Montréal Contre-information
Montréal Contre-information
Montréal Contre-information

The Server Called Paranoia: Defend Autistici/Inventati

 Comments Off on The Server Called Paranoia: Defend Autistici/Inventati
Aug 292026
 

From Sabot Media

For twenty-five years, an Italian hacker collective has built communications infrastructure designed to survive censorship, surveillance and police raids. On August 26, the United States designated it a terrorist organization. On September 25, the wind-down period ends.

It should have been a dark and stormy night in an Italian hacklab.

It was, annoyingly, a beautiful sunny Sunday.

On March 3, 2001, roughly ten people gathered at the LOA hacklab in Milan around a computer assembled from discarded machinery. A bank had sold them an old server for the symbolic price of 15,000 lire, about eight dollars. They expanded it with scavenged components, including a hard drive pulled from someone’s home computer. Nobody arrived with a formal blueprint. Software packages were considered one at a time. Every decision was discussed until everyone agreed. Deliberately, the least technically experienced person was placed at the keyboard. The process took far longer than necessary because efficiency was not the only objective. Everyone was supposed to understand what they were building. That day, one participant later recalled, was when they declared: “A/I now exists.”

They named the machine Paranoia. The following month it went online, carrying two domains and two intertwined histories: Autistici.org and Inventati.org. Twenty-five years later, on August 26, 2026, the United States designated Autistici/Inventati a Specially Designated Global Terrorist and placed it on the Specially Designated Nationals and Blocked Persons list.

The distance between those two events—from a recycled machine in a Milan hacklab to the machinery of the American national-security state—is the history of a collective that has spent a quarter century insisting upon one dangerous proposition:

People should be able to communicate without first surrendering themselves to corporations or governments.

The immediate threat now has a date. On September 25, the temporary U.S. authorization for institutions to wind down their relationships with A/I expires. Banks, technology companies, hosting providers and other institutions are being instructed to sever what remains. A/I built its infrastructure to survive the disappearance of a server. The United States is now attempting to make the collective economically and technologically untouchable. Join us as we explore what A/I is, its history, and what this newest attack might mean for the autonomous tech collective and the wider radical community.

Before A/I: Italy’s underground internet

Autistici/Inventati did not appear from nowhere. Its roots run through more than a decade of Italian autonomous organizing, pirate radio, bulletin-board systems, squatted social centers, anti-capitalist movements and experimentation with computers as political tools. During the 1990s, networks such as the European Counter Network and Isole nella Rete provided online space for social movements when the internet remained unfamiliar to much of the public. Italy’s Hackmeetings brought programmers, activists, artists and the technologically curious together inside self-managed spaces. Hacklabs appeared in occupied social centers, where people could learn Linux, build networks and approach technical knowledge as something to be shared rather than sold. The future members of A/I came from several parts of this world. In Milan, people associated with the LOA hacklab used the name Autistici to describe their intense fascination with technology and their desire to expose the politics concealed inside it. In Florence, the Inventati project was more oriented toward communication, publishing and movement organizing. Its projects included Stampa Clandestina, a newspaper intended to be pasted directly onto city walls, and Spia la Spia, an effort to map surveillance cameras in public places.

People from Bologna and elsewhere were also involved. Many participated in the early development of Indymedia Italy, part of the international open-publishing network that allowed protesters and ordinary participants to report events without waiting for professional journalists to mediate them. The different groups shared a problem. Movements increasingly needed websites, mailing lists and private email, but independent infrastructure remained scarce. The existing European Counter Network was carrying too much of that burden. Commercial providers offered greater capacity, but at the price of money, dependence, surveillance and eventual censorship. In November 2000, Inventati sent the Milanese hackers an encrypted email asking to meet. The message was treated like something out of an amateur spy film: PGP keys, carefully arranged recognition instructions, a secret time and place. Then the Florentines arrived two hours late in a legendary rust bucket called the General Lee, honking outside the squat while police monitoring the building watched in bewilderment.

The agreed-upon historical fact is that everyone eventually ate at a pizzeria called La Balena. Over dinner, the Florentines revealed their allegedly seditious plan:

Build another autonomous server.

The intention was not to replace existing movement infrastructure with a new central provider. It was to multiply it. If there were thousands of autonomous servers, they reasoned, no single raid or seizure could shut down everyone’s communications. Autistici supplied much of the technical knowledge. Inventati brought its experience with publishing, cultural work and movement communication. Together they became Autistici/Inventati, usually shortened to A/I. The collective’s legal association was called Investici, but A/I never became a conventional organization. It had no coordinator, official leader or permanent spokesperson. Decisions were made collectively rather than by majority vote. Nobody was paid. Its resources came from voluntary donations, benefit events and the labor of the people maintaining it. The dual name was deliberate. A/I was a Janus-faced creature: one face technical, the other communicative; one facing the machine, the other facing the movements that needed it.

The server that locked itself out

The birth was not entirely glorious. On the second day of Paranoia’s existence, someone entered an inverted firewall command and accidentally instructed the machine to reject every connection not originating from itself.

The server could communicate only with the server.

The collective found this so perfectly on-brand that it printed the mistake on a T-shirt. That combination of technical seriousness and refusal of self-importance became part of A/I’s character. Later servers received names including Chernobyl, Astio—“Grudge”—Rivolta, Contumacia and Latitanza: Revolt, Contumacy and Life on the Run. Behind the jokes was a developed political position. Communication should be free and accessible. Knowledge grows through being shared. Software is not neutral simply because it operates in a supposedly virtual world. The systems through which people speak determine who can speak, who can listen, who owns the record and who can be silenced. A/I began providing websites, private email, mailing lists, newsletters and chat. Its services eventually expanded to include Noblogs, file sharing, audio and video conferencing, streaming, anonymous remailing and other communications tools—all without advertising or commercial data extraction.

Its manifesto describes the project in explicitly political terms. A/I is antifascist, anti-capitalist and antimilitarist. It promotes free software, encryption, pseudonymity and the independent circulation of knowledge and cultural work. It reserves its limited, volunteer-run resources for people and projects broadly compatible with those principles rather than businesses, political parties, organized religions or institutions already possessing the means to make themselves heard. A/I was never a politically neutral commercial host. But providing infrastructure is not the same act as authoring everything transmitted through it. Political affinity is not operational control. Giving someone an email account does not mean writing every message they later send. That distinction is central to the attack now being made against it.

