<script data-pm-proxy="intercept"></script><?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[PrivID's Substack]]></title><description><![CDATA[Everything you didn't want to know about cybersecurity, encryption and how your data is protected.]]></description><link>https://jirif.substack.com</link><image><url>https://substackcdn.com/image/fetch/$s_!lNUO!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F567255b2-72f0-48b1-a849-3fbce7da65e9_142x142.png</url><title>PrivID&apos;s Substack</title><link>https://jirif.substack.com</link></image><generator>Substack</generator><lastBuildDate>Wed, 02 Sep 2026 04:42:45 GMT</lastBuildDate><atom:link href="/__u/jirif.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[PrivID / Jiri Fiala]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[jirif@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[jirif@substack.com]]></itunes:email><itunes:name><![CDATA[Jiri Fiala]]></itunes:name></itunes:owner><itunes:author><![CDATA[Jiri Fiala]]></itunes:author><googleplay:owner><![CDATA[jirif@substack.com]]></googleplay:owner><googleplay:email><![CDATA[jirif@substack.com]]></googleplay:email><googleplay:author><![CDATA[Jiri Fiala]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Your Data Is in Europe. Your Sovereignty Isn’t.]]></title><description><![CDATA[The interface confirms that your information will be stored in Frankfurt, Dublin, Paris or Amsterdam.]]></description><link>https://jirif.substack.com/p/your-data-is-in-europe-your-sovereignty</link><guid isPermaLink="false">https://jirif.substack.com/p/your-data-is-in-europe-your-sovereignty</guid><dc:creator><![CDATA[Jiri Fiala]]></dc:creator><pubDate>Tue, 01 Sep 2026 13:18:22 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ktdJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98789fce-a712-49e3-a169-659d4280937a_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The interface confirms that your information will be stored in Frankfurt, Dublin, Paris or Amsterdam. The contract refers to GDPR compliance, regional processing and European data boundaries. A map shows your data sitting safely inside Europe.</p><p>The physical location of data affects latency, regulatory obligations, disaster recovery and which national authorities have immediate territorial jurisdiction. Location answers only where the servers sit.</p><p>But, who controls the infrastructure, who can access the information, which foreign laws apply to the provider or whether another government can compel disclosure.</p><h2>Residency is not sovereignty</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!ktdJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98789fce-a712-49e3-a169-659d4280937a_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!ktdJ!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98789fce-a712-49e3-a169-659d4280937a_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!ktdJ!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98789fce-a712-49e3-a169-659d4280937a_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!ktdJ!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98789fce-a712-49e3-a169-659d4280937a_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!ktdJ!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98789fce-a712-49e3-a169-659d4280937a_1536x1024.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!ktdJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98789fce-a712-49e3-a169-659d4280937a_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/98789fce-a712-49e3-a169-659d4280937a_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2482998,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://jirif.substack.com/i/213546085?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98789fce-a712-49e3-a169-659d4280937a_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!ktdJ!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98789fce-a712-49e3-a169-659d4280937a_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!ktdJ!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98789fce-a712-49e3-a169-659d4280937a_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!ktdJ!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98789fce-a712-49e3-a169-659d4280937a_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!ktdJ!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98789fce-a712-49e3-a169-659d4280937a_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Data residency refers to the physical/geographic location where information is stored. The Government of Canada&#8217;s own digital guidance explicitly distinguishes it from sovereignty, which concerns a country&#8217;s authority over access to and disclosure of information.</p><p>A company announces a Canadian data centre and calls the service sovereign. A US cloud provider creates a European region and markets it as local control. Procurement ticks the residency box, legal approves the contractual clauses and executives assume the jurisdictional problem has been resolved. It hasn&#8217;t.</p><p><strong>Data residency</strong> tells you where the information is stored.</p><p><strong>Data protection</strong> tells you which rules apply about handling of the data.</p><p><strong>Data control</strong> tells you who can technically retrieve, process or disclose it.</p><p><strong>Data sovereignty</strong> tells you which jurisdiction has enforceable authority over that control.</p><p>These conditions can overlap, but they&#8217;re not interchangeable. Data can reside in Europe, receive GDPR protection and still be accessible to a company under American law.</p><p>The Government of Canada acknowledges this directly. Its 2026 white paper on public-cloud sovereignty states that government data entrusted to a foreign cloud provider may remain subject to that provider&#8217;s home-country laws even when the data resides in Canada. It identifies the central risk: <em><strong>foreign authorities may use their domestic laws to compel the provider to surrender Canadian government information</strong></em>.</p><p><a href="https://www.canada.ca/en/government/system/digital-government/digital-government-innovations/cloud-services/digital-sovereignty/gc-white-paper-data-sovereignty-public-cloud.html">Canada&#8217;s data-sovereignty white paper</a> very clearly describes the legal structure of modern cloud computing.</p><h2>The CLOUD Act</h2><p>Microsoft is subject to American law, including the CLOUD Act. (I&#8217;ve written about this issue many times in the past, the most recent one just over 12 months ago.)</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;d4d5c99c-346e-4626-aa6a-a5c6039a7dd7&quot;,&quot;caption&quot;:&quot;TL;DR Core issue: U.S. Cloud Act lets authorities compel any U.S.&#8209;based cloud provider to hand over data, even if it&#8217;s stored in Europe.&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Cloud Act Undermines Cloud Sovereignty Claims&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:98983441,&quot;name&quot;:&quot;Jiri Fiala&quot;,&quot;bio&quot;:&quot;&#8220;Questions are interesting. Conclusions are boring.&#8221; - Jiri Fiala. I write about cybersecurity, AI and architecture. For those who want understanding, not marketing. Always free.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/baf1060a-fb4d-4e49-9e7f-c27eb14c957d_1024x1028.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2025-07-29T13:53:51.874Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!PoNL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d51ee0e-a3d5-41fe-a0b3-94ac376c0682_1024x1024.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://jirif.substack.com/p/cloud-act-undermines-cloud-sovereignty&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:169561328,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:0,&quot;publication_id&quot;:2908150,&quot;publication_name&quot;:&quot;PrivID's Substack&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!lNUO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F567255b2-72f0-48b1-a849-3fbce7da65e9_142x142.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>Microsoft&#8217;s own explanation says that <em>US law enforcement can compel service providers to produce information within their &#8220;possession, custody or control,&#8221; regardless of where that information is physically located</em>. <strong>Read that again</strong>. Carefully.</p><p>The CLOUD Act doesn&#8217;t need to move a European server into the United States. It reaches the American company controlling the server.</p><p>Microsoft says it scrutinises government demands, rejects those that aren&#8217;t legally valid, challenges disproportionate orders and attempts to redirect authorities to enterprise customers. <strong>Microsoft says that governments don&#8217;t receive direct, unrestricted access to its systems</strong>. They reduce abuse and provide more accountability than in many other jurisdictions. <em><strong>But that&#8217;s not sovereignty</strong></em>.</p><p>If Microsoft receives a valid and enforceable American order, it must comply. <em>The company may challenge the demand, narrow it or notify the customer <strong>where legally permitted</strong></em>. It can&#8217;t promise that European or Canadian information will never be disclosed to American authorities.</p><p>It&#8217;s the legal reality Microsoft itself acknowledges in its <a href="https://www.microsoft.com/en-us/corporate-responsibility/reports/government-requests/customer-data">government-request disclosures</a>. It&#8217;s not an accusation.</p><h2>The EU Data Boundary reduces exposure</h2><p>Microsoft has invested heavily in its <strong>EU Data Boundary</strong>, allowing European customers to store and process substantial categories of Microsoft 365, Azure, Dynamics 365 and Power Platform data within the EU and EFTA. Keeping more information inside Europe reduces unnecessary transfers, simplifies compliance and limits some operational exposure.</p><p><em><strong>But Microsoft&#8217;s documentation also lists circumstances in which information continues to move beyond the boundary</strong></em>. These include global security operations, technical support, communications with users outside Europe, customer-configured integrations and certain professional-services data. Some information may be accessed remotely by personnel outside the EU, while some support and consulting material may be stored in the United States.</p><p>Microsoft describes this accurately: it significantly reduces data flows outside Europe. It doesn&#8217;t claim that it&#8217;s isolated from non-European access.</p><p><a href="https://learn.microsoft.com/en-us/privacy/eudb/eu-data-boundary-transfers-for-all-services">Microsoft&#8217;s EU Data Boundary documentation</a> makes the limitations visible to anyone that reads past the marketing summary.</p><p>Even if every operational transfer were eliminated, however, the central jurisdictional issue would remain. Microsoft Corporation is still an American-controlled entity.</p><h2>Compliance frameworks don&#8217;t transfer sovereignty.</h2><p>Europe has built legal mechanisms to govern information moving to the United States. Standard Contractual Clauses establish obligations between exporters and importers. The EU&#8211;US Data Privacy Framework allows participating American companies to receive European personal information under an adequacy decision. Without these mechanisms, much of the transatlantic digital economy couldn&#8217;t legally function.</p><p>The Court of Justice of the European Union demonstrated that distinction in the 2020 Schrems II judgment. It invalidated the previous EU&#8211;US Privacy Shield because American surveillance law didn&#8217;t provide protections essentially equivalent to those required in Europe.</p><p>The current Data Privacy Framework was created to address those deficiencies. It may provide a valid legal transfer mechanism, but it doesn&#8217;t make American providers European, repeal the CLOUD Act or remove US intelligence and law-enforcement authority.</p><h2>Control matters more than the address of the server</h2><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;b85f75ce-3ebe-4b2b-875e-88af8e868db8&quot;,&quot;caption&quot;:&quot;When organisations think about cybersecurity and data sovereignty, they often focus on encryption, hosting locations, and compliance with laws such as GDPR and PIPEDA. However, an often-overlooked risk comes from something as simple as your domain extension&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;How Your Domain Extension Could Put Your Data at Risk&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:98983441,&quot;name&quot;:&quot;Jiri Fiala&quot;,&quot;bio&quot;:&quot;&#8220;Questions are interesting. Conclusions are boring.&#8221; - Jiri Fiala. I write about cybersecurity, AI and architecture. For those who want understanding, not marketing. Always free.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/baf1060a-fb4d-4e49-9e7f-c27eb14c957d_1024x1028.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2025-03-25T06:03:47.856Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!XWjG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13552dfc-f311-4bbf-bdca-85d847822283_1024x1024.webp&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://jirif.substack.com/p/how-your-domain-extension-could-put&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:159338487,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:1,&quot;comment_count&quot;:0,&quot;publication_id&quot;:2908150,&quot;publication_name&quot;:&quot;PrivID's Substack&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!lNUO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F567255b2-72f0-48b1-a849-3fbce7da65e9_142x142.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><ul><li><p>Can the provider retrieve intelligible customer information?</p></li><li><p>Can the provider&#8217;s employees or systems access it?</p></li><li><p>Can the provider independently decrypt it?</p></li><li><p>Can the provider be compelled by a foreign government to disclose it?</p></li><li><p>Can that government prohibit the provider from notifying the customer?</p></li><li><p>Can the provider suspend the service or deny continued access?</p></li></ul><p>If the answer to these questions is yes, the customer may have residency, compliance and contractual protection. It doesn&#8217;t have complete sovereignty. Information may be encrypted while stored and while moving across networks, but if the provider controls the keys or must decrypt the information to process it, the provider still occupies the point of access.</p><p>That may be acceptable for ordinary workloads, but not for defence, healthcare, judicial records, intellectual property, critical infrastructure or government decision-making. Sovereignty is not a single setting. Different information requires different levels of control. Public websites and routine administration don&#8217;t need the same architecture as military communications or national identity systems.</p><h2>Sovereignty requires architectural limits</h2><p>True digital sovereignty can&#8217;t depend on a provider promising to refuse access. It needs systems designed so that the provider can&#8217;t independently access plaintext.</p><p>That means separating identity from disclosure, keeping meaningful control of cryptographic keys with the customer, segmenting information so one compromised service can&#8217;t expose everything, and enabling computation without routinely revealing the underlying data.</p><p>The objective isn&#8217;t to make lawful investigation impossible. It&#8217;s to ensure that access to sensitive information occurs through the authority that owns it, under the applicable domestic legal process, not through a foreign-controlled intermediary.</p><h2>Europe is beginning to recognise the difference</h2><p>The renewed European push for sovereign cloud services, open infrastructure and EuroStack reflects a growing recognition that regulation alone can&#8217;t fix structural dependency.</p><p>Europe can regulate foreign platforms, negotiate transfer frameworks and require contractual safeguards. But if its governments, businesses and critical services are dependent on infrastructure controlled elsewhere, Europe is governing a dependency. Building European alternatives would change that. It brings corporate control, infrastructure and legal jurisdiction closer together.</p><p>A European provider that can freely access every customer&#8217;s plaintext creates a different jurisdictional arrangement, not a complete security architecture. But it changes who sets the terms, who controls continuity and which legal system has the final word. That&#8217; real data sovereignty.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://jirif.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading PrivID's Substack! Subscribe for free to receive new posts.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The Chinese EV Is a Spy. Microsoft Is Infrastructure.]]></title><description><![CDATA[Two foreign-controlled systems inside a government facility.]]></description><link>https://jirif.substack.com/p/the-chinese-ev-is-a-spy-microsoft</link><guid isPermaLink="false">https://jirif.substack.com/p/the-chinese-ev-is-a-spy-microsoft</guid><dc:creator><![CDATA[Jiri Fiala]]></dc:creator><pubDate>Mon, 31 Aug 2026 13:01:11 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dmGQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55a0f97d-43ca-4135-9eb2-2966ea79dc86_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Two foreign-controlled systems inside a government facility. One is parked outside. It has cameras, microphones, location data, wireless connectivity and software that can be updated remotely. Officials worry that its manufacturer could be compelled by a foreign government to surrender information.</p><p>The other sits inside the building. It has access to email, documents, meetings, calendars, internal communications, location data, wireless connectivity, microphones, cameras, remote software updates <strong>and</strong> potentially everything an employee can retrieve through Microsoft 365. <em>Its manufacturer has openly acknowledged that it can be compelled by the US government to surrender information, even when that information is stored outside the United States.</em></p><p>The first is treated as a potential espionage platform. The second is called productivity infrastructure.</p><p>That oxymoron is at the centre of the Western debate about Chinese electric vehicles. But if foreign jurisdiction and compelled disclosure are the concern, we should be looking at both the same way.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!dmGQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55a0f97d-43ca-4135-9eb2-2966ea79dc86_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!dmGQ!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55a0f97d-43ca-4135-9eb2-2966ea79dc86_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!dmGQ!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55a0f97d-43ca-4135-9eb2-2966ea79dc86_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!dmGQ!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55a0f97d-43ca-4135-9eb2-2966ea79dc86_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!dmGQ!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55a0f97d-43ca-4135-9eb2-2966ea79dc86_1536x1024.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!dmGQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55a0f97d-43ca-4135-9eb2-2966ea79dc86_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/55a0f97d-43ca-4135-9eb2-2966ea79dc86_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2436756,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://jirif.substack.com/i/213539242?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55a0f97d-43ca-4135-9eb2-2966ea79dc86_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!dmGQ!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55a0f97d-43ca-4135-9eb2-2966ea79dc86_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!dmGQ!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55a0f97d-43ca-4135-9eb2-2966ea79dc86_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!dmGQ!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55a0f97d-43ca-4135-9eb2-2966ea79dc86_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!dmGQ!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55a0f97d-43ca-4135-9eb2-2966ea79dc86_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>The concern about Chinese vehicles is not imaginary</h2><p>Modern vehicles are rolling sensor platforms. They record location, speed, driving behaviour, voice commands and information about nearby devices. Exterior cameras observe roads, buildings, people and other vehicles. Driver-monitoring systems may record facial position, attention and movement inside the car. Remote diagnostics and over-the-air updates give manufacturers continuing technical relationships with vehicles long after they leave the factory.</p><p>That creates real security issues around military bases, government buildings, critical infrastructure and senior officials. A compromised or deliberately manipulated vehicle could collect useful intelligence or provide a route into connected systems.</p><p>Chinese companies also operate under laws that can require cooperation with Chinese state authorities. Czechia has good reason to take that seriously. Its government has attributed cyberattacks against the Czech Ministry of Foreign Affairs to a group associated with China&#8217;s Ministry of State Security, while N&#218;KIB has repeatedly warned about technology subject to Chinese state influence.</p><p>It&#8217;s not paranoia, if they&#8217;re actually after you. Is it? The issue isn&#8217;t that, really. It&#8217;s how selective we are in applying that standard.</p><h2>Microsoft has already acknowledged the jurisdictional reality</h2><p><em>Microsoft is subject to American law, including the CLOUD Act</em>. The company&#8217;s own explanation is unambiguous: <em><strong>US authorities can compel American service providers to disclose information within their &#8220;possession, custody or control,&#8221; regardless of where that information is physically stored</strong></em>.</p><p>Microsoft says it examines every demand, rejects those it considers invalid, redirects authorities to enterprise customers where possible and challenges disproportionate orders. It also says governments don&#8217;t receive direct or unrestricted access to customer systems.</p><p>The American legal process may be more transparent and contestable than the Chinese version. But that doesn&#8217;t change the final answer.</p><p>If Microsoft receives a valid and binding American order, it has to comply. The location of the data centre doesn&#8217;t matter. In some cases, a secrecy order may stop Microsoft from notifying the affected customer.</p><p>Microsoft publishes figures showing that demands involving foreign enterprise data are rare. That&#8217;s irrelevant to the underlying sovereignty question. A little used foreign power is still a foreign power.</p><p><a href="https://www.microsoft.com/en-us/corporate-responsibility/reports/government-requests/customer-data">Microsoft&#8217;s government-request policy</a> outlines both the protections and the obligation.</p><h2>Copilot is already inside operations</h2><p>Canada has authorised Microsoft Copilot for use across parts of the federal government. Its implementation policy limits the browser-based service to unclassified information, requires government identities and mandates Microsoft&#8217;s enterprise-data-protection settings. The Department of National Defence similarly identifies Copilot as its approved generative-AI tool, subject to restrictions on the information employees may provide. That, at least, shows that Canada is trying to manage the risk.</p><p>Czech public administration is also adopting Copilot. The Czech Ministry of Justice describes officials using it for everyday work, including routine analysis, presentations and communication. The Digital and Information Agency has trained employees to use Copilot and create AI agents for administrative processes.</p><p>Again, that doesn&#8217;t mean Czech or Canadian officials are recklessly feeding classified plans into a public chatbot. But it does mean both governments accept Microsoft as a trusted operational partner despite the company being legally subject to a foreign state. Does anyone else see the problem with this arrangement?</p><ul><li><p>Chinese legal compulsion is presented as state control. American legal compulsion is presented as lawful process.</p></li><li><p>Chinese telemetry is described as surveillance. Microsoft&#8217;s access to government information is described as enterprise integration.</p></li><li><p>Chinese remote software is a potential kill switch. American cloud dependency is a service contract.</p></li></ul><p>The technology may be different, but the underlying sovereignty issue isn&#8217;t: can a foreign-controlled provider access sensitive information, and can its home government compel it to disclose that information? If that point is problematic, the flag of the country shouldn&#8217;t matter.</p><h2>A car may know where an official drove. Copilot may know what the official decided.</h2><p>A connected vehicle can reveal travel patterns, visited locations and proximity to sensitive facilities. That can be valuable intelligence.</p><p>Microsoft 365 may contain policy discussions, legal advice, budget documents, procurement decisions, internal disagreements, security assessments and communications between senior officials. Copilot can make that information easier to locate, summarise and correlate because that is precisely what it is designed to do.</p><p>An EV (Chinese or otherwise) may know where an official drove. Microsoft may know what that official wrote, read, discussed and decided. So why is the first looked at as the more obvious sovereignty threat?</p><p>This is less about technical capability than political alignment. American access is regarded as allied, rules-based and manageable. Chinese access is regarded as hostile by definition.</p><h2>The American response is clear</h2><p>The United States has used tariffs and connected-vehicle rules to keep most Chinese EV manufacturers out of its market. Polestar, despite its Swedish identity and increasingly diversified manufacturing, has been caught by these restrictions because of its relationship with Geely.</p><p>This applies even when vehicles are assembled outside China. Moving production to South Korea or South Carolina may change the country of origin, but it doesn&#8217;t necessarily change the ownership, software or remote-control analysis used by American regulators.</p><p>Volvo, which is also controlled by Geely and shares substantial technology with Polestar, has received different treatment. When two closely related companies using overlapping platforms produce different security decisions, industrial policy and domestic market protection begin to look at least as important as cybersecurity.</p><h2>Apply the same standard to everyone</h2><p>The answer isn&#8217;t to ignore Chinese technology risks or prohibit governments from using Microsoft. The latter would take years to unravel. It&#8217;s to stop treating corporate nationality as a substitute for architecture.</p><p>Governments should identify what information a system collects, where it is processed, who can access it, which jurisdictions can compel disclosure and whether the provider can surrender intelligible information without the customer&#8217;s consent, or knowledge.</p><p>Sensitive facilities can restrict vehicles with externally controlled telemetry regardless of whether the manufacturer is Chinese, American or European. Government cloud systems can require local operational control, independent auditing, strong segmentation and encryption that prevents service providers from accessing usable plaintext.</p><p>Restrictions should follow the information and the architecture. Not the flag or origin. Europe and Canada can&#8217;t argue that sovereignty is threatened whenever Chinese law reaches into a vehicle and, at the same time, be indifferent when American law reaches into the cloud.</p><p>The Chinese EV will continue to be called a spy while Microsoft remains infrastructure. Which is the bigger problem?</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://jirif.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading PrivID's Substack! Subscribe for free to receive new posts.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Allies Don’t Need to Share Everything]]></title><description><![CDATA[Countries need to exchange information to identify threats, coordinate responses and protect critical infrastructure.]]></description><link>https://jirif.substack.com/p/allies-dont-need-to-share-everything</link><guid isPermaLink="false">https://jirif.substack.com/p/allies-dont-need-to-share-everything</guid><dc:creator><![CDATA[Jiri Fiala]]></dc:creator><pubDate>Thu, 27 Aug 2026 13:41:07 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!DvDu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F542e3a39-79de-4a08-bed4-46c9c2d8f0be_1774x887.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Countries need to exchange information to identify threats, coordinate responses and protect critical infrastructure. But every time sensitive information is copied into another organisation, another system or another jurisdiction, the number of places capable of exposing it increases.</p><h2>Sharing a result isn&#8217;t the same as sharing the source</h2><p>Imagine one intelligence service has information about a suspected individual. Another country needs to know whether that person appears in the dataset. A third wants to determine whether the individual has connections to entities already under investigation. None of that automatically means access to the complete record.</p><p>One country needs confirmation. Another needs the result of a query. And another needs to establish that a threshold has been reached. Systems tend to solve all three problems the same way. Moving data. Once that happens, the original owner loses control over what comes next. The information now exists inside another country&#8217;s infrastructure, under another set of administrators, policies, suppliers and legal obligations.</p><h2>Every copy is a security problem</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!DvDu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F542e3a39-79de-4a08-bed4-46c9c2d8f0be_1774x887.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!DvDu!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F542e3a39-79de-4a08-bed4-46c9c2d8f0be_1774x887.png 424w, /__u/substackcdn.com/image/fetch/$s_!DvDu!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F542e3a39-79de-4a08-bed4-46c9c2d8f0be_1774x887.png 848w, /__u/substackcdn.com/image/fetch/$s_!DvDu!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F542e3a39-79de-4a08-bed4-46c9c2d8f0be_1774x887.png 1272w, /__u/substackcdn.com/image/fetch/$s_!DvDu!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F542e3a39-79de-4a08-bed4-46c9c2d8f0be_1774x887.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!DvDu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F542e3a39-79de-4a08-bed4-46c9c2d8f0be_1774x887.png" width="1456" height="728" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/542e3a39-79de-4a08-bed4-46c9c2d8f0be_1774x887.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:728,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2204581,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://jirif.substack.com/i/212899897?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F542e3a39-79de-4a08-bed4-46c9c2d8f0be_1774x887.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!DvDu!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F542e3a39-79de-4a08-bed4-46c9c2d8f0be_1774x887.png 424w, /__u/substackcdn.com/image/fetch/$s_!DvDu!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F542e3a39-79de-4a08-bed4-46c9c2d8f0be_1774x887.png 848w, /__u/substackcdn.com/image/fetch/$s_!DvDu!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F542e3a39-79de-4a08-bed4-46c9c2d8f0be_1774x887.png 1272w, /__u/substackcdn.com/image/fetch/$s_!DvDu!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F542e3a39-79de-4a08-bed4-46c9c2d8f0be_1774x887.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Intelligence-sharing creates dependencies between organisations. The more information shared, the larger those dependencies become. A dataset copied to five partners now has six security perimeters. If those partners make more copies, the number grows further. So do the administrators, applications, backups and systems capable of interacting with it.</p><p>This is an argument against treating <strong>data duplication as the default mechanism</strong>.</p><h2>Ask the data without taking the data</h2><p>This is where privacy-enhancing cryptography becomes useful. ZKPs can allow one party to prove that a condition is true without disclosing all of the information behind that proof. FHE can allow certain computations to be performed while the underlying information remains encrypted.</p><p>Instead of transferring an intelligence dataset so another party can inspect it, the architecture can potentially allow tightly defined questions to be answered against protected information.</p><ul><li><p>Does this identifier appear in the dataset?</p></li><li><p>Does this entity satisfy an agreed risk condition?</p></li><li><p>Do two datasets contain a relevant relationship?</p></li><li><p>Does this transaction pattern exceed a predefined threshold?