RSS Amplifier

RobertO’s Footnotes · Jan 9, 2026

The List

0
Sign in to vote or save

Robert Osborne · RobertO’s Footnotes

This is the seventh in a series exploring the hidden history of crypto: where it came from, who shaped it, and the systems of power it sought to subvert.

In late 1992, Timothy C. May recalled taking a short walk to buy bagels and coffee, discussing an idea with Eric Hughes and John Gilmore. Not a protocol. Not a company. An email list. A shared address where people who cared deeply about cryptography and privacy could argue in public, at speed.

A week later, it existed.

The first welcome message to subscribers included a cautious instruction: do not share the list address yet. The intention was to form a core group first, a slow and deliberate build.

That caution did not last.

Within months, the Cypherpunks mailing list had begun to expand beyond its founders’ expectations. It stopped belonging to anyone in particular. And that loss of ownership would become one of its defining characteristics.

In the earlier articles in this series, cryptography has been moving steadily away from its original home inside states, militaries, and intelligence agencies.

Whitfield Diffie and Martin Hellman had shown in 1976 that secrecy between strangers was mathematically possible without prior trust. David Chaum, in the 1980s, had explored what anonymity might look like in digital systems built to remember everything. Phil Zimmermann, in 1991, released strong encryption to the public and discovered that doing so could attract criminal investigation under laws that treated cryptographic software as munitions.

By 1992, these developments were no longer isolated. They were beginning to overlap.

The World Wide Web was spreading. Email was becoming routine. Personal computers were cheap enough to be common. And the questions people began to ask were changing. It was no longer simply whether secure or anonymous systems were possible, but who would be allowed to build them, and under what conditions.

The Cypherpunks mailing list emerged as a response to that moment. It was intended as a space where abstract arguments about privacy could be tested against implementation, political pressure, and the less comfortable realities of coordination and disagreement.

The choice of an email list was not incidental.

The list made participation cheap and international. The early archives show messages arriving from university domains, telecom companies, and large financial institutions. One April 1993 discussion includes a contributor writing from a major investment bank’s domain, using the phrase “becoming suits” as shorthand for fears that the group might drift toward corporate respectability rather than adversarial independence. Another subscription request from the same period came from a US military domain.

The list was not purely academic, and it was not hermetically sealed from the state. It was porous.

Email also produced a particular social structure. There was no formal hierarchy, but status formed quickly. Those who could explain cryptography clearly, write working code, and sustain long, combative arguments without disengaging became central figures. Authority emerged through persistence and competence rather than appointment.

Anonymity, initially uneven, grew in importance as the list expanded. Early contributors often posted under real names. Over time, pseudonyms became more common, partly out of principle, partly out of caution. Anonymity shifted from being a philosophical preference to a practical defence.

The list grew rapidly. By around 1994, estimates suggest roughly 700 subscribers. By the late 1990s, closer to 2,000. These numbers are approximate, but the trajectory is clear: what began as a core group became a crowd.

With growth came volume. During peak periods in the mid-to-late 1990s, dozens of messages per day were common. The list began to strain under its own success.

By the mid-1990s, splinter lists had appeared. There was an unmoderated version, an unedited feed for those who wanted messages without delay, and a dedicated “flames” list, described in the archives as “for masochists only”. The arguments had become intense enough to require their own containment.

This was not incidental noise. It reflected genuine disagreement over direction, priorities, and purpose.

The list’s most enduring debates clustered around a small number of themes, each tied to a real political pressure.

In 1993, the US government proposed the Clipper Chip, a system that would embed government access into encrypted communications. It was presented as a compromise: strong encryption, but with lawful access preserved.

For many on the list, this was a clarifying moment. It revealed that official acceptance of cryptography was conditional, and that privacy was expected to remain legible to authority. The opposition was not merely technical. It was structural. If privacy required permission, it was no longer privacy.

Anonymity provoked sustained disagreement. Some participants viewed it as essential to free speech and dissent, especially under regimes that punished disclosure. Others worried that anonymity would attract criminal behaviour and discredit the broader project.

This was not a hypothetical concern. The same tools that protected whistleblowers could shield extortionists. The list never settled this question, but it forced participants to confront it repeatedly, without moral shortcuts.

Another recurring tension concerned audience. Systems designed for ease of use invited mass adoption but also simplification, compromise, and eventual capture. Systems designed for committed users remained fragile, niche, and difficult to defend politically.

The list did not resolve this tension. It preserved it, embedding it into the DNA of later projects. Privacy would remain available, but rarely effortless.

The list mattered because ideas did not remain theoretical.

In 1997, Adam Back introduced Hashcash to the list as a way to combat email spam by attaching computational cost to messages. Spam prevention was the immediate aim, but the deeper idea was that computation itself could become a scarce resource.

In 1998, Wei Dai’s proposal for “b-money” circulated on the list, describing a system of pseudonymous money and contract enforcement without central authority. The proposal did not become a product, but it entered a shared vocabulary.

These were not isolated sparks. They were examples of how the list functioned: as a public workshop where proposals were exposed to criticism, refined, discarded, or quietly absorbed. Bitcoin did not emerge from the list directly, but many of its conceptual components had been argued over there, in plain text, years earlier.

Throughout the 1990s, the state’s posture toward cryptography hardened. Export controls, key escrow proposals, and surveillance mandates signalled that privacy would be tolerated only within boundaries defined by institutions.

The list’s response was not primarily protest. Protest was not the objective. The dominant impulse was construction.

This is where Hughes’s line takes on its full meaning:

“Cypherpunks write code.”

It was not a slogan. It was a strategic claim. Code was treated as leverage, a way to make certain forms of control difficult to impose rather than rhetorically contested.

John Gilmore’s well-known remark captured the same logic:

“The Net interprets censorship as damage and routes around it.”

The quote sounds like a law of nature. In practice, it described an intention: build systems that behave as if censorship were a fault, not an authority.

As the decade closed, participation declined. The original list became quieter. Many contributors moved on to projects, companies, or private correspondence. The archives remained, but the centre of gravity shifted elsewhere.

The list did not collapse so much as it dissolved

Its influence, however, did not depend on continuity. It had already seeded protocols, habits of argument, and assumptions about what privacy required. The belief that secure communication should not depend on institutional approval had been normalised among a technically capable minority.

Hughes’s assertion remained as a kind of distillation:

“We know that software can’t be destroyed and that a widely dispersed system can’t be shut down.”

The Cypherpunks were trying to build a world that did not need permission to exist. That was their objective. And measured against that goal, the list did not fail. It changed the terrain on which later battles would be fought.

  • Eric Hughes, “Cypherpunk’s Manifesto” (1993)

  • Cypherpunks mailing list welcome message and early list documentation (1992)

  • Cypherpunks mailing list archives (1992–2000), including April 1993 threads and list offshoot references

  • Timothy C. May recollections on the Cypherpunks group’s formation (archival interview / collected writings)

  • Electronic Frontier Foundation (EFF) archival material on the Clipper Chip and key escrow debates (1993–1994 and later retrospectives)

  • Adam Back, Hashcash announcement to the Cypherpunks mailing list (1997)

  • Wei Dai, b-money proposal circulated via the Cypherpunks mailing list (1998)

  • John Gilmore quote tracing and contemporaneous citations (“The Net interprets censorship as damage and routes around it”)

  • Steven Levy, Crypto: How the Code Rebels Beat the Government (2001)

  • Andy Greenberg, This Machine Kills Secrets (2012)

No posts

Read the original on cheekyrolo.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.