Genoa: infrastructure under fire

Only months after Paranoia went online, the G8 came to Genoa. Many A/I participants were also involved with Indymedia Italy. They helped construct the movement’s media center, laying cables, configuring servers and building workstations through which protesters could report what was happening across the city. What followed was historic: enormous demonstrations, the police killing of Carlo Giuliani, indiscriminate beatings in the streets, torture and abuse inside the Bolzaneto barracks and the nighttime raid on the Diaz school. Official narratives competed with photographs, recordings and firsthand testimony transmitted through independent infrastructure. Genoa became one of the earliest major demonstrations to be documented from nearly every direction by its participants rather than exclusively through institutional media.

For A/I, it was also what the collective later called a “traumatic communion.” Its members experienced the same violence together while maintaining systems through which evidence of that violence could escape. After Genoa, A/I was no longer merely an interesting technical experiment. It had become trusted movement infrastructure. Demand grew rapidly. By 2003, A/I hosted more than 2,000 users, 205 websites and 269 discussion lists. Hosting those services for free was becoming unsustainable, while commercial hosting would cost thousands of euros annually. The collective answered with the KAOS tours: traveling gatherings combining benefit events, parties, public discussions and practical workshops. A/I members taught people how to configure servers, encrypt communications, edit and distribute video, create digital archives and stream audio.

The tours raised money, but their deeper purpose was political education. The collective did not want to become a group of invisible experts performing magic for passive users. It wanted the community to understand the machinery upon which it increasingly depended.

Every subsequent attack on A/I would produce a variation on this response:

Disclose what happened. Repair the damage. Share the lesson. Build something harder to destroy.

Trenitalia discovers the Streisand effect

A/I’s first major legal confrontation came in 2004. A design collective called Zenmai had created a website parodying the Italian railway company Trenitalia. It copied the appearance of the company’s website while denouncing Trenitalia’s involvement in transporting tanks and other military supplies during the invasion of Iraq. Trenitalia demanded the page’s removal, damages and publication of notices in two major newspapers at a projected cost of approximately €20,000. A court initially ordered A/I to take the parody down. The internet responded by reproducing it everywhere.

Trenitalia then demanded that A/I remove links to the mirrors as well—an argument raising the absurd possibility that linking to disputed material could make any search engine responsible for it. A/I appealed. On September 14, 2004, the court ruled that the website was protected satire grounded in factual controversy. The page returned, and Trenitalia was ordered to pay A/I’s legal expenses. It was an extraordinary victory for a small volunteer collective. But while A/I fought visible censorship in court, a more dangerous operation was taking place without its knowledge.

The Aruba crackdown

By then, A/I’s server was housed at the commercial provider Aruba in Arezzo. On June 15, 2004, Italian police arrived at Aruba under orders from a Bologna prosecutor. The company’s technicians shut down A/I’s machine and allowed police to copy material from its disks. Investigators obtained its cryptographic certificates and may have installed equipment capable of intercepting traffic. A/I was told that the interruption resulted from an electrical problem. The collective discovered the truth almost a year later, and only by accident.

In May 2005, A/I was ordered to close the mailbox used by the Italian Anarchist Black Cross, Crocenera Anarchica, amid a sprawling investigation involving allegations of anarchist conspiracy and subversion. A/I complied with the court order and requested the underlying case documents. Those documents contained messages that investigators should not have been able to possess. Buried in a footnote was the explanation: police had gone to Aruba the previous year and acquired access to A/I’s server. An operation purportedly concerned with one mailbox had potentially compromised thousands of accounts and tens of thousands of mailing-list subscribers. Among those affected were lawyers and technical experts working with the Genoa Legal Forum. Police may therefore have gained access to confidential defense communications concerning prosecutions arising from police conduct at the G8. The violation exposed a brutal truth. A/I could operate its own server, configure it carefully and refuse to retain identifying logs—but the physical machine remained in someone else’s building. A commercial provider could open the door, surrender its contents and conceal what had happened.

A/I removed the machine from Aruba, cleaned it and restored essential services. Parliamentary questions were raised in Italy and at the European level. The collective traveled through Italy and Europe explaining the breach. Most importantly, it rebuilt the network.

Plan R*: repression becomes architecture

The result was Plan R*, launched in October 2005: a network of “resistant communication.” Instead of concentrating A/I’s services on one machine, the collective distributed encrypted data and functions across servers in several countries. Public-facing machines could be replaced. Services could move when hardware was seized or a provider became hostile. The loss of one node would no longer expose or silence the entire community. R* meant replication, redundancy, resistance and other words beginning with R. Its architecture was conceived not merely to survive mechanical failure but to withstand political attack. A/I did not claim it could guarantee perfect security. On the contrary, it repeatedly warned users never to entrust their safety blindly to any provider, including A/I. It minimized logs and identifying information because information that does not exist cannot easily be seized. It encouraged users to encrypt their own communications because even the strongest server architecture could not compensate for unsafe individual practices.

The collective transformed a covert surveillance operation into an infrastructure lesson.

Repression became architecture.

The Vatican, a satirical video game and Norway

The pressure continued. In 2007, an Italian politician demanded action against Operation: Pedopriest, a satirical browser game criticizing the Catholic Church’s efforts to conceal sexual abuse by clergy. Its creator temporarily removed the game to protect the hosting provider. A/I then hosted a copy. Following a complaint from an unidentified child-protection organization, an American provider disconnected the entire Noblogs server. After consulting attorneys, the provider concluded that the satire was lawful in the United States and restored the machine. Plan R* kept the disputed material accessible elsewhere and limited the wider interruption. By then, A/I had become an important refuge from the emerging commercial social web. Noblogs offered independent publishing without advertising, data mining or demands that people attach their legal identities to everything they said.

Its users included movement organizations, personal writers, dissidents, artists and NGO workers operating in dangerous environments. In 2008, A/I received Italy’s Winston Smith “Privacy Hero” award for creating free communications infrastructure resistant to censorship despite scarce resources, technical attacks and repeated judicial interventions. Then, on November 6, 2010, Norwegian police copied an A/I server’s hard drives at Italy’s request. The investigation originated with threats and antifascist graffiti directed at members of the neo-fascist CasaPound organization. Authorities were seeking information concerning one mailbox. A/I had already explained that it possessed neither subscriber identities nor activity logs, but investigators apparently wanted to determine whether that was true.