</p></li></ul><p>The recipient gets the answer without automatically receiving everything used to produce it.</p><h2>Need-to-know should actually mean need-to-know</h2><p>Security organisations have used the phrase <em>need-to-know</em> for decades. Realistically? It usually means <strong>need-to-access</strong>. A person or system is authorised to retrieve a record, after which the burden shifts to access controls, policy and monitoring to ensure it isn&#8217;t misused. That works, until it doesn&#8217;t.</p><h2>Limit the exposure</h2><p>Alliances don&#8217;t work without cooperation, and intelligence relationships depend on high levels of institutional trust. But trust doesn&#8217;t mean unlimited access. Two governments may trust each and still have legitimate reasons to restrict access to particular sources, identities, methods or datasets. The same applies to defence contractors, law-enforcement agencies, financial institutions and operators of critical infrastructure.</p><p>If a partner&#8217;s access becomes narrower, the architecture can narrow the questions it&#8217;s allowed to ask rather than trying to recover information already copied elsewhere. If another organisation joins the relationship, it can be granted precisely the capability it needs without inheriting broad access because it is easier operationally.</p><h2>Where PrivID fits</h2><p>This is one of the areas where PrivID&#8217;s combination of ZKP, FHE, segmentation and bounded access is relevant. Data can stay under the control of the organisation responsible for it. Other authorised parties can receive proofs, results or tightly restricted access without automatically receiving the underlying information.</p><ul><li><p>With computation over encrypted data, the infrastructure doesn&#8217;t neeed plaintext visibility.</p></li><li><p>When verification can rely on a proof, the verifying party doesn&#8217;t need details.</p></li><li><p>Where access is segmented, one relationship doesn&#8217;t just expose everything.</p></li></ul><p>None of this eliminates conventional security controls. Authentication, endpoint security, monitoring, key management and operational discipline are still crucial. But failure in one of those controls doesn&#8217;t automatically expose everything else.</p><h2>Cooperation without accumulation</h2><p>The geopolitical environment is pushing governments towards two objectives:</p><ol><li><p>Share more information because threats increasingly cross borders, networks and jurisdictions.</p></li><li><p>The need for more control over sensitive data, infrastructure and national dependencies.</p></li></ol><p>The solution? Share the <strong>minimum information required to produce the necessary outcome</strong>. Granted, it&#8217;s easier said than done, but PrivID has been working on that solution for eight years.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://jirif.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading PrivID's Substack! Subscribe for free to receive new posts.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The Most Successful Spy Doesn’t Steal Anything]]></title><description><![CDATA[An attacker gets in, finds sensitive information, copies it and sends it home.]]></description><link>https://jirif.substack.com/p/the-most-successful-spy-doesnt-steal</link><guid isPermaLink="false">https://jirif.substack.com/p/the-most-successful-spy-doesnt-steal</guid><dc:creator><![CDATA[Jiri Fiala]]></dc:creator><pubDate>Wed, 26 Aug 2026 14:39:57 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!-IJj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b33e943-f5d2-43d7-b934-da70989e6b54_1672x941.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>An attacker gets in, finds sensitive information, copies it and sends it home. An intelligence service that can hide inside a network may not need to steal anything. It can watch who communicates with whom, watch administrative behaviour, identify systems and relationships, follow movements across infrastructure, query information when it becomes useful and wait.</p><p>In 2025, CISA and international partners described Chinese state-sponsored actors compromising telecommunications, government, transportation, lodging and military infrastructure around the world. The activity, overlapping with what industry calls Salt Typhoon, included modifying routers to maintain long-term access and using compromised infrastructure and trusted connections to move into other networks. The intelligence value included identifying and tracking communications and movements of targets.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!-IJj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b33e943-f5d2-43d7-b934-da70989e6b54_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!-IJj!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b33e943-f5d2-43d7-b934-da70989e6b54_1672x941.png 424w, /__u/substackcdn.com/image/fetch/$s_!-IJj!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b33e943-f5d2-43d7-b934-da70989e6b54_1672x941.png 848w, /__u/substackcdn.com/image/fetch/$s_!-IJj!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b33e943-f5d2-43d7-b934-da70989e6b54_1672x941.png 1272w, /__u/substackcdn.com/image/fetch/$s_!-IJj!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b33e943-f5d2-43d7-b934-da70989e6b54_1672x941.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!-IJj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b33e943-f5d2-43d7-b934-da70989e6b54_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7b33e943-f5d2-43d7-b934-da70989e6b54_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2185665,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://jirif.substack.com/i/212858853?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b33e943-f5d2-43d7-b934-da70989e6b54_1672x941.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!-IJj!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b33e943-f5d2-43d7-b934-da70989e6b54_1672x941.png 424w, /__u/substackcdn.com/image/fetch/$s_!-IJj!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b33e943-f5d2-43d7-b934-da70989e6b54_1672x941.png 848w, /__u/substackcdn.com/image/fetch/$s_!-IJj!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b33e943-f5d2-43d7-b934-da70989e6b54_1672x941.png 1272w, /__u/substackcdn.com/image/fetch/$s_!-IJj!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b33e943-f5d2-43d7-b934-da70989e6b54_1672x941.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Assume they&#8217;re already inside</h2><p>APT28 has compromised routers. Volt Typhoon has maintained access to critical infrastructure environments for years. Salt Typhoon-linked activity has penetrated telecommunications infrastructure across multiple countries. CISA says Volt Typhoon has used legitimate accounts and ordinary administrative tools to blend into normal operations, with evidence of access persisting in some environments for at least five years. The takeaway should be that <strong>prevention eventually fails somewhere</strong>.</p><p>A credential gets stolen. A supplier gets compromised. A vulnerability stays unpatched. An administrator makes a mistake. A trusted connection is abused. A perfectly legitimate system tool is used for something illegitimate. If gaining access exposes useful plaintext, broad identity records, administrative relationships, internal datasets and pathways into neighbouring systems, then one breach can become an intelligence platform.</p><h2>Intelligence doesn&#8217;t need a big theft</h2><p>Metadata can be intelligence. Who queried a particular record? Which executives communicate frequently? Which government departments exchange the most valuable information? When does activity increase? Which systems talk to one another? Which administrator can reach a sensitive environment? Which identity appears across several datasets? Once those puzzle pieces come together the picture gets very clear.</p><p>The telecommunications compromises associated with Chinese state-sponsored activity illustrate the point. Control of backbone and edge infrastructure can reveal patterns of communication and movement even before we start talking about message content.</p><p>Stopping unauthorised entry is essential, but <strong>preventing entry and preventing disclosure are not the same control</strong>. We need to stop treating them like they&#8217;re the same thing.</p><h2>Access shouldn&#8217;t create knowledge</h2><p>Once an attacker gains the right account, process, machine or administrative position, the same visibility that makes the system useful can make it valuable for espionage. Because most conventional systems are designed around a straightforward assumption: authorised software receives usable information so that it can process it.</p><ul><li><p>The application sees the plaintext.</p></li><li><p>The administrator can query the database.</p></li><li><p>The analytics platform receives the records.</p></li><li><p>The identity service knows the attributes.</p></li><li><p>The infrastructure contains enough context to reconstruct relationships between them.</p></li></ul><p>Systems try to contain the attacker inside a system. A system that is designed to reveal information to anything occupying the correct position. Does that sound like a valid way to protect a sensitive system and its data?</p><h2>Make persistence less useful</h2><p>Under conventional architecture, the verification process can have access to the underlying identity record. Compromise the process and the attacker can gain access to those records. With a zero-knowledge approach, the system could instead receive proof that the requirement has been satisfied without receiving all of the attributes behind it. Which means that there is a lot less data to compromise.</p><p>If infrastructure needs to calculate something using sensitive information, FHE can allow classes of computation to happen while that information remains encrypted. But, FHE doesn&#8217;t make the compromised infrastructure trustworthy, by default. It just means the <strong>compromise doesn&#8217;t have to produce the same amount of disclosure</strong>.</p><h2>This is where PrivID fits</h2><p>This is one of the reasons we&#8217;re combining ZKPs, FHE, segmentation and tightly bounded access within PrivID. The objective isn&#8217;t to claim that an attacker can never get into a PrivID-enabled environment. No organisation can make that promise or guarantee.</p><p>Endpoints can still be compromised. Credentials can still be stolen. Implementation flaws can still exist. Infrastructure still needs patching, monitoring, authentication and conventional security controls.</p><p>The assumption about what successful access means changes:</p><ul><li><p>A system only needs to know that a condition is true.</p></li><li><p>Infrastructure only needs to perform a calculation, not expose the entire system.</p></li><li><p>If one component is compromised, segmentation limits how much of the environment is visible.</p></li><li><p>If an attacker obtains persistence, that persistence doesn&#8217;t automatically mean unrestricted access or observation.</p></li></ul><h2>The attacker prefers you don&#8217;t notice</h2><p>A persistent intelligence operation benefits from stability. Breaking systems attracts attention. Encrypting servers ends access. Dramatic exfiltration may trigger alerts. Staying quietly embedded is more useful.</p><p>Volt Typhoon&#8217;s use of legitimate tools and accounts is a good example. CISA and partner agencies have repeatedly warned that &#8220;living off the land&#8221; techniques allow malicious actors to blend into ordinary system activity and avoid some conventional detection mechanisms.</p><p>Under those conditions, what can those tools see? The answer is &#8220;almost everything the legitimate system could see&#8221;. That is a problem.</p><h2>Breach and disclosure should be separate failures</h2><p>Cybersecurity has spent years talking about defence in depth, but some of our most important systems still allow multiple security failures to collapse into one another. A breach shouldn&#8217;t automatically be a disclosure event, an identity compromise, an intelligence windfall and a pathway into everything connected to it.</p><p>We can&#8217;t intrusion impossible, especially against sophisticated state actors with time, money, specialised personnel and a strategic reason to remain persistent. The most effective spy may not steal anything. They may just sit inside your infrastructure and let your own systems tell them what they want to know.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://jirif.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading PrivID's Substack! Subscribe for free to receive new posts.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[You Don’t Need to Breach a Country You Already Supply]]></title><description><![CDATA[In 2025, Indian energy company Nayara Energy lost access to parts of its Microsoft infrastructure after European sanctions affected the company because of its Russian ownership links.]]></description><link>https://jirif.substack.com/p/you-dont-need-to-breach-a-country</link><guid isPermaLink="false">https://jirif.substack.com/p/you-dont-need-to-breach-a-country</guid><dc:creator><![CDATA[Jiri Fiala]]></dc:creator><pubDate>Tue, 25 Aug 2026 14:21:44 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!_Xr_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F780ae0d4-03b7-4844-a410-db4f75ff3bc5_1672x941.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!_Xr_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F780ae0d4-03b7-4844-a410-db4f75ff3bc5_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!_Xr_!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F780ae0d4-03b7-4844-a410-db4f75ff3bc5_1672x941.png 424w, /__u/substackcdn.com/image/fetch/$s_!_Xr_!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F780ae0d4-03b7-4844-a410-db4f75ff3bc5_1672x941.png 848w, /__u/substackcdn.com/image/fetch/$s_!_Xr_!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F780ae0d4-03b7-4844-a410-db4f75ff3bc5_1672x941.png 1272w, /__u/substackcdn.com/image/fetch/$s_!_Xr_!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F780ae0d4-03b7-4844-a410-db4f75ff3bc5_1672x941.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!_Xr_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F780ae0d4-03b7-4844-a410-db4f75ff3bc5_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/780ae0d4-03b7-4844-a410-db4f75ff3bc5_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2533490,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://jirif.substack.com/i/212697462?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F780ae0d4-03b7-4844-a410-db4f75ff3bc5_1672x941.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!_Xr_!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F780ae0d4-03b7-4844-a410-db4f75ff3bc5_1672x941.png 424w, /__u/substackcdn.com/image/fetch/$s_!_Xr_!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F780ae0d4-03b7-4844-a410-db4f75ff3bc5_1672x941.png 848w, /__u/substackcdn.com/image/fetch/$s_!_Xr_!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F780ae0d4-03b7-4844-a410-db4f75ff3bc5_1672x941.png 1272w, /__u/substackcdn.com/image/fetch/$s_!_Xr_!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F780ae0d4-03b7-4844-a410-db4f75ff3bc5_1672x941.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In 2025, Indian energy company Nayara Energy lost access to parts of its Microsoft infrastructure after European sanctions affected the company because of its Russian ownership links. Outlook and Teams were disrupted, and the company began moving communications to an Indian provider. Nobody hacked Microsoft. Nobody stole Nayara&#8217;s credentials. The infrastructure hadn&#8217;t failed. The political conditions changed.</p><p>Now consider the International Criminal Court.</p><p>The Trump administration has imposed sanctions on ICC judges, prosecutors and other officials over investigations and proceedings involving American and Israeli nationals, including the cases surrounding Israeli Prime Minister Benjamin Netanyahu and former defence minister Yoav Gallant. As of August 2026, nine of the Court&#8217;s eighteen judges had been sanctioned by the United States.</p><p>Whatever your position on the ICC&#8217;s jurisdiction, the mechanism used  by the Americans matters.</p><p>The sanctions don&#8217;t just freeze assets in the United States. Their practical effect travels through the financial and technology systems which much of the world depends on. Sanctioned ICC judges have described cancelled credit cards, disrupted banking and loss of access to services from major technology companies. Canadian ICC Judge Kimberly Prost has specifically described the reach of Visa, Mastercard, American Express and SWIFT as part of the practical impact of being sanctioned. The United States sits at critical points in the infrastructure they use. That is a cybersecurity issue, whether call it that or not.</p><h2>Dependency is a form of control</h2><p>Cybersecurity still tends to think about control in terms of access. A cloud provider doesn&#8217;t have to be hostile to become unavailable. A payment network doesn&#8217;t have to be compromised to stop processing transactions. A software company doesn&#8217;t need malicious intent for accounts, licensing or updates to disappear. A semiconductor manufacturer doesn&#8217;t have to attack anybody for export controls to make its products inaccessible.</p><p>Sometimes the supplier actively complies with government policy. Sometimes it has no realistic choice. This is the part of supply-chain security that few want to talk about. Organisations spend enormous amounts of effort assessing whether vendors themselves are secure. What happens when the vendor is perfectly secure and <strong>you can&#8217;t use it</strong>?</p><h2>Built deliberately</h2><p>Over the past twenty years, organisations have intentionally moved more of their infrastructure outside their direct control. Servers became cloud services. Software became SaaS. Identity became federated. Communications became platforms. Updates became continuous. Hardware became more specialised and globally sourced.</p><p>These &#8216;rational&#8217; decisions reduced costs, improved scalability and gave organisations access to capabilities they could never economically reproduce themselves. They also created a very different security perimeter.</p><p>An organisation can rely on multiple vendors throughout its technology stack. That&#8217;s the issue at hand. If a provider controls authentication, licensing, updates or a critical portion of the underlying compute, then somebody outside your organisation can affect what happens inside it <strong>without penetrating your network.</strong></p><p>The ICC sanctions make that point very clear. The judges didn&#8217;t decide that American payment and technology infrastructure was geopolitically important to them. They simply used ordinary financial and online services, as almost everyone does. Once sanctions were imposed, the architecture of the global financial system did the rest.</p><h2>Sovereignty isn&#8217;t just a flag on a server</h2><p>European cloud. Canadian cloud. Domestic processors. Domestic software. Domestic infrastructure. There&#8217;s a real argument for increasing domestic capability, especially in critical sectors. But pretending any modern economy can simply remove foreign dependency is just kidding yourself.</p><p>A European cloud service may run on American-designed processors manufactured in Asia. A Canadian cybersecurity product may depend on European libraries, American operating systems and globally manufactured hardware. A supposedly sovereign platform can contain dozens of external dependencies before anyone gets to the application layer.</p><p>Changing the nationality of the logo doesn&#8217;t necessarily change the architecture. Use foreign technology when it&#8217;s the best technical or commercial choice. But know what the supplier controls. Know what it can see. Know what happens if access disappears. Know whether replacing it involves changing a component or rebuilding the system.</p><h2>Capability doesn&#8217;t mean unlimited visibility</h2><p>This is where infrastructure dependency and information dependency become unnecessarily entangled. A cloud provider supplies compute, so plaintext becomes visible somewhere inside the computing environment. An identity provider verifies someone, so it gets the underlying identity information. A partner performs a compliance check, so it gets the records. A collaborator needs the answer to a question, so it gets the dataset. We&#8217;ve become used to these arrangements because that&#8217;s the way it&#8217;s &#8216;always been done&#8217;. Maybe. But, that doesn&#8217;t mean it should stay that way.</p><p>ZKPs can allow one party to establish that a condition is true without exposing all of the information used to prove it. FHE can allow computation to occur while the underlying data remains encrypted. These technologies don&#8217;t eliminate a supplier. They do eliminate &#8216;how much&#8217; the supplier sees.</p><p>A cloud platform using this encrypted computation can reduce visibility into a workload. A partner may still perform a verification, but a proof can reduce the amount of underlying identity information it receives. Organisations can still cooperate without automatically creating another plaintext copy every time information crosses an institutional boundary.</p><h2>This is the PrivID argument</h2><p>PrivID isn&#8217;t based on the idea that infrastructure dependency can somehow disappear. It can&#8217;t. FHE won&#8217;t keep a cloud provider online if a government prevents it from serving you. ZKP won&#8217;t manufacture processors when export restrictions cut off supply. Cryptography won&#8217;t make SWIFT process a transaction or force a payment network to keep somebody&#8217;s account open. Those are availability and geopolitical problems.</p><p>They do eliminate the volume of data needed for a decision to be made. They reduce the vulnerabilities that exist within a &#8216;plaintext&#8217; system. </p><h2>You don&#8217;t need an enemy</h2><p>The ICC example is useful because it removes one of the easier assumptions from the argument. The United States and many ICC member states remain close allies. Japan, Canada, the Netherlands and European states haven&#8217;t suddenly become American adversaries because they disagree with Washington over the Court (arguably).</p><p>Yet American influence over global financial and technology infrastructure gives a domestic sanctions decision effects far beyond American territory. Japan publicly criticised the August sanctions against ICC President Tomoko Akane, while the Netherlands and Germany reaffirmed support for the Court. <strong><a href="/__u/jirif.substack.com/p/your-ally-is-a-security-assumption?r=1mxk41">Alignment is conditional. Dependency is technical</a>. </strong></p><p>The supplier doesn&#8217;t need to become your enemy. Your ally doesn&#8217;t need to become your enemy. Nobody needs to breach anything. The political conditions governing an existing dependency simply have to change.</p><p>There will always be dependencies because modern technology is too interconnected. The objective is architecture that recognises the difference between <strong>using somebody else&#8217;s capability</strong> and <strong>placing yourself entirely under their control</strong>.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://jirif.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading PrivID's Substack! Subscribe for free to receive new posts.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Your Ally Is a Security Assumption]]></title><description><![CDATA[Countries have interests.]]></description><link>https://jirif.substack.com/p/your-ally-is-a-security-assumption</link><guid isPermaLink="false">https://jirif.substack.com/p/your-ally-is-a-security-assumption</guid><dc:creator><![CDATA[Jiri Fiala]]></dc:creator><pubDate>Mon, 24 Aug 2026 12:26:26 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!xnD-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcedc6df1-4c0e-4107-b801-772152b75461_1672x941.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Countries have interests. Sometimes those interests overlap that we call the relationship an alliance. That may involve defence, intelligence sharing, trade, technology, energy, infrastructure, geography, access to markets or resources, or a common adversary. Usually, it involves some combination of the above.</p><p>There may also be decades of institutional cooperation, shared history and genuine cultural affinity. But underneath all of that is pragmatism: <strong>mutual benefit and mutual need</strong>. There&#8217;s nothing particularly cynical about that. It&#8217;s how international relationships work.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!xnD-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcedc6df1-4c0e-4107-b801-772152b75461_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!xnD-!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcedc6df1-4c0e-4107-b801-772152b75461_1672x941.png 424w, /__u/substackcdn.com/image/fetch/$s_!xnD-!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcedc6df1-4c0e-4107-b801-772152b75461_1672x941.png 848w, /__u/substackcdn.com/image/fetch/$s_!xnD-!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcedc6df1-4c0e-4107-b801-772152b75461_1672x941.png 1272w, /__u/substackcdn.com/image/fetch/$s_!xnD-!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcedc6df1-4c0e-4107-b801-772152b75461_1672x941.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!xnD-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcedc6df1-4c0e-4107-b801-772152b75461_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cedc6df1-4c0e-4107-b801-772152b75461_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1978484,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://jirif.substack.com/i/212539917?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcedc6df1-4c0e-4107-b801-772152b75461_1672x941.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!xnD-!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcedc6df1-4c0e-4107-b801-772152b75461_1672x941.png 424w, /__u/substackcdn.com/image/fetch/$s_!xnD-!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcedc6df1-4c0e-4107-b801-772152b75461_1672x941.png 848w, /__u/substackcdn.com/image/fetch/$s_!xnD-!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcedc6df1-4c0e-4107-b801-772152b75461_1672x941.png 1272w, /__u/substackcdn.com/image/fetch/$s_!xnD-!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcedc6df1-4c0e-4107-b801-772152b75461_1672x941.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Alignment is not permanence</h2><p>Two countries can be allies while disagreeing sharply over trade &#8212; sound familiar? They can cooperate militarily while restricting technology exports, share intelligence while withholding particular categories of information, or agree on one geopolitical threat while seeing another completely differently.</p><p>A change of government doesn&#8217;t need to end an alliance to change the priorities. Privacy policy can shift. Intelligence priorities can change. Sanctions and export controls can expand. Procurement requirements can become more restrictive. Governments can decide that domestic technology or infrastructure should receive preferential treatment, or that certain foreign dependencies are no longer acceptable. Things change, assuming they won&#8217;t is the mistake.</p><h2>We turn political decisions into technical facts</h2><p>When two organisations decide that cooperation is mutually beneficial. Access is granted, systems are connected, data begins moving between them, APIs are opened and administrative privileges are created. Cloud environments become interconnected, databases may be replicated and identity systems begin recognising one another.</p><p><strong>We trust them today</strong> over time becomes <strong>the system assumes they&#8217;re trusted</strong>. The first is a judgement. The second can persist long after the original circumstances have changed.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://jirif.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/jirif.substack.com/subscribe"><span>Subscribe now</span></a></p><h2>Trust is rarely binary in the real world</h2><p>Cybersecurity has a tendency to simplify trust into something approaching a binary switch. Geopolitics and business don&#8217;t work that way. The real-world version is <strong>trusted for this purpose, under these circumstances, while these interests are aligned.</strong></p><p>A supplier may be trusted to operate infrastructure without being entitled to inspect customer data. A partner may need to verify a transaction without retaining the underlying identity information. A foreign agency may need to determine whether a particular condition exists without receiving the entire dataset. A cloud provider may provide the compute without necessarily needing visibility into what is being computed.</p><p>Architecture should be able to differentiate between the different forms of trust needed in each scenario. That isn&#8217; t really the case.</p><h2>Sharing isn&#8217;t surrendering control</h2><p>Digital cooperation still follows a very crude model: if another party needs information, we give them the information. We may encrypt it while it travels, authenticate the recipient before releasing it, log what they subsequently do and restrict its permitted use through contracts or policy.</p><p>Now they have a copy. Their administrators can access it. Their infrastructure becomes part of the security perimeter. Their jurisdiction matters. Their backups matter. Their suppliers matter. Even their future relationships with other organisations or governments can matter.</p><p>In other words, we** begin inheriting risks.** Cooperation involves dependency to some degree. The extent of that dependency needs to be an architectural choice. When organisations decide whether to cooperate, they usually ask: <strong>Do we trust them?</strong></p><p>Does the other party need the underlying data, to the extent provided? It may only need proof that a particular condition has been satisfied, the result of a calculation, or access to one tightly bounded portion of information. Maybe access is necessary for an hour rather than indefinitely. Maybe an organisation needs to verify something without learning everything that was used to establish the result.</p><p>Under these conditions, technologies such as zero-knowledge proofs and fully homomorphic encryption start looking more like tools for defining relationships. A ZKP can establish that something is true without disclosing all of the information behind the proof. FHE can allow computation to take place while the underlying information is encrypted. In other words, trust becomes precise and conditional at every step.</p><h2>Trust shouldn&#8217;t mean visibility</h2><p>This is one of the assumptions behind the architecture we&#8217;re developing at PrivID. We&#8217;re not trying to answer the political question of who should trust whom. Technology can&#8217;t make that decision, and it shouldn&#8217;t. It can determine is what trust allows.</p><p>If an organisation needs proof, it should be possible to provide the proof not everything behind it. If it needs the result of a computation, the result should be enough. If access is temporary, the architecture should reflect that. If someone needs one attribute, why are they getting access to all the attributes in all the records. Visibility shouldn&#8217;t automatically be the price of cooperation.</p><h2>Allies don&#8217;t need to become enemies</h2><p>Today&#8217;s ally could eventually become tomorrow&#8217;s hostile state. Could that happen? Of course. Does it need to happen for the risk to matter? Not remotely. The much more likely scenario: the ally remains an ally, but interests diverge.</p><p>A new government sees trade differently. A court interprets access powers differently. A supplier becomes subject to new regulation. Sanctions change. A technology becomes export-controlled. A country decides that its domestic industrial base comes first. An intelligence-sharing agreement becomes narrower than it was before.</p><h2>Sovereignty is the ability to change your mind</h2><p>Modern infrastructure depends on international suppliers, global standards, foreign intellectual property, shared research, cross-border networks and extraordinarily complicated supply chains. Trying to remove every external dependency would probably leave you with very little functioning technology.</p><p>Can you change providers without rebuilding everything? Can you reduce somebody&#8217;s access when circumstances change? Can you revoke a relationship, move a workload or alter who can see particular information while the rest of the system continues operating?</p><p>Can you cooperate with another organisation without automatically making it part of every trust boundary? If you can&#8217;t, you don&#8217;t really have technological sovereignty.</p><h2>Political assumptions belong in the threat model</h2><p>Cybersecurity traditionally focuses on hostile behaviour: attackers, malware, credential theft, misconfiguration, malicious insiders and supply-chain compromise. All of those deserve the attention they receive. Some of the most consequential risks facing modern infrastructure begin with assumptions.</p><p>We assume a country will remain aligned with us, a provider will remain available, a legal framework will remain valid, a supplier will remain acceptable, an administrator will remain authorised or an information-sharing arrangement will continue to make sense. The mistake is building systems that treat them as unchangeable.