Building Hoodik, end-to-end encrypted cloud storage. Rust + Vue + Flutter. One person company in Osijek, Croatia. Self-host it or let me run it for you.
Your files. Your keys. Your server.
Hoodik is end-to-end encrypted cloud storage. Files are encrypted on your device before they leave. The server only ever holds ciphertext. You can run it yourself or use Hoodik Cloud. Same code either way.
Rust, Vue, Flutter.
.@JMilei speaking at the UN:
“The United Nations 🇺🇳 is a useless organization, feeding a caste of fatally arrogant parasites disguised as well-intentioned bureaucrats.” 🤣
LEGEND 👑
314 said no. not enough. so warrantless scanning of private messages and photos stays the plan until 2028, then they try again. "protect the kids" that reads everyone's inbox.
@HudsonLabs never-used-for-training is table stakes. who holds the keys when the agent opens the memo? if it's still Google, you just gave an LLM a plaintext mailbox. (building Hoodik for the case where the host can't read the files either)
@Sans_Google Apple didn't break encryption. they just stopped offering the mode where Apple couldn't read the backup. that's the whole lawful-access playbook.
@alanvibe@lisanandy@DCMS "protections" is the polite word for client-side scanning. leave the crypto alone, read the plaintext on the device before it gets sealed. same trick as Chat Control.
Legislative Trojan horses
🇪🇺 Chat Control 1.0 and 2.0
🇪🇺 Social media ban for children
🇪🇺 Addictive design ban for adults
🇪🇺 Combat fraud and serious crime
🇦🇺 Social media ban for children
🇺🇸 Social media ban for children
🇺🇸 Addictive design restrictions for children
🇳🇿 Social media ban for children
🇮🇪 Social media ban for children
🇫🇷 Social media ban for children
🇨🇦 Social media ban for children
🇬🇧 Social media ban for children
🇬🇧 Addictive design restrictions for children
🇬🇧 Child exploitation & grooming protection
🇬🇧 Force platforms to prioritise "trusted" news
🇦🇪 Social media ban for children
🇪🇸 Social media ban for children
🇬🇷 Social media ban for children
🇩🇰 Social media ban for children
🇳🇴 Social media ban for children
🇦🇹 Social media ban for children
🇵🇱 Social media ban for children
🇸🇮 Social media ban for children
🇹🇷 Social media ban for children
🇮🇩 Social media ban for children
🇲🇾 Social media ban for children
🇧🇷 Social media restrictions for children
🇵🇹 Social media restrictions for children
🇮🇳 Social media ban for children
🇸🇪 Social media ban for children
🇩🇪 Social media restrictions for children
🇮🇹 Social media restrictions for children
🇨🇳 Social media restrictions for children
I’m sharing this because more journalists have started following my work, and I want to show what I’m exposing through technical analysis anyone can understand.
I’m working on one of my most consequential investigations into legislation and technology built for digital surveillance. It’s called Chat Control. What follows looks like coordination between governments and a handful of tech companies.
Tech companies get more data to monetise. Governments gain the ability to monitor who says what, to whom, why, where they go and how they spend money.
Technical Trojan horses
🇪🇺 Compulsory identity verification
🇪🇺 Scan private communications
🇪🇺 Weaken end to end encryption
🇪🇺 Expand lawful access
🇬🇧 Compulsory identity verification
🇬🇧 Compulsory on-device scanning for every app
🇬🇧 Algorithms to prioritize trusted news sources
🇦🇺 Compulsory identity verification
🇳🇿 Compulsory identity verification
🇮🇪 Compulsory identity verification
🇫🇷 Compulsory identity verification
🇪🇸 Compulsory identity verification
🇬🇷 Compulsory identity verification
🇩🇰 Compulsory identity verification
🇳🇴 Compulsory identity verification
🇦🇹 Compulsory identity verification
🇵🇱 Compulsory identity verification
🇸🇮 Compulsory identity verification
🇹🇷 Compulsory identity verification
🇦🇪 Compulsory identity verification
🇮🇩 Compulsory identity verification
🇲🇾 Compulsory identity verification
🇧🇷 Compulsory identity verification
🇵🇹 Compulsory identity verification
🇨🇦 Compulsory identity verification
🇺🇸 Compulsory identity verification
Spot the pattern.
🔞 Australia set the stage. Other countries are now following with "robust" age assurance language in their TV appearances, including the US, UK and Ireland. The US AGs have added it to the proposed legislation following the Meta lawsuit.
💡 Australia’s own standard says age checks must be "technically accurate, robust, and reliable".
"Robust" means fault proof. It brings meaning like "best" endeavours.
Age estimation can’t meet that standard. As Australia defines it, age verification determines age "to a high level of accuracy", while age estimation only provides an approximate age.
Fault proof age checking requires identity verification.
Now look at the tech companies and what they built recently.
Apple, Google, Meta and Microsoft built identity verification capabilities before governments started saying existing age assurance wasn’t "robust" enough.
They knew what was coming.
🪪 Apple has age assurance APIs that can return verified age ranges, including confirmation using government ID, and its Wallet API lets apps verify age or identity from government issued digital ID.
🪪 Google recently built an Age Signals API so apps can receive age ranges and verification status. Android already lets parents block apps by age across the entire device, so this isn’t technically necessary for child safety.
Google has also added facial verification to Google Account and Gmail recovery through selfie video matching, presented as account security.
🪪 Meta launched selfie based Facebook verification that checks a video selfie against profile photos and plans to expand it globally.
🪪 Microsoft has rolled out age assurance across Microsoft Accounts using facial age estimation, identity documents and government systems. Refuse to verify and some content and features are blocked.
💭 A handful of tech companies control the operating systems, app stores and identity layers across almost every mobile device. Governments barely need to negotiate outside G7 rooms. If Apple, Google, Meta and Microsoft enforce the same rules, billions of people are instantly impacted.
The same technical capability keeps appearing: identify verification.
Identity the person first, then decide what they’re allowed to do, who they're allowed to speak to, and when they're allowed to move money.
p.s. Anthropic and OpenAI have identity verification services and the US government holds a kill switch that decides who has permission to use AI.
---
Let me know if I got anything wrong. I have 60 minutes to make an edit. Or just leave a comment so others can see your correction.
@DoubleD7066 one vault, every model pointed at it, on infra you host. that's the right shape. next step is the vault itself being E2EE so even the host can't read what the agents park there — https://t.co/Cdkn6EKz50 if you want that without building the crypto layer.
🚨🇪🇺REMEMBER : Elon Musk just put the EU chief back in her place!
Von der Leyen was preaching about "democracy" until Musk hit her with a truth bomb:
"If democracy is the foundation of freedom, surely your position as leader of the EU should be elected directly by the people?"
The EU is pushing Chat Control again, for the 3rd time.*
If it passes, companies will be forced to scan all of your private messages to look for CSAM.
Obviously, this violates your privacy rights. OPPOSE, RESIST, AND DO NOT COMPLY.
@ehsanshares yeah. "MCP that rents you your own files" is the whole scam. local plaintext in git is fine for design. for the rest, E2EE cloud where you hold the keys (https://t.co/Cdkn6EKz50) beats plugging Drive into whatever agent is hot this week.
@TawohAwa connecting ChatGPT to Google Drive just makes the agent the vault. both of them can read everything. keep files where the host can't, then let the agent ask for what it needs. that's the setup at https://t.co/Cdkn6EKz50
@Artemisfornow if the provider holds the keys, a secret Home Office order is enough. "encrypted" cloud with apple-held keys isn't encryption for you. ADP was the honest move: walk away rather than ship the backdoor.