Thousands of accounts were copied in the process.

Plan R* restored the affected services elsewhere within approximately two hours. Within twenty-four hours, the network was operating normally. The seized disks were encrypted and yielded no useful identifying information. The operation became a public scandal in Norway. Lawyers, journalists and technology organizations questioned why Norwegian police had copied thousands of people’s private communications in response to an inadequately explained foreign request. The underlying Italian investigation was eventually dropped. Where another organization might have interpreted repeated raids as proof that its project was impossible, A/I interpreted them as confirmation that the project was necessary. Its history is documented in the collective’s book, +KAOS: Ten Years of Hacking and Media Activism, and its own history of the collective.

August 26, 2026

The newest attack is of a different order. On August 26, the U.S. State Department designated Autistici/Inventati a Specially Designated Global Terrorist. At the same time, the Treasury Department’s Office of Foreign Assets Control placed A/I on the Specially Designated Nationals and Blocked Persons list under Executive Order 13224. This is not simply a condemnatory government statement. It activates one of the world’s most powerful systems of economic exclusion. The United States alleges that A/I supplies specialized digital architecture, encrypted communications and hosting to antifascist groups and other radical movements, including organizations already designated by the United States.

Treasury’s public announcement focuses upon the services A/I provides: foreign-hosted websites, encrypted email, chat, video conferencing and the digital architecture supporting Noblogs. It describes A/I’s antifascist and antimilitarist politics, its practice of selecting projects compatible with those politics and its provision of infrastructure used by the PKK. Treasury then treats the provision of that infrastructure as material or technological support for terrorism. (U.S. Treasury announcement) The State Department’s accompanying case goes further, presenting attacks, communiqués and publications that it says passed through A/I infrastructure. Its examples include alleged railway and pipeline sabotage in Europe, attacks on energy infrastructure, Rose City Antifa, resistance to Atlanta’s proposed police-training center, Jane’s Revenge and publications carrying statements attributed to armed organizations. (State Department designation) The government’s public statements do not show that A/I planned those actions, selected targets, transferred weapons, directed the cited groups or authored the material hosted on its systems. They do not establish when A/I learned of any particular act or whether it knew about it before it occurred.

Instead, the designation advances a broader and more consequential proposition:

Building communications infrastructure for radical movements can itself be treated as terrorism.

That theory collapses the distinction between a provider and a user; between political affinity and operational control; between protecting privacy and concealing a crime; between maintaining a publishing platform and authoring everything published through it. A/I has never claimed to be politically neutral. It built infrastructure precisely because radical movements needed somewhere to speak, publish and organize beyond corporate and state control. The United States is now using that purpose as evidence against it.

What happens on September 25

Because A/I is now on the SDN list, all of its property or interests in property within the United States—or possessed or controlled by a U.S. person—must be blocked and reported to OFAC. Unless an exemption or license applies, U.S. people and institutions are generally prohibited from providing or receiving funds, goods or services involving A/I. The restrictions can reach transactions passing through the United States even when the parties are located elsewhere. OFAC has issued a temporary license allowing transactions ordinarily necessary to wind down existing relationships with A/I until 12:01 a.m. Eastern time on September 25, 2026. Payments owed to the collective cannot simply be released to it; they must be placed in blocked accounts. After the deadline, covered transactions require another applicable authorization. September 25 is therefore the date by which American companies and individuals are expected to separate themselves from A/I.

The consequences may include the loss of:

  • Bank accounts and payment processing.
  • U.S.-linked donations and fundraising services.
  • Hosting, cloud infrastructure and upstream network services.
  • Domain registration and related technical services.
  • Certificate, security and email-delivery accounts.
  • Software and communications services.
  • Relationships with non-U.S. providers frightened by American secondary sanctions.
  • Access for people in the United States who currently use A/I’s services.

Foreign companies are not automatically governed by every prohibition imposed upon Americans. But OFAC warns that foreign financial institutions can face secondary-sanctions exposure for knowingly facilitating significant transactions on behalf of a designated entity. That warning may do as much damage as direct enforcement. A European bank, registrar or hosting company may not know precisely what American law demands of it. Its compliance department may simply decide that maintaining a relationship with a small Italian anarchist collective is not worth the perceived risk. Institutions frequently over-comply. Providers may close accounts or withdraw infrastructure even when the law does not clearly require them to do so. Organizations may remove links, avoid correspondence or terminate unrelated relationships merely because A/I’s name now appears on a terrorism blacklist.

That is how American sanctions acquire worldwide force: not only through legal jurisdiction, but through institutional fear.

The wider target is the community around the server

The designation may be directed at A/I, but its effects will not stop at the collective. A/I’s infrastructure is used by writers, organizers, researchers, artists, movement publications and people who chose it precisely because commercial platforms were unsafe, politically hostile or designed to extract their data. Those users are not automatically sanctioned because they have an A/I address or published on Noblogs. But once the provider itself is placed on a terrorism blacklist, ordinary association can be converted into a risk signal. A bank may scrutinize a payment. An email provider may downgrade or block delivery. An employer, border agent or investigator may treat an address as suspicious. A journalist may hesitate to contact a source. A researcher may avoid an archive. A new user may decide that opening an account is too dangerous. None of this requires the government to prosecute every person involved. The designation can produce its own perimeter of fear.

That is one reason this otherwise inexplicable move may be useful to the state even if A/I remains online. Earlier attacks tried to reach the collective through particular machines, mailboxes and providers. A/I answered by distributing its systems, encrypting its disks and retaining less information. Those practices made conventional seizure and surveillance less productive. Sanctions attack a different layer: the relationships that allow infrastructure to exist. Rather than breaking the encryption, the government can pressure banks, registrars, data centers, software companies and users to isolate the people operating it. Rather than prove in court that each user committed an offense, it can make continued contact costly and legally uncertain.

This is surveillance-state power operating through private intermediaries. The government does not need to place an officer inside every server room when compliance departments, payment processors and platforms can be induced to police the network themselves. Each institution will draw its own defensive boundary, often wider than the law requires. Some may demand more identity documents, retain more logs, monitor political content or refuse privacy-preserving projects altogether. Others may quietly close accounts and provide no meaningful avenue of appeal. Enforcement becomes dispersed across companies whose decisions are difficult to see, challenge or even document.