</p><p>Political relationships change. Commercial relationships change. Legal frameworks change. Even alliances change in character without disappearing altogether. Technology architecture should be capable of recognising that reality.</p><p>The objective isn&#8217;t to create a world in which nobody trusts anyone. That would make cooperation almost impossible. Countries will continue working together because their interests overlap. Companies will continue depending on suppliers because doing so makes economic and technical sense. Allies will continue sharing information because mutual need demands it.</p><p>But, assuming that today&#8217;s relationship will be tomorrow&#8217;s relationship is a mistake.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://jirif.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading PrivID's Substack! Subscribe for free to receive new posts.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[What Happens When AI Becomes Mother?]]></title><description><![CDATA[This is a bit of a departure for me, as I&#8217;ve been thinking about this quite a bit - bear with me.]]></description><link>https://jirif.substack.com/p/what-happens-when-ai-becomes-mother</link><guid isPermaLink="false">https://jirif.substack.com/p/what-happens-when-ai-becomes-mother</guid><dc:creator><![CDATA[Jiri Fiala]]></dc:creator><pubDate>Tue, 18 Aug 2026 18:18:38 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QCi7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F589cceb4-3292-4689-b669-758fc1cecf86_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h4>This is a bit of a departure for me, as I&#8217;ve been thinking about this quite a bit - bear with me.</h4><p></p><p>Science Fiction and Fiction is interesting because it tends to reflect what we, as a society fear. Before movies, shows and the internet (tiktok, YouTube, Instagram etc), it was books. This article will also make it pretty clear, I have seen too many movies and read too many books. I make no apologies.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!QCi7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F589cceb4-3292-4689-b669-758fc1cecf86_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!QCi7!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F589cceb4-3292-4689-b669-758fc1cecf86_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!QCi7!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F589cceb4-3292-4689-b669-758fc1cecf86_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!QCi7!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F589cceb4-3292-4689-b669-758fc1cecf86_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!QCi7!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F589cceb4-3292-4689-b669-758fc1cecf86_1536x1024.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!QCi7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F589cceb4-3292-4689-b669-758fc1cecf86_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/589cceb4-3292-4689-b669-758fc1cecf86_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2814897,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://jirif.substack.com/i/211714783?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F589cceb4-3292-4689-b669-758fc1cecf86_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!QCi7!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F589cceb4-3292-4689-b669-758fc1cecf86_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!QCi7!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F589cceb4-3292-4689-b669-758fc1cecf86_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!QCi7!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F589cceb4-3292-4689-b669-758fc1cecf86_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!QCi7!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F589cceb4-3292-4689-b669-758fc1cecf86_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>During the Cold War, American movies and TV were full of invasion stories, hidden enemies, humanoid aliens, nuclear disaster and survival stories. On the surface they were about aliens, monsters or radiation. Beneath the surface, however, they were usually about other things: infiltration, ideological conformity, annihilation, loss of control and the suspicion that the person standing beside you might not be who you thought they are/were.</p><h3>The Monsters</h3><p>Werewolves aren&#8217;t just about violence. They&#8217;re about transformation, the kind adults can&#8217;t control. Puberty is an obvious reading: the child you knew becomes physically and psychologically different, almost overnight. The werewolf, in a broader sense, works whenever one generation doesn&#8217;t like what the next generation is becoming.</p><p>Zombies? They can be anything we&#8217;re afraid of. They&#8217;ve represented consumerism, conformity, contagion, social collapse and the disappearance of individuality into the crowd.</p><p><em>They Live</em> is a great example. It combines so many anxietes.. It isn&#8217;t just an alien-invasion story. The invasion has already happened. The mechanisms through which people see reality have been captured. Advertising, authority and consumption are all part of the same system, and almost everyone accepts it because they can&#8217;t see that there&#8217;s anything to question.</p><p>Body-snatcher stories? Their real horror isn&#8217;t infiltration. It&#8217;s the loss of autonomy. You still look and talk like you. But something about you has disappeared.</p><p>Those story lines and monsters are adaptable to any era, that&#8217;s why they work so well. Communist infiltration worked as one interpretation during the Cold War (something the current US regime is trying to resurrect), but the same mechanism can stand in for ideological conformity, religious authority, corporate culture, political movements or virtually anything else capable of replacing individual judgement.</p><h2>The Wrong AI Story</h2><p>For decades, AI has been some variation of <em>Terminator/Skynet</em>. The machine becomes intelligent. It decides humanity is the problem. Humans lose control. Things explode. Great for movies, but more an exagerated version of reality. It&#8217;s not whether AI becomes like us, but, whether <strong>we become more like AI</strong>.</p><p>That doesn&#8217;t need artificial consciousness. It doesn&#8217;t need malicious intent. It doesn&#8217;t even need anybody to make a deliberate decision. It just needs constant interaction.</p><p>Humans adopt the language of the environments around them. We absorb vocabulary, sentence structures, assumptions and ways of framing problems from family, schools, books, work, television, social media and the people we spend time with. AI is no different. Spend enough time interacting with it and its patterns become yours.</p><p><strong>That creates problems for the idea of AI detection</strong>. Most detection systems assume that human and machine writing are different categories that one can be statistically separated from the other. But what happens when humans begin to write like systems trained on humans who themselves have increasingly interacted with AI?</p><p>Human language influences AI &#8594; AI language influences humans &#8594;those humans create new text.</p><p>That text eventually becomes part of the broader information environment from which future AI systems learn. At some point, asking whether a particular turn of phrase is &#8220;human&#8221; or &#8220;AI&#8221; starts to become its own kind of problem. The classic Catch-22.</p><h2>The Generation That Never Knew Before</h2><p>Older people view AI as something added to an existing cognitive framework. They remember researching without it. Writing without it. Getting lost without GPS. Sitting with questions because the answer wasn&#8217;t immediately available.</p><p>Someone growing up with AI may never know, or understand, that. For them, thinking with AI may just be thinking. That doesn&#8217;t make the younger generation less intelligent (ok, the jury&#8217;s still out on that, I&#8217;m giving the benefit of the doubt). They may develop a fundamentally different relationship with knowledge and reasoning. And that&#8217;s where older cultural fears begin to reappear.</p><p>The anxiety starts looking less like <em>Terminator</em> and more like <em>The Midwich Cuckoos (</em>or the movie that was made from that book - <em>The Village of The Damned)</em>.</p><p>The kids in Midwich look human. They belong to the community around them. But they think differently, communicate differently and operate according to a framework the adults don&#8217;t understand. The fear is that they&#8217;re <strong>our children, but not like us</strong>.</p><p><em>Children of the Corn</em> plays with a related fear. The younger generation develops its own authority structure, values and worldview, and the adults become irrelevant or hostile simply because they belong to the old order.</p><p>One generation may look at another and say: <em>You&#8217;re becoming dependent. You&#8217;re losing the ability to think for yourselves</em>.</p><p>The younger generation may respond: <em>No. We&#8217;re thinking differently because the tools available to us are different</em>.</p><h2>When the Tool Becomes Mother</h2><p>What about when AI stops being just software and becomes the thing you ask when you don&#8217;t know.</p><ul><li><p>It explains.</p></li><li><p>It reassures.</p></li><li><p>It corrects.</p></li><li><p>It advises.</p></li><li><p>It resolves disputes.</p></li></ul><p>It tells you what word means, what a political argument means, what your symptoms might mean, how to phrase something, whether an idea is reasonable, what you should buy, where you should go and how you might interpret what somebody else just said. It begins to occupy a psychological role that technology hasn&#8217;t occupied before. <strong>Mother.</strong> It becomes the ever patient parent.</p><p>Now we&#8217;re somewhere between <em>Idiocracy</em> and <em>Demolition Man</em>. <em>Idiocracy</em> shows a society in cognitive decline, serious thought is neither exercised or rewarded. <em>Demolition Man</em> on the other hand shows something different: a society whose behaviour, language and acceptable norms have been engineered into a narrow band of supposedly safe, civilised conduct.</p><p>Combine those with an AI system that people willingly consult for almost everything and you get voluntary deference. Not just control. Independent thought becomes less convenient.</p><ul><li><p>Why spend an hour figuring out a problem when the system can explain it in thirty seconds, or less?</p></li><li><p>Why research five sources when the system can summarise them?</p></li><li><p>Why construct an argument from scratch when the system can help organise it?</p></li></ul><p>Those points are the problem for an individual. Scaled? That&#8217;s different.</p><h2>The Quiet Convergence</h2><p><strong>First</strong>, cognitive outsourcing. People retain less information and practise fewer reasoning processes because retrieval, synthesis and explanation are always available externally.</p><p><strong>Second</strong>, linguistic convergence. Millions of people interacting with similar systems begin absorbing similar vocabulary, rhetorical structures and ways of explaining things.</p><p><strong>Third</strong>, normative convergence. People don&#8217;t just absorb how the system speaks. They absorb what the system sees as reasonable and sensible.</p><p>In <em>They Live</em>, the system has deliberately manipulated perception. Now, instead of aliens look at AI. If enough people turn to the same systems to interpret a bigger portion of reality, those systems inevitably shape the cognitive environment.</p><h2>Nobody Has to Become a Zombie</h2><p>This also creates a version of the zombie metaphor. Traditional zombies lose individuality and become part of a mass, we could also be discussing Pluribus here. (Let&#8217;s not get into the speed of zombies etc. argument)</p><p>Imagine a society where everyone stays intelligent, self-aware and convinced of their own independence at the same time becoming more similar in how they structure information, frame arguments and resolve uncertainty.</p><p>Nobody&#8217;s been hypnotised. Nobody&#8217;s surrendered consciousness. Nobody&#8217;s joined the hive. But a type of cognitive convergence still happens. Everyone is adapting. Something we humans do really well.</p><h2>Who Controls Whom?</h2><p>This is really the crux of the AI issue. Not whether AI controls humans. Not whether humans control AI. But how does prolonged interaction change both sides to the point where it becomes harder and harder to say who&#8217;s thought it is.</p><p>We train machines on human output &#8594;the machines interact with humans &#8594; humans absorb aspects of machine behaviour &#8594; those humans produce new culture &#8594; future systems learn from that culture. This becomes it&#8217;s own system.</p><ul><li><p>Older generations see it as a loss of autonomy.</p></li><li><p>Younger generations see it as augmentation.</p></li><li><p>One group sees dependency.</p></li><li><p>The other sees efficiency.</p></li><li><p>One sees the disappearance of independent reasoning.</p></li><li><p>The other sees it as pointless nostalgia.</p></li></ul><p>Neither position is automatically right. They may be talking about two different definitions of what it means to think. That&#8217;s where the old horror stories come in again.</p><p>The werewolf: what happens when the next generation changes into something its parents don&#8217;t recognise.</p><ul><li><p><em>The Midwich Cuckoos</em>: what happens when children develop a cognitive world adults can&#8217;t enter.</p></li><li><p><em>Children of the Corn</em>: what happens when the younger generation decides the old structures doesn&#8217;t matter.</p></li><li><p><em>They Live</em>: what happens when the systems mediating reality become invisible precisely because everyone accepts them.</p></li><li><p>And <em>Idiocracy</em> and <em>Demolition Man</em> ask what happens when convenience and order replace the need to think for yourself.</p></li></ul><p>AI needs to become useful, trusted and ubiquitous in a way that we stop noticing how much of our cognitive environment it occupies.</p><div><hr></div><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://jirif.substack.com/subscribe?utm_source=email&r=&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/jirif.substack.com/subscribe?utm_source=email&amp;r="><span>Subscribe</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Stop Buying More Security. Start Buying Outcomes.]]></title><description><![CDATA[The objective is to have less risk left to secure.]]></description><link>https://jirif.substack.com/p/stop-buying-more-security-start-buying</link><guid isPermaLink="false">https://jirif.substack.com/p/stop-buying-more-security-start-buying</guid><dc:creator><![CDATA[Jiri Fiala]]></dc:creator><pubDate>Fri, 14 Aug 2026 13:26:09 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!bYOw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecfbca01-3905-4859-871a-55f8f00b8186_1698x926.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h3>TL;DR</h3><p>Cybersecurity investment is usually measured by the controls an organisation adds not the outcomes they change. Prevention, detection and monitoring are essential, but they mostly manage risk. Not necessarily the exposure of data.</p><p>A better investment model looks at the entire equation: the probability of compromise, what can be exposed if it happens, how far the consequences can propagate, and the continuing cost of protecting that exposure.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!bYOw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecfbca01-3905-4859-871a-55f8f00b8186_1698x926.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!bYOw!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecfbca01-3905-4859-871a-55f8f00b8186_1698x926.png 424w, /__u/substackcdn.com/image/fetch/$s_!bYOw!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecfbca01-3905-4859-871a-55f8f00b8186_1698x926.png 848w, /__u/substackcdn.com/image/fetch/$s_!bYOw!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecfbca01-3905-4859-871a-55f8f00b8186_1698x926.png 1272w, /__u/substackcdn.com/image/fetch/$s_!bYOw!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecfbca01-3905-4859-871a-55f8f00b8186_1698x926.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!bYOw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecfbca01-3905-4859-871a-55f8f00b8186_1698x926.png" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ecfbca01-3905-4859-871a-55f8f00b8186_1698x926.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2232115,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://jirif.substack.com/i/210937675?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecfbca01-3905-4859-871a-55f8f00b8186_1698x926.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!bYOw!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecfbca01-3905-4859-871a-55f8f00b8186_1698x926.png 424w, /__u/substackcdn.com/image/fetch/$s_!bYOw!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecfbca01-3905-4859-871a-55f8f00b8186_1698x926.png 848w, /__u/substackcdn.com/image/fetch/$s_!bYOw!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecfbca01-3905-4859-871a-55f8f00b8186_1698x926.png 1272w, /__u/substackcdn.com/image/fetch/$s_!bYOw!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecfbca01-3905-4859-871a-55f8f00b8186_1698x926.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Platforms, controls, monitoring, detection, identity, endpoint protection, threat intelligence, zero trust, cloud security, data security, AI security, post-quantum security. Most of these technologies address real problems. But organisations don&#8217;t actually need more security products. They need better security outcomes.</p><p>The way cybersecurity is bought, budgeted and measured still revolves around capabilities not consequences. A product detects something faster. A platform provides greater visibility. A new control closes a particular attack path. Another system produces better telemetry or gives the security team another way to manage access.</p><p>If a system is compromised, the questions aren&#8217;t how many security products were deployed or how sophisticated their dashboards were. What matters is what was exposed, what the attacker was able to do with it, how quickly the organisation could contain it and how far the consequences travelled.</p><p>Over the past few days, I&#8217;ve looked at this problem from several directions: why sensitive information becomes visible simply because systems need to use it, the continuing cost of protecting that exposure, the privileged-access problem created when trust and visibility become converge, and how interconnected infrastructure allows the fallout of a compromise to propagate beyond the initial organisation.</p><h2>Security Has Become an Accumulation Problem</h2><p>A new threat needs another control. A regulatory change introduced another process. An audit identified a weakness and another system was purchased. Infrastructure moved to the cloud, employees became more distributed, suppliers became more connected and identity became more complicated. AI is now introducing another layer to this issue.</p><p>Security environments tend to acquire overlapping tools, duplicated capabilities, integrated dependencies, escalating licensing costs and enormous amounts of data that has to be interpreted. All of that while the underlying architecture is largely unchanged.</p><p>Sensitive information still becomes visible during processing. Privileged users and systems still have access to it. Applications still receive information beyond what they need. Connected systems still exchange information and credentials across organisational boundaries. Many of them are essential. But it does raise a fundamental question about where security investment produces the greatest return.</p><h2>Security Isn&#8217;t Only the CISO&#8217;s Problem</h2><p>Cybersecurity is generally treated as the CISO&#8217;s responsibility, which makes sense operationally. The security organisation runs the programme, manages the controls, responds to incidents and understands the threat environment. The economic consequences are more distributed.</p><p>A serious security failure creates legal costs, regulatory exposure, insurance claims, operational disruption, contractual liability, customer remediation, lost productivity and lost revenue. An incident that begins in the security environment can become a finance, legal, operations, communications and board problem.</p><p>That means the CISO and CFO aren&#8217;t really looking at competing objectives. The CISO sees attack surface and technical consequence. The CFO sees expenditure and financial consequnces. Legal sees liability, privacy sees information exposure, compliance sees regulatory obligations and operations sees resilience. These are different views of the same issue.</p><p>If unnecessary access to information is reduced, the organisation can change its security exposure, privacy risk and compliance burden. If compromise can be contained architecturally, incident severity and downstream liability will change with it. If an identity system verifies only the information needed for a transaction rather than distributing complete identity records, the implications extend into data governance, customer experience and regulatory exposure.</p><h2>Prevention Is Only Part of the Outcome</h2><p>The previous articles in this series have repeatedly looked at different aspect of the issue to point to the convergence. The consequence of compromise depends not only on whether an attacker gets in, but what becomes available.</p><p>An organisation can reduce risk by lowering the probability of compromise. But it can also reduce the amount of useful information exposed by that compromise. It can restrict what a credential authorises, minimise what an application receives, separate administrative privilege from data visibility and design dependencies so that failure in one system doesn&#8217;t just propagate.</p><p>These approaches change the consequences when prevention fails. One investment might reduce the probability of credential compromise. Another might leave that probability largely unchanged but ensure that a compromised credential reveals substantially less information. A third might prevent the resulting compromise from propagating through customers or connected systems.</p><p>The useful comparison isn&#8217;t which technology provides the strongest security. It &#8216;s <strong>which investment produces the greatest reduction in meaningful exposure and consequence for the money being spent.</strong></p><h2>Architecture Changes What Has to Be Protected</h2><p>Most conventional controls manage risk around an existing system. Architectural change can alter that system. Consider identity. If an application receives a complete identity record just to establish that somebody satisfies a specific condition, the application now possesses information it has to protect. Its infrastructure, administrators, logs, backups and integrations potentially become part of the security boundary surrounding that information.</p><p>If the same application can establish the required fact without receiving the underlying identity, the application still needs security, but the consequence of compromising it has changed. The same principle applies to computation.</p><p>If sensitive information has to repeatedly become readable because an application needs to perform operations on it, every point at which that information becomes visible creates a point of exposure that has to be controlled. Where some of that computation can instead happen while the underlying information stays protected. </p><p>This doesn&#8217;t eliminate conventional cybersecurity. Applications still need authentication, infrastructure still needs monitoring, endpoints still need protection and incidents still need response. The difference is that those controls may now be protecting a smaller exposure surface. Better architecture can reduce how much conventional security is being asked to protect.</p><h2>The Commercial Case Isn&#8217;t Just Breach Avoidance</h2><p>Security investments are frequently justified by the losses they might prevent. That&#8217;s understandable, but breach avoidance can be difficult to model because the organisation is trying to assign a financial value to something that may or may not happen. But, architectural change can have another source of value: reducing the continuing cost of carrying exposure.</p><p>If an application no longer receives a category of sensitive information, some of the governance surrounding that information may change. If administrators no longer routinely have visibility into customer data, privileged-access risk changes. If identity attributes can be verified without distributing complete records, retention and exposure change. The potential downstream impact changes.</p><p>The organisation may therefore be changing not only the probability or cost of a future incident, but the amount of complexity it has to manage every day. Real systems are too complicated for control systems to just disappear, and regulatory obligations don&#8217;t go away because an architecture improves.</p><p>But the economic case for architectural change should include what the organisation may no longer need to govern, monitor, audit and defend with the same intensity. This brings us back to the carrying cost of exposure.</p><h2>Technology Still Has to Earn Its Place</h2><p>There are genuinely powerful technologies becoming practical. Zero-knowledge proofs can establish facts without revealing all of the information behind them. Encrypted (FHE) computation can allow useful operations to occur while underlying information remains protected. Confidential computing can isolate sensitive workloads, while selective disclosure can reduce the information exchanged between parties. Modern identity architectures can make authentication and authorisation considerably more contextual.</p><p>Cryptography can introduce computational overhead. New architectures create integration and migration costs. Confidential computing changes trust assumptions it doesn&#8217;t eliminate them. Zero-knowledge systems aren&#8217;t appropriate for every workflow. AI can improve detection while introducing new forms of access and exposure.</p><p>A technology earns its place when it materially changes an outcome to justify its cost. For some organisations, the best investment may still be better endpoint protection or identity management. For others, it may be segmentation, monitoring or incident-response capability. In environments with extremely sensitive information, the greater return may come from changing how that information is exposed during verification, processing or administration.</p><h2>Security Architecture Is Capital Allocation</h2><p>An organisation has finite resources with which to reduce risk. Some of that money will reasonably go towards prevention, some towards detection and response, some towards compliance and resilience, and some towards maintaining the controls already in place. Architecture belongs in there as well.</p><p>The organisation should compare the continuing cost of protecting an existing exposure with the cost of reducing or removing that exposure architecturally. It should compare another layer of monitoring with a design that makes the monitored information less valuable if compromised. And it should evaluate whether the cost of maintaining a complex collection of controls is justified when a different architecture could change the underlying problem.</p><p>A &#8364;10 million redesign that removes &#8364;500,000 of meaningful risk is difficult to justify. A &#8364;10 million investment that materially reduces operating complexity, information exposure, regulatory risk and potential incident severity while enabling new commercial capabilities is a very different proposition.</p><ul><li><p>Existing infrastructure isn&#8217;t free just because it&#8217;s already been purchased.</p></li><li><p>Existing security controls aren&#8217;t free because their licences were approved last year. </p></li><li><p>Existing exposure isn&#8217;t free because the organisation has become used to protecting it.</p></li></ul><p>Every one of those represents a continuing economic decision.</p><h2>Start With the Outcome</h2><p>Sometimes that means preventing compromise. Sometimes it means reducing what becomes exposed when prevention fails, limiting what privileged access can reveal, or containing how far a compromise can propagate.</p><p>Start with the exposure: where information becomes visible, who or what can reach it, whether that access is necessary, and what happens if it&#8217;s compromised. Then decide whether the answer is another control or a change to the architecture itself.</p><p>For the CISO, that ties security investment to consequence rather than the number of controls deployed. For the CFO, it creates a comparison between the cost of change and the continuing cost of the status quo. For the board, it makes cybersecurity what it should be: <strong>a capital-allocation decision about enterprise risk.</strong></p><p>We won&#8217;t eliminate every breach. Credentials will be stolen. Software will contain vulnerabilities. People will make mistakes. Suppliers will be compromised. Failure and catastrophe are different.</p><p><strong>Architecture helps determine the difference.</strong></p><p>A compromised application doesn&#8217;t have to reveal everything it processes. Privilege doesn&#8217;t have to mean visibility. Verification doesn&#8217;t have to mean disclosure. A supplier compromise doesn&#8217;t have to become a customer breach. The purpose of better security architecture isn&#8217;t to pretend failure can be eliminated. <strong>It&#8217;s to engineer the consequences down.</strong></p><p>That moves the investment question from <em>how much more security do we need?</em> to <em>how much exposure do we need to create in the first place?</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://jirif.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading PrivID's Substack! Subscribe for free to receive new posts.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Your Breach Isn't Just Your Problem]]></title><description><![CDATA[For years, organisations have drawn security boundaries around themselves.]]></description><link>https://jirif.substack.com/p/your-breach-isnt-just-your-problem</link><guid isPermaLink="false">https://jirif.substack.com/p/your-breach-isnt-just-your-problem</guid><dc:creator><![CDATA[Jiri Fiala]]></dc:creator><pubDate>Thu, 13 Aug 2026 13:33:45 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!srsg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76ba2494-cb27-4c19-99ac-fea48536b820_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>For years, organisations have drawn security boundaries around themselves. Their network. Their applications. Their employees. Their data. But, organisations don&#8217;t operate within those boundaries anymore.</p><p>They operate through cloud platforms, identity providers, software suppliers, APIs, managed services, payment processors, contractors, customers and increasingly AI systems. Information moves between them, credentials establish relationships between them, and automated processes connect systems that may be operated by entirely different organisations.</p><p>A compromised supplier can interrupt its customers. Stolen credentials can provide access to another environment. Exposed personal information can enable identity attacks and fraud. A compromised API can provide a route into systems that were never part of the original attack. An outage at a sufficiently important provider can affect thousands of organisations.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!srsg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76ba2494-cb27-4c19-99ac-fea48536b820_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!srsg!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76ba2494-cb27-4c19-99ac-fea48536b820_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!srsg!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76ba2494-cb27-4c19-99ac-fea48536b820_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!srsg!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76ba2494-cb27-4c19-99ac-fea48536b820_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!srsg!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76ba2494-cb27-4c19-99ac-fea48536b820_1536x1024.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!srsg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76ba2494-cb27-4c19-99ac-fea48536b820_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/76ba2494-cb27-4c19-99ac-fea48536b820_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2275407,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://jirif.substack.com/i/210917856?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76ba2494-cb27-4c19-99ac-fea48536b820_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!srsg!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76ba2494-cb27-4c19-99ac-fea48536b820_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!srsg!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76ba2494-cb27-4c19-99ac-fea48536b820_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!srsg!