PRIVACY · HARDWARE TRUST · ELECTRONIC SURVEILLANCE COUNTERMEASURES

Locking Out the Spy Agencies

Modern cyber security usually assumes that software, encryption and access control can protect a device that remains physically trustworthy. The historical record shows why a high-end intelligence adversary changes that threat model: exploit chains, firmware implants, supply-chain interdiction, endpoint compromise and traffic analysis can attack the layers around encryption rather than the cipher itself.

Evidence standard on this page: declassified documents, court records, official government sources and mainstream reporting are presented as documented history. Allegations and unresolved cases are labelled as such. The project’s own security technology is proprietary and has not yet received independent hardware-assurance certification, so its strongest claims are presented as design objectives pending external testing.

Vault 7: compromising the endpoint instead of breaking the message

In 2017 WikiLeaks published the material it called Vault 7, describing CIA cyber tools aimed at phones, computers and smart televisions. The U.S. Justice Department later confirmed in the prosecution of former CIA programmer Joshua Schulte that he stole and transmitted the CIA files that WikiLeaks published as Vault 7 and Vault 8. Public reporting on the files described tools targeting iOS, Android, Windows, macOS and Samsung smart TVs, including the “Weeping Angel” concept that could turn a television into a listening device. The important security lesson is not that encryption is useless; it is that if an adversary controls the endpoint, information may be captured before encryption or after decryption.

Former-CIA perspective — user-supplied video

The NSA record includes hardware and supply-chain attacks

Documents published from the NSA’s Tailored Access Operations era described techniques that went beyond ordinary malware. Reporting on the ANT catalog documented firmware and hardware implants for servers, routers, firewalls, USB devices and computers. A declassified NSA article published by the National Security Archive described supply-chain interdiction: shipments of networking equipment could be intercepted, redirected, implanted and then returned to delivery. That history matters because reinstalling an operating system does not remove a malicious component placed beneath it in firmware or hardware.

Our design premise: software-only security is insufficient against an adversary that can alter the machine itself. Artificial Inventor’s security research therefore centers on hardware-enforced trust boundaries, physical state verification and architectures intended to make a software-only bypass insufficient. The project’s objective is that protected actions cannot be authorized merely by compromising an operating system or application. We will not describe an untested system as literally impossible to defeat in every conceivable adversary model; that claim must survive independent physical penetration testing and hardware assurance review.

National Security Archive — NSA supply-chain interdiction documentDER SPIEGEL — NSA ANT hardware and firmware catalogWIRED — NSA custom hardware tools

Windows, zero-days and the move toward sovereign Linux

France announced in 2026 that the French state would begin moving government workstations away from Windows toward Linux as part of a broader strategy to reduce dependence on non-European technology. China has separately pushed government and state entities toward domestic processors, operating systems and databases, with many of the approved operating systems built on Linux. The official rationale in both countries is broader than Windows vulnerabilities — it includes sovereignty, supply-chain control and dependence on foreign vendors — but the security context is real: Microsoft Windows repeatedly appears in CISA’s Known Exploited Vulnerabilities catalog, and actively exploited Windows zero-days continue to require emergency patching.

French government — move from Windows toward LinuxReuters — China phasing foreign hardware/software from government systemsCISA — Known Exploited Vulnerabilities catalog

Traffic analysis: hiding the relationship, not only the message

Encrypting content does not necessarily hide who communicates with whom, when they communicate, or how much data moves. NSA materials and public disclosures have long described the use of communications metadata and “pattern-of-life” analysis to map relationships. Our separate electronic-surveillance-countermeasures design addresses that problem by generating large amounts of cover traffic and decoy traffic, obscuring timing and volume relationships so that a passive observer cannot reliably distinguish a real conversation from background activity. This is a privacy architecture aimed at defeating traffic analysis rather than merely encrypting payloads.

Design principle: the observer should see an intentionally noisy communications environment rather than a clean social graph. Cover traffic, timing obfuscation and decoy flows are used so the existence of an encrypted connection does not automatically identify the real parties or the real moment of communication. As with the hardware architecture, resistance to sophisticated statistical analysis has to be measured empirically rather than asserted from theory alone.