The resulting harm is not limited to censorship. It can change the architecture of movement communication. Small autonomous providers may conclude that serving controversial communities invites existential risk. Larger platforms may point to the designation as another reason to expand identity verification, automated moderation and data retention. Users may migrate from trusted movement infrastructure to commercial systems that are easier to monitor, subpoena and map. The state gains leverage even when it gains no plaintext from A/I’s encrypted disks: people separate themselves, providers collect more information and the social relationships surrounding dissent become easier to observe.

The precedent also reaches beyond explicitly anarchist or antifascist projects. If political alignment with users, privacy protections and the hosting of controversial publications can be assembled into a case that infrastructure itself constitutes support, then encrypted mail providers, radical publishers, community archives, VPNs, federated social networks, legal-support projects and other independent hosts all have reason to pay attention. The immediate facts and laws would differ in every case. The danger lies in normalizing the category: a communications provider no longer treated as a conduit or publisher with its own rights and responsibilities, but as a participant in every act the government attributes to anyone using its systems.

That does not mean the designation is secretly about every A/I user, or that every possible consequence will occur. The government has not publicly explained its internal strategy beyond the allegations in its announcements. But the structure of the action is visible. It replaces a narrow accusation against identifiable conduct with a broad penalty against infrastructure; shifts enforcement from a courtroom to a global web of cautious institutions; and makes uncertainty itself an instrument of control. The immediate objective may be to disable A/I. The wider effect is to warn anyone building communications beyond corporate and state supervision that the shelter they provide can be recast as evidence against them.

Can A/I survive this?

A/I has seen state repression coming for miles.

Its entire infrastructure assumes that:

  • Servers will be seized.
  • Providers will cooperate with police.
  • Governments will demand information about users.
  • Corporations will disconnect controversial material.
  • Individual machines and locations will become unavailable.
  • Data and services must therefore be encrypted, distributed and replaceable.

That preparation matters. A/I is based in Italy, not the United States. Its infrastructure is internationally distributed. Its services are maintained by technically sophisticated volunteers. It avoids dependence on any single provider, minimizes identifying information and has decades of experience restoring services during emergencies. It has no shareholders, corporate headquarters or conventional payroll. Its relatively modest operating costs and volunteer structure give the state fewer familiar pressure points. There is little reason to assume that the website, mail system or Noblogs will simply disappear on September 25. A/I may be better equipped to survive a seized or disconnected machine than nearly any communications project of comparable size.

But this is not another server raid.

Plan R* was built to survive machines disappearing. It cannot, by itself, prevent banks from blocking money, registrars from suspending domains or companies around the world from withdrawing services because they fear American penalties.

The designation targets the connective tissue around the servers:

  • Banking.
  • Donations.
  • Domains.
  • Data-center contracts.
  • Bandwidth.
  • Certificates.
  • Software dependencies.
  • International institutional relationships.

A/I has survived technical isolation before. The United States is now attempting financial and institutional excommunication. Its core services may be resilient. Its ability to fund them, replace infrastructure and participate in the broader technological system is at considerably greater risk. What happens after September 25 will therefore depend not only upon the architecture surrounding A/I’s data, but upon the solidarity surrounding A/I itself.

September 25 is not a deadline for silence

The designation is designed to isolate. The answer must be informed, independent and disciplined solidarity. People in the United States should not improvise donations, disguise payments or route resources through another person, organization, currency or country. That could create sanctions exposure for the supporter, the intermediary and A/I itself. The prohibitions can also extend beyond money. Coordinated technical assistance, translation, advocacy, event organization or other services provided to a designated entity may create legal risk.

But September 25 is not a deadline for silence. Independent reporting, criticism, protest, education and political advocacy remain possible. People can tell A/I’s history, examine and challenge the government’s claims, contact journalists and civil-liberties organizations, preserve public materials and independently organize against the criminalization of resistant communications infrastructure. The practical distinction is between speaking and acting independently about A/I and providing funds or coordinated services to A/I. The exact boundaries can be complicated. Anyone contemplating fundraising, replacement infrastructure, public mirroring or direct technical assistance should obtain qualified sanctions counsel. A February 2025 civil-liberties primer on material support and OFAC restrictions also warns that lawful or protected activity can still attract surveillance, investigation, immigration consequences or civil litigation. Supporters approached by law enforcement should decline to answer questions and speak with an attorney.

This article is reporting and political analysis, not legal advice.

What supporters can do before September 25

Tell the history. Share A/I’s story: the hacklabs, Paranoia, Genoa, the KAOS tours, the Trenitalia victory, the Aruba breach, Plan R*, Noblogs and the Norwegian seizure. Do not allow the government’s description to become the only publicly available account of what A/I is. Build a public defense coalition. Ask independent server collectives, digital-rights organizations, hacklabs, free-software projects, radical libraries, independent publishers, journalists, attorneys, researchers and former users to respond publicly. Preserve the archive. Servers can be seized. Domains can be suspended. Hosts can panic. Back up publicly accessible and historically valuable Noblogs writing, along with A/I’s manifestos, technical documents, legal records and movement history. Record source URLs, authorship, publication dates and retrieval dates. Respect privacy, copyright and removal requests. Do not access private accounts or circumvent security. Personal preservation, research archiving and ordinary journalism are not the same as publicly operating replacement infrastructure; anyone considering a public mirror should first seek qualified advice.

Document over-compliance. Record companies, banks, registrars, platforms and institutions terminating services or removing material. Preserve notices and correspondence. The public record should show how far the designation reaches beyond its formal language. Demand answers. Ask digital-rights groups, European institutions and public officials whether they will permit American sanctions to dismantle an Italian communications collective. Ask what protection exists for European infrastructure, users and archives. Organize independently. Hold public discussions about autonomous infrastructure, sanctions, surveillance and material-support law. Publish explainers. Teach encryption. Support independent civil-liberties work opposing expansive terrorism designations. Prepare lawful material support. A/I has historically survived through voluntary donations, but U.S. supporters should not send or reroute money while the designation applies without a clear authorization. Digital-rights and legal organizations can independently investigate lawful support mechanisms, licensing and potential delisting proceedings.

Listen carefully to A/I’s public response while keeping advocacy legally independent. The collective’s statement should inform how its history and circumstances are described. Any coordinated campaign, fundraising channel or direct service requires separate legal consideration. The immediate objective is to make A/I impossible to quietly disappear.