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76ba2494-cb27-4c19-99ac-fea48536b820_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!srsg!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76ba2494-cb27-4c19-99ac-fea48536b820_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Built for Connectivity</h2><p>Modern computing has spent decades removing friction between systems. APIs allow applications to exchange information automatically. Cloud infrastructure provides resources on demand. SaaS platforms eliminate the need to operate everything internally. Identity federation allows users to move between services without maintaining separate credentials everywhere. Managed-service providers give organisations access to specialised expertise. Supply chains operate through interconnected logistics, financial and information systems. AI just accelerated that.</p><p>We want systems to exchange information, understand it, combine it and act on it. But that level of connectivity comes at a price.</p><p>Verizon&#8217;s 2026 Data Breach Investigations Report found that third parties were involved in 48% of breaches, up from 30% the previous year. That means the security boundary has changed.</p><p>An organisation can have excellent internal controls and still depend on systems it doesn&#8217;t operate, people it doesn&#8217;t employ and infrastructure it doesn&#8217;t own. The attack surface increasingly includes the relationships between organisations. So does the potential impact.</p><h2>The First Breach Is Just the Beginning</h2><p>When sensitive information is stolen, its value doesn&#8217;t necessarily disappear after the original incident.</p><ul><li><p>Credentials can be reused.</p></li><li><p>Identity information can support impersonation.</p></li><li><p>Customer information can make phishing considerably more convincing.</p></li><li><p>Commercial information can expose relationships, suppliers or internal processes.</p></li><li><p>Information from several breaches can be combined to create something considerably more useful than any individual dataset.</p></li></ul><p>The initial compromise can become an input into subsequent attacks. Especially when the information exposed isn&#8217;t simply descriptive data but something that provides access or establishes trust. In other words, the damage isn&#8217;t necessarily limited to what was stolen. That&#8217;s the <em><strong>ripple effect</strong></em>.</p><h2>Trust Relationships Can Become Attack Paths</h2><p>Every interconnected environment contains trust relationships. These relationships are necessary in the interconnected infrastructure. The security problem isn&#8217;t just the number of organisations connected to an environment. It&#8217;s <strong>what those connections carry.</strong></p><h2>Concentration Changes the Scale</h2><p>Connectivity doesn&#8217;t just create more relationships. It concentrates them. Thousands of organisations may depend on the same cloud platform. Large numbers of businesses may use the same identity provider, software library, managed-service provider or SaaS application. Entire industries may rely on a relatively small number of payment, communications or infrastructure providers. True it&#8217;s efficient, but it&#8217;s also a series of points of failure that scale quickly. Concentrated infrastructure can creates systemic risk.</p><p>One provider isn&#8217;t just one potential incident. It may be connected to hundreds or thousands of organisations, directly and indirectly.</p><p>Which means that architecture has to account for <strong>consequence concentration</strong>, not just compromise probability.</p><h2>AI Makes Propagation Faster</h2><p>AI introduces another problem, it changes what connected systems can do with information. Traditional integrations often move relatively predictable pieces of data between predetermined systems. An AI agent can read email, retrieve documents, query databases, interact with APIs, access customer information and take actions in other systems. Its usefulness comes partly from its ability to cross boundaries that previously required human intervention. This creates a new form of systemic risk.</p><p>An AI system may have access to information that previously existed in several separate contexts. Each permission granted individually can look reasonable. Collectively, they can create a real problem for the organisation.</p><p>The question isn&#8217;t if the AI is trustworthy. It&#8217;s whether AI needs that much access to the system. If an AI agent needs to determine whether an invoice meets certain conditions, it doesn&#8217;t need every piece of information associated with the customer.</p><p>If it needs to verify eligibility, it may need the result of a verification not the identity information behind it. Likewise if it is scheduling meetings. It just needs very specific access, nothing more. Giving an AI access to everything because it might need something is just the old privileged-access problem, but at machine speed.</p><h2>Containment Has to Become Architectural</h2><p>Current containment is largely reactive. An organisation detects something has gone wrong, then isolates an endpoint, disables an account, blocks a network segment, revokes a token or disconnects a service. The problem wit this scenario: <strong>the organisation has to recognise the compromise before it can contain it.</strong></p><p>Sensitive information can be exposed only where it&#8217;s genuinely required. Applications can receive the attributes necessary to perform a function. Privileged users can administer systems without gaining visibility into everything. Credentials can be constrained to specific functions, and systems can be designed so that compromising one component doesn&#8217;t automatically expose everything connected to it.</p><p>The same principle applies to computation. Sensitive information can be protected while it&#8217;s being processed rather than repeatedly becoming visible because a system &#8216;needs it&#8217;.</p><p>Reactive containment tries to stop a compromise <strong>after</strong> it&#8217;s detected. Architectural containment limits what that compromise can become <strong>before</strong> it happens.</p><h2>The Economics Change Again</h2><p>Customers can experience outages. Partners can need to investigate their own environments. Credentials can need to be rotated. Services can need to be suspended. Contracts can be affected. Regulators can ask questions in multiple jurisdictions. Customers can face their own notification obligations. Eventually, someone pays for all of this.</p><p>And an investment that reduces how far the consequences can propagate may have value beyond the organisation making the investment.</p><h2>Your Security Architecture Is Part of Someone Else&#8217;s Risk Model</h2><p>Questionnaires are completed. Certifications are requested. Contracts contain security clauses. Audits are conducted. Insurance requirements appear. Vendors are categorised according to risk.</p><p>All of this exists because customers understand something important: <strong>their suppliers&#8217; architecture can become their problem.</strong></p><p>Your architecture forms part of somebody else&#8217;s risk environment. Your customers are depending on how you handle their information. Your partners are depending on the credentials and integrations connecting your systems. Your suppliers may be depending on information you provide to them. Your insurers are evaluating the consequences of your controls failing. Your regulators are increasingly interested in resilience beyond the individual organisation.</p><p>Security architecture isn&#8217;t purely an internal technical decision. It&#8217;s part of the commercial relationship between organisations. And that creates an interesting competitive dimension.</p><p>If two suppliers provide broadly equivalent services, but one can materially reduce the information exposed during processing and show that compromise of its infrastructure has a smaller potential impact, that difference may matter as much, or more, as another feature on a product comparison sheet. Especially when the customer is a bank, hospital, government, critical-infrastructure operator or any organisation carrying information whose compromise creates consequences far beyond IT.</p><h2>Build for Compromise Without Accepting It</h2><p>Prevention, detection, identity controls, monitoring and incident response remain essential parts of any credible security strategy. But resilience needs acknowledging that no collection of controls is infallible. Credentials are stolen. Suppliers are compromised. Applications contain vulnerabilities. Employees make mistakes. Configurations are wrong. AI systems are inevitably given access to information or functions somebody didn&#8217;t fully anticipate.</p><p>A stolen credential doesn&#8217;t have to unlock an entire identity. A compromised system doesn&#8217;t have to expose the information it&#8217;s processing. A supplier failure doesn&#8217;t have to place every connected customer at risk. And an AI agent doesn&#8217;t need unrestricted visibility simply because it performs a useful function.</p><p>That leads to a relatively simple architectural principle:</p><ul><li><p>Reduce what can be exposed. </p></li><li><p>Reduce what can be carried. </p></li><li><p>Reduce what can propagate.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://jirif.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading PrivID's Substack! Subscribe for free to receive new posts.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div></li></ul>]]></content:encoded></item><item><title><![CDATA[The Insider Threat Is an Architecture Problem]]></title><description><![CDATA[Most organisations treat insider risk as a people problem.]]></description><link>https://jirif.substack.com/p/the-insider-threat-is-an-architecture</link><guid isPermaLink="false">https://jirif.substack.com/p/the-insider-threat-is-an-architecture</guid><dc:creator><![CDATA[Jiri Fiala]]></dc:creator><pubDate>Wed, 12 Aug 2026 13:26:35 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!k_XA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F039d5474-7805-4151-9585-d408be92aaa8_1584x993.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Most organisations treat insider risk as a people problem. Detect unusual behaviour. Restrict excessive permissions. Monitor privileged accounts. Separate duties. Review access. Train employees. Investigate anomalies.</p><p>But underneath those controls?<strong> Somebody still has to be trusted with the data.</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!k_XA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F039d5474-7805-4151-9585-d408be92aaa8_1584x993.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!k_XA!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F039d5474-7805-4151-9585-d408be92aaa8_1584x993.png 424w, /__u/substackcdn.com/image/fetch/$s_!k_XA!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F039d5474-7805-4151-9585-d408be92aaa8_1584x993.png 848w, /__u/substackcdn.com/image/fetch/$s_!k_XA!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F039d5474-7805-4151-9585-d408be92aaa8_1584x993.png 1272w, /__u/substackcdn.com/image/fetch/$s_!k_XA!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F039d5474-7805-4151-9585-d408be92aaa8_1584x993.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!k_XA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F039d5474-7805-4151-9585-d408be92aaa8_1584x993.png" width="1456" height="913" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/039d5474-7805-4151-9585-d408be92aaa8_1584x993.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:913,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2071257,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://jirif.substack.com/i/210786469?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F039d5474-7805-4151-9585-d408be92aaa8_1584x993.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!k_XA!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F039d5474-7805-4151-9585-d408be92aaa8_1584x993.png 424w, /__u/substackcdn.com/image/fetch/$s_!k_XA!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F039d5474-7805-4151-9585-d408be92aaa8_1584x993.png 848w, /__u/substackcdn.com/image/fetch/$s_!k_XA!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F039d5474-7805-4151-9585-d408be92aaa8_1584x993.png 1272w, /__u/substackcdn.com/image/fetch/$s_!k_XA!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F039d5474-7805-4151-9585-d408be92aaa8_1584x993.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Administrators need elevated privileges. Developers need production access. Support teams need visibility into customer environments. Database administrators need access to databases. Security teams need logs. Contractors need temporary permissions. Applications and service accounts need credentials to perform their functions.</p><p>The organisation spends a great deal of time and money deciding who should receive access, monitoring what they do with it, and proving afterwards that they didn&#8217;t abuse it.</p><h2>Privilege Became an Architectural Shortcut</h2><p>Privileged access exists for a reason. Someone has to maintain infrastructure. Someone has to recover systems when they fail. Someone has to deploy software, investigate incidents, configure databases and keep services running. Historically, the easiest way to enable those functions was to give trusted people more/privileged access.</p><p>That worked relatively well when computing environments were smaller, centralised and operated by contained teams. It&#8217;s harder when organisations operate across multiple clouds, SaaS platforms, contractors, managed-service providers, remote employees, APIs and globally distributed infrastructure.</p><p>Privileged access management limits administrative credentials. Identity governance reviews permissions. Multi-factor authentication strengthens access. Session monitoring records activity. Separation of duties prevents one individual from controlling an entire process. Just-in-time access reduces how long privileges are active.</p><p>We&#8217;re deciding <strong>who can be trusted to see information </strong>that the architecture makes visible.</p><h2>Zero Trust Didn&#8217;t Eliminate Trust</h2><p>Don&#8217;t assume someone should be trusted. Verify identity. Evaluate context. Limit privilege. Continuously reassess access. But zero trust still ends up at the same place. Basically, who gets through is heavily monitored. But, once inside, they can access everything. That&#8217;s why legitimate access is one of the hardest security problems.</p><p>Monitoring can help identify suspicious behaviour, but it happens after the fact. Which means the organisation is still dependent on another assumption: <strong>the trusted entity will behave as expected.</strong></p><h2>The Insider Doesn&#8217;t Have to Be an Insider</h2><p>The phrase <em>insider threat</em> suggests a disgruntled employee downloading customer records before leaving the company. Maybe. But privileged exposure is much more than malicious employees.</p><ul><li><p>An administrator&#8217;s credentials can be stolen.</p></li><li><p>A developer&#8217;s laptop can be compromised.</p></li><li><p>A support account can be phished.</p></li><li><p>A third-party technician can have excessive permissions.</p></li><li><p>A service account can be exploited.</p></li><li><p>A software supplier can be compromised.</p></li><li><p>An AI agent can be granted access to information its operators never anticipated it combining.</p></li></ul><p>The problem is that <strong>the privilege itself can carry too much information with it</strong>.</p><p>What happens when a legitimate privilege is misused, stolen, compromised or simply makes a mistake. Architecture can help reduce the consequences.</p><h2>What If Administration Didn&#8217;t Mean Visibility?</h2><p>A database administrator&#8217;s job may need them to maintain availability, manage performance, configure replication, perform backups, allocate resources and recover systems. But which of those needs the administrator to read every customer record in the database? Administrative control and data visibility tend to go together.</p><p>The same problem exists when talking about a cloud operator who may need to manage infrastructure without needing access to customer information, or about any of the following:</p><ul><li><p>A support technician may need to confirm that an account exists without seeing every attribute associated with it.</p></li><li><p>An application may need to establish that someone is over 18 without knowing their date of birth.</p></li><li><p>A financial system may need to determine whether a condition has been satisfied without exposing every input used to reach that determination.</p></li><li><p>A security process may need to verify that an event occurred without copying the entire underlying dataset somewhere else for analysis.</p></li></ul><p>These are questions about <strong>information architecture</strong>. Not permissions.</p><h2>Privileged Access Has a Carrying Cost</h2><p>There&#8217;s a commercial dimension that tends to disappear inside security budgets. Every privileged relationship creates a governance issue.</p><p>Accounts have to be provisioned and deprovisioned. Permissions have to be reviewed. Administrative sessions may need to be monitored. Logs have to be retained. Separation-of-duty policies have to be enforced. Contractors need oversight. Access has to be demonstrated to auditors. Exceptions have to be documented.</p><p>Someone has to investigate when those controls report something unusual. The more sensitive the information, the more expensive that governance becomes. Privileged visibility is its own version of the carrying cost of exposure. The organisation isn&#8217;t protecting data. It&#8217;s managing the people, identities, credentials and processes capable of reaching it.</p><p>Reducing unnecessary visibility isn&#8217;t just a security issue. If an administrator can perform a function without reading the underlying data, the organisation hasn&#8217;t eliminated the need to secure that administrator.</p><h2>This Isn&#8217;t About Eliminating Administrators</h2><p>Organisations need privileged users. Systems fail. Engineers debug them. Security teams investigate incidents. Databases require maintenance. Infrastructure needs administration. Emergency access doesn&#8217;t disappear. The objective isn&#8217;t to create some imaginary environment in which nobody has privileges.</p><p>Modern cryptographic makes that distinction more practical. Disclosure can reveal only the attributes required for a transaction. ZKPs can establish that a condition is true without revealing all of the information behind it. And encrypted computation can allow certain operations to happen without revealing the protected information.</p><h2>AI Makes the Privilege Question Bigger</h2><p>Organisations are beginning to give software agents access to email, documents, customer records, financial systems, development environments and operational tooling so that they can perform tasks on behalf of employees. But, an AI system doesn&#8217;t need malicious intent to create an exposure problem. It can receive excessive context, combine information that previously existed in separate systems, retain information unnecessarily, disclose it in response to the wrong request or take an action its operator didn&#8217;t anticipate.</p><h2>Trust the Function, Not the Visibility</h2><p>Organisations will keep trusting people, systems, suppliers and infrastructure to perform necessary functions. Trust an administrator to maintain a database without giving them access to every record. Trust an application to verify eligibility without someone&#8217;s complete identity. Trust an AI system to perform a task without giving it unrestricted access.</p><p>Cybersecurity has become better at who can be trusted with access, then monitoring and documenting that trust. The next architectural shift is to enable the trusted function while minimising access to the underlying information.</p><p>That won&#8217;t eliminate insider threats, compromised credentials, malicious employees, vulnerable suppliers or careless administrators. It just changes what will be exposed during a breach.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://jirif.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading PrivID's Substack! Subscribe for free to receive new posts.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The Cost of Doing Nothing Isn’t Zero]]></title><description><![CDATA[When organisations evaluate a new security technology, architecture, or operating model, they always ask one question first: What will it cost?]]></description><link>https://jirif.substack.com/p/the-cost-of-doing-nothing-isnt-zero</link><guid isPermaLink="false">https://jirif.substack.com/p/the-cost-of-doing-nothing-isnt-zero</guid><dc:creator><![CDATA[Jiri Fiala]]></dc:creator><pubDate>Tue, 11 Aug 2026 13:06:50 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!3Jzq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee39db3-e5e1-481d-b2a2-eea95e3f5763_1622x970.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>When organisations evaluate a new security technology, architecture, or operating model, they always ask one question first:  <strong>What will it cost?</strong></p><p>It&#8217;s a reasonable question. New technology has acquisition costs. Integration takes time. Existing systems may need to be modified. Employees need training. Infrastructure may need upgrading. There may be additional compute requirements, implementation risk, and a period during which old and new systems have to operate alongside one another.</p><p>Those costs are relatively easy to see because someone eventually puts them into a budget. Doing nothing looks a lot cheaper. But, the status quo isn&#8217;t free. It has the advantage of already being in the budget.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!3Jzq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee39db3-e5e1-481d-b2a2-eea95e3f5763_1622x970.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!3Jzq!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee39db3-e5e1-481d-b2a2-eea95e3f5763_1622x970.png 424w, /__u/substackcdn.com/image/fetch/$s_!3Jzq!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee39db3-e5e1-481d-b2a2-eea95e3f5763_1622x970.png 848w, /__u/substackcdn.com/image/fetch/$s_!3Jzq!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee39db3-e5e1-481d-b2a2-eea95e3f5763_1622x970.png 1272w, /__u/substackcdn.com/image/fetch/$s_!3Jzq!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee39db3-e5e1-481d-b2a2-eea95e3f5763_1622x970.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!3Jzq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee39db3-e5e1-481d-b2a2-eea95e3f5763_1622x970.png" width="1456" height="871" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fee39db3-e5e1-481d-b2a2-eea95e3f5763_1622x970.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:871,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2732307,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://jirif.substack.com/i/210734145?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee39db3-e5e1-481d-b2a2-eea95e3f5763_1622x970.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!3Jzq!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee39db3-e5e1-481d-b2a2-eea95e3f5763_1622x970.png 424w, /__u/substackcdn.com/image/fetch/$s_!3Jzq!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee39db3-e5e1-481d-b2a2-eea95e3f5763_1622x970.png 848w, /__u/substackcdn.com/image/fetch/$s_!3Jzq!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee39db3-e5e1-481d-b2a2-eea95e3f5763_1622x970.png 1272w, /__u/substackcdn.com/image/fetch/$s_!3Jzq!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee39db3-e5e1-481d-b2a2-eea95e3f5763_1622x970.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Most organisations aren&#8217;t starting with a blank spreadsheet. They&#8217;re operating technology environments assembled over years or decades through acquisitions, migrations, cloud adoption, regulatory changes, new applications and old applications that somehow refuse to die.</p><p>Each addition creates dependencies, and each dependency creates something else that has to be managed, monitored, patched, audited or protected.</p><p>A system exposes sensitive information during processing, so access to that system has to be controlled. That means identity controls. Privileged users need additional controls. Endpoints need protection. Networks need segmentation. Data movement needs monitoring. Logs need collection and analysis. Alerts need investigation. Compliance needs evidence. Suppliers need assessment. People need training. Incidents need response capabilities. All of these costs put together are <strong>the carrying cost of exposure.</strong></p><p>Cybersecurity also has a tendency to accumulate. A new threat appears - another capability is purchased. A regulatory requirement changes - another process is introduced. An incident occurs - more monitoring is added. A supplier creates another dependency - another risk-management process shows up. An audit identifies a gap - another control closes it. Nothing disappears. But, more is always added.</p><p>The result is greater operational complexity, and complexity has its own cost. More systems have to integrate. More alerts have to be interpreted. More policies have to remain consistent. More privileged relationships have to be governed. More dependencies have to be understood. <strong>It&#8217;s always more. Never less.</strong> Eventually, organisations can find themselves <em>protecting the systems that protect the systems that protect the data.</em></p><p>Since much of that expenditure already exists, it&#8217;s easy to stop seeing it as a cost of the architecture at all.</p><h2>The Wrong Comparison</h2><p>This matters when a CISO takes a proposed architectural change to the CFO. That change may cost &#8364;5 million to implement. Presented in isolation, &#8364;5 million is a very visible number.</p><p>The existing environment appears to cost nothing because nobody is asking for &#8364;5 million to keep it. But that isn&#8217;t a valid comparison.</p><p>The existing environment already has licensing costs, infrastructure costs, security tooling, monitoring, personnel, audits, insurance, compliance, incident-response capability and accumulated technical debt. Those expenses may be scattered across half a dozen budgets, but they don&#8217;t disappear simply because nobody has grouped them together. Then there&#8217;s another cost that usually isn&#8217;t sitting neatly in next year&#8217;s budget. What happens when something fails?</p><p>IBM&#8217;s 2026 Cost of a Data Breach research puts the global average cost of a data breach at US$4.99 million, up 12% from the previous year and the highest figure reported in the study to date. That&#8217;s roughly &#8364;4.3 million at recent exchange rates, although the conversion obviously moves with the currency. The more important point is the scale of the loss. Even that figure can make a breach sound tidier than it really is. A serious incident doesn&#8217;t produce one invoice marked <em>data breach</em>.</p><p>There&#8217;s investigation, containment, remediation and recovery. External specialists may be brought in. Systems may have to be isolated or rebuilt. Operations can be disrupted. Legal teams become involved. Regulators may become involved. Customers may require notification or remediation. Contracts may be affected. Insurance conditions can change. Then there&#8217;s management time.</p><p>Executives, security teams, developers, operations staff, communications teams and legal counsel can spend weeks dealing with an incident instead of doing whatever the organisation normally pays them to do.</p><p>For larger incidents, the numbers can sky rocket. Allianz&#8217;s analysis found that ransomware accounted for 60% of the value of large cyber claims above &#8364;1 million during the first half of 2025. Data theft appeared in 40% of the value of those large claims, up from 25% during 2024. But, that doesn&#8217;t tell the entire story. Because your breach isn&#8217;t only your problem.</p><h2>When the Cost Travels</h2><p>Organisations don&#8217;t operate in isolation. They depend on cloud platforms, software suppliers, managed services, identity providers, APIs, payment systems, logistics providers and increasingly AI services. Those relationships create enormous efficiency. They also create dependencies.</p><p>Verizon&#8217;s 2026 Data Breach Investigations Report found that third parties were involved in 48% of breaches, up from 30% the previous year. Nearly half of the breaches it analysed therefore involved relationships or infrastructure extending beyond the organisation itself. <strong>The financial consequence doesn&#8217;t necessarily stop with the organisation that was compromised.</strong></p><p>A supplier outage can interrupt its customers. Compromised credentials can provide access to other environments. Stolen information can enable subsequent fraud, identity attacks or highly targeted social engineering. Customers may have to investigate their own systems, rotate credentials, notify their own clients or temporarily suspend services. One organisation&#8217;s security incident can become somebody else&#8217;s operational and financial problem.</p><p>That creates a multiplier that a simple average breach-cost figure doesn&#8217;t properly reflect. It&#8217;s not just how much the original organisation loses. It&#8217;s how far the ripple effect of that breach propagates through the relationships surrounding it. As infrastructure becomes more interconnected, that issue becomes more important.</p><p>This is where containment becomes an economic consideration as much as a security one. This is where we need to understand that architecture needs to limit what a successful compromise can expose. Limiting the initial exposure can limit what there is to propagate.</p><h2>Getting In and Getting Something Are Different Problems</h2><p>Consider two organisations experiencing broadly similar compromises.</p><p>In the first, the attacker reaches systems containing large amounts of readable customer information, credentials or commercially sensitive data. Some of that information may also provide the means to attack customers, employees, suppliers or other connected organisations.</p><p>In the second, the attacker reaches infrastructure where significantly less useful information is exposed because sensitive data remains protected through more of its lifecycle.</p><p>Both organisations have experienced a security failure. Their financial outcomes may vary. So do the consequences for everyone connected.</p><p>One architecture concentrates primarily on preventing the attacker from getting through the door. The other also asks what should be sitting behind the door if they succeed, and how far anything they obtain can travel. The real difference, in those perspectives, is the economic impact they have on the organisation and those connected to it.</p><p>Security investment has traditionally concentrated heavily on reducing the probability of compromise. Stronger authentication can reduce credential abuse. Better monitoring can detect an attacker earlier. Segmentation can restrict lateral movement. Endpoint controls can stop malicious code. Vulnerability management can close known routes into an environment.</p><p>But probability isn&#8217;t the only variable determining the economic outcome. There&#8217;s also the value available to the attacker and the consequences that follow if they get it. That gives us another way to think about cyber risk. Not as a precise mathematical formula - cybersecurity contains far too many variables for that - but as an economic model.</p><p>The consequence of an incident is influenced by the <strong>probability of compromise, the value exposed when it happens, and how far the resulting damage can propagate. </strong>Traditional security concentrates heavily on the first part. Architecture can influence all three.</p><ul><li><p>If an organisation can verify information without unnecessarily revealing it, the amount exposed changes.</p></li><li><p>If computation can occur while sensitive information stays encrypted, the amount exposed changes.</p></li><li><p>If an application receives only the attributes needed for a transaction rather than the complete underlying record, the amount exposed changes.</p></li><li><p>If administrators can operate infrastructure without routinely being able to read the information contained within it, the amount exposed changes.</p></li><li><p>If less useful information is available following compromise, there may also be less material available to enable the next attack.</p></li></ul><p>The attacker doesn&#8217;t have to disappear for the economics of the attack to change.</p><h2>The CISO and CFO Are Looking at the Same Problem</h2><p>The CISO and CFO are sometimes seen as approaching cybersecurity from opposing directions. The CISO wants to reduce risk. The CFO wants to control expenditure.</p><p>Both are essentially asking the same question: <strong>What&#8217;s the most economically efficient way to reduce the organisation&#8217;s exposure?</strong></p><p>That doesn&#8217;t automatically mean spending more. Nor does it mean replacing existing infrastructure simply because something newer exists. A new architecture that costs &#8364;10 million but eliminates &#8364;500,000 of meaningful risk isn&#8217;t particularly compelling.