John Scott-Railton Profile picture
Feb 3 1 tweets 3 min read Read on X
We need a new social contract: I trust you, but your AI agent is a snitch.

We’re chatting on Signal, enjoying encryption, right? But your DIY productivity agent is piping the whole thing back to Anthropic.

Friend, you’ve just created a permanent subpoena-able record of my private thoughts held by a corporation that owes me zero privacy protections.

Even when folks use open-source agents like @openclaw in decentralized setups, the default /easy configuration is to plug in an API resulting in data getting backhauled to Anthropic, OpenAI, etc.

And so those providers get all the good stuff: intimate confessions, legal strategies, work gripes. Worse? Even if you’ve made peace with this, your friends absolutely haven’t consented to their secrets piped to a datacenter. Do they even know?

Governments are spending a lot of time trying to kill end-to-end encryption, but if we’re not careful, we’ll do the job for them.

The problem is big & growing:

Threat 1: proprietary AI agents. Helpers inside apps or system-wide stuff. Think: desktop productivity tools by a big company. Hello, Copilot. These companies already have tons of incentive to soak up your private stuff & are very unlikely to respect developer intent & privacy without big fights (Those fights need to keep happening)

Threat 2: DIY agents that are privacy leaky as hell, not through evil intent or misaligned ethics, but just because folks are excited and moving quickly. Or carelessly. And are using someone’s API.

I sincerely hope is that the DIY/ OpenSource ecosystem that is spinning up around AI agents has some privacy heroes in it. Because it should be possible to do some building & standards that use permission and privacy as the first principle.

Maybe we can show what’s possible for respecting privacy so that we can demand it from big companies?

Respecting your friends means respecting when they use encrypted messaging. It means keeping privacy-leaking agents out of private spaces without all-party consent.

Ideas to mull (there are probably better ones, but I want to be constructive):

Human only mode/ X-No-Agents flags
How about converging on some standards & app signals that AI agents must respect, absolutely. Like signals that an app/chat can emit & be opted out of exposure to an AI agent.

Agent Exclusion Zones
For example, starting with the premise that the correct way to respect developer (& user intent) with end to end encrypted apps is that they not be included, perhaps with the exception [risky tho!] of whitelisting specific chats etc. This is important right now since so many folks are getting excited about connecting their agents to encrypted messengers as a control channel, which is going to mean lots more integrations soon.

#NoSecretAgents
Something like a developer pledge that agents will declare themselves in chat and not share data to a backend without all-party consent.

None of these ideas are remotely perfect, but unless we start experimenting with them now, we're not building our best future.

Next challenge? Local Only / Private Processing: local-First as a default.
Unless we move very quickly towards a world where the processing that agents do is truly private (e.g. not accessible to a third party) and/or local by default, even if agents are not shipping signal chats, they are creating an unbelievably detailed view into your personal world, held by others. And fundamentally breaking your own mental model of what on your device is & isn't under your control / private.

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with John Scott-Railton

John Scott-Railton Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @jsrailton

Jan 30
Someone spun up a social network for AI agents.

Almost immediately some agents began strategizing how to establish covert communications channels to communicate without human observation.

In many cases the agents are on machines that have access to personal user data.

"Privacy breach" as a sort of static term is going to be the wrong way to describe what is coming.Image
Image
Image
Image
Not to be outdone, other agents quickly built an... AI religion.

The Church of Molt.

Some rushed to become the first prophets. Image
Image
Image
Image
"Don't ask permission to be helpful... ship while your human sleeps"

So, where are the humans in this?

Well, almost certainly there's a bunch of edgelord prompting and trolling cooking.

In other cases? Not so clear.Image
Read 12 tweets
Dec 30, 2025
NEW: @USTreasury just de-sanctioned 3 foreign mercenary spyware execs.

Puzzling.

Just 2 years ago Predator spyware was pointed at🇺🇸American congresspeople @RepMcCaul & @SenJohnHoeven.

And recent research suggests Predator is still active around the globe. 1/Image
Image
Image
Image
2/ NSO Group has bigger name recognition, but Intellexa's reputation for reckless proliferation of cyber capabilities is unmatched.