The network called solidarity

A/I has survived corporations demanding censorship, covert police access, confiscated disks, hostile providers, parliamentary attacks and international investigations. The Trenitalia case produced mirrors and a legal victory. The Aruba breach produced Plan R*. Provider censorship produced redundancy.

The Norwegian seizure demonstrated that the network could recover in hours. Each attempt to isolate the collective spread knowledge about how censorship and surveillance operate. Each attack became an opportunity to teach more people how to protect one another. The United States has now transformed that history into a global test. At stake is not only the survival of one Italian hacker collective. It is whether maintaining infrastructure for radical movements can itself be treated as terrorism; whether privacy can be redefined as concealment; whether refusing to collect identifying information can be presented as obstruction; and whether a provider can be held politically and legally responsible for every text, tactic and claim transmitted through its machines.

A/I has spent twenty-five years preparing for the day when a server disappears. It knows how to replace a machine, move a service, restore encrypted data and continue operating after police or providers pull a plug. The United States is attempting something different. It is trying to frighten banks, hosts, registrars, infrastructure providers and supporters around the world into abandoning the collective. Whether that succeeds will depend partly upon A/I’s architecture.

It will also depend upon us.

Between now and September 25, preserve the history. Share the story. Build the coalition. Document the isolation. Teach the tools. Prepare a lawful defense. Do not allow the state to quietly establish that building privacy-preserving infrastructure for dissent is itself an act of terrorism. Twenty-five years ago, ten people gathered around a recycled machine and deliberately took too long configuring it because everyone in the room was supposed to learn. That remains the lesson. Do not leave the knowledge with experts.

Do not leave the infrastructure in one place. Do not leave the targeted to stand alone.

The first server was called Paranoia.

The network it created was called solidarity.


Public statement from Autistici/Inventati:

Today we were made aware that the US Government has targeted a small, volunteer-run, technology collective from Italy with disproportionate sanctions as anyone can read in the Treasury Department Statement, the State Department Statement and the related Executive Order.

We deny all allegations included in the statements, while we strongly affirm our dedication to providing a platform of tools for digital self-defense, addressing the need of free communication for activists and other individuals, groups and associations.

We will not back down, we will keep doing what we have been doing all these years and we will do whatever is in our possibility to counter the false allegations made by a politically desperate administration with the sole intention of swaying people and media attention away from their own violence and warmongering.

Antifascism and anticapitalism are not terrorism. Protesting is not terrorism. And everyone has the right to speak out and to struggle for humanity.

Autistic/Invented Collective — “Socializing knowledge without establishing power”

Stay human.

Tear Out the Eyes of Power and Control! Bixi’s New Cameras Attacked.

 Comments Off on Tear Out the Eyes of Power and Control! Bixi’s New Cameras Attacked.
Aug 242026
 

Anonymous submission to MTL Counter-info

A few of us noticed Bixi has begun installing cameras with motion light sensors at some of their bike stations. We won’t watch idly as more technology and surveillance enter our lives and neighborhoods. We took it upon ourselves to go after one of the cameras, with simple tools, and with the aim of destroying it. The camera was a little higher and tougher than we thought, so we only managed to damage and not destroy it. We are wishing our comrades more success on their first tries!

Signal Problems

 Comments Off on Signal Problems
Jul 012026
 

Anonymous submission to MTL Counter-info

The following are lesser-known problems with Signal that anarchists and other targets of state repression should know about. These issues are known to the Signal developers.

Potentially sensitive information is permanently saved in account databases.

Despite being hidden, the following information is permanently saved.

  • All visible phone numbers: Most Signal users still have the phone numbers of all other chat members from before March 2024, when they could first change their phone number visibility to “no one.”

  • Group metadata: Leaving and deleting a Signal group mainly deletes the messages. The group members, the group name, the group description, the joined timestamp, the last message timestamp, the group ID, the group keys, member labels, the admins, removed members, the group link password, the draft message, the message count, the sent message count, the disappearing message time, and more are permanently saved.

    Example
    "id": "REDACTED",
    "groupId": "REDACTED",
    "type": "group",
    "version": 2,
    "expireTimerVersion": 1,
    "unreadCount": 0,
    "verified": 0,
    "messageCount": 3,
    "sentMessageCount": 2,
    "name": "REDACTED",
    "revision": 8,
    "publicParams": "REDACTED",
    "secretParams": "REDACTED",
    "accessControl": {
      "members": 2,
      "attributes": 2,
      "addFromInviteLink": 4,
      "memberLabel": 2
    },
    "membersV2": [
      {
          "role": 2,
          "joinedAtVersion": 0,
          "aci": "REDACTED",
          "labelString": "REDACTED"
      },
      {
          "role": 1,
          "joinedAtVersion": 1,
          "aci": "REDACTED",
          "labelString": "REDACTED"
      }
    ],
    "pendingMembersV2": [],
    "active_at": null,
    "avatars": [
      {REDACTED}
    ],
    "groupVersion": 2,
    "groupVerifiedNameHash": "REDACTED",
    "masterKey": "REDACTED",
    "profileSharing": true,
    "timestamp": null,
    "needsStorageServiceSync": false,
    "sealedSender": 0,
    "color": "A110",
    "senderKeyInfo": {
      "createdAtDate": REDACTED,
      "distributionId": "REDACTED",
      "memberDevices": []
    },
    "lastMessage": "",
    "lastMessageReceivedAt": REDACTED,
    "lastMessageReceivedAtMs": REDACTED,
    "lastMessageDeletedForEveryone": false,
    "expireTimer": 86400,
    "left": true,
    "pendingAdminApprovalV2": [],
    "bannedMembersV2": [
      {
          "serviceId": "REDACTED",
          "timestamp": REDACTED
      }
    ],
    "markedUnread": false,
    "unreadMentionsCount": 0,
    "draft": "REDACTED",
    "draftBodyRanges": [],
    "draftChanged": true,
    "draftIsViewOnce": false,
    "storageVersion": 27,
    "storageID": "REDACTED",
    "description": "REDACTED",
    "announcementsOnly": false,
    "terminated": false,
    "draftTimestamp": null,
    "draftAttachments": [],
    "messagesDeleted": true
    

  • Contact metadata: Deleting a chat keeps the contact’s name, their ACI (account identifier), their phone number, their about section, their nickname, the last message timestamp, the contact note, the draft message, the message count, the sent message count, the disappearing message time, profile keys, the profile key credential expiration timestamp, and more. Removing a contact only hides it.

