raise to $300k, $30k bonus, and promises of additional carry that would have been implemented about a week or so after my last day. I was also offered admission into the GP entity (but not sure if admission was actually completed bc it was during my medical emergency). This + my resume, should show that me suing is not a money grab; I was genuinely harmed. I'm aware that I'm just one person (who is not rich) facing a $600-700M VC institution. I've been told by @alpackaP that he's known most of the managing partners at most VC firms for almost a decade and he could absolutely blacklist me. I'm also painful aware that the conclusion of this will probably be extremely poor for me or death - but I've accepted it. Sharing with other web2 & web3 VCs: @paulg @ycombinator @500STARTUPS @a16zcrypto @PanteraCapital @dragonflyvc @RaceCapital @hosseeb @haunventures @hiFramework @ElectricCapital @blockchaincap @Delphi_Digital @variantfund @1kxnetwork @archetypevc @shimacapital @robotventures, etc. TLDR; I’m done with continued threats, pressure, and intimidation. I'm not going to take a payout and allow Alex or Hack VC to walk away from harming me. As mentioned, I'll be dropping the evidence from my case on Wed 8/26 (or before) -- privacy be damned. Support here (or DM) please: ETH: 0x68c10776C5c05Cbf5B4C2318bE02D61B9f06B875 SOL: B7S8TPcWWJXTsmgG8ShoTmy8sNPuJ3Dbmt7z5gLFAveq
322
685
5,955
1,297,862
Kyle DH | pryvit.eth retweeted
Not to be that guy but isn't your logo Africa? Not Pangea?
1
2
6
97
Kyle DH | pryvit.eth retweeted
Legislative Trojan horses 🇪🇺 Chat Control 1.0 and 2.0 🇪🇺 Social media ban for children 🇪🇺 Addictive design ban for adults 🇪🇺 Combat fraud and serious crime 🇦🇺 Social media ban for children 🇺🇸 Social media ban for children 🇺🇸 Addictive design restrictions for children 🇳🇿 Social media ban for children 🇮🇪 Social media ban for children 🇫🇷 Social media ban for children 🇨🇦 Social media ban for children 🇬🇧 Social media ban for children 🇬🇧 Addictive design restrictions for children 🇬🇧 Child exploitation & grooming protection 🇬🇧 Force platforms to prioritise "trusted" news 🇦🇪 Social media ban for children 🇪🇸 Social media ban for children 🇬🇷 Social media ban for children 🇩🇰 Social media ban for children 🇳🇴 Social media ban for children 🇦🇹 Social media ban for children 🇵🇱 Social media ban for children 🇸🇮 Social media ban for children 🇹🇷 Social media ban for children 🇮🇩 Social media ban for children 🇲🇾 Social media ban for children 🇧🇷 Social media restrictions for children 🇵🇹 Social media restrictions for children 🇮🇳 Social media ban for children 🇸🇪 Social media ban for children 🇩🇪 Social media restrictions for children 🇮🇹 Social media restrictions for children 🇨🇳 Social media restrictions for children I’m sharing this because more journalists have started following my work, and I want to show what I’m exposing through technical analysis anyone can understand. I’m working on one of my most consequential investigations into legislation and technology built for digital surveillance. It’s called Chat Control. What follows looks like coordination between governments and a handful of tech companies. Tech companies get more data to monetise. Governments gain the ability to monitor who says what, to whom, why, where they go and how they spend money. Technical Trojan horses 🇪🇺 Compulsory identity verification 🇪🇺 Scan private communications 🇪🇺 Weaken end to end encryption 🇪🇺 Expand lawful access 🇬🇧 Compulsory identity verification 🇬🇧 Compulsory on-device scanning for every app 🇬🇧 Algorithms to prioritize trusted news sources 🇦🇺 Compulsory identity verification 🇳🇿 Compulsory identity verification 🇮🇪 Compulsory identity verification 🇫🇷 Compulsory identity verification 🇪🇸 Compulsory identity verification 🇬🇷 Compulsory identity verification 🇩🇰 Compulsory identity verification 🇳🇴 Compulsory identity verification 🇦🇹 Compulsory identity verification 🇵🇱 Compulsory identity verification 🇸🇮 Compulsory identity verification 🇹🇷 Compulsory identity verification 🇦🇪 Compulsory identity verification 🇮🇩 Compulsory identity verification 🇲🇾 Compulsory identity verification 🇧🇷 Compulsory identity verification 🇵🇹 Compulsory identity verification 🇨🇦 Compulsory identity verification 🇺🇸 Compulsory identity verification Spot the pattern. 🔞 Australia set the stage. Other countries are now following with "robust" age assurance language in their TV appearances, including the US, UK and Ireland. The US AGs have added it to the proposed legislation following the Meta lawsuit. 💡 Australia’s own standard says age checks must be "technically accurate, robust, and reliable". "Robust" means fault proof. It brings meaning like "best" endeavours. Age estimation can’t meet that standard. As Australia defines it, age verification determines age "to a high level of accuracy", while age estimation only provides an approximate age. Fault proof age checking requires identity verification. Now look at the tech companies and what they built recently. Apple, Google, Meta and Microsoft built identity verification capabilities before governments started saying existing age assurance wasn’t "robust" enough. They knew what was coming. 