Orply.

DoxxNet Builds a Peer-to-Peer Mesh to Bypass Centralized App Servers

Barrett LyonJoel Garzaa16zThursday, October 1, 202614 min read

DoxxNet founder Barrett Lyon argues that privacy tools such as VPNs leave the internet’s underlying reliance on centralized infrastructure largely unchanged. In a conversation with a16z’s Joel de la Garza, he describes DoxxNet as a separately controlled mesh network designed to let users communicate and transfer files directly, without routing those exchanges through central application servers. Lyon says the project reflects a broader need to rethink internet protocols as tracking expands and collected data becomes easier to analyze with AI.

DoxxNet treats the network—not just the app—as the privacy problem

Barrett Lyon is building DoxxNet around a claim that familiar privacy tools leave the basic structure of internet communication intact. A VPN can change the route a user’s traffic takes and the address websites see. It does not, by itself, change how online services are built, who operates the infrastructure in between, or how much information apps and trackers collect.

Lyon described many VPNs as entry and exit points: a provider leases a server, installs its software, and lets users connect to it. The connection is encrypted on the way to that server, and the user’s internet requests then emerge from that node. In this model, the VPN changes where traffic appears to come from. Lyon said this can offer a way around treating an IP address as a person’s identity, but he questioned whether that arrangement amounts to the broader kind of security people may infer from using a VPN.

His alternative is not simply another route through a VPN server. Lyon said DoxxNet uses VPN protocols as an entrance to a separately controlled network: a parallel environment in which the company can create policies, manage addresses and domains, and enable connections between users. He described 196 domains that do not exist on the public internet. Users can register domains, lease IP or mesh addresses, and set policy inside that environment. Lyon said the system can make those changes in milliseconds.

That difference matters to the applications built on top of the network. Instead of relying on a conventional central service to connect two users, DoxxNet’s applications are intended to use the mesh to establish direct connections. Lyon named phone calls, video calls, chat and file transfer as examples. His broader point is that the network itself can be adjusted to make peer-to-peer applications work, rather than treating direct communication as a feature that an app must somehow add on top of the existing infrastructure.

The project grows out of Lyon’s long-standing interest in internet protocols. He argues that protocol design has stagnated: newer services mostly sit on top of established foundations rather than replacing or rethinking them. At the same time, he sees privacy eroding, censorship spreading and VPNs gaining popularity without addressing all the underlying dependencies. DoxxNet, he said, is an attempt to combine those concerns into a different network architecture.

Lyon described account creation as a short sequence rather than a conventional identity check. A user completes a small puzzle intended to prove they are human and receives a token. The user can change the token, delete the account or make a new one, he said. To connect with a friend, one person shares a certificate through an invitation that looks like an ordinary in-app action. Lyon described the process as a cryptographic exchange that gives the two users additional privileges: they have decided to trust one another, and their phones can then communicate directly over the mesh.

The technical mechanism is deliberately hidden behind familiar interactions. Joel Garza observed that asking people to work with public-key infrastructure by name would be a poor way to make a product usable. Lyon replied that the arrangement is not public infrastructure in the conventional sense; the important part for the user is the exchange of trust between two people, not a visible cryptography workflow. He said the resulting connection does not require phone numbers, email addresses or names.

Garza characterized the connection as a way to chat without leaving a record. Lyon did not describe that as an independently verified guarantee; his concrete explanation centered on how exchanges are routed. Rather than sending a file to an application server for the recipient to retrieve, he said, the sender’s phone can act as a server for a friend. He contrasted this with WhatsApp, Signal, iMessage and Telegram, saying that these services can make an exchange look direct even though the sender is actually sending material to a server, which the recipient then pulls from. He also said upload infrastructure may be slow or geographically distant from the sender.

Lyon said DoxxNet’s applications are designed to remove that intermediary from the exchange: a file goes from one user’s device to the other’s. He described transfers as having no file-size limit and gave a 20-gigabyte file as an example. He also said the communications use three or four layers of encryption and characterized the system as post-quantum. Those are Lyon’s descriptions of the service; he did not use the discussion to detail the implementation or establish what metadata might still be generated by a particular exchange.

The mesh’s direct-connection model is the feature Lyon emphasized. Its practical examples are specific: user-managed mesh or public addresses, domains within the network, direct communication between trusted phones, and large file transfers that are intended not to pass through an application server. These capabilities come with a different operating model from familiar messaging apps. Users need to be on DoxxNet’s network and establish a trust relationship with the person they want to reach; Lyon presented the invitation and certificate exchange as the way to do that. The discussion did not establish how the service handles every case where a peer is offline or cannot connect directly.

Lyon described the larger project as a toolkit for freedom of speech; Garza put it another way, as freedom from surveillance. The distinction between those aims and the technical mechanism is important to the design as Lyon described it: the mesh provides a different environment for applications, while direct connections are meant to reduce dependence on central application servers.

A VPN’s promise depends on who owns the servers

For Lyon, the ownership question is central. A VPN provider may promise “no logs,” but the user still has to ask whether the infrastructure is owned by the VPN company or leased from someone else, who that landlord is, and what policies govern the equipment. Carriers and interconnection providers add further layers beyond the server itself. If the company does not control its equipment, he argued, it cannot fully set policy for it.