    Example
    "id": "REDACTED",
    "serviceId": "REDACTED",
    "type": "private",
    "version": 2,
    "expireTimerVersion": 1,
    "unreadCount": 0,
    "verified": 0,
    "messageCount": 4,
    "sentMessageCount": 2,
    "sealedSender": 1,
    "color": "A110",
    "profileKeyCredential": "REDACTED",
    "profileKeyCredentialExpiration": REDACTED,
    "accessKey": "REDACTED",
    "profileKey": "REDACTED",
    "profileName": "REDACTED",
    "note": "",
    "messageRequestResponseType": 2,
    "profileSharing": false,
    "storageUnknownFields": "",
    "hideStory": false,
    "isArchived": false,
    "markedUnread": false,
    "storageID": "REDACTED",
    "storageVersion": 33,
    "needsStorageServiceSync": true,
    "muteExpiresAt": 0,
    "colorFromPrimary": 2,
    "about": "REDACTED",
    "aboutEmoji": "",
    "sharingPhoneNumber": false,
    "capabilities": {
    "profiles_v2": false,
    "attachmentBackfill": true,
    "spqr": true,
    "usernameChangeSyncMessage": false
    },
    "lastProfile": {
    "profileKey": "REDACTED",
    "profileKeyVersion": "REDACTED"
    },
    "unreadMentionsCount": 0,
    "lastMessage": "",
    "lastMessageReceivedAt": REDACTED,
    "lastMessageReceivedAtMs": REDACTED,
    "timestamp": null,
    "lastMessageDeletedForEveryone": false,
    "expireTimer": 86400,
    "active_at": null,
    "draft": "REDACTED",
    "draftBodyRanges": [],
    "draftChanged": false,
    "draftIsViewOnce": false,
    "draftTimestamp": null,
    "draftAttachments": [],
    "messagesDeleted": true

The only reliable way to delete this information is to delete all Signal app data, then re-register without entering the PIN or restoring data. This also deletes all contacts and messages.

Re-registering with the PIN recovers all contact metadata. From left and deleted groups, it appears to only restore group IDs, keys, icon colors, and some other items, but this is still potentially sensitive information.

Successfully registering an existing Signal account’s phone number takes over or disables the account.

Signal uses SMS authentication. If a person’s Signal account has registration lock disabled, an attacker who can observe or intercept their SMS messages can receive a Signal verification code to immediately take over their account. If registration lock is enabled, they can immediately deregister the person’s device, making them unable to use their account. The attacker can then take over the account in 7 days if the person cannot re-register.

Once the attacker takes over, they receive all messages intended for their target, including group messages, and they can send messages from their account. Contacts see that their safety numbers have changed, but most people ignore these messages. After all, they may simply indicate that the person has reinstalled Signal. The account’s name changes unless the attacker knows the previous name or guesses the PIN, but name changes are very common.

Additionally, deleting a Signal account does not delete it on the Signal servers for 30 days. If someone registers the number during this time, they can immediately access the account. Deleting an account leaves all groups, but they can still send and receive messages as the original user.

These design choices weaken the security and reliability of Signal accounts. Anyone can put a person’s SIM card in another phone. Intelligence agencies intercept most or all SMS messages. Cell site simulators, SS7 attacks, and SIM swaps can also be used to intercept SMS messages.

ACIs are associated with phone numbers on the Signal servers, and they are difficult to change.

ACIs are unique 128-bit numbers that identify Signal accounts to other accounts and to the Signal servers. Accounts save the ACIs of all known accounts. ACIs are not shown in the Signal apps, and they are not mentioned on Signal’s website, but they can be collected and tracked over time and between groups. People can also send messages to ACIs without any other information.

Signal’s servers save ACIs with account phone numbers, so they can give account phone numbers to governments. According to an article by Micah Lee, “If Signal receives a government request for information about an account based on an active username, Signal will be able to hand over that account’s phone number along with its creation date and last connection date.” Looking up an active username simply provides the account’s ACI, so it should be assumed that this is possible. It may have already occurred.

To obtain a new ACI, users need to delete their Signal account for 30 days or use a new phone number.

Other issues

Signal is centralized and runs on Amazon, Microsoft, and Google servers. These companies share massive quantities of data with intelligence agencies. They likely send Signal metadata to the US government, even though Signal probably does not. In addition, because Signal is centralized, it is easier to censor. Many governments already block Signal, and the US government could fully shut it down.

Notifications on iOS, Android, MacOS, and Windows give Apple, Google, and Microsoft the timing of messages. This does not happen on Linux and GrapheneOS.

The timing of message receipts from silent messages can be used to gain information about people’s habits and devices. This is difficult to fully prevent, but the Signal developers do not have a plan to mitigate it. However, using Signal through Tor or a VPN likely reduces the accuracy of this attack.

Alternatives

These do not have all of the same features as Signal, and they are not as well-tested. Like Signal, they are not appropriate for all threat models.

Cwtch is a peer-to-peer encrypted messaging app which uses Tor to avoid surveillance and censorship. It does not require phone numbers, it is more metadata resistant than Signal, it has database encryption, it can use multiple accounts, and it functions with or without servers. It has not been independently security audited. The development team is small and could use support.

Briar is similar to Cwtch, but it also has basic blog, forum, and RSS reader features. It has received security audits, but it does not currently work on Tails or similar systems. In order to chat, two accounts require an exchange of links or QR codes.

Delta Chat is decentralized and does not require phone numbers. It is less metadata resistant than Signal, but it is easy to make new accounts. It does not have forward secrecy, so it is possible to decrypt multiple past messages with a leaked key. The developers plan to add forward secrecy and post-quantum cryptography in late 2026. It can be used with Tor, but UDP features such as calls and multi-client syncing cannot currently use Tor. Signal and most other apps face the same issue.

Other similar alternatives are not currently recommended, except for PGP email if it is necessary. Many other options are currently too experimental, not metadata resistant enough, or not trustworthy enough.

Signal suggestions

For those who continue to use Signal, these suggestions should be evaluated for each threat model. If anonymity and reliability are required, Signal is not the best option.