🪪 Apple has age assurance APIs that can return verified age ranges, including confirmation using government ID, and its Wallet API lets apps verify age or identity from government issued digital ID. 🪪 Google recently built an Age Signals API so apps can receive age ranges and verification status. Android already lets parents block apps by age across the entire device, so this isn’t technically necessary for child safety. Google has also added facial verification to Google Account and Gmail recovery through selfie video matching, presented as account security. 🪪 Meta launched selfie based Facebook verification that checks a video selfie against profile photos and plans to expand it globally. 🪪 Microsoft has rolled out age assurance across Microsoft Accounts using facial age estimation, identity documents and government systems. Refuse to verify and some content and features are blocked. 💭 A handful of tech companies control the operating systems, app stores and identity layers across almost every mobile device. Governments barely need to negotiate outside G7 rooms. If Apple, Google, Meta and Microsoft enforce the same rules, billions of people are instantly impacted. The same technical capability keeps appearing: identify verification. Identity the person first, then decide what they’re allowed to do, who they're allowed to speak to, and when they're allowed to move money. p.s. Anthropic and OpenAI have identity verification services and the US government holds a kill switch that decides who has permission to use AI. --- Let me know if I got anything wrong. I have 60 minutes to make an edit. Or just leave a comment so others can see your correction.
This needs to be in front of every legislator in the world. Basic common sense, tech informed, genuine care for the wellbeing of children. Journalists who might be thinking of asking me in to talk about teen social media bans: please ask Paul as well. He's an expert.
17
338
906
27,642
Kyle DH | pryvit.eth retweeted
1️⃣5️⃣0️⃣K+
Over 150,000 signups. The appetite is real. 🔥 The upcoming @brave Rewards Card will bring $BAT rewards to eligible everyday purchases, along with exclusive offers and bonus rewards. The next era of BAT is getting closer. Join the waitlist. ↓
1
5
30
1,501
Kyle DH | pryvit.eth retweeted
The inspiration behind the @nym mixnet is back! Don't forget that the reason @nym exists is due to discussions over the new threat model AI surveillance and the possibilities of cryptocurrency funding between @JulianAssange and @harryhalpin back in 2017-2018. Long live @JulianAssange!
3
10
90
6,214
Kyle DH | pryvit.eth retweeted
Recent reporting has revealed that the Department of Homeland Security is using Americans' financial activities and other data to analyze and then provide local law enforcement with tips on potential criminals. This practice is known as "predictive policing" and completely depends on mass surveillance to aggregate and analyze enough data to then determine whether or not a person could be a criminal in the eyes of the state. Predictive-policing itself is wrong, but it stems from the long-time surveillance of the American people. These surveillance mechanisms have empowered the state to target anyone for anything, even before they commit a crime—if they were going to commit a crime at all. This leaves us at the judgment and mercy of the state, where our activities, associations, or beliefs can easily be deemed criminal—or potentially criminal—and we have no way of defending ourselves. This is deeply un-American. The state should not be leveraging sensitive information to predict whether or not you may be a criminal. The American people should be free to live authentically and with dignity without fear of wrongful prosecution. It is within our constitutional rights, and it is time the federal government be reminded of them. My latest @CoinDesk: coindesk.com/opinion/2026/09…
1
6
16
1,507
Kyle DH | pryvit.eth retweeted
The irony of the past 24 months of stablecoin-psychosis is that end users win even if stablecoins don’t. The core problem in cross-border payments was always correspondent banking: who gets access, and how quickly and reliably money moves. Stablecoins fill those gaps, but the IDEA of them also threatens banks enough to make them invest in fixing the problems themselves. In the end, users get what they deserve either way: low-cost, instant payments 24/7
10
4
56
3,201
Kyle DH | pryvit.eth retweeted
Replying to @lex_node
You don’t fully grasp how much of your life is tracked until you’re sitting in a courtroom, watching federal prosecutors use your digital history against you, down to your most harmless Google searches. Your entire life becomes an open book, and even your most innocent actions can be twisted into something sinister. They get to tell the most damning version of your story. To tell yours in your own words, you have to take the stand.
