đź‘“ The Surveillance Snowden Warned Us About - Community Call #2617

:glasses: The Surveillance Snowden Warned Us About - Community Call #2617

This week’s community call marks the 13th anniversary of the Snowden revelations. @sudonym sat down with @claudianym - Chief Scientist of Nym and one of its co-founders - for a personal and academic look at what those revelations meant for the privacy field, how they pushed Nym into existence, and where the fight stands today.

Big thanks to everyone who joined live.

:magnifying_glass_tilted_left: Before the Bombshell

Claudia in the early 2010s had drifted away from network privacy. She’d done her PhD on it but was diversifying. The field had largely moved on too - towards connection-based systems like Tor, optimized for low latency. The Global Passive Adversary threat model was treated as too paranoid to design against.

“These revelations made clear that this global passive adversary - or even global active adversary almost - was not just a theoretical construct or a paranoid delusion, but was very existing in the world.”

:satellite: What’s a GPA?

Sudo asked her to unpack the term. The Global Passive Adversary is the assumption you make when designing a mixnet: some subset of mix nodes are honest and unobservable from outside, but the adversary sees everything that moves on the network. Pre-2013, “they can see the whole internet” sounded hyperbolic. Then the Verizon metadata program leaked, and:

“Now we have evidence.”

:newspaper: The Revelations That Hit Hardest

Claudia ran through the highlights from a researcher’s perspective:

  • Bulk metadata collection (Verizon) - exactly the kind of thing GPA models had been theorizing about, deployed at scale
  • Fiber optic backbone taps - core internet infrastructure wiretapped, buffered for days, filtered
  • PRISM - back-end interface into 9 major providers (Microsoft, Apple, Facebook, Google, Yahoo, etc.) for pulling emails, chats, whatever
  • XKeyScore - the search engine over all the collected data. Sudo’s reaction:

“This was for me the most terrifying part. Like your magic search bar on macOS - you just type in an email address or IP and pull a profile on the spot.”

  • NSA undermining crypto standards at NIST - participating in standards processes while pushing weakened parameters that they alone could break. Claudia: very risky play - offensive advantage now, defensive weakness forever.
  • Egotistical Giraffe - the Tor attack program. Surprise: it was underdeveloped. Just one or two people working on it, hadn’t really exploited what they had. “They were not doing as well as we thought they could have been.”

And the chilling caveat: this is all 13 years old. iPhone 6 era. We have no idea what the current state of the art looks like, especially with AI in the loop.

:seedling: From Revelations to Nym

Pre-Snowden, Claudia and colleagues had tried to fund mixnet research through European Commission grants. It kept failing - the topic was niche, impact looked unconvincing on paper.

Post-Snowden, the EC’s framing shifted. In 2014, PANORAMIX got funded - three-to-four years of research. Loopix was developed under PANORAMIX. Ania did her PhD under it. Aggelos Kiayias (now a Nym advisor and Chief Scientist at IOHK/Cardano) was the one who walked into the room with the original proposal and pulled the founding group together: Claudia, Harry, Ania.

“Panoramix is foundational for the Nym network that comes after. In that sense, there is a direct line from these revelations to where we are today.”

:balance_scale: The 13-Year Scorecard

Content encryption: we won. End-to-end messaging is standard. HTTPS is universal. Wasn’t always like that.

Metadata: still very hard. Nym is “one of the very few” working mixnets in deployment.

“Metadata is when you’re doing things - source, destination, timing, volume. Making that invisible is much harder, much more effort, much more leaky than encrypting content.”

:robot: Crypto Wars 3

Sudo framed the present as the third wave of the encryption fight:

  • Crypto Wars 1: cypherpunks legalize encryption (gave us TLS, HTTPS)
  • Crypto Wars 2: post-Snowden push for E2E everywhere
  • Crypto Wars 3: client-side scanning, age verification gates, “child safety” framings of mass identification

Claudia listed the new fronts:

  • Client device security - if your phone is compromised, no pipeline matters. Pegasus and family are the proof of concept.
  • AI accelerating both sides - faster vulnerability discovery, faster patching, faster correlation across data stores. The next-generation XKeyScore with AI on top is the unstated terror here.
  • Data brokers - agencies don’t need to collect what they can buy. The FBI is on record. Claudia assumes NSA too.