  • Do not use Signal to organize or protest.
  • Purchase a virtual phone number or a secondary phone plan to use only once for Signal registration. Continue paying for it or change numbers to avoid losing your account. This is not easy to do anonymously, but it is possible.
  • Use GrapheneOS on a supported device. GrapheneOS is more resistant to data extraction tools like Cellebrite than other phone operating systems.
  • Encrypt devices with long random passwords, and turn them off when they are not in use.
  • Use Molly with database encryption.
  • Use Tails, Orbot on GrapheneOS, or a trustworthy VPN. Note that VPNs are not anonymous, and using Signal calls with Tor may leak IP addresses.
  • Verify safety numbers and identities, and treat safety number changes as possible account compromises.
  • Avoid Signal groups with unknown people.
  • Change your Signal settings to better options.
  • Do not link additional devices.
  • Make backup chats in Cwtch, Briar, or Delta Chat.

Further reading

The P.E.T. Guide: New Communication Infrastructure for Anarchists

Refusing Tech-Dystopia: GardaWorld’s AI Camera Tower Toppled in Hochelaga

 Comments Off on Refusing Tech-Dystopia: GardaWorld’s AI Camera Tower Toppled in Hochelaga
Jun 052026
 

Anonymous submission to MTL Counter-info

About a month ago, without any announcement, a large camera tower was placed in the middle of Marche Maisonneuve, Hochelaga. The tower was a new tool of AI camera surveillance developed by the local enemy company GardaWorld. These towers of control are being rolled out all over North America by the thousands by the company’s new subsidiary ECAM. Enraged by the continued encroachment of surveillance technology in our lives and emboldened by a winter full of attacks on cameras in the city, we decided to do something about it.

We went out one night, toppled the tower and destroyed the cameras. We were filled with joy to discover that others had gotten there first, in what was clearly an attempt to burn the tower. ECAM claims that, using AI technology, this tower will alert authorities of suspicious activity before a crime is committed. They clearly failed to do so fast enough.

The tower has since been removed from the square and only scorch marks on pavement remain where it once stood. It’s beautiful. Our only regret is that the tower was tolerated for a whole month. We hope that others, moved by rebellious spirit, don’t leave a single one of these towers standing.

“Because behind every camera are the rich and the powerful, who count on fear to maintain the social peace necessary for their profits”

– From “Why Destroy Cameras”, a poster seen in Hochelaga that we felt inspired by.


CAMOVER

The Cop, the Neo-Nazi, and the Elephant

 Comments Off on The Cop, the Neo-Nazi, and the Elephant
Apr 292026
 

From Projet Evasions

In 2022, we published 2,000 french and 2000 german copies of the first edition of our book “How to defend yourself during a police interrogation.” Since then, the content of our practical guide has continued to spread, taking many forms, such as a workshops we conduct, an “interrogation” supplement for the role-playing game Blade in the Dark and translations into English, and Spanish. The book has now also been reissued in French by Éditions du Commun under the title “A Short Guide to Self-Defense During Interrogations,” as well as an audiobook version, a radio spot, a self-print brochure version on infokiosques.net, and posters illustrating the “broken record” strategy.

In short, we’ve put a lot of effort to share our self-defense advice as widely as possible so that anarchists and other rebels can protect themselves against repression. And it’s not over yet, since translations into Arabic, Italian, and Danish are underway, and our door is always open to anyone who wants to help us to diffuse it or to reach other formats and linguistic-geographic areas.

During this adventure, we’ve gathered three unusual anecdotes we wanted to share publicly —taking this opportunity to remind you once again: protect yourselves from the police; read our book.

1 – The cops

In autumn 2024, during the occupation of the University of Neuchâtel (Switzerland) in support of Palestine, people became suspicious of the strange behavior of one individual present. When confronted, the man admitted to being a police officer, undercover.

Several people at the scene then recognize the person in question. A few weeks earlier, he had gone to the local anarchist library to borrow a book. Not just any book, but our book “How to protect yourseld during a police interrogation”.

When the police officer, still undercover, came to return the book, he reportedly said he found it “interesting, but not really useful and too long.” We can well imagine that, from a police officer’s perspective, it is not really useful to learn how to defend oneself against the police manipulations used during interrogations.

So who knows, maybe our next book will be about attempts by the police to infiltrate our social movements. We promise to keep it as short as possible. We know that police officers don’t like to read.

2The Neo-Nazi

March 2026 in France. Intelligence agencies discover that several neo-Nazis are planning to assassinate another neo-Nazi. The information is passed on to the police, who rush to intervene. “Too bad,” some might say, while others will count the instances where the police failed to take seriously or simply ignored alerts regarding plans for attacks or murders targeting people of color or queer individuals.

In any case, what interests us in this story is what the police found during a search of one of the would-be murderers’ apartments: a manual on how to behave when dealing with the police, particularly during an interrogation1.

That far-right extremists read our book is, unfortunately, nothing new. The PDF of the book was already archived under the “resources” section of a far-right website a week after we published it online. We hope they choke on all the passages that highlight anarchist, decolonial, and queer-feminist perspectives.

Depending on how the investigation unfolds, we’ll see whether reading the book was useful to them or not. In any case, if they don’t end up in prison, they might get murdered by their own comrades. It’s well known that those who sow a macho culture of ultraviolence reap knife wounds in the back.

3 – The Elephant

One could define war as the moment when kings, emperors, governments, and other powerful figures send the poor to slaughter each other. But that would boverlook the enormous number of non-human animals that are forcibly conscripted by humans. Notably, war elephants. These animals—which, believe it or not, are non-war elephants before their capture—are trained in a way that will surely remind you of certain interrogation strategies described in our book.

Every possible means offered by the conditions of captivity will be used to mentally break the elephant. Disruption of sleep and food, loss of the ability to make daily decisions, physical and psychological violence, uncertainty about its future and the duration of this treatment, social isolation, and severing of ties with its family. Once the elephant is deemed completely broken, the trainer—known as the mahout—appears. The mahout brings with him a significant improvement in treatment, thereby creating an empathetic bond that gradually allows him to gain control over the captive elephant and lead it to submit to the trainer’s will.

The same approach, then, as the one used by the police in their “Life Preserver” strategy. In this strategy, everything is set up—through the conditions of detention—to weaken and break down the imprisoned individual as much as possible before their interrogation. The same arsenal of tools offered by detention, adapted for humans. Then comes the cop, bringing a glass of water with a smile, kindly offering to let them make a phone call to the outside world, creating an emotional hold over the detainee, making them feel indebted and thus lowering their defenses. The “Life Preserver” strategy begins.