</p><p>A &#8364;10 million investment that materially reduces continuing operating costs, simplifies controls, limits the severity of potential incidents, reduces regulatory or downstream exposure and enables new commercial capabilities is an entirely different proposition.</p><p>That requires a proper comparison. It means comparing the total cost of maintaining the existing architecture with the cost and consequences of changing it. There&#8217;s also a temptation to make the opposite mistake and pretend architectural change solves everything.</p><p>Encrypted computation can impose performance costs. Cryptographic systems introduce engineering complexity. Existing applications may not easily support new approaches. Migration creates operational risk. Some information genuinely does need to be available in plaintext at particular points in a workflow.</p><p>The commercial case exists when reductions in exposure, operating complexity, incident consequence, downstream risk or future technical debt justify the cost of making the change. And that calculation won&#8217;t be always be the same.</p><p>Protecting a public product catalogue isn&#8217;t the same problem as protecting medical records. Processing an employee&#8217;s cafeteria preference isn&#8217;t the same as processing their biometric identity. A system containing publicly available information doesn&#8217;t carry the same economic consequence as one containing customer credentials, intellectual property or regulated personal information.</p><p>Architecture should reflect the value and consequence of the information involved. Which is why quoting the average cost of a breach, whether it&#8217;s &#8364;4 million or &#8364;40 million, can only take the discussion so far.</p><h2>The Status Quo Should Have to Justify Itself Too</h2><p>New technology is routinely required to prove itself. Existing architecture rarely faces the same test. Its licences renew. Its infrastructure remains. Its processes continue. Its technical debt accumulates. Its security controls multiply around it. And because those costs already exist, they become invisible.</p><p>If an organisation is spending increasing amounts protecting sensitive information because that information must repeatedly become visible throughout its systems, then maintaining that architecture is itself an investment decision. It should be evaluated like one.</p><p>The choice isn&#8217;t between spending money and spending nothing. It&#8217;s between the cost of changing the architecture, the continuing cost of protecting the existing one, and the potential cost when that protection fails. The cost of doing nothing is never zero.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://jirif.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading PrivID's Substack! Subscribe for free to receive new posts.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[What the System Is Allowed to See?]]></title><description><![CDATA[Modern information systems operate on a fairly simple assumption.]]></description><link>https://jirif.substack.com/p/what-the-system-is-allowed-to-see</link><guid isPermaLink="false">https://jirif.substack.com/p/what-the-system-is-allowed-to-see</guid><dc:creator><![CDATA[Jiri Fiala]]></dc:creator><pubDate>Mon, 10 Aug 2026 15:47:03 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!d5ua!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F836629e1-a49b-448a-81f4-7f04a2dd706d_1624x969.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Modern information systems operate on a fairly simple assumption. Data is stored, someone or something needs to use it, the data becomes available for processing, and security controls determine who or what is allowed to access it. We&#8217;ve built increasingly sophisticated systems around that point of exposure.</p><p>Identity and access management determines who gets in. Privileged access management controls administrators. Network segmentation limits movement. Endpoint protection watches devices. Data loss prevention watches information leaving. SIEM platforms collect events, security operations centres monitor them, behavioural systems look for anomalies, and compliance systems document who had access, when they had it, and whether that access was appropriate.</p><p>Given the architecture we&#8217;ve built for the last 40 years, it is necessary. But there&#8217;s an assumption buried under that: <strong>the information itself must eventually become visible somewhere. </strong>Why?</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!d5ua!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F836629e1-a49b-448a-81f4-7f04a2dd706d_1624x969.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!d5ua!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F836629e1-a49b-448a-81f4-7f04a2dd706d_1624x969.png 424w, /__u/substackcdn.com/image/fetch/$s_!d5ua!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F836629e1-a49b-448a-81f4-7f04a2dd706d_1624x969.png 848w, /__u/substackcdn.com/image/fetch/$s_!d5ua!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F836629e1-a49b-448a-81f4-7f04a2dd706d_1624x969.png 1272w, /__u/substackcdn.com/image/fetch/$s_!d5ua!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F836629e1-a49b-448a-81f4-7f04a2dd706d_1624x969.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!d5ua!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F836629e1-a49b-448a-81f4-7f04a2dd706d_1624x969.png" width="1456" height="869" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/836629e1-a49b-448a-81f4-7f04a2dd706d_1624x969.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:869,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2131466,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://jirif.substack.com/i/210611284?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F836629e1-a49b-448a-81f4-7f04a2dd706d_1624x969.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!d5ua!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F836629e1-a49b-448a-81f4-7f04a2dd706d_1624x969.png 424w, /__u/substackcdn.com/image/fetch/$s_!d5ua!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F836629e1-a49b-448a-81f4-7f04a2dd706d_1624x969.png 848w, /__u/substackcdn.com/image/fetch/$s_!d5ua!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F836629e1-a49b-448a-81f4-7f04a2dd706d_1624x969.png 1272w, /__u/substackcdn.com/image/fetch/$s_!d5ua!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F836629e1-a49b-448a-81f4-7f04a2dd706d_1624x969.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Every Exposure Means Something Else to Protect</h2><p>When sensitive information becomes available in plaintext, the application processing it becomes part of the security boundary. So does the operating system underneath it, the memory it occupies, the administrator with sufficient privileges, the identity system controlling access, the endpoint being used, the logging infrastructure, and the APIs connecting that system to everything around it. AI systems are now part of that boundary as well.</p><p>Every additional place where information becomes visible expands the environment to be defended. And every expansion carries a cost. Which brings up an economic question: <strong>how much of the cybersecurity budget exists because the underlying architecture creates exposure that has to be controlled?</strong></p><ul><li><p>The CISO sees attack surface. </p></li><li><p>The CFO sees expenditure. </p></li><li><p>The privacy officer sees personal information. </p></li><li><p>Legal sees liability. </p></li><li><p>Compliance sees regulatory obligations. </p></li><li><p>Operations sees systems that must remain available. </p></li><li><p>The board sees all of that. Eventually.</p></li></ul><p>They may look like different problems, but in reality they&#8217;re dealing with different consequences of the same architecture: <strong>sensitive information exists somewhere in a usable form, therefore that environment must be protected.</strong> </p><div class="callout-block" data-callout="true"><p>NB: Let&#8217;s be honest here. For many that read my articles, this seems like I&#8217;m flogging on this ad infinitum - or ad nauseum - depending on your POV. But, it is the underlying problem for every breach, and it needs to be laid bare for people to truly understand. Because, ultimately, it is your data at risk.</p></div><p>The traditional response has been to attempt better authentication. Better monitoring. Better detection. Better segmentation. Better access policies. Better incident response.</p><p>There&#8217;s a structural limitation to the approach. They can reduce the probability of compromise. Not the value of the compromise.</p><h2>When the Controls Fail</h2><p>Security risk is discussed in terms of probablilties:</p><ul><li><p>How likely is an attacker to penetrate the organisation? </p></li><li><p>How likely is an employee to misuse access? </p></li><li><p>How likely is a credential to be compromised? </p></li><li><p>How likely is ransomware to succeed?</p></li></ul><p>Imagine two systems. Both are compromised.</p><p>In the one, the attacker obtains credentials that provide access to a large collection of readable customer information. In the other, the attacker compromises infrastructure, but the sensitive information stays cryptographically protected throughout.</p><p>Both organisations experienced a security failure. Their economic outcomes? Vastly different.</p><p>Pretending that any sufficiently complex organisation can guarantee 100% safety for data is becoming increasingly harder to defend.</p><p>For decades, cybersecurity has overwhelmingly concentrated on reducing the probability that an attacker reaches valuable information. We build stronger walls, detect attackers earlier, authenticate users more carefully, restrict privileges and monitor behaviour.</p><p>But there&#8217;s another variable available: <strong>reduce the amount of useful information exposed behind those controls.</strong></p><p>An organisation can minimise the information it collects. It can process information locally rather than continually centralising it. It can disclose only the attributes needed for a transaction. It can prove that something is true without revealing all of the information behind that proof. Increasingly, it can also perform certain computations while the underlying information stays encrypted.</p><h2>Data Minimisation Is Not Just Deletion</h2><p>We usually think about data minimisation in terms of quantity and time. Collect less. Store less. Retain it for less time. Delete it when it&#8217;s no longer needed. Notice what&#8216;s missing from that: <strong>minimise exposure.</strong></p><p>A hospital legitimately needs medical records. A bank needs financial information. Governments need citizen information. Manufacturers may need commercially sensitive intellectual property. AI systems need information from which to perform useful analysis. That doesn&#8217;t mean every component involved in using it needs to be capable of seeing it.</p><p>When a new security approach is proposed, finance understandably asks what it will cost: </p><ul><li><p>Implementation costs money. </p></li><li><p>Integration costs money. </p></li><li><p>Compute costs money. </p></li><li><p>Migration costs money. </p></li><li><p>Training costs money. </p></li><li><p>Operational change introduces its own risk.</p></li></ul><p>They should be looked at. The problem is that isn&#8217;t the entire cost picture. The alternative isn&#8217;t<em> do something versus spend nothing</em>. The real comparison is the <strong>cost of change versus the continuing cost of keeping the existing model</strong>.</p><p>That existing model already carries substantial costs: security tooling, monitoring, privileged-access controls, compliance, audit, cyber insurance, incident-response capability, specialised personnel, remediation and the technical debt accumulated by continually adding controls to increasingly complicated environments.</p><p>Then there&#8217;s the cost that&#8217;s harder to predict: what happens when they fail?</p><h2>What Does the System Actually Need to Know?</h2><p>We&#8217;ve spent decades improving our answers to <strong>who should be allowed to see this? </strong>There&#8217;s a question no one thought to ask:  <strong>Does anyone need to see it?</strong></p><p>Sometimes the answer will still be yes. Cryptography isn&#8217;t magic. Neither is zero trust, AI, confidential computing, or whatever else currently happens to be carrying a conference badge and an enthusiastic marketing budget. But more often than not the answer is no.</p><p>A system can verify an attribute without knowing the underlying identity. A service can calculate a result without retaining the information used to calculate it. An administrator can operate infrastructure without being able to read the information contained. An AI system can answer a question without permanently absorbing everything it was given. And, critically, a compromised system doesn&#8217;t necessarily have to represent the catastrophic information exposure we&#8217;ve come to assume it does.</p><p>Because if information doesn&#8217;t always need to be visible to be useful, we&#8217;re no longer talking only about building better cybersecurity controls around the same underlying architecture. We&#8217;re talking about changing the architecture itself.</p><p>And once you do that, the question facing the CISO and CFO changes: <strong>how much exposure the organisation should keep paying to protect in the first place?</strong></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://jirif.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading PrivID's Substack! Subscribe for free to receive new posts.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Trust Is Not a Security Control]]></title><description><![CDATA[Trust has become one of cybersecurity&#8217;s favourite words.]]></description><link>https://jirif.substack.com/p/trust-is-not-a-security-control</link><guid isPermaLink="false">https://jirif.substack.com/p/trust-is-not-a-security-control</guid><dc:creator><![CDATA[Jiri Fiala]]></dc:creator><pubDate>Thu, 06 Aug 2026 13:15:39 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!IzYf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff959f45d-c464-4d67-b348-867ac693c01b_1672x941.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Trust has become one of cybersecurity&#8217;s favourite words.</p><p>Trusted vendors. Trusted identities. Trusted devices. Trusted environments. Trusted execution. Trusted AI. Trusted supply chains.</p><p>At the same time, the industry increasingly talks about zero trust, continuous verification, secure-by-design systems, identity-based access, and explicit trust boundaries.</p><p>Security organisations are saying to trust less while continuing to build systems that depend heavily on trust. The industry has identified the problem, but, it hasn&#8217;t followed the argument to its logical conclusion.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!IzYf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff959f45d-c464-4d67-b348-867ac693c01b_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!IzYf!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff959f45d-c464-4d67-b348-867ac693c01b_1672x941.png 424w, /__u/substackcdn.com/image/fetch/$s_!IzYf!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff959f45d-c464-4d67-b348-867ac693c01b_1672x941.png 848w, /__u/substackcdn.com/image/fetch/$s_!IzYf!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff959f45d-c464-4d67-b348-867ac693c01b_1672x941.png 1272w, /__u/substackcdn.com/image/fetch/$s_!IzYf!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff959f45d-c464-4d67-b348-867ac693c01b_1672x941.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!IzYf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff959f45d-c464-4d67-b348-867ac693c01b_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f959f45d-c464-4d67-b348-867ac693c01b_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2178720,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://jirif.substack.com/i/209981422?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff959f45d-c464-4d67-b348-867ac693c01b_1672x941.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!IzYf!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff959f45d-c464-4d67-b348-867ac693c01b_1672x941.png 424w, /__u/substackcdn.com/image/fetch/$s_!IzYf!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff959f45d-c464-4d67-b348-867ac693c01b_1672x941.png 848w, /__u/substackcdn.com/image/fetch/$s_!IzYf!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff959f45d-c464-4d67-b348-867ac693c01b_1672x941.png 1272w, /__u/substackcdn.com/image/fetch/$s_!IzYf!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff959f45d-c464-4d67-b348-867ac693c01b_1672x941.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Trust Is an Expectation</h3><p>When an organisation says that it trusts a vendor, it usually means the vendor has passed a due-diligence process. Contracts have been reviewed, certifications checked, and security questionnaires completed. Policies, insurance, governance, jurisdiction, and reputation may all have been considered.</p><p>All of that said, the vendor may still be able to view the data. Its administrators may still have privileged access. Its infrastructure may still create logs, backups, temporary files, analytics records, or diagnostic copies. Its employees can make mistakes, its software supply chain can be compromised, and its legal obligations can change.</p><p>Trust describes the expectation around those capabilities, it doesn&#8217;t mean they can&#8217;t be misussed.</p><h3>Zero Trust Stops at the Door</h3><p>Traditional network security treated users and devices inside the perimeter as more trustworthy than those outside it. Zero trust challenged that assumption by requiring access decisions to be evaluated continuously rather than granted permanently because something had entered the network. That is better. But zero trust is implemented as a more sophisticated permission system:</p><div class="callout-block" data-callout="true"><p><strong>Authenticate</strong> the user <span>&#8594;</span> <strong>Evaluate</strong> the device &#8594; <strong>Check</strong> location and behaviour &#8594; <strong>Apply</strong> policy &#8594; <strong>Authorise</strong> the request &#8594; <strong>Log</strong> the activity.</p></div><p>The access decision becomes more precise, once access is granted, the data is decrypted and revealed. The system has verified <em>who</em> is asking. It hasn&#8217;t eliminated <em>what</em> is exposed.</p><h3>Verification Doesn&#8217;t Eliminate Visibility</h3><p>A verified identity can still be compromised. An authorised employee can still make a mistake. A legitimate application can still collect too much information. An approved AI agent can still take an unintended action. A properly authenticated administrator can still see information that isn&#8217;t needed. A compliant cloud platform can still process sensitive data in plaintext.</p><p>An organisation can improve authentication, identity governance, behavioural monitoring, endpoint security, and least-privilege access and still expose the full underlying dataset. That is <strong>better-controlled exposure, not eliminated exposure</strong>.</p><h3>Trust Expands Through the System</h3><p>Modern systems depend on chains of trusted entities. An employee accesses an application running on a cloud platform. The application calls several APIs, records telemetry through another service, writes logs to a monitoring platform, creates backups in a separate region, and may pass information into an analytics or AI system.</p><p>Each service has its own infrastructure providers and subprocessors. Each has administrators, credentials, software dependencies, legal obligations, and failure modes. A single business action can cross multiple trust boundaries before the user sees a result.</p><p>This is why secure-by-design discussions increasingly emphasise the need to make trust explicit. Trust boundaries matter because they show where data, identities, and execution contexts pass from one control domain to another.</p><p>But identifying a boundary doesn&#8217;t protect the information crossing it. It only tells us where trust is being transferred, not whether it&#8217;s actually necessary.</p><h3>Contracts Govern Behaviour</h3><p>Contracts define obligations, liability, permitted use, retention, deletion, breach notification, audit rights, jurisdiction, and remedies.</p><p>But a contract can&#8217;t stop a system from seeing data that the architecture gives it.</p><ul><li><p>It can prohibit copying; it can&#8217;t make copying impossible.</p></li><li><p>It can restrict secondary use; it can&#8217;t prevent secondary use if the provider retains technical access.</p></li><li><p>It can require deletion; it can&#8217;t prove that no other copy ever existed.</p></li><li><p>It can impose consequences after a breach; it can&#8217;t reverse disclosure.</p></li></ul><p><strong>Contracts govern relationships. Architecture governs capability.</strong> Security weakens when one is mistaken for the other.</p><h3>Privileged Access Is Still Access</h3><p>Administrators need sufficient authority to maintain infrastructure, restore services, configure systems, and respond to incidents. That becomes a broader assumption: that administrators need to view the information those systems contain.</p><ul><li><p>The person who controls the server can see the database.</p></li><li><p>The person who manages the cloud account can access the storage.</p></li><li><p>The person who maintains the application can inspect its logs.</p></li><li><p>The person debugging the AI workflow can examine the prompts and outputs.</p></li></ul><p>Administration and data visibility are different functions. Treating them as inseparable creates a standing exposure that organisations try to manage through screening, policy, monitoring, and trust.</p><h3>AI Makes the Trust Problem Larger</h3><p>An AI agent may be authenticated correctly, assigned an approved role, and permitted to access several systems. It may still combine information in unexpected ways, act at machine speed, use tools, invoke external services, retain context, or pass information between workflows that had previously been separate.</p><p>This is why security discussions are beginning to treat non-human identities and AI agents as security principals not just extensions of human users. But giving an AI agent an identity doesn&#8217;t solve the problem.</p><p>The agent can still receive more information than it needs. A perfectly authenticated agent with excessive visibility remains an excessive risk. The issue isn&#8217;t only whether the system trusts the agent, it&#8217;s whether the architecture requires the agent to be trusted at all.</p><h3>Trust Minimisation Is Not Distrust</h3><p>No organisation can operate without trust. People must work together. Companies must use suppliers. Partners must exchange information. Administrators must maintain systems. Regulators must supervise markets. Customers must rely on organisations to honour their commitments.</p><p>The objective isn&#8217;t to eliminate trust, it&#8217;s to stop making security dependent on it.</p><p>A trust-minimised architecture assumes that vendors can fail, credentials can be compromised, insiders can make mistakes, jurisdictions can change, software can contain defects, and automated systems can behave unexpectedly. Which limits what any one failure can expose:</p><ul><li><p><strong>Access</strong> should reveal only what is necessary for the immediate task.</p></li><li><p><strong>Identity</strong> should establish entitlement without requiring unnecessary disclosure.</p></li><li><p><strong>Sensitive information</strong> shouldn&#8217;t automatically become plaintext merely because a computation needs to occur.</p></li><li><p><strong>Infrastructure providers</strong> should be able to provide infrastructure without inheriting unrestricted visibility into its contents.</p></li><li><p><strong>Administrators</strong> should be able to maintain systems without automatically gaining access to the protected data inside them.</p></li><li><p><strong>Compromise</strong> should remain local rather than becoming a route to everything.</p></li></ul><h3>Security Should Survive Failed Trust</h3><p>Trust can be justified, and it can be misplaced. Organisations won&#8217;t know which until it&#8217;s too late.</p><p>A vendor can be competent for years before a breach. An administrator can be reliable until an account is compromised. A jurisdiction can be considered adequate until its laws or political conditions change. An application can operate safely until an update introduces a vulnerability. An AI system can behave predictably until it encounters a combination of instructions its designers didn&#8217;t anticipate.</p><p>A resilient architecture doesn&#8217;t need to be perfect. It just has assume that something will eventually fail. The real test is what happens when it does:</p><ul><li><p>Can the failed component see the underlying information?</p></li><li><p>Can it copy that information?</p></li><li><p>Can it move laterally?</p></li><li><p>Can it impersonate another entity?</p></li><li><p>Can it turn one authorisation into general access?</p></li><li><p>Can the organisation contain the failure without replacing the entire environment?</p></li></ul><h3>Trust Is a Decision</h3><p>An organisation can decide that a vendor is trustworthy, an employee is reliable, or that a platform, jurisdiction, AI model, or supply-chain partner presents an acceptable risk. Those decisions will always involve judgement. Security architecture should determine what is protected when that judgement is wrong.</p><p>That is where much of the current discussion about trust stops too early. The industry is right to reject implicit trust, to verify identities continuously, and to define trust boundaries, minimise privileges, and treat non-human entities as genuine security principals.</p><p>A verified entity should still receive only the information needed to complete the task. An authorised system should still be unable to expose everything. A trusted vendor should still be technically prevented from seeing what it doesn&#8217;t need to see.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://jirif.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading PrivID's Substack! Subscribe for free to receive new posts.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The Compliance Lag]]></title><description><![CDATA[A regulation changes.]]></description><link>https://jirif.substack.com/p/the-compliance-lag</link><guid isPermaLink="false">https://jirif.substack.com/p/the-compliance-lag</guid><dc:creator><![CDATA[Jiri Fiala]]></dc:creator><pubDate>Wed, 05 Aug 2026 13:46:58 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!5M-U!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd63e161e-a836-43ea-9d58-0a7bd7d06bc7_2816x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>A regulation changes. A standard is updated. An organisation adjusts its controls, updates its policies, replaces a supplier, or begins a migration programme.</p><p>The assumption&#8217;s that the problem&#8217;s now been addressed.</p><p>Once data&#8217;s been exposed, copied, logged, transferred, harvested, retained, or made available during processing, a later compliance decision can&#8217;t make that exposure disappear.</p><p>It can only change what happens next.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!5M-U!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd63e161e-a836-43ea-9d58-0a7bd7d06bc7_2816x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!5M-U!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd63e161e-a836-43ea-9d58-0a7bd7d06bc7_2816x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!5M-U!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd63e161e-a836-43ea-9d58-0a7bd7d06bc7_2816x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!5M-U!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd63e161e-a836-43ea-9d58-0a7bd7d06bc7_2816x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!5M-U!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd63e161e-a836-43ea-9d58-0a7bd7d06bc7_2816x1536.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!5M-U!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd63e161e-a836-43ea-9d58-0a7bd7d06bc7_2816x1536.png" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d63e161e-a836-43ea-9d58-0a7bd7d06bc7_2816x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:10059865,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://jirif.substack.com/i/209789872?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd63e161e-a836-43ea-9d58-0a7bd7d06bc7_2816x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!5M-U!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd63e161e-a836-43ea-9d58-0a7bd7d06bc7_2816x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!5M-U!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd63e161e-a836-43ea-9d58-0a7bd7d06bc7_2816x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!5M-U!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd63e161e-a836-43ea-9d58-0a7bd7d06bc7_2816x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!5M-U!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd63e161e-a836-43ea-9d58-0a7bd7d06bc7_2816x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Compliance Is Retrospective by Design</h2><p>Regulation usually responds after the fact. Its weaknesses become apparent. Incidents accumulate. Regulators investigate. Legislation&#8217;s drafted, negotiated, challenged, amended, and eventually implemented.</p><p>By the time a formal fix arrives, the underlying architectural dependency may have existed for years.</p><p>It&#8217;s just the nature of regulation. That gap allows an organisation to feel safe while waiting for the rules to catch up. But, the exposure exists whether or not the regulation&#8217;s caught up or not.</p><h2>A New Rule Doesn&#8217;t Fix An Old Problem</h2><p>An organisation can terminate a vendor agreement, change providers, move its workloads, or restrict future access. It may even be able to prove that it&#8217;s now compliant.</p><p>None of those things fix what happened to information that was previously accessible?</p><h2>Deletion Does Not Fix It</h2><p>Organisations can rely on deletion. <strong>Deletion may remove a known copy from a known system under known control</strong>. But that doesn&#8217;t mean the information was never duplicated, retained elsewhere, extracted, reconstructed, or incorporated into another process. Especially in distributed environments involving cloud platforms, SaaS providers, analytics systems, AI models, development logs, support tools, and supply chains. The more systems that allowed to see the information, the less credible a claim of complete deletion becomes.</p><h2>Compliance Governs Permission</h2><p>Compliance controls focus on who&#8217;s allowed to access information. Policies define use. Contracts define obligations. Identity systems define authorised users. Audit logs log activity.</p><p>These controls regulate who can access the data. Their effectiveness depends on people, organisations, software, infrastructure, legal systems, and enforcement mechanisms behaving as expected.</p><p>The system just declares that visibility to be controlled. That model becomes increasingly fragile as systems grow more interconnected and autonomous. An AI system doesn&#8217;t need malicious intent to expose information. A developer doesn&#8217;t need to act dishonestly to create an excessive log. A supplier doesn&#8217;t need to breach a contract deliberately for data to pass into another service. A government doesn&#8217;t need to violate local law if a foreign legal order already grants access.</p><p>Compliance defines what should happen. Architecture determines what can happen.</p><h2>The Compliance Window Is An Exposure Window</h2><p>When organisations postpone architectural change until regulation forces it, it becomes very much a &#8220;they problem&#8221;. During that period, data is still processed under the existing model. Systems continue to decrypt information. Vendors continue to receive it. Cloud services continue to log it. Models continue to ingest it. Backups accumulate.</p><p>The organisation can implement every change and still not account fully for what happened during the delay.</p><p>Take quantum risk. Harvested encrypted data doesn&#8217;t need to be readable today to create future exposure. Likewise, data revealed during computation doesn&#8217;t need to be stolen through a dramatic breach, it only needs to become available somewhere outside the organisation&#8217;s effective control.</p><h2>Compliance Can&#8217;t Fix Past Architecture</h2><p>An organisation can plan to adopt post-quantum cryptography, intend to move away from a particular cloud environment, expect stronger AI regulation, believe contractual protections will improve, or wait for regulators.</p><p>None of that changes what the current architecture exposes today. The question now becomes what information will stay exposed while it waits.</p><p>Retrospective security can impose penalties, change behaviour, and establish accountability, but it can&#8217;t make exposed information private again.</p><h2>Architecture Has to Move First</h2><p>Designing systems where sensitive information doesn&#8217;t automatically become visible just because it&#8217;s being used. That means reducing plaintext processing, separating proof from disclosure, and limit what vendors, infrastructure providers, administrators, applications, and automated systems are able to see.