PRP Foundations · artigo 1

IP works. The Internet we built on top of it does not

Collateral blocking, coercible platforms, and pressure on private communications show why the network architecture must be reconsidered.

In 1974, Vint Cerf and Robert Kahn proposed a solution to a problem that was both technical and political: how could networks built with different technologies and run by different organizations communicate without turning one of them into the central network?

Their answer became the foundation of the Internet. Instead of imposing a single infrastructure, the protocol would create a network of networks. Each participant could operate its own infrastructure while sharing a minimal set of conventions for carrying packets.

That choice worked extraordinarily well. Half a century later, IP connects homes, universities, companies, satellites, phones, and data centers. Yet a dispute with one company can remove a social network from an entire country. An IP block aimed at an illegal service can disable innocent services. Protecting a call with encryption can make it incompatible with demands for government supervision.

These episodes have different causes, actors, and mechanisms: technically imprecise blocking, concentrations of power in platforms and infrastructure, and regulatory mandates that put privacy and encryption in tension with the investigation of abuse. They are neither legally nor morally equivalent. They do, however, share one characteristic: network architecture determines which interventions are possible—and who ultimately bears their effects.

IP has not stopped working. We have come to demand things from it—and from the structures built around it—that it was never designed to provide.

The promise of an open network

The networks Cerf and Kahn wanted to connect were incompatible. ARPANET, packet radio, and satellite networks had different characteristics. The solution could not require rebuilding each one.

Cerf later described the goal as universal, non-proprietary, unpatented protocols outside the control of a vendor. Existing networks would not even need to know that they belonged to something larger. A gateway—the ancestor of today's routers—would carry packets between them. (Scientific American)

The core would do relatively little: carry datagrams as flexibly as possible. Functions that required application knowledge would remain at the edges. The important state of a conversation would belong to its participants rather than to intermediary equipment, a property known as fate sharing. (RFC 3724)

This never meant that coordination was absent. Shared protocols, unique numbers, and global parameters always required administration. ARPA, the Network Information Center, IANA, Jon Postel, and later the IETF, regional registries, and ICANN all played coordinating roles.

The distinction matters: interoperability requires coordination, but coordination need not imply sovereignty over participants.

The Internet knows where

An IP address helps the network decide where to send a packet. It does not necessarily identify a person, organization, publication, or even one service. A server can move. Thousands of websites may share an address. A global service may use many addresses at once. A mobile carrier may place thousands of users behind shared addressing.

Nevertheless, infrastructure addresses are used to enforce decisions about content. We intend to reach conduct, a work, or a responsible party, but tell the network to block a location. It is like trying to seize a book by closing the building where someone reported seeing it.

Cloud and content-delivery networks make the mismatch worse. The same infrastructure serves unrelated customers, while one service can move across many providers.

Thiago Ayub and Pedro de Botelho Marcos examined 304 Brazilian blocking orders issued between December 2022 and June 2025, involving about 26,000 domains. Their IX Forum 19 study shows how IP blocking can potentially affect far more domains than the original targets. (Presentation)

This concern is already part of Brazil's principles for Internet governance. The seventh principle in CGI.br's 2009 declaration is the non-liability of network intermediaries: action against unlawful activity should target those directly responsible rather than the means of access and transport. The principle does not remove accountability; it directs it toward the actor while preserving shared infrastructure, freedom, privacy, and human rights. (CGI.br official English edition)

CGI.br is not alone. The European Union's Digital Services Act preserves the mere conduit exemption for intermediaries that only transmit information and prohibits general monitoring obligations. The civil-society organizations behind the Manila Principles similarly argue that intermediaries should not be liable for third-party content they did not modify and that restrictions must be specific, necessary, and proportionate. (European Union, Manila Principles)

The network complies. It simply does not understand the legal meaning of what it carries.

An order aimed at content can affect several services when enforced through an IP block.
An order aimed at content can affect several services when enforced through an IP block.

When a dispute reaches people who are not parties

In August 2024, Brazil's Supreme Federal Court ordered the complete suspension of X in the country until the platform complied with court orders, paid fines, and appointed a legal representative.

The measure did not affect only the company. Individuals and legal entities that used technological workarounds such as VPNs to evade the suspension and continue using X became subject to a daily fine of R$50,000. A panel of the Court confirmed the decision and clarified its reach. (STF)

The decision did not prohibit installing or using a VPN for every purpose. It targeted deliberate circumvention. Even so, people and businesses outside the original dispute between the Court and the platform faced a financial penalty for maintaining a communication that had been lawful until the order.

One can maintain that no company is above the law while still asking whether removing a communications infrastructure from an entire society—and threatening its users with fines—is a necessary and proportionate response to the provider's noncompliance.

The episode reveals a property of platform architecture: when identity, audience, publishing, and distribution belong to one company, controlling that company is an inexpensive way to control all those relationships at once.

When privacy becomes a regulatory incompatibility

In March 2026, Discord completed end-to-end encryption for voice, video, and Go Live sessions. With E2EE, the server helps participants connect but lacks the keys needed to observe their audiovisual content.

In August, following the death of a teenager and an investigation into groups accused of encouraging self-harm and suicide, Brazil's data-protection authority suspended Go Live, screen sharing, and equivalent features. Their return would require demonstrated safeguards and explicit authorization. (Decision No. 3/2026)

Protecting children is a real obligation. Groups that drive victims toward violence cannot be romanticized as free expression. But the decision creates an unavoidable technical question: how can a platform automatically inspect, on its server and in real time, what encryption prevents that server from seeing?