NSA — metadata used to map communications relationshipsThe Guardian — NSA metadata and pattern-of-life analysis

Kidnappings, extraordinary rendition, black sites and the CIA torture program

The threat model is not limited to malware. The post-9/11 record includes a CIA program of extraordinary rendition, secret detention and coercive interrogation in which detainees were captured or transferred outside ordinary judicial processes and held at clandestine “black sites” abroad. The U.S. Senate Select Committee on Intelligence published a major study of the CIA Detention and Interrogation Program in 2014, based on millions of pages of CIA records. European Court of Human Rights judgments have also found European states responsible for assisting CIA secret detention and rendition operations. These are documented historical facts, not internet speculation.

Secret detention and torture

The Senate report documented brutal interrogation practices and serious failures in oversight and accountability. European human-rights cases concerning Poland, Romania and Lithuania likewise examined secret CIA detention facilities and transfers. The historical lesson for privacy engineering is that the consequences of surveillance and intelligence targeting can extend far beyond loss of data: identifying, locating and classifying a person can become the first step in detention or coercive state action.

John Kiriakou

Former CIA officer John Kiriakou became the first CIA officer with direct knowledge of the post-9/11 interrogation program to publicly confirm waterboarding. He later served a 30-month federal prison sentence after pleading guilty to disclosing information identifying a covert CIA officer. Kiriakou has described the prosecution as retaliation for exposing torture; the Justice Department stated that he was imprisoned for the unlawful disclosure of a covert officer’s identity. Both facts belong in an accurate account.

U.S. Senate Intelligence Committee — CIA Detention and Interrogation Program studyEuropean Court of Human Rights — secret detention / CIA black-sites factsheetU.S. Department of Justice — John Kiriakou sentencing

Bilal Abdul Kareem and the secret “kill list” litigation

Bilal Abdul Kareem, an American journalist reporting from Syria, filed a federal lawsuit in 2017 alleging that the U.S. government had placed him on a secret targeting or “kill list” and that five near-miss air strikes were attempts to kill him. The court record confirms that he experienced or narrowly survived at least five aerial bombings and that he believed he had been targeted by the United States. His lawsuit named, among others, the CIA and Department of Defense. The case was ultimately dismissed without a judicial finding that the United States had targeted him: the government invoked the state-secrets privilege, and later appellate proceedings concluded that the complaint had not plausibly established that the strikes were attributable to the United States or specifically aimed at Kareem.

Why this matters: the Kareem case illustrates the constitutional and technical problem created when secret targeting systems use communications, metadata, location and association information. Even where a plaintiff cannot prove that he was targeted, the combination of secret criteria, classified evidence and lethal-force authorities creates a profound due-process question. Privacy therefore cannot be reduced to hiding message content; it must also address metadata, association and traffic analysis.

Federal complaint — Zaidan & Abdul Kareem v. U.S. officialsU.S. District Court — Kareem case and state-secrets dismissalWashington Post — journalist’s challenge to alleged kill-list placement

Pegasus: when a phone becomes an intelligence sensor

The Israeli company NSO Group developed Pegasus, a commercial spyware platform capable of turning a compromised smartphone into an extraordinarily invasive surveillance device. Amnesty International and Citizen Lab have documented Pegasus targeting of journalists, activists, human-rights defenders and political figures. Their research linked a Saudi-associated Pegasus operator to targets including dissidents and journalists, and found that people close to murdered Washington Post columnist Jamal Khashoggi were selected for or infected with Pegasus before and after his killing. Khashoggi’s fiancée Hatice Cengiz was found to have Pegasus on her phone four days after his murder; Amnesty also reported targeting of his wife and son. NSO Group has denied that its technology was connected to Khashoggi’s murder.

The distinction matters: public forensic evidence does not establish that Pegasus itself “assassinated” Khashoggi or that it was the causal tool that led his killers to him. What it does establish is a broader and deeply troubling pattern in which highly invasive commercial spyware has been used against dissidents, journalists and civil society. Citizen Lab has specifically warned that surveillance targeting and targeted violence have appeared in the same environments, which is why abuse of zero-click and zero-day capabilities is a human-rights issue as well as a cyber-security issue.

Jamal Khashoggi and the Saudi leadership — user-supplied video

The U.S. intelligence community publicly assessed in 2021 that Crown Prince Mohammed bin Salman approved an operation to capture or kill Jamal Khashoggi. The video above is commentary; the primary intelligence assessment is linked separately.

The historical assassination record is real — and specific

There is no basis for the blanket statement that U.S. intelligence agencies “kill anyone who opposes them.” There is, however, an extensive declassified record of assassination planning and covert-action doctrine that deserves to be discussed accurately. The U.S. Senate’s Church Committee documented CIA plots involving Fidel Castro and other foreign leaders. A declassified 1954 CIA document titled A Study of Assassination discussed covert killing techniques, including contrived accidents. Operation Northwoods is also frequently cited in discussions of false flags, but attribution matters: it was a 1962 Joint Chiefs of Staff proposal to manufacture pretexts for intervention in Cuba, not a CIA plan, and it was never implemented.

