A Web That Never Forgets, Yet Allows Return
A Web That Never Forgets, Yet Allows Return
Trust, causality, repentance, and safety after the individual
How can the web remain free while resisting cyberattacks, fraud, exploitation, terrorist violence, and other serious harm?
The usual answers begin with the individual. One side attempts to protect an isolated person and the information that belongs to that person. The other side attempts to identify, rank, monitor, and exclude dangerous individuals.
I begin from a different premise.
I do not regard the individual as an independent and permanent substance. My Christianity was chosen after encountering Buddhism, not before it. I therefore carry into it the understanding that there is no self standing outside relation, that all things arise through conditions, and that causal relation does not end when a body dies.
I wrote about this experience in I Cannot Die, and about the difference between an isolated individual and a person within relation in The Correct Japanese Translation of “Individual” is “Kojin”.
From this premise, privacy is not an ultimate metaphysical wall around a sovereign self. Death is not the deletion of a node. A changed name, a discarded account, or a new cryptographic key does not erase the consequences of what occurred.
Yet this does not require permanent exile.
The design principle is:
No permanent self.
No erasure of causality.
No permanent condemnation.
Trust begins again from zero.
Return requires a new commitment.
This is the foundation I propose for Kotoba, Kotobase, and a safer web.
1. Earth has become one village
In 1968, Apollo 8 returned the image known as Earthrise. Humanity could see Earth as one bounded world, suspended in darkness, rather than as an indefinitely extensible map. NASA describes that image as a reminder that we are residents of one planet that requires our care.
For most of history, a person or community could imagine escape toward another continent, frontier, colony, or new society. That model is ending. There is no undiscovered continent beyond the network. Information, capital, software, weapons, pathogens, pollution, and consequences circulate around one Earth.
The world is becoming an island society on a planetary scale: a village in which everyone can eventually become connected to everyone else.
The present web is a transitional form. It still permits people and institutions to abandon an identity, jurisdiction, platform, or victim population and reappear elsewhere as though no relation existed. Attackers automate this. Corporations rename themselves. States deny provenance. Accounts are deleted. Evidence disappears. A person expelled from one service returns through another identity with no causal continuity.
A global village cannot depend on that kind of escape.
It needs a memory of relation.
2. The record is eternal; judgment is not closed
The right to be forgotten does not exist in the metaphysical architecture described here. What has entered the world has changed the conditions from which later events arise. Its effects may continue through other people, institutions, language, descendants, software, and memory after the body that initiated it has disappeared.
No technical system can capture the whole of this causality or prove metaphysical eternity. A ledger is not karma. A model is not God. Kotobase can only preserve a bounded and verifiable projection of consequential events.
Within that boundary, however, the rule should be append-only:
- an event is not deleted;
- a statement is attributed to its issuer;
- evidence retains provenance;
- a correction is appended rather than silently replacing the past;
- a false allegation remains visible as an allegation that was later refuted;
- a revoked credential remains visible as a credential whose validity ended;
- a judgment records the policy, evidence, model, uncertainty, and time under which it was made; and
- later conduct may change the meaning of the history without changing the history itself.
This distinction is essential. An immutable record is not an immutable verdict.
If an accusation is recorded, the system must not transform the existence of the accusation into eternal truth. If a model makes an error, the error, challenge, correction, and model update all become part of the causal record. If a person repents and repairs harm, the wrongdoing, repentance, repair, and later life all remain.
The event remains. Its meaning is never sealed forever.
This is also a necessary boundary between the philosophical statement and current law. Existing legal systems may require erasure, restriction, correction, or minimization of personal data. Article 17 of the European Union’s GDPR, for example, establishes a right to erasure under stated conditions and exceptions. A present implementation must comply with applicable law. It should therefore avoid placing raw personal data on an irreversible public ledger. It can preserve lawful commitments, provenance, revocations, and restricted evidence without pretending that a legal deletion makes the underlying causal event never to have occurred.
3. Trust belongs to a relation, not a soul
A single ID rank is the wrong primitive.
It collapses different questions into a number: Is this key controlled by the same actor? Has this person repaid a debt? Is this device compromised? May this agent publish at machine speed? Is this transaction lawful in this jurisdiction? Has this model made reliable evaluations in this domain?
These are not one property.
Trust is a relation among a subject, an issuer, an action, a resource, a time, and evidence. It should be represented as a graph of scoped claims. Each claim needs at least:
| Field | Meaning |
|---|---|
| Subject | the person, persona, device, organization, service, or agent being evaluated |
| Issuer | the entity or model making the claim |
| Scope | the exact action or relationship to which the claim applies |
| Evidence | the observations and attestations supporting it |
| Policy and model | the rule set and evaluator version used |
| Confidence | uncertainty rather than simulated certainty |
| Time | issuance, expiry, and evaluation epoch |
| Causal parents | earlier events and claims on which it depends |
| Status | active, expired, revoked, challenged, corrected, or superseded |
Several identities can be linked to strengthen continuity or assurance. Human Passport, formerly Gitcoin Passport, demonstrates one approach: it aggregates multiple credentials or “Stamps” into a humanity score. BrightID uses a social graph to estimate unique participation. Ethereum Attestation Service provides a more general primitive: structured, signed attestations that may reference other attestations. ERC-8004 proposes identity, reputation, and validation registries for agents.