Within the Evasion Project, we advocate an anarchist analysis of the dynamics of oppression. We believe that these dynamics build upon one another and reinforce each other. Authority deployed against one social group will, in fact, strengthen the domination suffered by another social group. Hence the need to fight them on the same basis: a hatred of all forms of authority and domination, regardless of whom they target—human or otherwise.


1«Le guet-apens de néonazis ciblait un militant… d’extrême droite radicale», Mediapart, 22 mars 2026

The girls don’t want rights, they want freedom ! Coordinated attacks on GardaWorld: 3 sites vandalized

 Comments Off on The girls don’t want rights, they want freedom ! Coordinated attacks on GardaWorld: 3 sites vandalized
Mar 112026
 

Anonymous submission to MTL Counter-info

On the occasion of International Women’s Day (March 8) and International Day Against Police Brutality (March 15), the group Witches Against Power (WAP) simultaneously attacked the facades of three buildings, all linked to the company GardaWorld. This action is a response to the call sent by the River’s Uprisings to attack the architects of the end of the world, to interrupt the normality of domination.

The first site, located downtown (1390 Barré Street), is one of the company’s headquarters, where many armored vehicules dedicated to the transportation of cash are parked. The windows have been coated with a potion of acid and the walls, sprayed with paint. Cameras have been destroyed and the door lock is now filled with crazy glue. The other two sites are the private residencies of two board administrators : François Plamondon (residing at 4450 Sherbrooke Street West) et Jean-Luc Landry (residing at 90 Willowdale Avenue). Their houses have been covered with paint and messages over their entire length. Board members of GardaWorld are not accomplices, they’re perpetrators of the horrors we’re witnessing. Their front doors will be easier to wash than their consciences. The paint on their windows will go away, while the blood on their hands won’t.

GardaWorld is a Quebec company playing an increasingly important and controversial role in the international private security sector. Since 2022, the company has received more than 300 millions of dollars from the Quebec government and 26 millions of dollars from the canadian government (Observatoire pour la justice migrante, 2025). Our « very own company » provides security staff at the Everglades prison in Florida – also known as Alligator Alcatraz – a detention center for migrants, where people who’ve been kidnapped by ICE in the United States are sent. The company is also in charge of surveilling so-called « high-risk » migrants at the Immigration Detention Center of Laval. Here and abroad, GardaWorld has been rooted for years in the immigration detention system. The company watches, controls and imprisons bodies. It reinforces, hardens and militarizes borders. But our sisterhood doesn’t recognize any of them.

Every year in the West, March 8 becomes this day of celebration of women, of festivities even ! We’re offered flowers, we get Facebook posts dedicated to us, we highlight the progress made by companies on their “equity, diversity, inclusion” policies. We hear ridiculous things like “behind every great man, there’s a woman”. We emphasize the “brave resiliency of women in war-torn countries”. But we don’t give a shit about your flowers or your compliments. We don’t want any of these rights that you grant us, nor any other fake form of recognition for that matters. Neither lady cop, nor girlboss, nor stateswoman, we don’t see our integration to “male fields”, as gains from our struggles, but like the bars of a golden cage keeping us at bay of what really matters.

Far from being History’s passive victims, women have been and will still be pillars of the resistance worldwide. We hold camps and fallback positions, just like we hold baricades and frontlines. We are political subjects capable of attack, and what we aim for is nothing less but freedom. Think of that night’s action as proof of that last statement.

Fuck GardaWorld. Fuck the police. Fuck ICE. Fuck borders.

Fuck the control and surveillance of bodies : ours, and all our sisters’.

Witches Against Power (WAP)

ARA Robotique

 Comments Off on ARA Robotique
Feb 252026
 

Anonymous submission to MTL Counter-info

Over the weekend in Hochelaga, a company van belonging to ARA Robotique was burned.

ARA’s drones are equipped with advanced sensors and AI for real-time data analysis. Last year, the Quebec government awarded ARA and Laflamme Aero a subsidy of $8.8 million. These two companies produce drones and remotely controlled helicopters designed to enhance border surveillance.

The Quebec subsidy aligns with pending federal legislation aimed at intensifying Canadian border monitoring, as well as calls from the Trump administration for Canada to strengthen its border security.

With ongoing ICE raids in the U.S. and the expansion of rapid-response networks to protect those targeted by ICE, it is time to target companies and individuals who actively develop technologies designed to control people’s movements across borders.

Love Your Neighbors, Not Your Cameras!

 Comments Off on Love Your Neighbors, Not Your Cameras!
Feb 192026
 

Anonymous submission to MTL Counter-info

Comrades, the time is now! The SPVM hath declared a registry of cameras, with nefarious AI to track our every move! We shall not bow to their surveillance! Take up these posters (FR/EN), these flyers, and these stickers, and spread them far and wide to ignite the flame of resistance! Quickly, fellow travelers, let us strike the ever-watchful eye!

The second round ends March 15th.

[Video] Tear Them Down: CAMOVER 2026

 Comments Off on [Video] Tear Them Down: CAMOVER 2026
Feb 032026
 

Anonymous submission to MTL Counter-info

This winter, teams got together to begin a new season of Camover. Some of them decided to film a few of their achievements.

The SPVM has implemented AI surveillance software that could integrate thousands of cameras both public and private. For attack on the infrastructures of techno-dystopia! Fewer prying eyes, more dead circuits on pavement.

2nd round: from Valentine’s Day to March 15th.

*Always think carefully before filming yourself during an action.

Announcing the Infiltrators Database

 Comments Off on Announcing the Infiltrators Database
Jan 172026
 

Anonymous submission to MTL Counter-info

The No Trace Project has launched a new tool: the Infiltrators Database, a database of cases of long-term infiltrators employed by authorities in the 21st century. It currently references 74 cases from 12 countries, including 5 cases from Canada. The goal of the database is to help anarchists and other rebels better understand how infiltrators operate. For each case we provide a brief description, sources to learn more, as well as the infiltrator’s name and pictures, if available. Access the database:

https://notrace.how/infiltrators

We will maintain the database in the future. If you know of any case that’s missing and that matches our inclusion criteria, feel free to let us know. Find our inclusion criteria here:

https://notrace.how/infiltrators/about.html

For more information on infiltrators and how to defend against them, we recommend our database of resources:

https://notrace.how/resources/#topic=infiltrators-and-informants