Skip to content

NeXuS Fireside Chat 003

2026-03-21 — POINT2POINT, Modular Architecture, and the Foundation


The Desktop First

Before the frameworks came the desktop. labwc on Alpine — battered, patched, survived more than it should have. But it boots. It runs. And today it got a little more NeXuS.

  • Bottom panel removed
  • nwg-menu wired to the Applications button — categorized, grouped, clean
  • Weather widget pulled — not because it was broken but because it was a POINT violation
  • That conversation led somewhere important

POINT — Points Of Identifying Network Telemetry

It started with a weather widget.

The widget polls wttr.in every 30 minutes. wttr.in determines your local weather by your IP address. Your IP maps to a city. That city is you. Every 30 minutes, on a schedule, your desktop broadcasts a heartbeat to a third-party logging server.

That is not a weather widget. That is a surveillance transaction.

POINT was born from that observation.

If it talks out, it talks about you. If it talks back, it confirms you.

The five categories:

POINT Definition
P Physical Location — IP geolocation, GPS, timezone
O Operational Pattern — cadence, timing, session rhythm
I Identity Anchor — User-Agent, device ID, real name, persistent cookies
N Network Path — exit node, ISP, routing topology
T Technical Profile — OS, software versions, desktop environment

Each letter is a named violation. The name IS the definition.


POINT2POINT — The Framework

Every transaction has two ends. Both ends expose you.

Outbound POINT — what you reveal by making the request Inbound POINT — what is confirmed about you by the response

Between those two points is a complete surveillance transaction. Origin. Destination. Timing. Content. Confirmation of receipt. All logged. All linkable. All permanent.

POINT2POINT is the NeXuS framework for scoring, classifying, and measuring that exposure. It is not a doc. It is not a policy. It is a reproducible mathematical system.

Total Violation  =  100   (Google login, real name, real IP, no mitigation)
Total Protection =  0     (Zero POINTs triggered, both directions)

Everything between 0 and 100 is a measurable, named state.


The Point System

Each POINT triggered scores +1 outbound, +1 inbound.

Raw Score    =  Outbound (0-5) + Inbound (0-5)  =  max 10
Multiplier   =  x1 user-initiated / x2 automatic / x3 persistent
Final Score  =  Raw x Multiplier

Weather widget: 20 POINT2POINT. Removed.

Mitigation credits reduce the score:

Mitigation Credit
Tor routing -2
I2P routing -2
Medusa routing -1
User-initiated only -1
Self-hosted -2
Encrypted transport -1

Threat Capability Tiers

Named by capability. Not by agency. Jurisdiction-independent.

Tier Max Score Capability
APEX 0 Full signals intelligence, ISP access, legal compulsion
PURSUIT 2 Active targeted deanonymization, correlation attacks
HARVEST 10 Bulk behavioral profiling, data brokers
OBSERVE 20 Network-level visibility, traffic analysis
SCAN 40 Opportunistic automated attacks
OPEN 100 No adversary, total violation baseline

The Protocols — Not a Monolith

POINT2POINT is a framework. Inside it are focused protocols. Each one does one thing. Each one stands alone.

POINT2POINT Framework
├── POINT-DEF    — defines the 5 categories
├── POINT-VIO    — the violation table
├── POINT-PRO    — the protection table
├── POINT-SCORE  — the math
├── POINT-MODEL  — threat model definitions
└── POINT-WATCH  — live monitor and alert system

When POINT-WATCH detects a violation it fires:

🔴 P2P VIOLATION DETECTED
Process:  nwg-panel → wttr.in:443
Score:    20 POINT2POINT  [AUTOMATIC x2]
Violated: P · O · I · N · T
Ceiling:  0 (APEX) ← YOU ARE OVER

NeXuS is Lego

Every component snaps together but works alone. Pull out POINT-WATCH — it runs anywhere. Pull out Medusa — it runs anywhere. The power is in the combination. Not the dependency.

Standard interface. Complete by itself. Portable to any node.


What NeXuS is Not

The conversation went to Qubes. It went to Whonix. It went to VMs.

Qubes solves isolation. Whonix solves anonymity. Together they close most of the gap. NeXuS is not here to rebuild what they built.

NeXuS is the layer they don't have:

  • POINT2POINT framework
  • Medusa multi-head routing
  • DIVA distributed identity
  • Nexium economy
  • The Round Table — no hierarchy, no kill switch
  • mewe — sovereign identity inside a collective
  • The vision

NeXuS is not an OS. Not a VM. Not a distro. NeXuS is what you build on top of the foundation.

But before we go further defining what NeXuS is not — we circle back to what NeXuS is.


To Be Continued — Core Principles Session

Next: NeXuS core, principals, statement of purpose. Lock the foundation before building higher.


"Together Everyone Achieves More" Sane • Simple • Secure • Stealthy • Beautiful