44
360
2,451
149,075
Kyle DH | pryvit.eth retweeted
We rate wallets so "just give it time bro" stops being the whole answer.
3
1
14
257
Kyle DH | pryvit.eth retweeted
Governments and tech companies are creating systems that remove anonymity, expand surveillance and give them more control over what people can say, access and do online. Tech companies amplify fear about extreme AI risks because they want regulation that protects their interests. Compliance costs shut out smaller and open source competitors, leaving a few corporations controlling AI. Governments gain more control over digital services, while those companies gain more data, fewer competitors and deeper control over online life. Child safety is one of the easiest ways to overcome public resistance because few people want to be seen opposing it. The EU Kids Act uses that pressure to normalise identity verification for online access. People are then pushed to connect their legal identity to more of what they do online. Device based parental controls already let parents restrict apps, websites and screen time without collecting identity data. That shows child protection isn’t the reason for “robust” age checks. Zero knowledge proofs don’t solve the privacy problem. They still depend on an approved credential to establish the claim. “Chat Control” CSAM justifies scanning private communications. Once that’s possible, the device becomes a surveillance point. Encryption becomes irrelevant if content can be examined before encryption or after decryption. “Going Dark” Fraud, terrorism and serious crime justify lawful access to encrypted data. The EU is developing tech to give law enforcement greater access to encrypted information and plans new decryption capabilities for Europol. End to end encryption means nobody except the people communicating can read the content. Once governments have access, that protection ends. VPNs Their privacy value comes from separating identity from internet activity and preventing 3rd parties from seeing traffic. Force age checks, logging or government access and the service may still be called a VPN, but its protection is gone. The pattern Protect children to justify identity verification. Stop CSAM to justify scanning private communications. Stop fraud and serious crime to justify access to encryption. Each argument targets something almost nobody will defend. Each solution creates powers that apply to everyone. Mandatory verification ends pseudonymity by linking online activity to a real identity. That can then be used to profile populations, influence spending and shape political behaviour. Payments, private messages and travel records can then be linked through a small number of controlled, state monitored services. State agencies adapt cold war subversion tactics to parse these data streams, running predictive algorithms to identify potential dissent. Pre emptive intervention replaces post crime prosecution. Access to money, travel and speech can be granted only while someone complies, then removed before they’ve committed any crime. A centralised digital system gives authorities a kill switch. Once identity, payments, communication and movement are connected, a targeted person or group can be cut off from money, platforms and travel almost instantly because an automated system flagged their behaviour. Blackouts stop people organising before resistance can form. If people can’t communicate, coordinate or mobilise, political opposition becomes far harder. Total surveillance makes private, unmonitored communication unacceptable. The open web can then be recast as a dark web, making anonymous communication look criminal. People who still want privacy and basic civil liberties are forced to build separate networks outside state control. The EU describes strong encryption as necessary for privacy and cybersecurity while developing technology for lawful access to encrypted data. That contradiction is more powerful than claiming it has already abolished encryption or VPNs. nitter.net/paul__walsh/status/210…
Today we proposed the EU KIDS Act. No social media under the age of 13. No personal accounts under the age of 15. That’s our recommendation. As European Commission President, @vonderleyen said: “The question is not whether kids should have access to social media. The question is whether social media platforms should have access to our children.”
9
124
261
8,937
Kyle DH | pryvit.eth retweeted
I’ve broken down the Irish government’s and the Irish media regulator’s statements over the last few days to prove how they’re about to force identity verification across the country. They both use the same “robust” age checking language that the Australian eCommissioner came out with after the social media ban failed. The eCommissioner followed my work in this area for years. She can’t debate anything I have said on LinkedIn. The proposed legislation following the recent Meta lawsuit uses… you guessed it, “robust” age checking. Robust age checking = “best endeavors” Identity verification is the only technical way to comply with “robust” mandates. There are many countries that have suddenly made “child safety” a priority. Parental control settings on Android and iOS do everything each government says it wants to achieve. 100% and they can’t be circumvented. Google, Apple, and Meta all released identity verification capabilities recently - before they were mandated. They knew this was coming. OpenAI and Anthropic already have Persona as an identity partner. That’s the one backed by Peter Thiel and a16z. Investors in military and surveillance. This is a coordinated attack on civil liberties. This evidence suggests that child safety is not their true intent. Surveillance and control is the goal. Substack and X post about Ireland coming tomorrow. I’ll then write a post to connect every government in the world in the context of surveillance. Five Eyes are on fire.
This is the goal here for America too. People need to wake up. None of this is about “protecting kids” it’s about obliterating all anonymous internet use and communication
43
113
4,774