<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Resilient on Syst(em)</title>
    <link>https://sy.st/tags/resilient/</link>
    <description>Recent content in Resilient on Syst(em)</description>
    <generator>Leet - sy.st</generator>
    <language>en-US</language>
    <managingEditor>Leet (i[a]sy.st)</managingEditor>
    <webMaster>i[a]sy.st (Leet)</webMaster>
    <copyright>© sy.st</copyright>
    <lastBuildDate>Sat, 29 Aug 2026 13:00:37 +0100</lastBuildDate><atom:link href="https://sy.st/tags/resilient/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Your registrar is European. Is your registry too ?</title>
      <link>https://sy.st/blog/autistici/</link>
      <pubDate>Sat, 29 Aug 2026 13:00:37 +0100</pubDate>
      <author>i[a]sy.st (Leet)</author>
      <guid>https://sy.st/blog/autistici/</guid>
      <description>&lt;h2 id=&#34;introduction&#34;&gt;Introduction&lt;/h2&gt;
&lt;div class=&#34;pFirst&#34;&gt;&lt;p&gt;On 26 August, the US State Department and Treasury designated A/I aka Autistici and Inventati a &amp;ldquo;specially designated global terrorist&amp;rdquo; under Executive Order 13224. A/I is a volunteer collective in Italy that has provided free email, hosting, mailing lists and blogs for activists since 2001. Without any legal proceedings, with just a press release this has shown how centralized and censorable the internet is when a european collective lost its main domain due to US sanctions.&lt;/p&gt;
&lt;/div&gt;
&lt;h2 id=&#34;domain&#34;&gt;Domain&lt;/h2&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;$ whois autistici.org
| status:      serverHold, clientTransferProhibited, serverTransferProhibited, serverUpdateProhibited
| registrar:   Gandi SAS
| expiration:  2029-08-10
| last changed: 2026-08-28T01:57:20Z
&lt;/code&gt;&lt;/pre&gt;&lt;div class=&#34;pFirst&#34;&gt;&lt;p&gt;First, a little bit about the technical consequences of this listing. The registrar of the main domain &lt;code&gt;autistici.org&lt;/code&gt; is still Gandi SAS, a French registrar that was known for its activism. It was a good choice (the one I chose for my website too, btw).&lt;/p&gt;
&lt;p&gt;So why is the website inaccessible when US sanctions do not concern European companies ? Well, the bad choice here was the TLD. The suspension statuses are serverX which mean they were set by the &lt;strong&gt;registry&lt;/strong&gt;, not the registrar. This is because &lt;code&gt;.org&lt;/code&gt; is operated by Public Interest Registry, a US non-profit which makes by extension the .org a domain bound by OFAC sanctions. All of this to say that their main (and probably others are about to follow) domain is suspended and cannot even be moved to a company outside of the US as it will always be under the same .org registry.&lt;/p&gt;
&lt;p&gt;A/I took a lot of technical precautions so that their services were private and resilient. Nothing here makes them less private which is good. However, their resilience plan only ever concerned the servers. As they did have 9 mirror domains but those only used three different tlds with only one being under a tld not owned by a US registry. So they did have redundancy of domains but not redundancy of jurisdictions.&lt;/p&gt;
&lt;p&gt;PS : Maybe giving the tld most-used by human right organizations and activists solely to a US company wasn&amp;rsquo;t a good idea ? I hope most organizations will start to move away from it.&lt;/p&gt;
&lt;h2 id=&#34;but-just-add-a-backdoor-for-the-terrorists-&#34;&gt;But just add a backdoor for the terrorists !!!&lt;/h2&gt;
&lt;p&gt;The US government has not accused A/I of doing anything illegal itself other than providing technical support for illegal acts. It has accused A/I of hosting people who did do illegal things and of filtering its users by political affinity which it factually does.&lt;/p&gt;
&lt;p&gt;If I had to bet the listed allegations are not false and I would trust the US government (I know) on that. However, none of those establish that A/I wrote any of it, knew about it in advance, or had any control over it. The argument is that running the pipe makes you responsible for what goes through. This makes every email provider and ISP a co-conspirator to crimes. This is the reason the simple counter argument to &amp;ldquo;just add a backdoor for the terrorists&amp;rdquo; has always been : you cannot build an exception that only opens for people you dislike, because you will not always be the one holding the key.&lt;/p&gt;
&lt;p&gt;The word &amp;ldquo;terrorist&amp;rdquo; is not a description here. Whoever is in control gets to apply it, and it works on any activist group. If you think that&amp;rsquo;s fine because you don&amp;rsquo;t like anarchists, the only thing standing between you and the same treatment is that the people currently holding the definition happen to agree with you.&lt;/p&gt;
&lt;/div&gt;
&lt;h2 id=&#34;hail-the-free-speech-absolutists&#34;&gt;Hail the free speech absolutists&lt;/h2&gt;
&lt;div class=&#34;pFirst&#34;&gt;&lt;p&gt;For several years now a large part of the US political spectrum has explained to us that deplatforming and the control of online speech is the gravest threat facing civilisation, that private moderation decisions are effectively state censorship, and that the answer to bad speech is more speech which I fully agree with. The United States government has now just deplatformed an email provider by executive order. I now hope all of those US free-speech absolutists will do something about this even though it might be to support a community they despise, because of the argument made previously on the moving definition of &amp;ldquo;terrorists&amp;rdquo;.&lt;/p&gt;
&lt;/div&gt;
&lt;h2 id=&#34;solutions-to-domain-suspension-for-email-providers&#34;&gt;Solutions to domain suspension for email providers&lt;/h2&gt;
&lt;div class=&#34;pFirst&#34;&gt;&lt;p&gt;A solution could have been to use the .it tld as by the time Italy would want to seize their domain they would have had more issues as an Italian organization. But that would still only move the issue to another jurisdiction rather than removing it.&lt;/p&gt;
&lt;p&gt;The only concrete technical solution to this that A/I could have implemented would be onion domains. Those can&amp;rsquo;t be seized as long as the keys are kept secure. This does not replace the domain, and it shouldn&amp;rsquo;t pretend to. A Gmail user will never be able to send an email to a &lt;code&gt;.onion&lt;/code&gt; email address. This isn&amp;rsquo;t a solution for everyday communications but this is a solution that should be implemented by any email provider used by activists or that have governments or police as their threat model. This permits for everyone communicating between those services to go through the onion network and to a .onion domain making communications more secure and private.&lt;/p&gt;
&lt;/div&gt;
&lt;h2 id=&#34;what-you-can-actually-do-to-support-ai--before-the-25-of-september&#34;&gt;What you can actually do to support A/I ? (before the 25 of September)&lt;/h2&gt;
&lt;p&gt;I will not paraphrase what they said, just go read their post : &lt;a href=&#34;https://cavallette.noblogs.org/2026/08/10083/2&#34;&gt;https://cavallette.noblogs.org/2026/08/10083/2&lt;/a&gt;.&lt;/p&gt;
</description>
    </item>
    
  </channel>
</rss>
