Degrees Of Freedom | blarg

6 min read Original article ↗

August 10, 2026

Untitled

This started off life as a thread on Mastodon, about Google’s upcoming decision to restrict all software installation to be beholden to Google Play’s chain-of-custody developer identification process. For whatever it’s worth, my opinions here were mostly born from my experience with pre-signed-webextensions Firefox way back when, where before 57 people could install arbitrary addons from anywhere, and did.

The numbers there, both in absolute terms and as a fraction of the total user base, were genuinely horrifying, bad enough twelve years later I still don’t even want to type them in. You don’t need to take my word for it, I guess, but the addons team at the time were fucking superheroes who absolutely saved the world from its own worst kicking-and-screaming self, and nobody noticed.

(I noticed. Hi Kev, hi Caitlin. Hi team; much love and respect, always.)

One of the things I think we got right moving Mozilla off IRC to Matrix was the decision that pseudonymity was fine, but a purist approach to anonymity wasn’t viable.

The reasoning was – even before the AI slop glut infected the world – that if you’re going to maintain any sort of community safety standards in a world where a bad actor can easily generate an arbitrary number of synthetic identities, then you have to have some enforcement mechanism that can’t trivially be overwhelmed or circumvented. (Like IRC was and remains, if we’re being honest.)

Today, in the middle of the slopocalypse, I don’t think any purist approach to anonymity is viable if you value community safety, even if you pay it little more than lip service. It doesn’t matter if you’re a mendacious app-store landlord adding fancy parapets to your walled garden or a tiny group of devs trying to keep your people safe when some hackernewsbro with a keyboard, a VM and a grudge decides that anyone with eyeliner and a piercing saying he should quit being a dick means it’s D-Day In The Gender Wars. The tooling and response options are different, but the basic problem is not.

Traditionally, if that’s the right word, absolutist notions of anonymity are a fundamentally libertarian position, as incoherent and irresponsible as any libertarian position. Likewise, developer-identification mandates are of a kind with the age-verification mandates popping up around the world, serving the purposes of the state in a way that’s fundamentally oppressive. Both are, I think, extreme and dangerous responses to the idea (and today, the trivial creation) of bulk synthetic identities; crucially, neither admits the existence of community or any idea of community-sized collective safety.

In implementation terms, the zero-anonymity-permitted position is a statist position that happens to be exceedingly convenient for arbitrary adcorp targeting and policy enforcement. As a mechanism, it means that individuals can be specifically and arbitrarily targeted, both by states and complicit corporations (and maybe vice versa, corporations and complicit states) whether its’ for ads, propaganda, or stripping people of various technically-expected or societally-guaranteed freedoms.

The total-anonymity position, in the same way, shelters some people in some ways from those risks, but also means that there are effectively no ways to mitigate committed bad actors able to automate harassment beyond completely isolating their target, which is often as not a victory condition for the harasser. And these days, those bad acts are cheap.

Both of these are just threat models. And I believe the explicit conversation both the total-visibility statist and doctrinaire-anonymity libertarian want to avoid having is: What’s Your Threat Model?

It’s difficult to imagine a more fundamental, essential conversation in security, and when we’re having that conversation, we also have to ask who’s in the room.

Corporations are in a sense strongly hierarchical communities blessed by, constrained by and often colluding with the state. Human communities exist with the consentful support of their members. The place that states, corporations and libertarians have common ground – common bedrock, really – is the certainty that that there is no such thing as an unblessed/unsanctioned community that matters, and definitely no such thing as a positive obligation to such a community. It’s negative space in the conversation that think is as morally repulsive as it is invisible.

Freedom to and freedom from, sure, but also positive obligations to defend what freedoms to, to prevent the possibilities of, what those obligations are specifically: this is a longstanding hobbyhorse of mine because as long as the only two significant actors in this conversation are “the individual human” and “the state” and corporations are a blessed proxy and communities are an after (or never) thought, then ultimately I don’t think we’ll be able to reap any of the real societal benefits we could gain from a specific understanding of specific risks and tradeoffs that acknowledged that communities exist and matter.

Anyway, to drag this all the way back to where it started, arbitrary corporate insistence on mandatory identity verification can only exist in a world where the state insists on the same, and more broadly where we don’t insist that our rights and freedoms deserve the same care and scrutiny that things like car tires or plumbing fixtures get every day – “you must be free from these specific risks, under these specific circumstances as established in these debates and codified in these documents.”

(And obviously, you know the punchline: liability. We’ll get there.)

Pure anonymity defeats provenance, which imposes very real, very specific safety risks on people and communities. However, it also provides some protection to individuals at specific kinds of risk, to people in specific contexts.

Mandated provenance provides some very real, very practical safety guarantees to people and communities, but also imposes specific risks and arbitrary future risks to people in specific contexts.

There’s a huge spectrum between these two positions.

I think that when it comes to identity and security we have an obligation to be specific and transparent about our processes, reasoning and threat modelling around anonymity, gradiential pseudonymity and identity, and particularly to be transparent in defaults and accessible in terms of opt-ins opt-outs, and positive obligations. And that the legitimacy of these discussions will be in their transparency

Thanks for coming to my inside-my-head talk.