That is the distinction Lyon draws between a VPN tunnel and a separately controlled network. A VPN can encrypt a connection to a provider’s server and change the apparent source of a user’s traffic. But, in his account, it does not necessarily give the provider control over every part of the infrastructure that handles that traffic, or create a new environment in which applications can communicate directly. DoxxNet uses VPN protocols to reach its mesh; the mesh is the network Lyon says the company can configure and operate.

Lyon said DoxxNet has built 26 sites around the world with redundant routing. He described the company as operating its own equipment, from software to physical infrastructure, and said routing components and AI systems run on its hardware. He also described a US-based company and a Swiss company handling European operations, with regional separation intended to make governance part of the system’s design. His stated point is to be explicit about who owns the service and why it is run the way it is—not to ask users to trust an opaque provider solely because it advertises privacy.

That approach is also a response to the incentives behind free services. “If you’re not paying for it, you are the product,” Lyon said, warning that some free VPNs may be collecting value from the users they claim to protect. Garza raised concerns about VPN apps hosted abroad and about the overlap that can exist between state apparatus and organized crime. Lyon’s answer was not that every provider is untrustworthy, but that a privacy policy alone does not settle the question of control.

The speakers also pointed to a more direct reason not to treat a familiar app name as proof of safety. Garza described a messaging service that the FBI had built and marketed to organized criminal groups. Users who distrusted better-known tools adopted it believing it was secure; the operation led to arrests and indictments. The example was offered as a warning about the difficulty of knowing who is behind an ostensibly private communications service.

Lyon said the network’s routing components run on DoxxNet’s own hardware, rather than sending their data to large third-party inference providers. He said the system is operated by a team of about 12 people, with no network administrator or sysadmin: AI handles those tasks. Lyon remains closely involved, and he argued that a small group of people with access to the network reduces the potential insider-threat “blast radius.”

He also said the AI systems run in a secured environment and that context and inference stay on DoxxNet’s equipment. The company monitors its hardware with cameras, he added, and nobody goes in to touch it. When Garza asked whether agents review the camera footage, Lyon clarified that DoxxNet does not run its own camera-watching agents; the camera companies provide the agents. He said the company receives alarms when something moves.

The operating model Lyon described combines automation with a small human team and physical monitoring. He presented the limited number of people with network access as one way to limit insider risk, not as a replacement for his own oversight: he said he remained on top of the system. His skepticism toward large inference providers fits the company’s effort to keep network context and routing inference on equipment it controls. It also creates a reliance on the company’s own ability to operate and secure that equipment, a responsibility Lyon described as part of building the network rather than outsourcing it.

Censorship and tracking both exploit the network’s visibility

The case for a different network is not limited to hiding traffic from a VPN provider. Lyon and Garza discussed how network-level controls can be used to enforce rules that are really about identity, age or content. Lyon’s objection is that the network is being asked to solve the wrong problem. An IP address is not a driver’s licence, he said, and restrictions based on age should be handled at a different layer rather than by treating a network address as proof of a person’s identity.

Garza raised an example from a US state that required users to verify themselves to access certain sites, including sites the state deemed inappropriate. Lyon said he sees this kind of censorship creeping into the United States, as well as existing elsewhere. His concern is not only the policy itself but the bluntness of enforcing it through network controls.

He described the risk of collateral blocking through geographic classification. In one case he cited, Cisco Umbrella reportedly classified a major carrier as French. France had a rule requiring the blocking of more than 100 piracy sites; the response, Lyon said, was to block France, creating the possibility that a mistaken location classification could sweep in users who were not in France. The example illustrates Lyon’s point about “blast radius”: when a policy is attached to a network category, errors in classification can make people subject to restrictions they were never meant to face.

Commercial services can create comparable distortions. Garza recounted a company whose chatbot service focused on partnership or companionship being classified as adult content by several classification engines. Lyon said DoxxNet had encountered a related issue because its name contains “doxx,” which can trigger filters. In that case, after the company applied through the relevant registration process, a provider opened access to it. The exchange shows how automated categories can shape what a service can reach, even where the label may not reflect its actual purpose.

The other major source of visibility, in Lyon’s account, is advertising technology. He said apps and websites contain trackers that collect information about how people use them. He named WhatsApp’s “TIT.WhatsApp.net” and Apple telemetry as examples, arguing that telemetry or metadata can still function as tracking. He said such signals can often be blocked without breaking an app or most websites, because the rest of the service continues to load. That was his description of the trackers he had in mind, not a guarantee that blocking tracking signals will never affect a given service.

The more important issue, he argued, is accumulation. A single purchase may seem unremarkable. Combined with activity across apps and websites, however, the data can reveal habits, schedules, income, shopping patterns and life changes. Garza suggested that the data might show someone preparing for a child or a divorce. Lyon’s point was that the accumulated record could reveal such events before a person has told their spouse.

That possibility changes the stakes of tracking. Garza described a new scale of “coin-operated intelligence”: increasingly capable AI systems can be applied to huge quantities of collected data. Lyon put the mechanism plainly: feed a person’s data into a large language model and ask what it says about them. The concern is not that any one tracker knows everything. It is that many separate signals can be assembled and analyzed to make a detailed picture.