:shield: Targeted vs Mass

Sudo: “I’m more okay with Pegasus existing than mass surveillance of everybody all the time.” Both bad, but the scaling matters.

Claudia: it’s a scaling problem - and AI threatens to remove the scaling friction that has kept “targeted” tools roughly bounded. Plus, even surveillance bounded by law is misused: Pegasus has been deployed against opposition politicians and journalists in Hungary (and Sudo’s pointed reminder: Hungary is far from alone).

Her case against “nothing to hide, nothing to fear”:

“Your data is being collected and analyzed and decisions are being made on it. You’re not a target until you are.”

The frame to use isn’t “do I have something to hide” - it’s autonomy. Manipulation. Decisions about you that aren’t yours. Local laws that change (abortion, dissent). Police work should be hard by design, because mass collection always overflows the targeted use case it was sold as.

:light_bulb: Three Things That Got Better

Claudia’s grudging optimism:

  1. Awareness. Early 2000s, “privacy researcher” was a conversation-killer on airplanes. Now it’s a mainstream concern.
  2. Decentralization push. Less promiscuity about routing all data through US-controlled services. Reshoring, GDPR, the whole regulatory shift.
  3. Encryption everywhere. Security culture went from “annoying” to “tolerated” because people understand the alternative.

“The bad thing isn’t the revelations - it’s that it was happening in the first place.”

:red_question_mark: Q&A Highlights

Q: When a Latin American government buys black-box intelligence software from Silicon Valley - are they importing security or exporting digital sovereignty?
Claudia: Exporting sovereignty. Buying intel tooling from a foreign power means trusting that power deeply with your domestic operations. Homegrown is preferable, especially “in an increasingly hostile world where even countries that were allies, it’s not clear what this means anymore.”

Q: How can everyday citizens defend against digital colonialism when our own data protection laws have national security loopholes?
Two-pronged. Tech: use and contribute to free and open source - you can’t fork Google Maps, but you can fork a community tool and bend it toward local needs. Politics: the laws have national security loopholes because politicians wrote them that way. This is ultimately a political fight, not a technical one.

Q: Do you use AI tools like Claude in your research?
Yes, recently. It’s powerful for navigating source code and reconstructing how an algorithm actually works in a large system - tasks that would otherwise eat days. But:

“You have to be extremely questioning of everything you get back. It’s a great new tool, but a tool to be used with caution.”

Sudo’s framing: never let AI think for you - you’ll get dumber and you’ll trust hallucinations.

Q: Where do you see Nym in 5 years?
Claudia: Scale. The mission is privacy for all of humanity, and that only works if enough people use the system.

“Privacy loves company.”

Q: British digital “passportization” and digital ID in general?
Claudia: ID for civic functions (taxes, voting, banking) is normal across mainland Europe and has been for decades. The thing that’s qualitatively different is ID required to do a Google search or log into email - that’s the line being quietly pushed in Australia, the UK, and elsewhere. Sudo: if this is going to happen, the only acceptable implementation is zero-knowledge - prove the predicate (age, citizenship) without revealing the identity. Anything else is the surveillance regime in disguise.

:stopwatch: Timestamps

  • 00:04:36 - What’s a Global Passive Adversary
  • 00:14:21 - NSA undermining crypto standards
  • 00:16:31 - PRISM and XKeyScore
  • 00:23:14 - From revelations to Nym’s founding
  • 00:28:21 - Why metadata is harder than content
  • 00:36:29 - Crypto Wars 3: client-side scanning, Pegasus, AI
  • 00:43:48 - The “nothing to hide” rebuttal
  • 00:50:11 - Three wins post-Snowden
  • 01:01:02 - Using Claude / AI in research
  • 01:07:22 - Digital ID and zero-knowledge IDs

Watch the full recording: YouTube Link

Big thanks to Claudia for the time, the nostalgia trip, and the grounded read on where things stand. This week’s PoEp password commemorates Citizen4 - the pseudonym Snowden used to contact Laura Poitras and Glenn Greenwald, and the name of the documentary that captured the whole thing (well worth a watch if you haven’t seen it).

The community push this week: Nym is sending free NymVPN passes to anyone who asks nicely on Telegram. Pass them to friends - a project that exists, in large part, because of the risk Snowden took 13 years ago, deserves to reach as many people as possible.

:green_heart: