Skip to main content

Private by default

Private by default

As an "Oregon Trail" kid, I literally grew up with computers. From my first IBM PS/2 to my homemade whitebox tower (which was really beige), I was always attracted to computers — building them, using them, and especially defragmenting the hard drives in them. 🙂 But like so many, it was the internet that changed the course of my life.

For the record, I remember a tech time before dial-up, and it was actually pretty fantastic: my floppy-disk era with Prince of Persia and Carmen Sandiego, the CD-ROM years (Myst! Encarta!), and then the inevitable slide into Duke Nukem, Wolfenstein, and the "Barney" version of Doom.

From Mozart to Myspace

But everything took off when I got online for real. As a student at Juilliard, I spent hours in  practice rooms, but during breaks I’d find my way to the Juilliard computer lab, where I’d often hang with my fellow bass playing buddy Miles. Right next to scores by Mozart and Mahler, the lab housed a few computers with a solid internet connection. Along with my well-worn O’Reilly books on Linux sys administration, I felt like an entire world had opened up for me, I was hooked.

Graduating class from Juilliard 2001
Graduating class from Juilliard 2001
Classic O’Reilly books that taught me Linux
Classic O’Reilly books that taught me Linux

I spent hours online, staring at a blank screen or refreshing cnn.com and AskJeeves until inspiration sent me somewhere new. Ultimately, the simple act of browsing (and a night shift job without much oversight) led me to a career: web hosting, cloud computing, and now this.

What I loved most about those early years was the openness. Between Craigslist apartment listings, free news, mailing list archives and web-hosting forum threads, the internet felt like a huge hangout space full of interesting people. One could still feel the culture of the ARPANET humming in the wires:  inherently trusting, curious, and inviting.

Nostalgia only gets you so far

Alas, those days are largely over. 

Memories of a simpler time (even if that was just five years ago) has no real home in an AI-fueled internet. The recent "agent swarm" attack on Hugging Face is a potent signal that we need to rethink our approach. We need to adjust our default online behaviour from “public by default” where the whole point was to be open to connections from anyone or anything, to one centered around privacy, control, and careful curation.

Happily, serious internet builders have honed this approach for decades. Private, point-to-point connections (direct connect, MPLS, and the like) require intentionality around who crosses a boundary, and how, and where. With swarms of murder-hornet-style agents roaming the internet alleys, why would one leave thousands of public endpoints sitting out there? Or trust BGP to route your critical data based on upstream knobs you can’t control?

Of course, today's world is far more complex than it was even five or ten years ago. Workloads are going everywhere, and data is following. Each startup (let alone major enterprise) uses dozens of providers, from Supabase and Descope to Stripe and Anthropic. 

So what's the path forward?

Make it smooth 

Connecting all of this (dare I say “mess”?) is something the internet is shockingly good at, but that convenience comes at a cost. Mainly it’s a loss of control and visibility, which is a small price to pay compared to the alternative: point to point connections, network boundaries, bulky zero trust solutions, and multi day service now tickets to “the network guy” to make changes? Who wants to deal with that?   Who has the time!

Unfortunately, the “encrypt is and forget it” approach that many developers turn to first isn’t great. Humans make too many mistakes, and agents are too good at finding cracks in the seams. The best approach really is to keep everything possible off the public internet as a first line of defense just like you do in your cloud provider VPC… the only trick is how to do that everywhere?

In order to make this possible, our industry has to “meet or beat” the experience of using the public internet in order to add value like policy, privacy, and control.

The Datum approach

We don’t have all the answers, but we’re working on solutions that we think developers and their agents can take advantage of and actually come back for more. 

The first is Connectors, specifically a “dial by key” QUIC tunnel based on the Iroh protocol. This allows you to leverage lightweight, secure connectivity anywhere (a container, an agent, a doorbell, your phone) without using the public internet. True zero trust.

Next up is our Galactic VPC, which is an SRv6 overlay network that gives you a place to land diverse connections, add policy, and squeeze out some good telemetry.  Basically your own private backbone. 

Finally, we’re focusing on making dedicated and virtual Interconnects enjoyable to use. Since nothing beats the public internet better than private, low-latency, fast-lane pipes to all the right clouds, buildings and networks.

We've spent a lot of time making these work well for platform engineers and their agents, but I think our secret sauce is a radical commitment to open source and interoperability. If we're going to help thousands of new clouds and millions of builders participate in the internet the way the big guys do (with real control, private by default) the tooling has to go anywhere.

The open, trusting internet I fell in love with isn't coming back, but I think we can build a better version by inviting thousands of new providers into the private-by-default foundations the big guys use. 

Thousands of new networks. Millions of network-aware builders. All private by default. 

I can see the t-shirts already!