DoxxNet’s response, Lyon said, is to remove as much of that tracking as possible at the network level, not merely offer an app that avoids one category of data collection. He wants the system to recover an older conception of the internet: a place where people can connect and create without being persistently observed by advertisers, governments or other parties. He described the project as a toolkit for freedom of speech; Garza sharpened the phrase to freedom from surveillance.

The system depends on infrastructure people can mistake for a nuisance

Lyon’s argument for building a new network sits alongside a broader claim: new protocols and services require physical infrastructure, and public decisions about that infrastructure can be shaped by misleading representations. He and Garza discussed criticism of data centers, including claims about their water use and videos that appear to show their noise. Lyon said the facilities he has visited are not noisy outside in the way some viral clips suggest; he believes some videos use audio recorded inside and present it as though it were heard outdoors.

On water, Lyon described data centers as using closed cooling systems that may need replenishment after a failure or through evaporation. He cited a data center near Reno that had a large lake nearby, which he said people interpreted as evidence that the facility ran on the lake. His explanation was that a reserve could be used to refill a system if a chiller failed and the system had to be drained. The exchange offered Lyon’s account of those systems, not a detailed examination of water use across data centers.

He also pointed to the economic and infrastructure effects he associates with data centers: jobs, technical workers and improved infrastructure, including faster internet in some areas. He described a large data center park in Virginia as a mostly unremarkable landscape of buildings, parking and rabbits, rather than the kind of visibly contested site suggested by some online material.

Garza and Lyon speculated that public opposition to data centers may be manipulated by commercial interests, but they did not name an organization, identify a campaign or present evidence establishing that explanation. Lyon’s concern was that people may be making decisions about essential infrastructure based on social media posts or viral videos they do not know how to assess. He argued that building computing and network capacity is necessary for future technology, and that opposition framed through misleading online material could lead to poor infrastructure decisions.

For Lyon, the issue is not separate from DoxxNet’s own plans. Building a parallel network means owning equipment, maintaining sites and relying on data centers and connectivity. The privacy argument is not an argument against infrastructure. It is an argument about who controls that infrastructure, what policies govern it and whether users can communicate without routing every exchange through centralized services.

Lyon’s earlier work was built around networks under pressure

Barrett Lyon’s experience with infrastructure predates DoxxNet by decades. In high school, he and a friend ran a business called DoxxNet, selling shell accounts for five dollars a month. They had about a thousand users and built a small community around the service. He later shut it down but kept the domain name.

Attacks on those servers pushed him toward distributed denial-of-service defense. Lyon began compiling techniques for surviving attacks, presented the material at SANS and saw it reach people through Google. Calls from companies followed. The attacks were not merely technical disruptions: he described extortion, competitors taking down one another’s watch businesses during the Christmas sales period, and gambling sites going dark shortly before the Super Bowl.

His response was to build a company that could provide defensive capacity at a scale individual businesses could not afford to buy for themselves. Prolexic turned large-scale protection into a leased service, an early cloud-service model in Lyon’s telling. It was later acquired by Akamai, which kept the Prolexic name. Lyon later built Defense.net, which became F5 Silverline, and BitGravity, a video-focused content delivery network. That work included ways to reduce wasted bandwidth when viewers skipped through progressive video files.

The through line is not that DoxxNet repeats those earlier businesses. It is that Lyon has repeatedly treated network architecture and capacity as things that can be built, operated and made available through a service. His earlier companies protected businesses and delivered content; DoxxNet, he said, turns that infrastructure experience toward consumers and agents. He also anticipated that the network might face denial-of-service attacks from the public internet, while raising a different operational problem: what happens if someone gets onto the network and misuses it from inside. Lyon acknowledged that privacy does not remove the need to follow the law.

His work mapping the internet also began as a practical exercise. As a penetration tester, Lyon drew network diagrams to understand how an organization’s systems fit together. He automated the process, then bet colleagues $50 that he could use a similar technique to map the internet. After being hit by a car while cycling and temporarily unable to walk, he had time to write the code. The project became Opte, a visualization of internet connections that has appeared in the Museum of Modern Art’s permanent collection and in other exhibitions.

A chart shown during the discussion presents two complex network maps side by side, labeled 2005 and 2021. Both show dense clusters of nodes and connections. The displayed comparison connects Lyon’s mapping work to his interest in how networks change over time, though the discussion does not explain the chart’s underlying data or what particular changes the two maps are meant to demonstrate.

That perspective helps explain why DoxxNet is aimed below the level of a single messaging feature. Lyon wants to change the routes, addressing and direct connections available to applications. He sees the current internet as layered with services that depend on established protocols and centralized intermediaries. His proposal is to create room for new protocols and applications by building a network the company can control—and then seeing how users adapt to it.

The internet has really kind of stagnated a bit from protocol design.

Barrett Lyon

The frontier, in your inbox tomorrow at 08:00.

Sign up free. Pick the industry Briefs you want. Tomorrow morning, they land. No credit card.

Sign up free