Hitmen / covert-action commentary — user-supplied video

Video commentary is not itself evidence; the historical claims on this page are sourced separately.

Missing and deceased U.S. scientists: investigation, facts and speculation

In April 2026 the U.S. House Committee on Oversight and Government Reform formally requested information from NASA, the FBI, the Department of Energy and the Department of War about a cluster of missing or deceased people connected to nuclear, aerospace and other sensitive research. The committee itself described the underlying public reporting as unconfirmed. That distinction is essential: the existence of an inquiry does not prove a common cause, an intelligence operation or an “industrial complex” assassination program.

News coverage of the scientist cases

Maj. Gen. William Neil McCasland

The retired Air Force Research Laboratory commander disappeared from Albuquerque on February 27, 2026 and remains listed as missing. Public speculation has focused on his aerospace and classified-program background, but law enforcement has not established that his disappearance was caused by his research or by an intelligence agency.

Monica Jacinto Reza

The JPL materials-processing engineer disappeared while hiking in the Angeles National Forest in June 2025. She remains missing. Reporting has described professional overlap with Air Force-funded advanced-materials work, but no public evidence establishes an intelligence operation.

Michael David Hicks

Hicks worked at JPL from 1998 to 2022 and specialized in comets and asteroids, including DART, NEAT, Dawn and Deep Space 1. He died in July 2023 at age 59. A cause of death was not made public in the memorial sources we reviewed. His documented research was planetary science, not anti-gravity.

Nuno Loureiro

The MIT fusion and plasma physicist was murdered in December 2025. This case should not be presented as evidence of a secret scientist-elimination program: authorities linked his murder to the same suspect responsible for the Brown University mass shooting, a former classmate, who later died by suicide.

One name in the broader public discussion that was associated with anti-gravity and exotic-physics research is Amy Eskridge, founder of the Institute for Exotic Science. FOX 11 reported that prior interviews included claims of harassment related to her work. That does not establish that her death was caused by the government, and it would be inaccurate to describe the entire scientist cluster as anti-gravity researchers.

U.S. House Oversight — missing nuclear and rocket scientists inquiryFOX 11 Los Angeles — 11 missing/dead scientists under scrutinyNew Mexico DPS — William McCasland missing-person listingThe Charley Project — Monica Reza case summary and source linksUniversity of Arizona — Michael Hicks memorial and research historyMIT — statement after authorities identified Loureiro’s killer

What we are building: devices intended to make remote infiltration physically impossible

Our security work is based on two separate assumptions. First, if the attacker can own the operating system, firmware or supplied hardware, the defense must move beneath ordinary software into physically enforced trust boundaries and independently verifiable hardware states. Second, if the attacker can learn relationships from metadata even when content is encrypted, privacy has to include traffic-analysis resistance as well as cryptography.

The objective is not “better antivirus.” It is a system in which compromising ordinary software is no longer enough to authorize protected operations, combined with communications that are deliberately difficult to map from timing and volume alone.

Our planned product family extends this architecture to phones, tablets, laptops and desktop computers. The engineering objective is absolute rather than incremental: protected functions should be governed by physical mechanisms and independently verifiable hardware states so that malware, a zero-day exploit or administrator-level software control cannot simply override them. In the project’s terminology, these are devices designed so that the protected security boundary is physically impossible to bypass through software alone, while the communications layer is designed to resist traffic analysis by surrounding real exchanges with continuous cover and decoy traffic.

Release objective: we intend to bring this technology to market as a new class of privacy hardware aimed at ending the familiar cycle in which every software defense is eventually defeated by another exploit. The product goal is a phone or computer that cannot be covertly converted into somebody else’s microphone, tracker or intelligence sensor simply because an operating system, app, firmware component or network service has been compromised.

No responsible security claim should be exempt from testing. We describe the architecture as proprietary and unique to our project and our target is complete resistance to the penetration methods described on this page. Until independent laboratories have evaluated the production hardware against physical attacks, supply-chain tampering, side channels, malicious peripherals, baseband attacks and advanced traffic analysis, “cannot be infiltrated at all” remains our engineering claim and release objective rather than an externally certified fact. The point of the design is to make that claim testable in hardware rather than dependent on trust in software.