These projects are useful precedents, but their primitives should not be elevated into a universal measure of human worth. Multiple credentials can establish continuity, uniqueness, or a history of participation. They cannot prove goodness. A cryptographic signature proves who signed a claim, not that the claim is true.
Kotoba and Kotobase should therefore store the claims and their relations, not collapse them into a permanent global score.
4. Repentance is a state transition
Permanent exclusion is not necessary. A person who caused harm must be able to return.
But return cannot mean deleting an account, choosing a new name, and escaping the causal line. That is identity laundering, not repentance.
Repentance is a verifiable state transition:
- The harmful act and its consequences are acknowledged.
- Dangerous or compromised capabilities are revoked.
- Evidence is preserved and affected people can answer.
- Restitution, repair, treatment, surrender, or other remaining obligations are defined.
- The old authority is relinquished.
- A new commitment is declared and witnessed.
- A new cryptographic principal begins a new identity epoch.
- Trust in that epoch begins at zero.
- Capabilities are reacquired gradually through subsequent conduct.
Baptism, ordination, taking vows, and public declaration can express this transition. They mark the death of the old self as an operative commitment, not the deletion of its causal history. Because death is not annihilation, the new epoch remains permanently linked to the old one.
The ceremony does not award trust. It creates the condition under which trust may be built again.
The state after transition is therefore:
| State | After repentance |
|---|---|
| Causal history | preserved |
| Prior claims | preserved with their status and context |
| Remaining obligations | inherited |
| New trust | zero |
| Risk assessment | recalculated, not automatically cleared |
| Capabilities | minimal at first, expanded through evidence |
| New commitment | public, signed, and auditable |
Forgiveness is not forgetting.
Forgiveness means that the past is not allowed to close the future forever.
The wrongdoing remains forever. The acknowledgment remains forever. Restitution remains forever. A lifetime in which the act is never repeated also remains forever. Later good does not erase earlier evil; it changes the complete causal form in which that history is understood.
5. A web without exile still needs strong containment
To reject permanent exile is not to permit unlimited action.
A stolen administrator key must be revoked immediately. Malware must be isolated. Fraudulent transfers must be stopped. Child exploitation material must be preserved and referred through the applicable lawful process. Credible preparation for terrorist violence or financing must trigger proportionate containment, evidence handling, and competent-authority review. A compromised model must lose access to tools and secrets.
The system should restrict the concrete capability through which harm can occur:
| Situation | Immediate response | Path of return |
|---|---|---|
| Stolen account or key | revoke sessions and rotate keys | reauthenticate and recover legitimate authority |
| Bot swarm or denial of service | rate-limit, require cost, isolate traffic | regain quotas through clean behavior and evidence |
| Malware or hostile agent | sandbox, stop tools and network access | submit a changed artifact and pass renewed evaluation |
| Fraud or dangerous transaction | hold the transaction and preserve evidence | resolve identity, authority, restitution, and legal conditions |
| Harmful public content | restrict the specific item and record reasons | correct, contextualize, appeal, or republish lawfully |
| Abuse in an encrypted group | member report, targeted disclosure, key rotation | new participation under a new commitment and group consent |
| Serious organized violence | contain relevant capabilities and use lawful process | never automatic; determined by evidence, obligations, and later conduct |
Public reading should remain open by default. Publishing at machine speed may require rate, provenance, or cost attestations. Accessing medical records requires delegation. Moving regulated funds may require identity and sanctions claims bound to that transaction. Administering infrastructure requires short-lived capabilities and signed receipts.
The rule is:
Do not classify a human being when a dangerous capability can be contained.
The record may be permanent. Enforcement should remain scoped, reasoned, and responsive to new evidence.
6. Privacy is transitional; confidentiality is still necessary
If there is no isolated self, privacy cannot be an absolute metaphysical property owned by that self. Information already exists through relation. In a sufficiently connected world, the fantasy that a life can be made causally private will continue to weaken.
But it does not follow that every byte should be readable by everyone at every moment.
Confession, medical treatment, the location of a victim, a cryptographic key, an unfinished thought, and the evidence in an active investigation require conscious boundaries. Uncontrolled exposure can itself create harm, coercion, spectacle, and mob punishment. A society that publishes every confession immediately may destroy the possibility of honest confession. A system that makes every old failure frictionlessly searchable may claim to permit repentance while making return socially impossible.
Encryption therefore remains necessary, but its justification changes.
It is not a proof that an autonomous individual owns an inviolable private universe. It is a discipline governing when information enters a relation, who may act upon it, and how that access is audited. This is consistent with the boundary principle described in Love as Self-Expansion: non-separation does not eliminate the need for conscious boundaries.
The direction of history may be toward a world in which everyone is connected and much more becomes knowable. The transition must still protect keys, vulnerable people, due process, and the conditions for truthful repentance.
Auditability does not require universal plaintext.
7. LLMs evaluate claims, not eternal persons
The ordinary third-party evaluator in this architecture should be a model or agent, not a permanent human committee.
