Software is a Belief System
Software isn't real. You can't touch it, you can't hold it. It only works because computers "believe" the instructions. And whoever writes the instructions? They have ALL the power. It's like the God-Kings, but with code instead of stories.
The word "software" was coined by Paul Niquette in 1953 to describe "absolute power" over "slavishly obedient hardware." Software is not physical; it's an abstraction that exists only in imagination, controlling physical hardware through abstract signals. This makes it structurally identical to religious or monarchical belief systems.
Software creates a new type of abstract power hierarchy. The administrator who controls the code controls the system. And just like with God-Kings, the controlled population has no physical means of resistance.
Lowery's analysis of software as a belief system (pp. 246-256) draws a structural parallel between software control signals and religious/monarchical authority. Both operate through abstract commands that require "belief" (execution compliance) from the controlled substrate. The etymological origin of "software" as a metaphor for abstract dominance over physical hardware reinforces this parallel.
Six Security Challenges
Software has six big problems that make it impossible to truly secure:
1. Too complex for anyone to fully check
2. No physical limits on what it can do
3. Commands are invisible
4. Changes happen instantly, so you can't watch
5. You can't physically stop an admin
6. One person can control billions of people
And every "security fix" is just MORE software controlled by MORE admins. Turtles all the way down!
The thesis identifies six fundamental security challenges inherent to software systems. Each challenge compounds the previous: infinite state spaces make verification impossible, physically unconstrained designs defy prediction, invisible control signals prevent monitoring, non-continuous state changes escape surveillance, administrators cannot be physically constrained, and the resulting asymmetric power allows a single admin to control billions.
The cumulative effect is devastating: every additional security layer is just more software controlled by more administrators. You can't solve the problem from inside the problem.
Lowery systematically enumerates six software security challenges (pp. 257-272) that collectively demonstrate the impossibility of achieving trustworthy security through logical (software-based) constraints alone. The critical insight is the recursive trap: each security layer introduces new administrators with new attack surfaces, creating an infinite regress problem: "turtles all the way down."
Neo-Technocratic God-Kings
The people who run Google, Apple, Meta, Amazon, and Microsoft are like modern pharaohs. They control what you see, what you buy, who you talk to, and what you're allowed to do, for BILLIONS of people at once. Ancient pharaohs could only dream of that kind of power.
Software administrators of major platforms represent neo-technocratic God-Kings. They data mine populations, A/B test behavioral modifications, and control access to resources billions depend on. A single admin action can affect billions simultaneously, wielding power that exceeds anything ancient God-Kings could imagine.
The "Metaverse" concept represents the logical endpoint: moving populations into fully software-controlled virtual environments where administrators have total, absolute control over every aspect of the user's experience.
Lowery's neo-technocratic God-King analysis (pp. 273-283) maps the four-step God-King creation process onto modern platform companies. He argues that platform administrators exercise abstract power functionally equivalent to, and in many cases exceeding, historical monarchical and theocratic authority. The scale differential is the key: whereas a pharaoh controlled millions, a single platform administrator controls billions.
The Repeating Pattern
Remember how power keeps flipping back and forth? First, the strongest person wins (physical). Then someone invents stories and rules to control people without fighting (abstract). Then people get fed up and fight back (physical again). Then new stories and rules take over (abstract again). This has happened over and over for thousands of years.
Right now, we're stuck in an "abstract" phase. Tech companies control us with code and rules. Wars are already being fought online: hacking, stealing data, spreading lies. But here's the problem: there's no way to push back PHYSICALLY through the internet. You can't punch a hacker through your screen. And that's exactly the missing piece.
Throughout history, the same cycle has repeated: physical power rises to constrain abstract power hierarchies, then new abstract hierarchies form, then physical power rises again to constrain them. Prehistoric sapiens developed symbolic languages (abstract), which led to God-Kings (abstract power), which were overthrown by physical warfare, which led to new abstract institutions like democracies, and the cycle continues.
Modern sapiens equipped with computers have repeated this ancient pattern at unprecedented speed. In just decades, software has created abstract power hierarchies that took millennia to develop in agrarian societies. Digital-age wars are already being fought in, from, and through cyberspace. But there is a critical gap: there is currently no mechanism to project physical power through cyberspace. Without a "cyber warfighting protocol," populations have no physical means to constrain the abstract power of their digital rulers.
Lowery identifies a recurring pattern in human power dynamics (pp. 284-286): the Physical-to-Abstract-to-Physical cycle that has characterized power projection throughout history. Whereas prehistoric sapiens took tens of thousands of years to develop symbolic languages and codify abstract power hierarchies, modern sapiens equipped with computers have replicated this process in mere decades, giving administrators control authority over society's digital-age resources at unprecedented speed and scale.