The authority did not literally order a backdoor or client-side scanning. Those would be possible responses, not the text of the order. Other options include identity or age restrictions, user reports with evidence, metadata and behavioral analysis, adding a supervising participant, or removing the feature from the jurisdiction.

There is no neutral architectural choice. Making content available for supervision increases the ability to detect certain abuses automatically, but also makes legitimate communications technically observable. Making it unavailable to the intermediary preserves confidentiality in general, but prevents the server from detecting those abuses by examining content. The architecture does not resolve this conflict: it determines which capabilities exist, who can exercise them, and which risks every participant bears.

A channel is not private merely because it is encrypted. We must also ask what the software observes before encryption and after decryption.

Encryption protects transport while content remains available at both endpoints.
Encryption protects transport while content remains available at both endpoints.

The same control points at different scales

Brazil does not currently have a direct equivalent of China's Great Firewall or Russia's TSPU system. Institutions, scale, permanence, and avenues of challenge are different. Treating them as identical would weaken a serious critique.

The technical control points are nevertheless recognizable.

Citizen Lab measurements document DNS manipulation and other filtering by China's Great Firewall. In Xinjiang, the United Nations documented a much wider system joining device inspection, biometric collection, and surveillance to the detention of members of Muslim minorities. (GFWatch)

Russian providers must install TSPU, an acronym for “technical means for countering threats.” This equipment enables the state to use deep packet inspection to filter, throttle, and reroute traffic from private networks centrally. The physical infrastructure remains distributed while logical control is concentrated.

The lesson is not that every blocking order instantly turns a democracy into an authoritarian regime. Technical capabilities outlive the intentions used to justify them. Infrastructure installed to fight piracy, protect children, or execute a legitimate decision may later be used by another authority, against other targets, with fewer safeguards.

A prudent political architecture asks not only whether today's government can be trusted, but how much power the system would give to the worst possible one.

The gap platforms filled

IP alone did not create this concentration. It did not create social networks, app stores, identity providers, search engines, or global clouds. But it also did not answer needs that became central: proving control of an identity; locating information independently of its host; verifying content without trusting its delivery channel; moving social relationships between services; discovering communities without a sovereign directory; or moderating abuse without preemptively observing every conversation.

Platforms filled these gaps. In exchange for convenience, they came to control accounts, audiences, reputations, and social archives. Packet forwarding remained decentralized while social experience became centralized in applications.

This concentration already supports surveillance at population scale. In 2025, 81 percent of Brazilian Internet users used social networks. Platform privacy policies themselves describe the collection and processing of content, metadata, relationships, interactions, device characteristics, location, and activity received from outside partners. In a report on major social-media and video services, the United States Federal Trade Commission characterized such practices as vast surveillance aimed at monetizing personal information. (ICT Households 2025, Meta Privacy Policy, FTC)

This surveillance no longer results only from commercial choice. Brazil's regulatory framework has added a compulsory layer: age assurance, proactive action, identification of illegal activity and children's accounts, and continuous risk monitoring. Private platforms therefore perform supervisory functions mandated by public authorities in addition to the collection already driven by their own business models. (ANPD — platform obligations)

This does not mean that the state directly and continuously reads every communication. It means that population-scale platforms are required to maintain capabilities to classify, detect, and intervene in user activity. The result is hybrid infrastructure: built in part for commercial purposes, then turned by regulation into a private instrument of compulsory supervision. Data demands and direct state access are an additional layer, not the only way in which public power participates in the system.

Cerf later acknowledged an assumption that did not hold. He had imagined a completely open network in which every computer could interact and each endpoint would defend itself. In practice, firewalls, perimeters, and private networks emerged. (Oral history)

Every layer of protection added intermediaries. Useful intermediaries became necessary intermediaries. Necessary intermediaries became points of coercion.

A working protocol under validation

PRP begins with the finding that building another platform on the same structure of dependency is not enough. That finding has already produced a working protocol. The current effort is not limited to ideation: it is testing behavior, stabilizing interfaces, and consolidating the properties the architecture is intended to provide.

A different architecture would have to separate identity from location, allow content to be verified independently of its source, and make social relationships portable. It would need multiple routes, hosts, and discovery mechanisms. It would need to preserve the opacity of private communication even while recognizing that the same protection can be used for criminal purposes. The protocol does not inspect content and makes it impossible, within the protocol layer itself, to detect or prevent such conduct. Prevention, investigation, and accountability must take place at the endpoints and through institutions outside the protocol, based on lawfully obtained evidence. It would also need to coordinate identifiers and rules without turning coordination into central sovereignty.

Having a working implementation does not close these questions. Peer-to-peer networks can be observed, blocked, or captured. Federated systems can reconcentrate around a few servers. Cryptographic identities may be secure yet difficult to recover or moderate. Replication can preserve legitimate knowledge and criminal material alike.

PRP is therefore in a concrete validation and stabilization phase: protocol, code, and experiments already support the discussion, while some decisions still need to be tested under varied conditions before they can be treated as definitive. This series will follow that process, connecting technical choices to the social and institutional questions that motivated them:

If every global network needs shared standards, identifiers, and decisions, how can they be coordinated without creating a sovereign authority over identity, discovery, publishing, and communication?

That is the next step in this validation journey.