Models can examine large causal graphs, compare evidence, detect contradictions, identify repeated patterns, and issue signed assessments. They can do this across organizations without giving one platform a monopoly over trust.
But no LLM can observe repentance directly. It cannot see the heart. It can evaluate only the correspondence among declaration, restitution, later action, and available evidence.
Evaluation should therefore be divided among independent roles:
- an evidence agent reconstructs the observable causal sequence;
- a risk agent identifies plausible harm and adversarial behavior;
- an advocate agent searches for exculpatory evidence, alternative explanations, and disproportionate consequences;
- a policy agent maps the case to an explicit rule and jurisdiction;
- an audit agent checks provenance, model versions, conflicts, and procedural integrity; and
- a deterministic authority kernel decides whether the required attestations and capabilities permit the requested action.
The agents issue claims. They do not become sovereign.
For a consequential decision, the receipt should contain the evidence references, policy, model and prompt version, confidence, dissenting assessments, result, scope, and conditions for challenge. A later model may disagree, but it must append a new assessment rather than rewrite the old one.
No evaluator model should directly release a decryption key, transfer funds, delete evidence, or obtain ambient access to external systems. Kotoba should express those effects as explicit capabilities. Kotobase should preserve the request, attestations, decision, key release, external effect, and later review as one causal chain.
Model diversity can reduce correlated error, but it cannot create certainty. LLM-as-a-judge research has documented position, verbosity, and self-enhancement biases. A quorum of opaque models is still opaque unless evidence and procedure remain inspectable.
8. What the architecture can and cannot guarantee
This architecture cannot guarantee that no crime will occur, that every attacker will be detected, that no innocent person will be restricted, or that a declaration of repentance is sincere.
Strong end-to-end encryption also cannot coexist with complete provider-side semantic inspection of all private content. If an intermediary can always distinguish prohibited plaintext from permitted plaintext, the content is not confidential from that intermediary. Safety in encrypted spaces must therefore depend on participant controls, authenticated reports, bounded disclosures, and targeted lawful process rather than a universal decryption capability.
An open identity system cannot prevent every return under a new name. What it can do is make consequential capabilities depend on accumulated, scoped evidence, while a formal repentance transition preserves causal continuity and starts new trust at zero.
Under explicit cryptographic, operational, and governance assumptions, the system can provide:
- confidentiality against unauthorized intermediaries;
- signed provenance and tamper-evident event history;
- scoped and revocable authority;
- multi-party evaluation of consequential actions;
- evidence-preserving correction rather than silent rewriting;
- visible continuity across identity epochs;
- bounded containment when harm is credible; and
- a real path by which a person can return without escaping responsibility.
That is not perfect safety. It is a system in which power, judgment, memory, and return are all constrained.
9. The first Kotoba and Kotobase proof
The first implementation should not begin with a universal identity system or a single global trust score.
It should prove one complete transition:
- A principal requests a protected Kotobase action.
- Kotoba makes every possible effect and required capability explicit.
- Independent agents issue scoped evidence, risk, advocacy, and policy attestations.
- A deterministic kernel returns allow, deny, step-up, quarantine, or defer.
- The resulting capability or key is released only when the policy is satisfied.
- Kotobase records the request, evidence references, decision, effect, and receipt in an append-only causal graph.
- A challenge appends counterevidence and a new judgment.
- If the principal enters a repentance transition, the old capability ends, a new epoch begins at trust zero, obligations remain linked, and later conduct accumulates new trust.
This one round trip would unite cybersecurity, identity, audit, model evaluation, accountability, forgiveness, and freedom without pretending that any of them is absolute.
Declaration
I do not seek a web that forgets.
I seek a web that remembers truthfully: who claimed what, what occurred, which consequences followed, which judgment was made, which error was corrected, which harm was repaired, and which commitment came next.
I do not seek a web that permanently divides humanity into good people and bad people.
I seek a web that stops harmful capabilities, preserves causal responsibility, and always leaves open the demanding path of repentance.
The old self is not deleted. It is transformed by a new vow.
The new identity does not inherit trust. It begins from zero.
The past remains forever. The future remains open.
References
- NASA, Apollo 8’s Iconic Earthrise, photograph taken December 24, 1968.
- NASA, Explore Earth — Apollo 8, on Earthrise and one shared planet.
- NIST, Zero Trust Architecture, SP 800-207.
- IETF, The Messaging Layer Security Protocol, RFC 9420.
- IETF, Certificate Transparency Version 2.0, RFC 9162.
- W3C, Threat Model for Decentralized Credentials.
- Ethereum Attestation Service, Attestations.
- Human Passport, Passport Stamps and Credential Map and Weights.
- BrightID, What is BrightID?.
- De Rossi et al., ERC-8004: Trustless Agents.
- European Union, General Data Protection Regulation, Articles 16–17.
- European Union, Digital Services Act, Regulation (EU) 2022/2065.
- United Nations Office of Counter-Terrorism, Human rights and the rule of law.
- Zheng et al., Judging LLM-as-a-Judge with MT-Bench and Chatbot Arena, 2023.