"If history is going to repeat itself in clockwork fashion again, then agrarian society is due for another war. Except this time, it appears like it's going to be an electro-cyber war fought in, from, and through cyberspace over zero-trust, permissionless, and egalitarian control over digital-age resources."
— Lowery, p. 284
The thesis argues that without a "softwar" protocol, a mechanism for projecting physical power through cyberspace, entire populations, including nation states, remain vulnerable to systemic exploitation by a technocratic ruling class. This vulnerability could emerge domestically or from a foreign power.
Two Ways to Constrain a Computer
There are only two ways to control what a computer does:
Option 1: Rules (logical constraints). Write code that says "you can't do that." The problem? The person who wrote the rules can always change them. Every firewall, every password, every security system is just MORE rules written by MORE people you have to trust. We already showed this doesn't work.
Option 2: Physics (physical constraints). Make the computer need REAL electricity to do anything important. You can't hack physics. You can't trick thermodynamics. If changing a computer's state costs a ton of real-world energy, that's a wall no amount of clever code can get around.
The wild idea: what if you deliberately made a computer SLOW and WASTEFUL on purpose? What if being inefficient was actually the whole point?
Von Neumann's early observations about stored-program computers reveal a key insight: software has only two fundamental constraints, the physical limits of the hardware, and the imagination of the programmer. This means there are exactly two ways to constrain a computer program: logically (through code and rules) or physically (through the underlying hardware).
Logical constraints have been demonstrated to be ineffective. Every software security rule is written by an administrator who can change or circumvent it. Every additional security layer is just more software controlled by more administrators, the recursive trap we identified earlier. The alternative is physical constraints: deliberately designing a computer so that changing its state requires provable expenditure of real-world physical power (watts).
This is the "chain down" design concept: deliberately couple a computer to a physical power source so that every state change requires measurable energy expenditure. The counterintuitive insight is that computational inefficiency becomes a feature, not a bug. A deliberately inefficient computer that requires enormous energy to operate could provide unprecedented physical security in cyberspace, because the inefficiency itself IS the security mechanism.
Lowery returns to Von Neumann's foundational insight about stored-program state mechanisms (pp. 286-290) to identify two categories of constraint on computer programs: logical constraints (design logic conceivable by the program planner) and physical constraints (the physical limits of the state mechanism itself). Having established that logical constraints are demonstrably dysfunctional and incapable of securing software against systemic exploitation, the thesis turns to physical constraints as the alternative.
"To make cyberspace more secure, it is possible to find a way to physically constrain the underlying computers connected to the internet. This would imply that what cyberspace is missing is an open-source protocol and the supporting infrastructure needed to empower people to physically constrain computers."
— Lowery, p. 287
The "chain down" design concept proposes coupling state mechanisms to physical power sources so that state changes require provable watts. The thesis identifies the key insight that computational inefficiency, deliberately designing a state mechanism with intentionally difficult-to-change states, would have counterintuitively beneficial emergent properties for cyber security. The inefficiency is not a bug to be corrected but the primary value-delivered function: it represents the real-world physical costs imposed by the system onto participants in the virtual domain.
Physical Cost Function Protocols
Back in 1992, two computer scientists named Dwork and Naor had a clever idea to stop email spam: what if sending an email cost a tiny bit of electricity? Not money, but actual computer work that burns real watts. Sending one email? Barely noticeable. Sending a million spam emails? Your electric bill would be enormous.
Then in 1997, a programmer named Adam Back built a real version called "hashcash." It works in two steps: Step 1, your computer solves a hard math puzzle (burning electricity). Step 2, the solution becomes a "receipt" proving you spent that energy. Think of it like a postage stamp, but instead of paying money, you pay in watts.
Here's the key: the "work" in "proof-of-work" isn't just computer math. It's REAL thermodynamic work, actual electricity consumed. The proof is proof of POWER. That's physical. That's something you can't fake.
The concept of physical cost functions originated with Cynthia Dwork and Moni Naor's 1992 paper on "pricing functions." Their insight was elegantly simple: to secure access to resources, increase the physical cost of accessing them. Make control signals superfluously costly to send, and you eliminate superfluous control signals. They proposed requiring computers to solve moderately hard computational puzzles before accessing shared resources, effectively decreasing the BCRA of attacking software by increasing CA.
