NeXuS Fireside Chat 003¶
2026-03-21 — POINT2POINT, Modular Architecture, and the Foundation
The Desktop First¶
Before the frameworks came the desktop. labwc on Alpine — battered, patched, survived more than it should have. But it boots. It runs. And today it got a little more NeXuS.
- Bottom panel removed
- nwg-menu wired to the Applications button — categorized, grouped, clean
- Weather widget pulled — not because it was broken but because it was a POINT violation
- That conversation led somewhere important
POINT — Points Of Identifying Network Telemetry¶
It started with a weather widget.
The widget polls wttr.in every 30 minutes. wttr.in determines your local weather by your IP address. Your IP maps to a city. That city is you. Every 30 minutes, on a schedule, your desktop broadcasts a heartbeat to a third-party logging server.
That is not a weather widget. That is a surveillance transaction.
POINT was born from that observation.
If it talks out, it talks about you. If it talks back, it confirms you.
The five categories:
| POINT | Definition |
|---|---|
| P | Physical Location — IP geolocation, GPS, timezone |
| O | Operational Pattern — cadence, timing, session rhythm |
| I | Identity Anchor — User-Agent, device ID, real name, persistent cookies |
| N | Network Path — exit node, ISP, routing topology |
| T | Technical Profile — OS, software versions, desktop environment |
Each letter is a named violation. The name IS the definition.
POINT2POINT — The Framework¶
Every transaction has two ends. Both ends expose you.
Outbound POINT — what you reveal by making the request Inbound POINT — what is confirmed about you by the response
Between those two points is a complete surveillance transaction. Origin. Destination. Timing. Content. Confirmation of receipt. All logged. All linkable. All permanent.
POINT2POINT is the NeXuS framework for scoring, classifying, and measuring that exposure. It is not a doc. It is not a policy. It is a reproducible mathematical system.
Total Violation = 100 (Google login, real name, real IP, no mitigation)
Total Protection = 0 (Zero POINTs triggered, both directions)
Everything between 0 and 100 is a measurable, named state.
The Point System¶
Each POINT triggered scores +1 outbound, +1 inbound.
Raw Score = Outbound (0-5) + Inbound (0-5) = max 10
Multiplier = x1 user-initiated / x2 automatic / x3 persistent
Final Score = Raw x Multiplier
Weather widget: 20 POINT2POINT. Removed.
Mitigation credits reduce the score:
| Mitigation | Credit |
|---|---|
| Tor routing | -2 |
| I2P routing | -2 |
| Medusa routing | -1 |
| User-initiated only | -1 |
| Self-hosted | -2 |
| Encrypted transport | -1 |
Threat Capability Tiers¶
Named by capability. Not by agency. Jurisdiction-independent.
| Tier | Max Score | Capability |
|---|---|---|
| APEX | 0 | Full signals intelligence, ISP access, legal compulsion |
| PURSUIT | 2 | Active targeted deanonymization, correlation attacks |
| HARVEST | 10 | Bulk behavioral profiling, data brokers |
| OBSERVE | 20 | Network-level visibility, traffic analysis |
| SCAN | 40 | Opportunistic automated attacks |
| OPEN | 100 | No adversary, total violation baseline |
The Protocols — Not a Monolith¶
POINT2POINT is a framework. Inside it are focused protocols. Each one does one thing. Each one stands alone.
POINT2POINT Framework
├── POINT-DEF — defines the 5 categories
├── POINT-VIO — the violation table
├── POINT-PRO — the protection table
├── POINT-SCORE — the math
├── POINT-MODEL — threat model definitions
└── POINT-WATCH — live monitor and alert system
When POINT-WATCH detects a violation it fires:
🔴 P2P VIOLATION DETECTED
Process: nwg-panel → wttr.in:443
Score: 20 POINT2POINT [AUTOMATIC x2]
Violated: P · O · I · N · T
Ceiling: 0 (APEX) ← YOU ARE OVER
NeXuS is Lego¶
Every component snaps together but works alone. Pull out POINT-WATCH — it runs anywhere. Pull out Medusa — it runs anywhere. The power is in the combination. Not the dependency.
Standard interface. Complete by itself. Portable to any node.
What NeXuS is Not¶
The conversation went to Qubes. It went to Whonix. It went to VMs.
Qubes solves isolation. Whonix solves anonymity. Together they close most of the gap. NeXuS is not here to rebuild what they built.
NeXuS is the layer they don't have:
- POINT2POINT framework
- Medusa multi-head routing
- DIVA distributed identity
- Nexium economy
- The Round Table — no hierarchy, no kill switch
- mewe — sovereign identity inside a collective
- The vision
NeXuS is not an OS. Not a VM. Not a distro. NeXuS is what you build on top of the foundation.
But before we go further defining what NeXuS is not — we circle back to what NeXuS is.
To Be Continued — Core Principles Session¶
Next: NeXuS core, principals, statement of purpose. Lock the foundation before building higher.
"Together Everyone Achieves More" Sane • Simple • Secure • Stealthy • Beautiful