Skip to main content

Private by default

Private by default

As an "Oregon Trail" kid, I literally grew up with computers.

From my first IBM PS/2 to my homemade whitebox tower (which was really very beige), I was attracted to computers — building them, using them, and especially defragmenting the hard drives. 🙂 But like so many, it was the internet that changed the course of my life.

For the record, I had a rich tech life before dial-up, and it was actually pretty fantastic: my floppy-disk era with Prince of Persia and Carmen Sandiego, the CD-ROM years (Myst! Encarta!), and then the inevitable slide into Duke Nukem, Wolfenstein, and the "Barney" version of Doom.

From Mozart to Myspace

But everything took off when I got online for real.

As a student at Juilliard, I spent hours in the practice room, but during breaks I’d find my way to our tiny computer lab, where I’d hang with my fellow bass playing buddy Miles. Right next to scores by Mozart and Mahler, the lab housed a few computers hooked up to a pretty solid internet connection. Along with my well-worn O’Reilly books on Linux system administration, I felt like an entire world had opened up for me.

I was hooked!

Graduating class from Juilliard 2001
Graduating class from Juilliard 2001
Classic O’Reilly books that taught me Linux
Classic O’Reilly books that taught me Linux

Over the next few years I would spend hours online, staring at a blank screen or refreshing cnn.com and AskJeeves until inspiration sent me somewhere new. Ultimately, the simple act of browsing (and a night shift financial services job without much oversight) led to my actual career: web hosting, cloud computing, and now this.

What I loved most about those early years on the internet was the openness. Between Craigslist apartment listings, free news, mailing list archives and web-hosting forum threads, it felt like a huge hangout space full of interesting people. One could still feel the culture of the ARPANET humming in the wires: inherently trusting, curious, and inviting.

Nostalgia only gets you so far

Alas, those days are largely over. 

Memories of a simpler time (even if that was just five years ago!) have no real home in an AI-fueled internet. The recent "agent swarm" attack on Hugging Face is a potent signal that we need to rethink our approach. I think we need to wholesale adjust our default behavior from “public by default” (where the whole point is to be open to connections from anyone or anything), to a mindset centered around privacy, control, and careful curation. I think this is required not only from security/safety perspective, but also as a step to reinforce our personal agency.

Happily, serious internet builders have honed this approach for decades. We can learn from them! Private, point-to-point connections (direct connect, MPLS, and the like) require intentionality around who crosses a boundary, and how, and where.

Of course, today's world is far more complex than it was even five or ten years ago. Workloads are going everywhere, and data is following. Each startup (let alone major enterprise) uses dozens of providers, from Supabase and Descope to Stripe and Anthropic. 

But with swarms of murder-hornet-style agents roaming the internet, why would you leave thousands of public endpoints sitting out there? Or trust BGP to route your critical data based on upstream knobs you can’t control? I know I don't!

What's a path forward?

Connecting all of this (dare I say “mess”?) is something the internet is shockingly good at, but that convenience comes at a cost. Mainly it’s a loss of control and visibility, which has been a small price to pay compared to the alternative. This is especially true for a the developer and now builder generations, who have largely grown up in public clouds with programmatic networking portfolios.

Unfortunately, the “encrypt it and forget it” approach that most software people turn to first isn’t great. Humans make too many mistakes, and agents are too good at finding cracks in the seams. The best approach really is to keep everything possible off the public internet as a first line of defense just like you do in your cloud provider VPC… the only trick is how to do that everywhere?

In order to make this possible, our industry has to “meet or beat” the experience of using the public internet in order to add value like policy, privacy, and control.

The Datum approach

We don’t have all the answers, but we’re working on solutions that we think developers and their agents can take advantage of and actually come back for more. 

The first is Connectors, specifically a “dial by key” QUIC tunnel based on the Iroh protocol. This allows you to leverage lightweight, secure connectivity anywhere (a container, an agent, a doorbell, your phone) without using the public internet. True zero trust.

Next up is our Galactic VPC, which is an SRv6 overlay network that gives you a place to land diverse connections, add policy, and squeeze out some good telemetry.  Basically your own private backbone. 

Finally, we’re focusing on making dedicated and virtual Interconnects enjoyable to use. Since nothing beats the public internet better than private, low-latency, fast-lane pipes to all the right clouds, buildings and networks.

We've spent a lot of time making these work well for platform engineers and their agents, but I think our secret sauce is a radical commitment to open source and interoperability. If we're going to help thousands of new clouds and millions of builders participate in the internet the way the big guys do (with real control, private by default) the tooling has to go anywhere.

The open, trusting internet I fell in love with isn't coming back, but I think we can build a better version by inviting thousands of new providers into the private-by-default foundations the big guys use. 

Thousands of new networks. Millions of network-aware builders. All private by default. 

I can see the t-shirts already!