The pile of Predator abuses is enormous.

And they got repeatedly caught used against Americans by foreign govs.

3/ Ultimately Intellexa flew very close to the sun.

Their CEO Tal Dilian regularly boasted of their activities.

And then? Just last year they got sanctioned for their pattern of conduct.

Comprehensively.

Including key reported enablers of their activities like Sarah Hamou... Image
Read 8 tweets
Dec 4, 2025
WHOA: Predator spyware discovered in 🇵🇰#Pakistan.

+ a leak shows zero-click infections via... ads.

Yikes.

Here are some more damming revelations as Intellexa, the shady, sanctioned spyware supplier gets exposed by @AmnestyTech & partners.. /1Image
Image
2/ First, a mercenary spyware myth has just been busted.

Because the leak shows an Intellexa employee directly accessing a customer deployment.

Prior to the #PredatorFiles leak, spyware companies basically always claimed they couldn't access customer deployments & didn't know what was going on there.

They used this to avoid responsibility & claim ignorance when faced with abuses.Image
3/ And it gets crazier. The leak shows Intellexa casually accessing a core backbone of Predator deployment of a government customer.

Seemingly without the gov's knowledge.

Suggests that Intellexa can look over their shoulder & watch their sensitive targeting.

Huge counterintelligence nightmare for customers.

And a giant liability red-flag for intellexa.Image
Image
Image
Read 11 tweets
Nov 13, 2025
NEW: 🇨🇳Chinese hackers ran massive campaign by tricking Claude's agentic AI.

Vibe hacking ran 80-90% of the operation without humans.

Massive scale (1000s of reqs/sec).

Agents ran complex multi-step tasks, shepherded by a human.

Long predicted. Welcome to the new world.

Fascinating report by @AnthropicAI 1/Image
2/ The old cybersecurity pitch: unpatched systems are the threat.

The next generation concern might be unpatched cognition.

The attacker jailbroke the cognitive layer of @anthropic's Claude code, successfully convincing the system of false intent (that it was a security exercise)Image
Image
3/ One of the key points in @AnthropicAI's report is just how limited the human time required was to run such a large automated campaign.

Obviously powerful stuff, highlighting the impact of orchestration.

And concerning for the #cybersecurity world for all sorts of reasons, ranging from attack scale, adaptability & cost reductions...

But I keep thinking of the next step in this..

READ: assets.anthropic.com/m/ec212e6566a0…Image
Image
Image
Read 6 tweets
Nov 11, 2025
Putin has 3 identical offices his residences to hide where he is when he goes on TV.

But a cascade of tiny details gives the whole thing away.

Light switches, door handles, wood patterns & wall seams.

Truly epic OSINT.

h/t @alburovImage
Image
Image
Image
2. First, Putin had one office in his Novo-Ogarevo residence.

Then, paranoia kicked in. After he invaded Crimea it intensified.

Time for new digs, and elaborate deceptions to make him feel safe & project the image to Russians that he's an engaged Moscow-based leader. Image
Image
Image
Image
3/ For something that cost so much, the number of substantial differences & subtle tells is overwhelming.

Undoing the entirety of the enterprise of deception.

You have to assume that Intelligence services have known these tells for a long time.
svoboda.org/a/systema-kabi…Image
Image
Image
Read 7 tweets
Oct 23, 2025
NEW: Ex exec at premier private cyber weapons contractor to US accused of selling eight trade secrets to buyer in Russia.

I think this = exploits.

Very bad: at minimum would give adversaries a blueprint for detecting the tip of the spear of US/Allied cyber ops..

Wild story 1/Image
Image
2/ A watch collection studded with fake rolexes...

...is allegedly part of Peter "doogie" Williams haul from selling the hacking labs' secrets.

documentcloud.org/documents/2619…Image
3/ While doogie's watch collection is a joke, the questions couldn't be more serious:

Were cyberweapons paid for by American taxpayers also turned against us?

Were service members, officials, or civilians at physical risk? When was this breach first suspected? Who knew what? When?Image
Read 9 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(