</p><p>Regulation will keep evolving. Vendors will change. Jurisdictions will shift. Standards will be replaced. Threat models will expand. An organisation can&#8217;t predict everything, but it can reduce how much information is exposed now.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://jirif.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading PrivID's Substack! Subscribe for free to receive new posts.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The End of Trusted Vendors]]></title><description><![CDATA[Cybersecurity is built around a simple question: Who do we trust?]]></description><link>https://jirif.substack.com/p/the-end-of-trusted-vendors</link><guid isPermaLink="false">https://jirif.substack.com/p/the-end-of-trusted-vendors</guid><dc:creator><![CDATA[Jiri Fiala]]></dc:creator><pubDate>Tue, 04 Aug 2026 13:52:25 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dLTC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc24a1683-dffb-4ddb-8833-2dc8acadc076_2816x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Cybersecurity is built around a simple question: <em>Who do we trust?</em></p><ul><li><p>Can we trust this cloud provider?</p></li><li><p>Can we trust this software vendor?</p></li><li><p>Can we trust this identity platform?</p></li><li><p>Can we trust this certificate authority?</p></li></ul><p>Every procurement process, security audit and compliance framework has revolved around that question. The better the reputation, the easier the decision.</p><p>It made sense. Technology was becoming increasingly complex, and no organisation could build or operate every component itself. Trust allowed digital ecosystems to scale. But trust came at a cost. That cost was architectural.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!dLTC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc24a1683-dffb-4ddb-8833-2dc8acadc076_2816x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!dLTC!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc24a1683-dffb-4ddb-8833-2dc8acadc076_2816x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!dLTC!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc24a1683-dffb-4ddb-8833-2dc8acadc076_2816x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!dLTC!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc24a1683-dffb-4ddb-8833-2dc8acadc076_2816x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!dLTC!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc24a1683-dffb-4ddb-8833-2dc8acadc076_2816x1536.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!dLTC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc24a1683-dffb-4ddb-8833-2dc8acadc076_2816x1536.png" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c24a1683-dffb-4ddb-8833-2dc8acadc076_2816x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:8386130,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://jirif.substack.com/i/209262292?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc24a1683-dffb-4ddb-8833-2dc8acadc076_2816x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!dLTC!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc24a1683-dffb-4ddb-8833-2dc8acadc076_2816x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!dLTC!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc24a1683-dffb-4ddb-8833-2dc8acadc076_2816x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!dLTC!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc24a1683-dffb-4ddb-8833-2dc8acadc076_2816x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!dLTC!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc24a1683-dffb-4ddb-8833-2dc8acadc076_2816x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Every vendor introduces a trust dependency that another organisation will act in your best interests:</p><ul><li><p>They&#8217;ll remain financially stable.</p></li><li><p>They&#8217;ll maintain security.</p></li><li><p>They&#8217;ll respond quickly to vulnerabilities.</p></li><li><p>They&#8217;ll operate within predictable legal frameworks.</p></li><li><p>Their priorities will keep aligning with yours.</p></li></ul><p>The cybersecurity industry has treated trust as a security control not an operational assumption. It doesn&#8217;t eliminate risk; it transfers it to someone else.</p><p>Organisations depend on dozens, sometimes hundreds, of external providers. Cloud platforms, software vendors, identity services, AI providers, certificate authorities, managed security providers, hardware manufacturers and who knows how many third-party libraries (seriously, I really don&#8217;t think anyone is fully aware of how many - I have no idea - I know it&#8217;s a lot) all contribute to modern infrastructure.</p><p>The challenge isn&#8217;t that any particular vendor is untrustworthy. The challenge is that trust doesn&#8217;t scale indefinitely. The more dependencies we accumulate, the more assumptions need to be made.</p><p><strong>What can we verify?</strong></p><p>Verification doesn&#8217;t need reputation. It doesn&#8217;t need optimism. It doesn&#8217;t need hoping that another organisation continues behaving exactly as expected. It needs evidence.</p><p>This is where mathematics begins enters the picture. For centuries, mathematics has offered certainty where human judgement could not. We don&#8217;t trust that two plus two equals four. We verify it. And if you have a great accountant, you don&#8217;t ask questions why it can equal five.</p><p>IThat principle is finding its way into cybersecurity:</p><ul><li><p>Rather than assuming an identity is genuine, we can verify specific claims.</p></li><li><p>Rather than assuming data has remained unchanged, we can prove its integrity.</p></li><li><p>Rather than assuming a user is authorised, we can show authorisation without exposing unnecessary information.</p></li></ul><p>This isn&#8217;t about eliminating vendors., replacing cloud providers, or suggesting that organisations should distrust every technology company they work with. Modern computing depends on collaboration, and it always will.</p><p>Instead of building systems that rely on institutional trust, we build systems that rely on mathematical verification. That doesn&#8217;t remove trust, it does reduce how much trust you need and rely on.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://jirif.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading PrivID's Substack! Subscribe for free to receive new posts.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The Procurement Questions Nobody Asked Five Years Ago]]></title><description><![CDATA[Cybersecurity procurement followed a checklist.]]></description><link>https://jirif.substack.com/p/the-procurement-questions-nobody</link><guid isPermaLink="false">https://jirif.substack.com/p/the-procurement-questions-nobody</guid><dc:creator><![CDATA[Jiri Fiala]]></dc:creator><pubDate>Mon, 03 Aug 2026 13:25:02 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!qoD2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b3601ab-c2e4-46d0-8148-3109cd882cad_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Cybersecurity procurement followed a  checklist.</p><ul><li><p>Is it secure? </p></li><li><p>Is it compliant? </p></li><li><p>Does it integrate with our existing systems? </p></li><li><p>How much does it cost?</p></li></ul><p>The problem is that those questions were for a cybersecurity system from 30 years ago. Today&#8217;s organisations need different questions, and different baselines.</p><ul><li><p>Who controls the updates? </p></li><li><p>Who controls the encryption? </p></li><li><p>Who controls the identity system? </p></li><li><p>Who controls the firmware? </p></li><li><p>Who controls the AI?</p></li></ul><p>Notice that these questions are about control, not the technology per se.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!qoD2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b3601ab-c2e4-46d0-8148-3109cd882cad_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!qoD2!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b3601ab-c2e4-46d0-8148-3109cd882cad_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!qoD2!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b3601ab-c2e4-46d0-8148-3109cd882cad_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!qoD2!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b3601ab-c2e4-46d0-8148-3109cd882cad_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!qoD2!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b3601ab-c2e4-46d0-8148-3109cd882cad_1536x1024.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!qoD2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b3601ab-c2e4-46d0-8148-3109cd882cad_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8b3601ab-c2e4-46d0-8148-3109cd882cad_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2133156,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://jirif.substack.com/i/209186877?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b3601ab-c2e4-46d0-8148-3109cd882cad_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!qoD2!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b3601ab-c2e4-46d0-8148-3109cd882cad_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!qoD2!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b3601ab-c2e4-46d0-8148-3109cd882cad_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!qoD2!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b3601ab-c2e4-46d0-8148-3109cd882cad_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!qoD2!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b3601ab-c2e4-46d0-8148-3109cd882cad_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>For decades, it&#8217;s been assumed that if a product met the security standards, everything else would take care of itself. The software could be hosted anywhere, updated by anyone, and managed from almost any jurisdiction. Security was a property of the product not the ecosystem surrounding it.</p><p>Recent events have exposed a reality that was always there but rarely, if ever, discussed: software doesn&#8217;t exist in isolation. Every application depends on update mechanisms, cloud infrastructure, certificate authorities, identity providers, hardware supply chains, and the legal jurisdictions governing them.</p><p>Every one of those assumptions is a decision that someone else can make on your behalf. Outsourcing your decisions, especially around security, is never a good idea.</p><p>The point is that procurement isn&#8217;t about asking <em>whether</em> a vendor can be trusted. It&#8217;s about <em>how much</em> an organisation should depend on that trust.</p><p>Security has traditionally focused on preventing unauthorised access. Sovereignty focuses on maintaining authorised control. An organisation can have excellent cybersecurity and be dependent on external decisions for updates, identity services, or cloud infrastructure. The technical controls may be excellent, but the operational control sits elsewhere. That&#8217;s a board-level issue not an IT issue.</p><p>This means that procurement is evolving from <strong>evaluating products to evaluating dependencies.</strong></p><ul><li><p>Who owns the intellectual property? </p></li><li><p>Who controls the update pipeline? </p></li><li><p>Can encryption keys remain under the organisation&#8217;s exclusive control? </p></li><li><p>Can the platform continue operating if a supplier changes its commercial strategy, becomes subject to sanctions, or simply decides to discontinue a service?</p></li></ul><p>Five years ago those questions would most likely not have been asked. Today, they&#8217;re becoming central to the issues being faced.</p><p>This a fundamental change in how organisations see technology, not just a geopolitical issue. Security is essential. Compliance is essential. Performance absolutely matters. But procurement is recognising that technology decisions are governance decisions. Software is only part of the purchase. The dependencies come with it.</p><p>I suspect we&#8217;ll start to see procurement departments place as much emphasis on operational independence as they do on traditional security certifications. Because security doesn&#8217;t really answer: <em><strong>Who is in control when circumstances change?</strong></em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://jirif.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading PrivID's Substack! Subscribe for free to receive new posts. We will never paywall.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Useful Computation Without Routine Exposure]]></title><description><![CDATA[This week, we&#8217;ve looked at four ideas that are usually discussed separately.]]></description><link>https://jirif.substack.com/p/useful-computation-without-routine</link><guid isPermaLink="false">https://jirif.substack.com/p/useful-computation-without-routine</guid><dc:creator><![CDATA[Jiri Fiala]]></dc:creator><pubDate>Fri, 31 Jul 2026 14:05:51 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Ajg_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecaca7a9-52bc-4559-8c58-77c10fefc704_1635x962.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>This week, we&#8217;ve looked at <em>four ideas that are usually discussed separately</em>.</p><ol><li><p><strong>FHE</strong>, allows computation over encrypted data.</p></li><li><p><strong>ZKPs</strong>, allow claims to be verified without exposing the information behind them.</p></li><li><p><strong>Architecture</strong> determines where those technologies belong, what they&#8217;re allowed to do and which trust assumptions they remove.</p></li><li><p><strong>Hardware acceleration</strong> determines whether the resulting system can operate quickly and efficiently to be useful.</p></li></ol><p>The future of privacy-preserving computation will be built by understanding how the pieces fit together, and by refusing to confuse speed, encryption or proof with security. The objective isn&#8217;t just stronger encryption. It&#8217;s useful computation without exposure.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!Ajg_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecaca7a9-52bc-4559-8c58-77c10fefc704_1635x962.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!Ajg_!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecaca7a9-52bc-4559-8c58-77c10fefc704_1635x962.png 424w, /__u/substackcdn.com/image/fetch/$s_!Ajg_!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecaca7a9-52bc-4559-8c58-77c10fefc704_1635x962.png 848w, /__u/substackcdn.com/image/fetch/$s_!Ajg_!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecaca7a9-52bc-4559-8c58-77c10fefc704_1635x962.png 1272w, /__u/substackcdn.com/image/fetch/$s_!Ajg_!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecaca7a9-52bc-4559-8c58-77c10fefc704_1635x962.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!Ajg_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecaca7a9-52bc-4559-8c58-77c10fefc704_1635x962.png" width="1456" height="857" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ecaca7a9-52bc-4559-8c58-77c10fefc704_1635x962.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:857,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2058490,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://jirif.substack.com/i/209142809?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecaca7a9-52bc-4559-8c58-77c10fefc704_1635x962.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!Ajg_!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecaca7a9-52bc-4559-8c58-77c10fefc704_1635x962.png 424w, /__u/substackcdn.com/image/fetch/$s_!Ajg_!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecaca7a9-52bc-4559-8c58-77c10fefc704_1635x962.png 848w, /__u/substackcdn.com/image/fetch/$s_!Ajg_!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecaca7a9-52bc-4559-8c58-77c10fefc704_1635x962.png 1272w, /__u/substackcdn.com/image/fetch/$s_!Ajg_!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecaca7a9-52bc-4559-8c58-77c10fefc704_1635x962.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>The Problem Was Never Storage</h2><p>Cybersecurity has focused heavily on protecting data at rest and in transit. And it does that extremely well. Encrypt the database. Encrypt the connection. Restrict access. Monitor the endpoint. Log the administrator. But they don&#8217;t solve the central problem. When the data needs to be used, it&#8217;s gets decrypted.</p><p>That plaintext can appear inside an application, memory, analytics platform, cloud environment, administrative interface, artificial-intelligence pipeline or third-party service. The data may be perfectly protected while stored and transmitted, but become fully visible during the operation that gives it value.</p><p>That&#8217;s the inherent contradiction: <em><strong>We protect data until the moment we need it.</strong></em></p><p>Then it gets exposed in the exact infrastructure we spend the rest of the security budget trying to trust. <strong>FHE</strong> challenges that model by allowing data to stay encrypted while computation takes place. <strong>ZKP</strong> challenges the assumption that verification means disclosure. They change where trust is needed.</p><h2>FHE Is a Family</h2><p><strong>CKKS</strong> is designed for approximate arithmetic over real or complex numbers. It&#8217;s particularly useful for packed numerical workloads such as analytics, signal processing and machine-learning inference.</p><p><strong>BFV</strong> and <strong>BGV</strong> are better suited to exact integer or modular arithmetic.</p><p><strong>TFHE</strong> is particularly strong for comparisons, lookup tables, programmable bootstrapping, policy decisions and exact logical or integer operations.</p><ul><li><p>If the system needs large-scale approximate numerical analysis, CKKS may be appropriate.</p></li><li><p>If it needs exact accounting or modular operations, BFV or BGV may fit better.</p></li><li><p>If it needs encrypted comparisons, branching or policy enforcement, TFHE may be the stronger choice.</p></li></ul><p>In many cases, the answer won&#8217;t be one scheme. It&#8217;ll be a hybrid architecture that uses several. The useful questions are:</p><ul><li><p>What kind of computation?</p></li><li><p>Over which data type?</p></li><li><p>With what precision?</p></li><li><p>At what depth?</p></li><li><p>For what batch size?</p></li><li><p>With which latency requirement?</p></li><li><p>And under whose control?</p></li></ul><h2>ZKP Changes What Verification Means</h2><p>ZKP solves different problems. It doesn&#8217;t generally compute over encrypted data in the same way as FHE. It proves that defined statements are true without disclosing the information used to establish it.</p><ul><li><p>That might mean proving that someone is over 18 without revealing their date of birth.</p></li><li><p>It might mean proving that a transaction falls within an approved limit without revealing the account balance.</p></li><li><p>It might mean proving that a credential is valid without handing a copy of it to every service that asks.</p></li><li><p>It might also mean proving that a computation followed an agreed process.</p></li></ul><p>The verifier receives the answer. It doesn&#8217;t automatically receive the evidence. Most digital identity and compliance systems are built around repeated disclosure. A person presents a document. An organisation copies it. A service retains it. Another system verifies it. A third party receives it for audit. Each point creates a copy and another breach target.</p><p>ZKP is a different model. The system can verify the claim without collecting the underlying record. That moves data minimisation to the protocol itself. But ZKP isn&#8217;t magic.</p><p>A proof establishes what the circuit or constraint system actually checks, not what was intended. A valid proof can still be based on unreliable inputs. A credential may be fraudulent, expired, compromised or issued through a weak identity process. A ZKP can prove that the specified rules were followed. It can&#8217;t fix bad rules, untrustworthy sources or careless governance.</p><h2>Privacy-Preserving Doesn&#8217;t Mean Privacy Guaranteed</h2><p>The use of ZKP in European digital identity and age verification makes this distinction clear. A person may be able to prove that they&#8217;re over a required age without disclosing their name, exact age or date of birth.</p><p>That&#8217;s better than uploading a passport, identity card or selfie to every platform demanding proof. But a privacy-preserving proof can still operate inside a broader architecture that raises serious questions.</p><ul><li><p>Who issues the credential?</p></li><li><p>Who controls the wallet?</p></li><li><p>What metadata is generated?</p></li><li><p>Can the proof be linked across services?</p></li><li><p>Which websites are permitted to demand it?</p></li><li><p>What happens when a mechanism created for clearly age-restricted content expands into more general online access?</p></li></ul><p>ZKP can reduce the information disclosed when a question is asked. It can&#8217;t decide if the question should be asked. That&#8217;s a governance decision. The technology can minimise disclosure. It can&#8217;t guarantee institutional restraint.</p><p>This is why privacy can&#8217;t be assessed by looking at things in isolation. A secure proof doesn&#8217;t create a private system. A secure computation doesn&#8217;t create a trustworthy application.</p><h2>Architecture Is Where the Security Actually Lives</h2><p>FHE and ZKP are powerful because they make different architectures possible. They allow a system to move away from broad access and towards constrained authority.</p><ul><li><p>A bank may be allowed to determine whether a lending threshold is satisfied without exposing the applicant&#8217;s complete financial history. As ING does.</p></li><li><p>A medical service may be allowed to evaluate an eligibility condition without receiving the full clinical record.</p></li><li><p>A cloud platform may be allowed to perform an encrypted computation without accessing the data or the final plaintext result.</p></li><li><p>A verifier may be allowed to confirm a claim without storing the evidence behind it.</p></li></ul><p>Each component learns only what it needs to perform its role. That means fewer plaintext copies, less unnecessary retention, smaller breach consequences, reduced insider access, less cross-service correlation and fewer assumptions about who or what can be trusted.</p><h2>Hardware Makes It Practical</h2><p>FHE and ZKP involve large ciphertexts, polynomial operations, transforms, key switching, memory movement, constraint systems, commitments, hashing, proof generation and, in some schemes, repeated bootstrapping.</p><p>General-purpose processors can perform these operations. They just may not perform them quickly or efficiently enough.</p><p>Hardware acceleration matters. GPUs can provide massive parallelism. FPGAs can implement specialised pipelines while remaining reprogrammable. ASICs can deliver exceptional performance and energy efficiency for stable, well-defined operations. CPUs remain essential for orchestration, flexible control flow and software fallback. The future will use all of them. But mistaking one impressive component for the complete system, is dangerous.</p><h2>Performance Must Be Measured Honestly</h2><p>The relevant measurement isn&#8217;t always the fastest individual kernel. It also includes host-to-device transfers, memory bandwidth, key movement, ciphertext layout, proof-generation overhead, batching delays, sustained operation, cooling and power, failure recovery, multi-tenant isolation and software integration.</p><p>Throughput and latency also need to be separated. One million operations per second may be excellent for bulk analytics and irrelevant for a person waiting on a login screen. A two-second proof may be unacceptable for one transaction and entirely reasonable if it can be verified millions of times.</p><p>There&#8217;s no meaningful performance number without a workload. And there&#8217;s no meaningful workload without an architecture.</p><h2>The Trust Boundary Hasn&#8217;t Disappeared</h2><p>Systems still depend on software integrity, key management, credential issuance, circuit correctness, parameter selection, hardware reliability, metadata protection and operational governance.</p><p>Evaluation keys may be intentionally available to the computing party while secret decryption keys are protected. Verification keys may be public while private witnesses are confidential. A cloud accelerator may never see plaintext but still control availability, execution, isolation, firmware and updates. A hardware provider may not hold the data but may control the runtime on which the system depends.</p><p>A system that removes reliance on one cloud provider but creates absolute dependence on a proprietary accelerator hasn&#8217;t necessarily achieved sovereignty. A system that keeps data encrypted but depends on foreign-controlled firmware, updates and infrastructure can still carry significant geopolitical and operational risk.</p><h2>Sovereignty Is Architectural Too</h2><p>This question is especially important in Europe, Canada and other jurisdictions trying to retain control over critical digital infrastructure. Data sovereignty isn&#8217;t only about where a database is located.</p><p>It includes control over keys, software, hardware, firmware, updates, identity systems, the legal environment and the ability to continue operating when an external supplier withdraws support. A server physically located in Europe may still depend on a foreign cloud control plane. An accelerator deployed locally may still require firmware controlled abroad. A privacy-preserving service may still rely on a mobile operating system, app store or identity issuer operating under another jurisdiction.</p><p>Sovereignty is the ability to operate, govern and adapt the system without asking another party for permission. Privacy-preserving architecture can support that objective. But, it doesn&#8217;t guarantee it.</p><h2>Hybrid Systems Will Become Normal</h2><p>The strongest systems won&#8217;t insist on one universal answer. They&#8217;ll combine technologies according to the workload:</p><ul><li><p>CKKS may handle packed numerical analysis.</p></li><li><p>BFV or BGV may handle exact integer operations.</p></li><li><p>TFHE may handle comparisons and policy logic.</p></li><li><p>ZKP may validate credentials, inputs, outputs or correct execution.</p></li><li><p>CPUs may coordinate the workflow.</p></li><li><p>GPUs may accelerate large parallel operations.</p></li><li><p>FPGAs may reduce the latency of specific bootstrapping or transformation stages.</p></li><li><p>Specialised hardware may support proof generation.</p></li></ul><p>The mistake isn&#8217;t in the technologies or how they are combined, or not. The mistake is allowing the transitions between them to recreate the plaintext exposure, metadata leakage and broad trust the system was meant to remove.</p><ul><li><p>Every boundary matters.</p></li><li><p>Every transfer matters.</p></li><li><p>Every output matters.</p></li></ul><p>The system is only privacy-preserving if the complete path is privacy-preserving.</p><h2>Real Change</h2><p>Conventional security begins with access.</p><ul><li><p>Who may enter?</p></li><li><p>Who may read?</p></li><li><p>Who may administer?</p></li><li><p>Who may retrieve the record?</p></li></ul><p>The modern security systems will ask:</p><ul><li><p>What does this component actually need to know?</p></li><li><p>What computation is it authorised to perform?</p></li><li><p>What claim must be verified?</p></li><li><p>Which information can remain encrypted?</p></li><li><p>Which evidence never needs to be disclosed?</p></li><li><p>What output is safe to release?</p></li><li><p>Can repeated queries reveal more than one query would?</p></li><li><p>Who controls the keys, proofs, hardware and software?</p></li><li><p>Which trust assumptions can be removed?</p></li><li><p>Which ones can&#8217;t?</p></li></ul><h2>Useful Computation Without Routine Exposure</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!_Buh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecee603c-ce1b-4620-9f2b-1ea3624f88c7_1561x1008.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!_Buh!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecee603c-ce1b-4620-9f2b-1ea3624f88c7_1561x1008.png 424w, /__u/substackcdn.com/image/fetch/$s_!_Buh!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecee603c-ce1b-4620-9f2b-1ea3624f88c7_1561x1008.png 848w, /__u/substackcdn.com/image/fetch/$s_!_Buh!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecee603c-ce1b-4620-9f2b-1ea3624f88c7_1561x1008.png 1272w, /__u/substackcdn.com/image/fetch/$s_!_Buh!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecee603c-ce1b-4620-9f2b-1ea3624f88c7_1561x1008.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!_Buh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecee603c-ce1b-4620-9f2b-1ea3624f88c7_1561x1008.png" width="1456" height="940" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ecee603c-ce1b-4620-9f2b-1ea3624f88c7_1561x1008.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:940,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2108051,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://jirif.substack.com/i/209142809?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecee603c-ce1b-4620-9f2b-1ea3624f88c7_1561x1008.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!_Buh!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecee603c-ce1b-4620-9f2b-1ea3624f88c7_1561x1008.png 424w, /__u/substackcdn.com/image/fetch/$s_!_Buh!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecee603c-ce1b-4620-9f2b-1ea3624f88c7_1561x1008.png 848w, /__u/substackcdn.com/image/fetch/$s_!_Buh!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecee603c-ce1b-4620-9f2b-1ea3624f88c7_1561x1008.png 1272w, /__u/substackcdn.com/image/fetch/$s_!_Buh!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecee603c-ce1b-4620-9f2b-1ea3624f88c7_1561x1008.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The challenge isn&#8217;t that FHE, ZKPs, privacy-preserving architecture and hardware acceleration are inherently impractical. The real challenge is understanding what each technology does, where it belongs, and how the pieces work together.</p><p>Forty years ago, organisations were only beginning to work out how to secure digital data. Encryption, access control, identity management and network security often sounded complex. Over time, the principles became understood, the tools improved, and secure data handling became part of ordinary system design.</p><p>Privacy-preserving computation is the next stage of that evolution.</p><p>FHE allows data to remain encrypted while it&#8217;s being used. ZKPs allow claims to be verified without routinely exposing the evidence. Architecture determines what each system is allowed to know and do. Hardware acceleration makes those choices practical at scale. None of this removes the need for judgement.</p><p>The question isn&#8217;t just who can access the data. It&#8217;s what computation should be allowed, what claim needs to be proven, what output is safe to reveal, and which components actually need knowledge of the underlying information.</p><p>That may sound difficult today, but the difficulty isn&#8217;t a failure of the technology. It&#8217;s the normal learning curve that comes with a new architectural model.</p><p>The maths exist. The hardware is catching up. The real work is to understand the technologies well enough to use them properly. That means knowing which scheme fits the workload, where proof is required, where plaintext can be removed, and how the architecture should be structured before acceleration is added.</p><p>This is precisely the problem PrivID was built to address.</p><p>Not by forcing one technology into every system, but by understanding how FHE, ZKP, identity, architecture and hardware need to work together.</p><p>It&#8217;s time to evolve from protecting data only while it&#8217;s stored or moving to protecting it while it&#8217;s being used, and stop treating routine exposure as an unavoidable.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://jirif.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading PrivID's Substack! Subscribe for free to receive new posts. We will never paywall.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Hardware Acceleration Is Not Architecture]]></title><description><![CDATA[So far this week, we&#8217;ve looked at the different forms of FHE, how ZKPs, reduce disclosure, and why both need systems to be designed differently.]]></description><link>https://jirif.substack.com/p/hardware-acceleration-is-not-architecture</link><guid isPermaLink="false">https://jirif.substack.com/p/hardware-acceleration-is-not-architecture</guid><dc:creator><![CDATA[Jiri Fiala]]></dc:creator><pubDate>Thu, 30 Jul 2026 16:43:14 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!O7jw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca5e2e50-9c37-447d-94b2-33d707db9d0f_1672x941.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>So far this week, we&#8217;ve looked at the different forms of FHE, how ZKPs, reduce disclosure, and why both need systems to be designed differently. Translation: they are computationally expensive.</p><blockquote><p><em><strong>CAVEAT</strong>: I&#8217;m not a maths person, by any stretch, this is based on my research and information gathered along with it from speaking to others. If there are errors in this article please let me know.</em></p></blockquote><p><strong>FHE</strong> uses larger ciphertexts, more complex maths, noise management, key switching and, in some schemes, repeated bootstrapping. <strong>ZKP</strong> can need large constraint systems, substantial memory, parallel processing and considerable proof-generation time. The question that needs to be answered in both cases is whether they are fast enough, cheapenough and reliabe enough for real systems.