Two years before the formal academic papers, software engineer Adam Back privately released "hashcash," an operational proof-of-work protocol. The protocol uses a two-step process: first, consume watts by physically straining a computer with a special hashing algorithm; second, issue a "proof-of-power receipt" to the entity that solves it. Back's algorithm uses a lottery-style "pick the winning number" technique that is perfectly fair, equally difficult for everyone, with no shortcut or exploit possible. The only strategy is brute-force guessing, which requires real-world electricity.
Critically, the "work" in proof-of-work refers to real thermodynamic work: watts consumed by physical hardware. The terms "physical cost function," "proof-of-work," and "proof-of-power" are interchangeable. Each describes the same phenomenon: converting real-world electric power into an abstract receipt that verifies physical expenditure occurred.
Lowery traces the intellectual lineage of physical cost function protocols (pp. 291-296) from Dwork and Naor's 1992 "pricing functions" through Jakobsson and Juels' formal "proof of work" terminology (1999) to Adam Back's operational "hashcash" implementation (1997). The core principle across all implementations is identical: secure resources by increasing the physical cost (CA) of accessing them, thereby decreasing the BCRA of exploitation.
"We present a computational technique for... controlling access to a shared resource... The main idea is to require a user to compute a moderately hard, but not intractable, function in order to gain access to the resource, thus preventing frivolous use."
— Dwork and Naor (1992), cited in Lowery, p. 292
Back's hashcash protocol operationalized this concept via a two-step process: (1) physically strain a computer using a computationally difficult hashing algorithm that creates a "vacuum of electric power" requiring real watts to fill, and (2) issue an abstract proof-of-power receipt to the entity that solves the algorithm. The thesis emphasizes that proof-of-work protocols create real-world physical costs measurable in watts, not merely computational costs. The protocols are computationally inefficient not because of poor engineering, but because the inefficiency IS the primary value-delivered function: it represents the mechanism by which physical costs are imposed on participants in, from, and through cyberspace.
"The author will interchangeably use the term 'physical cost function' instead of 'pricing function' and 'proof of power' or 'bitpower' instead of 'proof-of-work' where the term 'physical cost' refers to the real-world physical deficit of electric power (a.k.a. watts) required to generate a proof of power."
— Lowery, p. 293
The Electro-Cyber Dome
But what if you could build a wall around your digital stuff, not made of code that can be hacked, but made of ELECTRICITY? A wall so thick that breaking through costs more energy than what's inside is worth?
That's the Electro-Cyber Dome Electro-Cyber Dome A defensive shield built from proof-of-power walls. Like a castle wall, but made of cumulative watts in cyberspace. Passive, scalable, non-lethal. Chapter 3 . A castle wall made of watts.
The Electro-Cyber Dome is the thesis's key visual concept: a "proof-of-power wall" that rejects any control signal without a valid proof-of-power stamp. Stack these walls into a dome-like structure around digital assets.
Properties: passive (doesn't attack), infinitely scalable (more hash = thicker walls), non-lethal (can't injure, only imposes energy costs), and recursive (Bitcoin secures itself behind its own dome). Dome strength equals the cumulative CA, the total watts an attacker must expend.
The Electro-Cyber Dome concept (pp. 297-302) formalizes the proof-of-power wall as a defensive structure in cyberspace. Each wall is an API-level constraint that requires a valid proof-of-power receipt before accepting any state-changing signal. Lowery draws explicit parallels to cellular membranes and medieval castle walls, arguing that the dome represents the first physically-grounded defensive structure in cyberspace, one whose security properties scale with energy expenditure rather than cryptographic complexity.
Build Your Electro-Cyber Dome
Imagine building a force field around your treasure chest. The more electricity you pump into it, the thicker and brighter the walls get. Hackers trying to break in would need to spend even more electricity than you did. That is what Bitcoin miners do every second of every day.
Bitcoin's proof-of-work creates what Lowery calls an "Electro-Cyber Dome," a thermodynamic shield around digital property. Each terahash of mining power adds another wall of energy that an attacker must overcome. The dome's strength scales with hash rate, making the cost to attack grow exponentially relative to the cost to defend.
Lowery argues (pp. 218-225) that proof-of-work mining constructs a "physically imposing structure in cyberspace," an Electro-Cyber Dome. The cost function is asymmetric: defenders contribute hash power additively, while attackers must exceed the cumulative hash rate. This produces a thermodynamic barrier analogous to physical fortifications, where CA scales superlinearly with network hash rate, collapsing BCRA toward zero.
From Pharaoh to CEO
The thesis draws a direct line from ancient Egyptian pharaohs to modern tech platform administrators. Both control resources through abstract power hierarchies. Both exploit populations through systems the population itself adopted. The only difference is scale: a pharaoh controlled millions, a platform admin controls billions.