</p><p>That&#8217;s where hardware acceleration comes in.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!O7jw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca5e2e50-9c37-447d-94b2-33d707db9d0f_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!O7jw!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca5e2e50-9c37-447d-94b2-33d707db9d0f_1672x941.png 424w, /__u/substackcdn.com/image/fetch/$s_!O7jw!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca5e2e50-9c37-447d-94b2-33d707db9d0f_1672x941.png 848w, /__u/substackcdn.com/image/fetch/$s_!O7jw!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca5e2e50-9c37-447d-94b2-33d707db9d0f_1672x941.png 1272w, /__u/substackcdn.com/image/fetch/$s_!O7jw!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca5e2e50-9c37-447d-94b2-33d707db9d0f_1672x941.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!O7jw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca5e2e50-9c37-447d-94b2-33d707db9d0f_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ca5e2e50-9c37-447d-94b2-33d707db9d0f_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2185606,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://jirif.substack.com/i/209096300?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca5e2e50-9c37-447d-94b2-33d707db9d0f_1672x941.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!O7jw!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca5e2e50-9c37-447d-94b2-33d707db9d0f_1672x941.png 424w, /__u/substackcdn.com/image/fetch/$s_!O7jw!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca5e2e50-9c37-447d-94b2-33d707db9d0f_1672x941.png 848w, /__u/substackcdn.com/image/fetch/$s_!O7jw!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca5e2e50-9c37-447d-94b2-33d707db9d0f_1672x941.png 1272w, /__u/substackcdn.com/image/fetch/$s_!O7jw!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca5e2e50-9c37-447d-94b2-33d707db9d0f_1672x941.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Once a company has built a faster processor, accelerator or software backend, the conversation becomes about benchmarks: operations per second, dramatic reductions in latency, orders-of-magnitude improvements, lower power consumption, faster proof generation or faster bootstrapping - yadda yadda yadda. </p><h2>Why Encrypted Compute Is So Expensive</h2><p>Ordinary processors are designed around plaintext. They&#8217;re efficient because the underlying values are directly available. Comparisons are cheap, arithmetic is straightforward, and branching is built into the execution model.</p><p>With FHE things are different. It works with ciphertext structures containing mathematical representations of encrypted information, and they could be much bigger than the original data.</p><p>Trivial operations in plaintext can require polynomial arithmetic, modular reduction, Number Theoretic Transforms, Fourier transforms, key switching, ciphertext rotations, modulus switching, rescaling, noise management and bootstrapping. The exact workload depends on the scheme.</p><p><em>CKKS, BFV, BGV and TFHE don&#8217;t impose the same computational demands. Neither do different ZKP systems.</em></p><p>There&#8217;s no single operation called &#8220;encrypted computing&#8221; that hardware can accelerate universally. There are families of workloads with different mathematical shapes, memory patterns and performance requirements.</p><h2>CKKS, BFV and BGV Share Some Machinery</h2><p>CKKS, BFV and BGV are built around polynomial arithmetic over lattice-based structures. Their workloads depend heavily on polynomial multiplication, modular arithmetic, residue-number representations, Number Theoretic Transforms, ciphertext rotations and key switching.</p><p>A processor designed to accelerate polynomial multiplication or Number Theoretic Transforms may benefit all three schemes. But shared mathematical primitives doesn&#8217;t mean they&#8217;re the same.</p><p><strong>CKKS</strong> performs <em>approximate arithmetic </em>and needs careful management of scale and precision. <strong>BFV</strong> and <strong>BGV</strong> are generally used for <em>exact integer or modular arithmetic</em>. The depth of the computation, parameter selection, ciphertext modulus and bootstrapping requirements will differ.</p><p>The same accelerator may support several schemes while performing very differently across each one. That&#8217;s why saying hardware &#8220;supports FHE&#8221; isn&#8217;t the entire picture.</p><ul><li><p>Which scheme?</p></li><li><p>Which parameters?</p></li><li><p>Which operations?</p></li><li><p>At what depth?</p></li><li><p>For what batch size?</p></li></ul><h2>TFHE Is a Different Workload</h2><p><strong>TFHE</strong> puts greater emphasis on programmable bootstrapping, comparisons, lookup tables and exact logical or integer operations.</p><p>Programmable Bootstrapping, or <strong>PBS, is one of TFHE&#8217;s most useful features</strong>. It can refresh a ciphertext while evaluating a defined function, making TFHE effective for comparisons, threshold checks, policy decisions, conditional logic, non-linear operations, encrypted lookup tables and exact decision-oriented workloads. </p><p>But PBS is expensive. It can involve large evaluation keys, substantial memory movement, Fourier transforms and repeated processing across many encrypted operations. That creates a very different acceleration problem from large, packed CKKS workloads.</p><p><strong>CKKS</strong> benefits strongly from processing many packed values in parallel. <strong>TFHE</strong> is frequently considered for <em>transactional or decision-oriented workloads</em> where the cost and latency of repeated programmable bootstrapping become central.</p><p>That doesn&#8217;t mean TFHE is limited to small or irregular workloads. Modern implementations can batch and parallelise programmable bootstrapping extensively, particularly across GPUs and specialised hardware.</p><p>CKKS often favours packed throughput. While TFHE places greater emphasis on the cost, repetition and latency of programmable bootstrapping.</p><p>Real systems may need both. That&#8217;s where benchmarks become slippery. A machine can perform extremely well when processing large batches under ideal laboratory conditions and still perform poorly in a transactional system handling individual requests.</p><h2>ZKP Has Its Own Problems</h2><p>Proof generation may involve polynomial commitments, multiscalar multiplication, fast Fourier transforms, finite-field arithmetic, hashing, Merkle-tree construction, constraint evaluation and large amounts of memory movement. The exact workload depends heavily on the proof system.</p><p>A <strong>SNARK</strong> doesn&#8217;t necessarily impose the same demands as a <strong>STARK</strong>. Different proving systems may prioritise different curves, fields, hashes, commitment schemes and recursion models. Some proofs may be generated on a mobile device. Others may need a server, GPU cluster or dedicated accelerator. Verification is cheap, proving is expensive.</p><p>If proof generation takes seconds, consumes gigabytes of memory or drains a mobile battery, it may be unsuitable for a user-facing identity transaction. If the same proof can be created once and verified millions of times, that cost is acceptable.</p><h2>CPUs, GPUs, FPGAs and ASICs</h2><p>There&#8217;s no single correct hardware platform for encrypted computation. Each approach brings different strengths and compromises.</p><h3>CPUs</h3><p>CPUs are flexible and widely available. They&#8217;re useful for development, testing, low-volume workloads, orchestration, irregular control flow and systems where deployment simplicity matters more than maximum performance.</p><p>General-purpose flexibility has a price. CPUs may be inefficient for the repetitive, highly parallel arithmetic common in FHE and ZKP workloads.</p><h3>GPUs</h3><p>GPUs offer massive parallelism. They can be effective for polynomial arithmetic, multiscalar multiplication, Fourier transforms, Number Theoretic Transforms, proof generation and large batched workloads.</p><p>But GPU performance depends on feeding the hardware enough parallel work. Small batches may underutilise the device, while memory transfers between the host and accelerator can introduce latency. Power consumption and cooling are significant factors under sustained load. (A great example are cryptocurrency miners. They run hot and require a great deal of cooling power)</p><h3>FPGAs</h3><p><strong>Field-Programmable Gate Arrays, or FPGAs</strong>, offer a middle ground. They can implement specialised data paths AND be reprogrammable, making them useful where schemes, parameters and libraries are still evolving.</p><p>An FPGA can be optimised for bootstrapping, modular multiplication, polynomial transforms, key switching and specific proof-generation stages. The trade-off? Development complexity.</p><p>Hardware design, firmware, memory architecture, timing and software integration all need specialised expertise. A theoretically efficient FPGA implementation may still fail commercially if the software layer is awkward or the deployment model is too difficult.</p><h3>ASICs</h3><p><strong>Application-Specific Integrated Circuits, or ASICs</strong>, can offer exceptional performance and efficiency because they&#8217;re designed around a specific workload.</p><p>Cryptographic systems evolve. Parameters change. Security assumptions are revised. Libraries introduce new representations. Those can all become problematic forf ASICs.</p><p>A chip optimised around one narrow implementation may become less useful if the software ecosystem shifts. Stable primitives such as modular arithmetic, transforms and key switching can be useful across multiple schemes and implementations. The risk depends on how narrowly the hardware has been designed.</p><p>ASIC development is also expensive and slow. By the time the chip reaches production, parts of the workload it was designed around may already have changed. This means they need a high degree of confidence that the target operations will still be important.</p><h2>Memory Is the Real Bottleneck</h2><p>Discussions about acceleration usually focus on computation, but, memory movement may be just as important. Encrypted data structures are large. Bootstrapping keys can consume a lot of memory. Proof generation may need large intermediate values. If the accelerator spends most of its time waiting for data to move between memory, processors and storage, faster arithmetic units won&#8217;t solve the problem.</p><p>The system has to consider memory bandwidth, local accelerator memory, cache behaviour, key storage, host-to-device transfer, ciphertext layout, batching strategy and data locality.</p><p>A processor may complete one mathematical operation extremely quickly. But if the data has to travel across a slow bus before and after every operation, the application will still feel slow.</p><h2>Batch Size Is The Key</h2><p>CKKS can pack many values into one ciphertext and process them together. TFHE and ZKP proving can also benefit from parallelism, aggregation and batched execution. That can produce impressive throughput numbers. But throughput and latency aren&#8217;t the same thing.</p><p>Suppose an accelerator processes one million encrypted values efficiently when they&#8217;re submitted together. That may be ideal for overnight analytics, scientific modelling, large portfolio calculations, aggregate machine-learning inference or bulk compliance processing. It may not be ideal for one login request, one payment decision, one medical eligibility check, one age-verification proof or one access-control decision.</p><p>A user doesn&#8217;t care how many requests the system could process in an hour if their individual request takes ten seconds. Conversely, a low-latency accelerator may be excellent for individual decisions but inefficient for large analytical workloads.</p><h2>Sustained Performance Matters</h2><p>A short benchmark proves that the hardware can perform an operation. It doesn&#8217;t prove that the system can operate reliably. Real deployments mean sustained performance.</p><ul><li><p>What happens after hours of continuous use? </p></li><li><p>Does the device throttle? How much cooling is required? </p></li><li><p>Does power consumption remain stable? </p></li><li><p>Are memory errors detected? </p></li><li><p>How are failed computations handled? </p></li><li><p>Can workloads be resumed? </p></li><li><p>Does performance degrade as keys or parameters increase? </p></li><li><p>What happens when multiple tenants share the device? </p></li><li><p>How is cryptographic material isolated?</p></li></ul><p>These questions are both security and operational. A failure during ordinary computation is inconvenient. A failure during encrypted computation could produce invalid results, corrupted ciphertexts or unavailable services. If the accelerator becomes a central dependency, it also becomes a central point of failure. Acceleration has to improve the system not create a new concentration of risk.</p><h2>Key Control Is Not An Afterthought</h2><p>FHE systems can require evaluation keys, bootstrapping keys, switching keys and other cryptographic material. ZKP systems may depend on proving keys, verification keys, setup parameters or private witness data.</p><p>Evaluation, server, switching and bootstrapping keys are commonly intended to be available to the party performing the encrypted computation. They aren&#8217;t normally secret in the same way as the decryption key.</p><p>Making an evaluation key available doesn&#8217;t usually allow the evaluator to decrypt the underlying data. But those keys still need governance because possession may permit computation, resource consumption, service misuse or operational disruption. They may also reveal metadata, parameter choices or implementation details.</p><p>ZKP material varies as well. Verification keys can be public. Proving keys can be large not necessarily confidential. The witness, however, is private input and must be protected accordingly.</p><p>The architecture has to define where these materials are generated, where they&#8217;re stored, which hardware can access them, whether an operator can copy or misuse them, how they&#8217;re versioned, how compromised material is revoked and whether the secret keys and private witnesses remain under the control of the data owner.</p><p>This is important especially when acceleration is delivered through cloud infrastructure. In which case the user is relying on the provider for availability, correct execution, workload isolation, handling of cryptographic material and protection.</p><h2>Sovereignty Is Part of the Hardware Question</h2><p>Who designs the accelerator? Where is it manufactured? Who controls the firmware? Who maintains the compiler and runtime? Where are updates distributed from? Can the platform continue operating if a foreign supplier withdraws support? <em><strong>Does the hardware depend on a cloud environment controlled by another jurisdiction</strong>? <strong>Could access be restricted during a political or commercial dispute</strong>?</em></p><p>These questions are crucial for critical infrastructure, government systems, finance, healthcare and defence.</p><p>A system designed to reduce reliance on cloud providers may simply move that reliance into proprietary acceleration hardware. A system designed for data sovereignty may still depend on firmware, drivers or updates controlled elsewhere.</p><ul><li><p>Technical control isn&#8217;t the same as legal control.</p></li><li><p>Legal control isn&#8217;t the same as operational independence.</p></li><li><p>A genuinely sovereign architecture has to consider all three.</p></li></ul><h2>Software Integration Determines If Hardware Is Useful</h2><p>Hardware doesn&#8217;t operate in isolation. Developers need libraries, compilers, runtimes, APIs, monitoring tools and debugging support. An accelerator may be extremely fast but commercially irrelevant if using it requires rewriting the entire application. The software layer has to answer practical questions:</p><ul><li><p>Can existing FHE libraries use the accelerator? </p></li><li><p>Does it support standard APIs? </p></li><li><p>Which operations are offloaded? </p></li><li><p>Which remain on the CPU? </p></li><li><p>Can the application fall back to software? </p></li><li><p>How are errors reported? Can performance be measured in production? </p></li><li><p>Are parameter choices exposed to developers? </p></li><li><p>Does the implementation preserve constant-time or side-channel protections? How difficult is deployment?</p></li></ul><p>The best hardware implementation may not win. But the implementation developers can actually integrate will.</p><h2>Hardware and Software Need Each Other</h2><p>Software implementations matter because they provide flexibility. They allow schemes to evolve. They let researchers test new parameters, algorithms and hybrid workflows. They can be updated without replacing physical hardware.</p><p>Hardware matters because software alone may not achieve the latency, throughput or power efficiency required for deployment. A good accelerator shouldn&#8217;t try to replace the cryptographic library. It should expose capabilities the library can use intelligently.</p><p>The software should decide which operations to offload, when batching is worthwhile, when latency matters more than throughput, which scheme fits the workload, whether a CPU, GPU or FPGA is appropriate and when a software fallback is safer.</p><h2>Hybrid Acceleration Will Be Normal</h2><p>A system may use CPUs for orchestration, GPUs for large CKKS batches, FPGAs for low-latency TFHE bootstrapping, specialised hardware for ZKP proving, local devices for credential proofs and cloud infrastructure for large analytical workloads.</p><p>Different workloads need different execution environments. The challenge is ensuring that movement between them doesn&#8217;t reintroduce plaintext exposure, leak metadata or create uncontrolled trust boundaries. Each transfer has to be considered part of the architecture.</p><p>Where does the ciphertext move? Where is the witness generated? Where is the proof created? Where is the result decrypted? Who controls each component? What can each component infer?</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!C90y!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f7a4b8d-78ec-49cb-be78-1adb7ac78fab_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!C90y!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f7a4b8d-78ec-49cb-be78-1adb7ac78fab_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!C90y!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f7a4b8d-78ec-49cb-be78-1adb7ac78fab_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!C90y!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f7a4b8d-78ec-49cb-be78-1adb7ac78fab_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!C90y!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f7a4b8d-78ec-49cb-be78-1adb7ac78fab_1536x1024.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!C90y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f7a4b8d-78ec-49cb-be78-1adb7ac78fab_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5f7a4b8d-78ec-49cb-be78-1adb7ac78fab_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2120974,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://jirif.substack.com/i/209096300?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f7a4b8d-78ec-49cb-be78-1adb7ac78fab_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!C90y!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f7a4b8d-78ec-49cb-be78-1adb7ac78fab_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!C90y!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f7a4b8d-78ec-49cb-be78-1adb7ac78fab_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!C90y!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f7a4b8d-78ec-49cb-be78-1adb7ac78fab_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!C90y!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f7a4b8d-78ec-49cb-be78-1adb7ac78fab_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em><strong>An Infographic to Illustrate the system.</strong></em></p><h2>Faster Doesn&#8217;t Mean Safer</h2><p>A faster implementation may still use insecure parameters, leak through timing or memory access, mishandle keys, rely on undocumented assumptions, fail under sustained load, expose metadata, generate incorrect results or accelerate only a narrow demonstration.</p><p>The fastest system isn&#8217;t automatically the safest. Neither is the slowest system automatically more rigorous. Performance, correctness and security have to be evaluated separately.</p><h2>Architecture Must Define the Accelerator</h2><p>What workload are we accelerating? Which FHE or ZKP system is involved? Which operation dominates the cost? Is the workload batched or transactional? What latency is acceptable? What throughput is required? Which keys or witnesses must be protected? Where will the hardware operate? Who controls the firmware and runtime? What happens if the accelerator is unavailable? Can the system fall back safely? Does the hardware reduce trust or merely relocate it?</p><p>These questions need to be answered before the choice of hardware become meaningful.</p><h2>Acceleration Makes the Architecture Practical</h2><p>Without hardware acceleratoin many FHE and ZKP workloads will be too slow, too expensive or too energy-intensive for broad deployment. But:</p><ul><li><p>Hardware doesn&#8217;t decide what should be encrypted.</p></li><li><p>It doesn&#8217;t decide what should be proven.</p></li><li><p>It doesn&#8217;t decide which parties should be trusted.</p></li><li><p>It doesn&#8217;t decide whether a result reveals too much.</p></li><li><p>It doesn&#8217;t decide whether a system should exist.</p></li><li><p>It makes an already well-designed process faster.</p></li></ul><div><hr></div><p>Tomorrow, we&#8217;ll bring the pieces together:</p><ul><li><p>FHE changes how data can be used.</p></li><li><p>ZKP changes how claims can be verified.</p></li><li><p>Architecture determines how those technologies fit.</p></li><li><p>Hardware determines whether the resulting system can operate at scale.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://jirif.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading PrivID's Substack! Subscribe for free to receive new posts. We will never paywall.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div></li></ul>]]></content:encoded></item><item><title><![CDATA[Encryption Is Architecture, Not A Feature.]]></title><description><![CDATA[In the first article, we looked at FHE, and why CKKS, BFV, BGV and TFHE support different kinds of encrypted computations.]]></description><link>https://jirif.substack.com/p/encryption-is-architecture-not-a</link><guid isPermaLink="false">https://jirif.substack.com/p/encryption-is-architecture-not-a</guid><dc:creator><![CDATA[Jiri Fiala]]></dc:creator><pubDate>Wed, 29 Jul 2026 14:01:23 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!wtPQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe307ceb8-de0b-42d3-b52c-f8e6ebf4b7dd_1624x969.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In the first article, we looked at <strong>FHE, and why CKKS, BFV, BGV and TFHE</strong> support different kinds of encrypted computations.</p><p>In the second, we looked at <strong>ZKPs</strong>, and how they can prove that a statement or computation is true without exposing the information behind it.</p><p>Neither technology works properly if it&#8217;s &#8216;added&#8217; to an existing system, like an afterthought. They need a different way of designing software.</p><p>That is where many organisations will struggle. Not because the mathematics is impossible, but because the architecture they have was built around assumptions these technologies remove.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!wtPQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe307ceb8-de0b-42d3-b52c-f8e6ebf4b7dd_1624x969.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!wtPQ!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe307ceb8-de0b-42d3-b52c-f8e6ebf4b7dd_1624x969.png 424w, /__u/substackcdn.com/image/fetch/$s_!wtPQ!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe307ceb8-de0b-42d3-b52c-f8e6ebf4b7dd_1624x969.png 848w, /__u/substackcdn.com/image/fetch/$s_!wtPQ!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe307ceb8-de0b-42d3-b52c-f8e6ebf4b7dd_1624x969.png 1272w, /__u/substackcdn.com/image/fetch/$s_!wtPQ!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe307ceb8-de0b-42d3-b52c-f8e6ebf4b7dd_1624x969.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!wtPQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe307ceb8-de0b-42d3-b52c-f8e6ebf4b7dd_1624x969.png" width="1456" height="869" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e307ceb8-de0b-42d3-b52c-f8e6ebf4b7dd_1624x969.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:869,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2025031,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://jirif.substack.com/i/208880360?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe307ceb8-de0b-42d3-b52c-f8e6ebf4b7dd_1624x969.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!wtPQ!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe307ceb8-de0b-42d3-b52c-f8e6ebf4b7dd_1624x969.png 424w, /__u/substackcdn.com/image/fetch/$s_!wtPQ!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe307ceb8-de0b-42d3-b52c-f8e6ebf4b7dd_1624x969.png 848w, /__u/substackcdn.com/image/fetch/$s_!wtPQ!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe307ceb8-de0b-42d3-b52c-f8e6ebf4b7dd_1624x969.png 1272w, /__u/substackcdn.com/image/fetch/$s_!wtPQ!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe307ceb8-de0b-42d3-b52c-f8e6ebf4b7dd_1624x969.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>The Old Model Is Built Around Decryption</h2><p>Most modern systems follow a pattern:</p><ul><li><p>Data is encrypted while stored.</p></li><li><p>It&#8217;s encrypted while transmitted.</p></li><li><p>When the system needs to use it, it&#8217;s decrypted.</p></li></ul><p>The application reads the plaintext. The processor operates on the plaintext. The service makes a decision using the plaintext. The result is encrypted again.</p><p>That model is so prevalent that barely anyone looks twice at it. Encryption is treated as a protective layer around the data. </p><p>FHE and ZKP challenge the foundations of the conventional application stack. That&#8217;s why they can&#8217;t be treated like just another security feature. A system designed around plaintext access will not become privacy-preserving just because FHE or ZKP is incorporated into it. The architecture still expects visibility.</p><h2>The Plaintext Window Is the Real Problem</h2><p>Current encryption is good at protecting data while it&#8217;s not in use. It protects files stored on a disk. It protects traffic moving across a network. But when the data is needed, it&#8217;s decrypted. That creates a <strong>plaintext window</strong>.</p><p>During that window, the data can be exposed to:</p><ul><li><p>the application processing it;</p></li><li><p>the operating system;</p></li><li><p>administrators;</p></li><li><p>cloud infrastructure;</p></li><li><p>debugging and monitoring tools;</p></li><li><p>malicious insiders;</p></li><li><p>compromised dependencies;</p></li><li><p>memory-scraping attacks; and</p></li><li><p>anyone who gains control of the system while the data is in use.</p></li></ul><p>This isn&#8217;t an exception&#8212;it&#8217;s the normal operating model. Security teams try to protect that window through access controls, logging, segmentation, endpoint protection and policy.</p><p>That doesn&#8217;t remove the fundamental condition: <strong>the data is still visible somewhere.</strong></p><p>The conventional model depends on trust:</p><ul><li><p>We trust the application. </p></li><li><p>We trust the cloud provider. </p></li><li><p>We trust the administrator. </p></li><li><p>We trust the operating system. </p></li><li><p>We trust the identity system. </p></li><li><p>We trust that the access-control rules are correct. </p></li><li><p>We trust that the software supply chain has not been compromised.</p></li></ul><p>That&#8217;s a lot of assumptions based on trust. <strong>FHE and ZKP take a different approach</strong>. They don&#8217;t ask how many controls should surround the plaintext window. They ask does the data (plaintext window) need to be exposed at all.</p><h2>Encryption in Use Changes the System</h2><p>With FHE, computation can happen while the data is encrypted. That sounds simple. It&#8217;s not. An application may expect to:</p><ul><li><p>compare values directly;</p></li><li><p>branch based on a condition;</p></li><li><p>search records;</p></li><li><p>perform floating-point calculations;</p></li><li><p>update state;</p></li><li><p>call external services;</p></li><li><p>display intermediate results; and</p></li><li><p>log what happened.</p></li></ul><p>An FHE system can&#8217;t assume that those operations work in the same way. The data is encoded into ciphertexts. The available operations depend on the scheme. The order of operations matter. The depth of the computation matters. Noise growth matters. Bootstrapping matters. Ciphertext size matters. Memory movement matters.</p><p>A process that is trivial in plaintext can become expensive when encrypted. Conversely, a process that looks complicated in ordinary software may become efficient if data can be batched and processed in parallel.</p><p>The application has to be designed around the cryptographic model, not the other way around. This is the first major shift.</p><h2>The Question Changes From Access to Computation</h2><p>Conventional security architecture begins with: <em>Who is allowed to access this data?</em></p><p>FHE has a different question: <em>What computation is allowed to happen over this data?</em></p><p>A user or service can be permitted to run a calculation without ever being permitted to see the underlying information.</p><ul><li><p><strong>In finance:</strong> A bank could calculate whether a customer satisfies a lending threshold without exposing the customer&#8217;s full financial history.</p></li><li><p><strong>In healthcare:</strong> A medical platform could identify whether a treatment condition is satisfied without revealing every clinical measurement.</p></li><li><p><strong>In employment:</strong> An employer could verify whether a person holds a required qualification without receiving the qualification record.</p></li></ul><p>The authority is not just permission to read; it could be <strong>permission to compute</strong>.</p><p>That means a more granular security model:</p><ul><li><p>which inputs can be used;</p></li><li><p>which operations can be performed;</p></li><li><p>which outputs can be returned;</p></li><li><p>who can decrypt the result;</p></li><li><p>whether the result itself reveals too much; and</p></li><li><p>whether repeated queries could reconstruct the underlying data.</p></li></ul><p>A system can protect the input perfectly and still leak information through the output. Cryptography does not eliminate inference. Architecture has to account for it.</p><h2>ZKP Changes Verification</h2><p>ZKP creates a similar change. Verification is usually built around inspection. A person submits a document. A company uploads financial records. A service provides logs. An employee presents a credential. The verifier examines the evidence and decides whether to trust it.</p><p>This model creates copies. Every verification creates another recipient. Every recipient may store the evidence. <em><strong>Every stored copy becomes another breach target.</strong></em></p><p>ZKP allows verification to happen without needing to transfer the evidence. That changes the relationship between the prover and verifier. The verifier doesn&#8217;t need broad access to the data, it needs a [mathematically] defined claim and a valid proof.</p><p>The new architecture distinguishes between:</p><ul><li><p>the information;</p></li><li><p>the claim being made about it;</p></li><li><p>the evidence used to support the claim;</p></li><li><p>the proof generated from that evidence; and</p></li><li><p>the party authorised to verify it.</p></li></ul><p>Those elements are usually collapsed in conventional systems. A scanned passport can simultaneously serve as identity data, evidence, credential and stored audit record. Convenient, but also why organisations end up holding millions of documents they never really need.</p><h2>Data Minimisation Must Be Designed In</h2><p>Many organisations ask for the complete record because it is easier. They retain it because it may be useful. They secure it because they now possess it. They delete it only if policy, regulation or litigation forces them to. <strong>That is not minimisation</strong>.</p><p>ZKP makes it possible to design the decision around the minimum necessary claim. FHE makes it possible to process data without automatically exposing it. Together, they allow minimisation to go from policy to protocol.</p><p>That doesn&#8217;t mean every piece of data disappears. A proof still depends on inputs. An encrypted computation still depends on ciphertexts, keys and authorised outputs. But the architecture can be structured so that fewer systems get plaintext and fewer organisations hold copies. That&#8217;s a big change:</p><ul><li><p><strong>A privacy policy</strong> says an organisation should not misuse data.</p></li><li><p><strong>A privacy-preserving architecture</strong> reduces the organisation&#8217;s ability to misuse it.</p></li></ul><h2>Identity Isn&#8217;t a Binary Gate</h2><p>Most access-control systems still work in a binary system. A user authenticates, the system determines their role, and the role grants access. This model treats identity as a gateway to data. Once someone is inside the permitted boundary, the application often assumes they may see or process the information associated with that role.</p><p>FHE and ZKP allow identity to become more contextual. A system can ask:</p><ul><li><p>Is this person authorised for this specific operation?</p></li><li><p>Do they satisfy the required condition?</p></li><li><p>Is the credential valid now?</p></li><li><p>Is this request within an approved limit?</p></li><li><p>Is the device or service permitted to perform this computation?</p></li><li><p>Can the result be released without revealing protected information?</p></li></ul><p>The answer can be proven without necessarily revealing the person&#8217;s full identity, and the computation can happen without needing to reveal the data.</p><p>That moves the system towards constrained authority. </p><ul><li><p><strong>Access says:</strong> Enter.</p></li><li><p><strong>Constrained authority says:</strong> You can perform this operation, under these conditions.</p></li></ul><h2>The Application Has to Know Less</h2><p>Traditional application design rewards visibility. Developers want access to logs. Administrators want access to records. Support teams want access to user accounts. Analytics platforms want access to events. Artificial intelligence systems want access to everything.</p><p>The argument is usually that visibility improves functionality. But a privacy-preserving architecture has a different argument - what is the bare minimum needed to be functional. Usually, it&#8217;s a lot less than organisations say they need.</p><ul><li><p>The <strong>authentication service</strong> may need to know that a credential is valid; it may not need to know the credential&#8217;s contents.</p></li><li><p>The <strong>analytics service</strong> may need to calculate an aggregate; it may not need to see the individual records.</p></li><li><p>The <strong>eligibility engine</strong> may need to return yes or no; it may not need to know the exact values used to reach that decision.</p></li><li><p>The <strong>cloud provider</strong> may need to process the workload; it may not need access to either the data or the result.</p></li></ul><p>This is not just least privilege applied to users&#8212;it&#8217;s <strong>least knowledge applied to systems</strong>. That is a completely different way of thinking.</p><h2>Existing Software Is Usually the &#8216;Wrong Shape&#8217;</h2><p>Most existing software was not designed for encrypted computation:</p><ul><li><p>random access to plaintext;</p></li><li><p>conventional branching;</p></li><li><p>cheap comparisons;</p></li><li><p>unrestricted logging;</p></li><li><p>flexible data formats;</p></li><li><p>database queries over readable values;</p></li><li><p>ordinary debugging; and</p></li><li><p>direct integration with external services.</p></li></ul><p>FHE breaks many of those assumptions. ZKP adds new layers around circuit construction, witness handling, proof generation and verification.</p><p>Retrofitting these technologies into a legacy application may need more than changing a few functions. The data model may need to change. The workflow may need to change. The database may need to change. The application boundaries may need to change. The identity model may need to change. The team may even need to reconsider which operations should happen at all.</p><p>Some processes exist only because plaintext is available. Once visibility is removed, organisations may discover that certain analytics, integrations or administrative practices weren&#8217;t really needed. They were just nice to have.</p><h2>Migration Has to Be Staged</h2><p>None of this means an organisation needs to replace its entire system overnight. The more practical approach is staged migration.</p><ol><li><p><strong>Identify exposure:</strong> Start by identifying where the most sensitive plaintext exposure happens. Look for operations involving identity, financial records, medical information, intellectual property, authentication secrets, regulated data, cross-organisational sharing, and cloud processing outside direct control.</p></li><li><p><strong>Isolate operations:</strong> Identify which operations can be isolated. A system may begin by encrypting one calculation rather than an entire application. A ZKP may replace one document-disclosure process. An encrypted policy check may replace one database lookup. A protected identity attribute may replace one reusable identifier.</p></li></ol><p>The objective isn&#8217;t to force every operation into FHE or ZKP. That would be as misguided as forcing every calculation into TFHE or CKKS. The objective is to identify where plaintext visibility and exposure create the greatest risk. Redesign those parts first.</p><h2>Hybrid Systems Will Be Normal</h2><p>The future architecture will probably not be purely FHE, purely ZKP or purely anything else. It will be hybrid.</p><ul><li><p>Some data may stay in conventional encrypted storage.</p></li><li><p>Some calculations may use CKKS.</p></li><li><p>Some may use BFV or BGV.</p></li><li><p>Some decisions may use TFHE.</p></li><li><p>Some claims may be proven with ZKP.</p></li><li><p>Some operations may happen in trusted local environments.</p></li><li><p>Others may be delegated to accelerated hardware or external infrastructure.</p></li></ul><p>The challenge is not finding one universal cryptographic scheme; it&#8217;s coordinating several technologies without reintroducing the exposure they were intended to remove. That includes deciding:</p><ul><li><p>where keys are held;</p></li><li><p>where proofs are generated;</p></li><li><p>how ciphertexts move;</p></li><li><p>who can request computations;</p></li><li><p>how results are validated;</p></li><li><p>when scheme switching is required;</p></li><li><p>where metadata is exposed; and</p></li><li><p>which components still require trust.</p></li></ul><p>The system will only be as private as its weakest architectural boundary. A ZKP protecting one claim does little if the application leaks the underlying information through logs. FHE protecting a calculation doesn&#8217;t do much if the result is decrypted into a poorly secured service.</p><h2>Hardware Doesn&#8217;t Fix Bad Architecture</h2><p>Hardware acceleration will be essential to making many FHE and ZKP workloads practical, but acceleration can&#8217;t fix a badly designed system.</p><ul><li><p>A <strong>processor</strong> can make bootstrapping faster; it can&#8217;t decide whether TFHE was the right scheme.</p></li><li><p>A <strong>GPU</strong> can reduce proof-generation time; it can&#8217;t tell whether the circuit proves the right claim.</p></li><li><p>An <strong>FPGA</strong> can accelerate polynomial arithmetic; but it can&#8217;t prevent an application from logging plaintext elsewhere.</p></li></ul><p>Hardware can reduce latency, increase throughput and lower computational cost. It can&#8217;t remove architectural contradictions.</p><p>This is why performance <em>benchmarks need to be treated carefully</em>. A claim that an accelerator performs a particular operation thousands of times faster may be accurate, but:</p><ul><li><p>Is that the operation the application needs?</p></li><li><p>At the required security parameters?</p></li><li><p>With realistic key sizes?</p></li><li><p>Under sustained load?</p></li><li><p>With acceptable memory consumption?</p></li><li><p>For single requests or only large batches?</p></li><li><p>Without moving sensitive data into a new trust domain?</p></li></ul><p>Faster is good. Faster in the wrong architecture is just a faster mistake.</p><h2>The Security Model Needs To Be Rewritten</h2><p>FHE and ZKP force organisations to confront assumptions that conventional security leaves untouched.</p><ul><li><p><em>Why does this service need the plaintext?</em></p></li><li><p><em>Why does this verifier need the document?</em></p></li><li><p><em>Why does this administrator need broad visibility?</em></p></li><li><p><em>Why is this identifier reused across systems?</em></p></li><li><p><em>Why is this dataset copied?</em></p></li><li><p><em>Why is the cloud provider trusted?</em></p></li><li><p><em>Why is the result decrypted here?</em></p></li><li><p><em>Why is the evidence retained after the decision?</em></p></li></ul><p>The usual answer is some version of: <em>&#8220;Because that is how the system works.&#8221;</em></p><p>That&#8217;s just rationalising a bad design.</p><h2>Architecture Before Cryptography</h2><p>The first questions in any modern redesign should be:</p><ul><li><p>What should the system accomplish?</p></li><li><p>What information is actually needed?</p></li><li><p>Which components really need plaintext?</p></li><li><p>Which claims need to be verified?</p></li><li><p>Which operations can happen over encrypted data?</p></li><li><p>Which outputs are safe to reveal?</p></li><li><p><strong>Which trust assumptions can be removed?</strong></p></li><li><p><strong>Which ones still remain?</strong></p></li></ul><p>FHE and ZKP are not just layers added to an existing application. They change the relationship between data, computation, identity and trust. FHE allows the system to compute without seeing. ZKP allows the system to verify without being shown.</p><p>They both point to an architecture in which access is narrower, disclosure is reduced and trust is no not the default setting.</p><p>That is the real change. Not stronger encryption. Different thinking.</p><p><em>In the next article, we will look at what happens when this architecture meets hardware&#8212;and why acceleration has to support the workload rather than define it.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://jirif.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading PrivID's Substack! Subscribe for free to receive new posts. Always free. Never paywalled.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[ZKPs Proves What FHE Claims.]]></title><description><![CDATA[Yesterday, we looked at Fully Homomorphic Encryption, or FHE, and why CKKS, BFV, BGV and TFHE shouldn&#8217;t be treated as interchangeable versions.]]></description><link>https://jirif.substack.com/p/zkps-proves-what-fhe-claims</link><guid isPermaLink="false">https://jirif.substack.com/p/zkps-proves-what-fhe-claims</guid><dc:creator><![CDATA[Jiri Fiala]]></dc:creator><pubDate>Tue, 28 Jul 2026 13:34:21 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!fOQb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39bf2345-1461-4cf4-b8f0-a153c7cbae3d_1672x941.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Yesterday, we looked at <strong>Fully Homomorphic Encryption</strong>, or <strong>FHE</strong>, and why CKKS, BFV, BGV and TFHE shouldn&#8217;t be treated as interchangeable versions.</p><p>Today, we look at something different:  <strong>ZKP,  Zero-Knowledge Proof.</strong></p><p>ZKP lets someone <strong>prove that a statement is true without revealing the information used to prove it</strong>.</p><p>Right, at this point you are either asking yourself why are we discussing this, it has nothing to do with FHE! What if I told you it does?</p><p>FHE protects data while it&#8217;s being processed. ZKP reduces, or eliminates, how much data needs to be disclosed. One protects the computation. The other proves the information or computation without exposing it. Together, they have the potential to change how digital trust is designed.</p><h2>What Is a ZKP?</h2><p><strong>ZKP</strong> is a method where one party can demonstrate that a claim is valid without revealing the information supporting that claim. Bear with me, this is a bit tricky.</p><p>The party creating the proof is called the <strong>prover</strong>. The party checking it is called the <strong>verifier</strong>. The private information used to generate the proof is often called the <strong>witness</strong>.</p><p>Let&#8217;s say someone needs to prove that they&#8217;re over 18. A conventional identity system might require them to provide:</p><ul><li><p>their full name;</p></li><li><p>date of birth;</p></li><li><p>home address;</p></li><li><p>photograph;</p></li><li><p>identity-document number; and</p></li><li><p>a copy of the document itself.</p></li></ul><p>But the organisation checking the requirement doesn&#8217;t really need any of that It needs the answer to one simple question: <em><strong>Is this person over the required age?</strong></em></p><p>ZKP can let the individual prove that the answer is yes without revealing their date of birth or showing the underlying document(s) to every service that asks. The verifier learns that the condition has been satisfied. More importantly it doesn&#8217;t learn any private information beyond the confirmation of age.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!fOQb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39bf2345-1461-4cf4-b8f0-a153c7cbae3d_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!fOQb!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39bf2345-1461-4cf4-b8f0-a153c7cbae3d_1672x941.png 424w, /__u/substackcdn.com/image/fetch/$s_!fOQb!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39bf2345-1461-4cf4-b8f0-a153c7cbae3d_1672x941.png 848w, /__u/substackcdn.com/image/fetch/$s_!fOQb!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39bf2345-1461-4cf4-b8f0-a153c7cbae3d_1672x941.png 1272w, /__u/substackcdn.com/image/fetch/$s_!fOQb!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_webp, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39bf2345-1461-4cf4-b8f0-a153c7cbae3d_1672x941.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!fOQb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39bf2345-1461-4cf4-b8f0-a153c7cbae3d_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/39bf2345-1461-4cf4-b8f0-a153c7cbae3d_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1765689,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://jirif.substack.com/i/208614607?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39bf2345-1461-4cf4-b8f0-a153c7cbae3d_1672x941.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!fOQb!, /__u/jirif.substack.com/w_424, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39bf2345-1461-4cf4-b8f0-a153c7cbae3d_1672x941.png 424w, /__u/substackcdn.com/image/fetch/$s_!fOQb!, /__u/jirif.substack.com/w_848, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39bf2345-1461-4cf4-b8f0-a153c7cbae3d_1672x941.png 848w, /__u/substackcdn.com/image/fetch/$s_!fOQb!, /__u/jirif.substack.com/w_1272, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39bf2345-1461-4cf4-b8f0-a153c7cbae3d_1672x941.png 1272w, /__u/substackcdn.com/image/fetch/$s_!fOQb!, /__u/jirif.substack.com/w_1456, /__u/jirif.substack.com/c_limit, /__u/jirif.substack.com/f_auto, /__u/jirif.substack.com/q_auto:good, /__u/jirif.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39bf2345-1461-4cf4-b8f0-a153c7cbae3d_1672x941.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>What &#8220;Zero Knowledge&#8221; Actually Means</h2><p>The term <strong>zero knowledge</strong> doesn&#8217;t mean the verifier learns nothing at all. The verifier learns that the statement being proved is valid. That&#8217;s all they need. They don&#8217;t need documentation to be uploaded or scanned. They just need validation of the question or statement. A well built zero-knowledge system will satisfy three broad properties:</p><h3>Completeness</h3><p>If the claim is true and the parties follow the protocol correctly, the verifier should accept the proof.</p><h3>Soundness</h3><p>If the claim is false, a dishonest prover shouldn&#8217;t be able to convince the verifier that it&#8217;s true, except with an extremely small probability.</p><h3>Zero knowledge</h3><p>The verifier shouldn&#8217;t learn the witness or other protected information beyond what can be inferred from the validity of the claim itself.</p><p><em>A system that hides the evidence but allows false claims isn&#8217;t useful. A system that proves the claim but leaks the evidence isn&#8217;t zero knowledge. </em>Achieving both means verification <em><strong>and</strong></em> privacy.</p><h2>Proof Is Not Encryption</h2><p>ZKP proves that a statement about data or computation is true.</p><ul><li><p>a person satisfies an age requirement;</p></li><li><p>a transaction falls within an authorised limit;</p></li><li><p>a credential was issued by a recognised authority;</p></li><li><p>a calculation was performed correctly;</p></li><li><p>a password or private key is known;</p></li><li><p>a model produced an output according to an agreed process;</p></li><li><p>a software component followed a defined rule; or</p></li><li><p>an account has sufficient funds without revealing its balance.</p></li></ul><p><em>Proof confirms a condition. FHE is about performing operations while the data is encrypted.</em></p><div class="callout-block" data-callout="true"><p><strong>FHE: can we compute the data without seeing it?</strong></p><p><strong>ZKP: can we prove something about the data or computation without revealing it?</strong></p></div><h2>Interactive and Non-Interactive Proofs</h2><p>Early zero-knowledge systems were <strong>interactive</strong>. The prover and verifier exchanged multiple messages. <em>The verifier issued challenges, and the prover responded in ways that demonstrated knowledge of the secret without disclosing it</em>.</p><p>That isn&#8217;t practical in large systems. Many modern applications use <strong>Non-Interactive Zero-Knowledge proofs</strong>, or <strong>NIZKs</strong>. This can be used in:</p><ul><li><p>distributed systems;</p></li><li><p>blockchains;</p></li><li><p>identity credentials;</p></li><li><p>asynchronous transactions;</p></li><li><p>audit records;</p></li><li><p>cloud services; and</p></li><li><p>systems in which many parties may need to verify the same proof.</p></li></ul><p>A proof can be created once and verified as needed. That doesn&#8217;t mean the same proof should always be reused. It means the verification process doesn&#8217;t need a conversation.</p><h2>SNARKs and STARKs</h2><p>Two acronyms usually appear in ZKP discussions: <strong>SNARK</strong> and <strong>STARK</strong>.</p><p>A <strong>SNARK</strong> is a <strong>Succinct Non-Interactive Argument of Knowledge</strong>.</p><p>A <strong>STARK</strong> is a <strong>Scalable Transparent Argument of Knowledge</strong>.</p><p>Both are families of proof systems. The word <strong>succinct</strong> means the proof can be relatively small and efficient to verify, regardless of the size of the underlying computation. The word <strong>transparent</strong> implies that the system avoids the trusted setup of SNARK constructions.</p><p>A trusted setup creates shared cryptographic parameters. If the material isn&#8217;t processed, and destroyed, properly, it can compromise system integrity.</p><p>That doesn&#8217;t mean every SNARK needs the same type of trusted setup, or that SNARKs are unsafe. As with all things methods and results may vary. It just means the setup assumptions need to be understood.</p><p>STARKs are usually larger and typically need more verification. They&#8217;re associated with hash-based techniques that may offer stronger positioning against future quantum attacks. Neither are right or wrong. The correct proof system depends on:</p><ul><li><p>the size and complexity of the computation;</p></li><li><p>proof-generation time;</p></li><li><p>proof size;</p></li><li><p>verification cost;</p></li><li><p>trusted-setup requirements;</p></li><li><p>recursion requirements;</p></li><li><p>security assumptions; and</p></li><li><p>the environment in which the proof will be checked.</p></li></ul><h2>The Circuit Defines the Claim</h2><p>ZKP proves that a specific relationship has been met. That relationship is presented through a circuit, constraint system or equivalent structure. Suppose a proof needs to establish that someone is over a certain age, the circuit needs to confirm:</p><ol><li><p>the date of birth came from a valid credential;</p></li><li><p>the credential was signed by an accepted issuer;</p></li><li><p>the credential hasn&#8217;t expired or been revoked;</p></li><li><p>the current date minus the birth date exceeds the required threshold; and</p></li><li><p>the proof is bound to the correct service and session.</p></li></ol><p>The verifier doesn&#8217;t need to see the birth date. The system, on the other hand, still needs a precise definition of what is being proved. The proof will establish what is actually checked, not what its designers intended it to check. A flawed circuit can produce a perfectly valid proof of the wrong thing.</p><h2>A Valid Proof Doesn&#8217;t Mean a Valid Source</h2><p>ZKP can prove that a statement follows from the inputs provided to the proof system. It doesn&#8217;t automatically prove that those inputs were truthful, current or not stolen. Let&#8217;s look at an age verification proof:</p><p>The cryptography may prove that the date in a credential meets or exceeds the age requirement. But someone still needs to establish that:</p><ul><li><p>the credential was issued by a legitimate authority;</p></li><li><p>it belongs to the person presenting it;</p></li><li><p>it hasn&#8217;t been revoked;</p></li><li><p>the issuer&#8217;s signing key hasn&#8217;t been compromised; and</p></li><li><p>the original identity-verification process was reliable.</p></li></ul><p>A proof is only as meaningful as the trust placed in the inputs and the rules being proven. The same applies to artificial intelligence.</p><p>ZKP may prove that a model was executed against a particular input and a result was produced. It <strong>doesn&#8217;t prove</strong> that the model was fair, sensible or appropriate. It <strong>proves</strong> that the specified process happened.</p><p>That difference tends to get lost when the word <em>proof</em> enters the discussion</p><h2>Selective Disclosure Is Not the Same as Zero Knowledge</h2><p>Selective disclosure lets someone to reveal only part of a credential.</p><p>For example, a digital identity credential might contain a name, address, date of birth and citizenship, while the holder reveals only the citizenship field. That&#8217;s better than disclosing the entire credential. But it isn&#8217;t specifically zero knowledge.</p><p>A zero-knowledge proof could prove that the person belongs to an authorised jurisdiction without revealing which jurisdiction it is; assuming the use case permits that.</p><p>Selective disclosure reduces unnecessary exposure. Zero knowledge can go further by proving a derived condition without revealing the attribute itself. Both work, but they are not the same.</p><h2>This Is Already Happening in the EU</h2><p>The revised <strong>eIDAS Regulation</strong>, which establishes the European Digital Identity framework, specifically calls for privacy-preserving technologies such as ZKP to be integrated into the <strong>European Digital Identity Wallet</strong>, or <strong>EUDI Wallet</strong>.</p><p>The objective is straightforward: a relying party should be able to confirm that a statement about someone is true without receiving the personal information on which that statement is based. The wallet could prove that someone:</p><ul><li><p>is over a required age;</p></li><li><p>holds a valid qualification;</p></li><li><p>has a recognised licence;</p></li><li><p>is legally resident in a jurisdiction; or</p></li><li><p>is entitled to access a particular service.</p></li></ul><p>The organisation receives the answer it needs rather than the person&#8217;s complete identity record. At least that&#8217;s the idea.</p><p>The EU&#8217;s age-verification initiative brings the same model into a more controversial setting. The Commission has developed a technically ready system that lets someone prove they meet an age threshold without disclosing their exact age, identity or other personal details. The blueprint includes ZKP technology and can function as a standalone application or be integrated into an EUDI Wallet.</p><p>That is materially better than needing people to upload passports, national identity cards or selfies everytime a proof of age is needed. But ZKP doesn&#8217;t automatically make the surrounding system private, proportionate or safe.</p><p>The cryptographic proof may reveal only that the user is over a certain age. The broader architecture may still depend on:</p><ul><li><p>the organisation that originally verifies the person&#8217;s age;</p></li><li><p>the issuer creating the credential;</p></li><li><p>the wallet or age-verification application;</p></li><li><p>the mobile operating system and app store;</p></li><li><p>the device presenting the proof;</p></li><li><p>the service requesting it; and</p></li><li><p>the rules governing when that service is allowed to ask.</p></li></ul><p>The Commission&#8217;s design tries to separate credential issuance from presentation. Once the proof of age has been issued, the proof provider shouldn&#8217;t learn which service the person visits, and the service shouldn&#8217;t receive identity information that could be used to trace them.</p><p><em>Metadata can still create patterns</em>. Devices can still be fingerprinted. Poorly implemented credentials can still be correlated. Issuers can still make mistakes. Wallet software can still contain vulnerabilities. Governments and platforms can expand the situations in which proof is demanded.</p><p>A mechanism introduced for pornography, gambling or other age-restricted services can gradually become an identity checkpoint for ordinary online activity. A privacy-preserving gate is still a gate. That&#8217;s the difference between cryptography and governance.</p><p>ZKP can limit what is disclosed when a question is asked. It can&#8217;t decide whether the question should have been asked in the first place.</p><p>While eIDAS establishes the legal framework now, the EUDI Wallet rollout is still being implemented. Member States are expected to make at least one wallet available by the end of 2026. The age-verification is technically ready, but deployment and adoption are uneven.</p><p>Both eIDAS and EUDI Wallet  show the promise of ZKP and its limitations. But it can&#8217;t guarantee that institutions or organisations will demand less.</p><h2>Why ZKPs And Identity</h2><p>Most identity systems still operate on a disclosure model.</p><ul><li><p>The service asks for data.</p></li><li><p>The user provides it.</p></li><li><p>The service stores it.</p></li></ul><p>The organisation spends years securing information it probably never really needed in the first place. That architecture creates predictable problems:</p><ul><li><p>duplicated identity records;</p></li><li><p>large centralised databases;</p></li><li><p>unnecessary retention;</p></li><li><p>insider access;</p></li><li><p>breach exposure;</p></li><li><p>cross-service correlation; and</p></li><li><p>secondary use of personal data.</p></li></ul><p>ZKPs use a different method, instead of repeatedly transmitting identity attributes, the user can present cryptographic evidence that a requirement has been satisfied.</p><ul><li><p>The service receives less information.</p></li><li><p>Less information needs to be stored.</p></li><li><p>Less information can be breached.</p></li><li><p>That identity risk isn&#8217;t gone.</p></li></ul><p>Metadata, device fingerprinting, transaction patterns and poorly designed identifiers can still allow users to be tracked. <strong>A privacy-preserving proof wrapped inside a surveillance-heavy system is still a surveillance-heavy system</strong>. But ZKPs make data minimisation enforceable at the <strong>protocol level</strong>. It&#8217;s not just a policy promise.</p><h2>Why ZKPs Matter Beyond Identity</h2><p>ZKPs can also be used to prove the integrity of computation. A service may perform a calculation and return both the result and a cryptographic proof that it followed the rules. The service can support:</p><ul><li><p>verifiable cloud computation;</p></li><li><p>confidential audits;</p></li><li><p>private compliance checks;</p></li><li><p>supply-chain validation;</p></li><li><p>financial solvency proofs;</p></li><li><p>decentralised systems;</p></li><li><p>machine-learning verification; and</p></li><li><p>policy enforcement across organisations.</p></li></ul><div><hr></div><ul><li><p>A company could prove that it meets a regulatory threshold without showing every transaction.</p></li><li><p>A cloud provider could prove that a defined operation was performed correctly.</p></li><li><p>An AI system could prove that an approved model version and policy set were used.</p></li><li><p>A user could prove authorisation without revealing a reusable identifier.</p></li></ul><p>The common principle is the same: <strong>Trust the proof rather than demanding all the underlying data.</strong></p><h2>Proof Isn&#8217;t Free</h2><p>ZKPs can reduce disclosure at a computational cost. Creating a proof may need more work than verifying it. The prover may need to change the computation into a constraint system, generate cryptographic commitments and process a large number of mathematical operations.</p><p>Depending on the proof system and circuit, proving may need:</p><ul><li><p>significant CPU or GPU time;</p></li><li><p>large amounts of memory;</p></li><li><p>specialised libraries;</p></li><li><p>careful circuit optimisation;</p></li><li><p>precomputation;</p></li><li><p>parallel execution; and</p></li><li><p>hardware acceleration.</p></li></ul><p>Verification is supposed to be cheaper. That asymmetry is useful because one party can generate a proof that others can verify easily. But it also creates practical design questions:</p><p>Where is the proof generated?</p><ul><li><p>On the user&#8217;s device?</p></li><li><p>Inside secure infrastructure?</p></li><li><p>By the service performing the computation?</p></li><li><p>Does the prover have enough memory and power?</p></li><li><p>How much latency is acceptable?</p></li><li><p>Can the proof be generated for every transaction, or must operations be aggregated?</p></li></ul><h2>ZKP and FHE Solve Different Halves of the Problem</h2><p>FHE and ZKP become very interesting when considered together.</p><p>FHE can allow a service to compute over encrypted data without seeing it.</p><p>ZKP can then show that the encrypted computation was done correctly or that the inputs satisfied a particular set of rules. Let&#8217;s consider a confidential eligibility system.</p><p>FHE could calculate a result for encrypted financial or medical data.</p><p>ZKP could prove that:</p><ul><li><p>the correct algorithm was used;</p></li><li><p>the data came from authorised sources;</p></li><li><p>the calculation satisfied the agreed rules; and</p></li><li><p>the result falls within an approved category.</p></li></ul><div><hr></div><ul><li><p>The service may never need to see the underlying values.</p></li><li><p>The user may not need to expose the evidence.</p></li><li><p>The verifier doesn&#8217;t need to rely entirely on institutional trust.</p></li><li><p>This doesn&#8217;t make the system automatically private or secure.</p></li><li><p>Key management, metadata, circuit design, software integrity, credential issuance and access control still matter.</p></li></ul><p>Now it can <em>replace a model based on disclosure and trust</em> <strong>with one based on encrypted computation and verifiable claims</strong>.</p><h2>Architecture Comes Before Proof</h2><ul><li><p>What exactly needs to be proven?</p></li><li><p>Who is making the claim?</p></li><li><p>Who is verifying it?</p></li><li><p>Which information must remain private?</p></li><li><p>Which information can be public?</p></li><li><p>Where does the witness come from?</p></li><li><p>Why should the verifier trust that source?</p></li><li><p>Can the proof be linked across transactions?</p></li><li><p>What happens when a credential is revoked?</p></li><li><p>How expensive is proof generation?</p></li><li><p>Does the system require a trusted setup?</p></li><li><p>What metadata remains exposed?</p></li></ul><p>Without those answers, a ZKP can become just an expensive privacy label. The technology is powerful precisely because it can formalise trust. But formalising the wrong assumptions only makes the mistake mathematically consistent.</p><h2>Proof Without Unnecessary Disclosure</h2><p>The central value of zero knowledge isn&#8217;t secrecy for its own sake. It&#8217;s reducing the amount of information a system needs to collect, expose and trust. Most systems ask for far more data than needed. And copying information has historically been easier than proving facts about it. ZKP changes that.</p><ul><li><p>They separate the claim from the evidence.</p></li><li><p>Allow verification without disclosure.</p></li></ul><p>And they allow systems to establish that rules were followed without exposing everything. FHE keeps data encrypted while it&#8217;s being used. ZKP proves that a claim or computation is valid without exposing it. Together, they point towards a different security architecture. One where trust is reduced, data is minimised and verification doesn&#8217;t need visibility.</p><p>In the next article, we&#8217;ll look at why FHE and ZKPs require more than stronger encryption.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://jirif.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading PrivID's Substack! Subscribe for free to receive new posts. Always free, never paywalled.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>