Category Archives: Security

1Password Quid Pro Quo With DHH Confirms Ties to Nazism

If you use 1Password, you should prepare to find another product.

On August 31, 2026, DHH, a man known for promoting Nazism and serving on the board of a Nazi merch platform, published a self-incriminating announcement.

His Omacom Foundation blog post (PDF) declares “there’s no quid pro quo here” for a $100,000 a year fee that 1Password will pay for access. He then describes the quid precisely: 1Password “has been part of Omarchy from day one,” the first thing installed on every machine, wired into the product by default.

Nobody uses the phrase “no quid pro quo” casually.

It is the operative test in American sponsorship tax law for whether a payment stays clean. Someone wrote that blog post knowing the standard and published the disqualifying facts beside it anyway. Perhaps this will help jog their sense of morals.

The Record

Date Event Classification Source
27 Jul 2021 Tobi Lütke and Harley Finkelstein personally invest in 1Password’s $100 million Accel round; Shopify executives invest alongside them; Shopify is a flagship 1Password customer Shopify’s founders now own a piece of 1Password; everyone in this story has money in everyone else TechCrunch, 1Password
Jun 2025 Omarchy ships with 1Password as the promoted commercial password manager: dedicated keybinding, CLI integration for scripts, manual copy stating “1password is a great solution”; the arrangement carried over from Omakub before it 1Password already had the prime spot a full year before any disclosed money moved Omarchy manual
Jul 2026 DHH, sitting Shopify director, publishes the remigration essay; the full conduct record of the Shopify cluster is public and documented Everything there was to know about DHH was public before anyone wrote a check flyingpenguin, flyingpenguin
21 Aug 2026 DHH announces the foundation “launches” with $8 million while writing, in the same post, “I’m incorporating the Omacom Foundation.” Present tense. No jurisdiction, no legal form, no board, no filings disclosed. Lütke among the $1 million founding patrons Millions pledged to a foundation that does not exist Omarchy
24-31 Aug 2026 Drew Houston and Peter Steinberger join; then Brian Armstrong of Coinbase and Yunjie Dai of TapTap appear on the patrons page; founding total reaches $12 million across twelve donors Nearly all the money comes from twelve rich men, which matters for tax status later Omarchy
31 Aug 2026 1Password and 37signals each commit $100,000 a year for three years; “no quid pro quo” published beside the description of first-install placement; DHH writes the mission “first has to be an amazing system for me, personally”; solicitation continues over a personal email address One post denies the deal, describes the deal, and admits who the whole thing is really for Omarchy

The Quid

Recognition is a logo on the website. That is not what 1Password holds, not by a mile. The post itself describes the position: a default slot in the install path of an operating system, a reserved system keybinding, command line integration promoted in the official manual, and manual copy that calls the product “a great solution.”

I mean how much more quid could it get? Under Treasury Regulation 1.513-4, the regulation that governs the “no quid pro quo” claim, a sponsor acknowledgment stays clean only if it avoids qualitative or comparative language and avoids endorsement.

Does “a great solution” sound like endorsement to you? It is qualitative language violating the regulation, published under the foundation’s own brand, attached to a vendor charged $300,000 over three years. That is what regulators call advertising. Advertising is a substantial return benefit.

A substantial return benefit is a quid pro quo.

The placement predates the squeeze for money by more than a year. That means it’s not an entry charge for a sponsor. It is a vendor paying to keep the position it was already in. The grocery trade calls that an arrangement known as “pay to stay”. The payment is a maintenance fee: “sure would be sad if something were to happen to someone around here, I mean if they don’t pay some dues, amiright Vinnie?”

The Cluster F*ck

The corporate patron seems to be mixed, if not corrupted with, the founding patron. Lütke and Finkelstein sit on 1Password’s cap table personally, alongside a group of Shopify executives, since July 2021. Shopify is one of 1Password’s marquee customers. If I’m reading the money flow correctly, Lütke pledged $1 million on August 21 and ten days later his portfolio company followed as one of the first two corporate commitments.

The interval between the investor’s founding contribution and the portfolio company’s corporate commitment was ten days.

“Patron” implies independent support. Every relationship in this chain is NOT independent. It looks to be prior, financial, and easily documented.

There’s No Box to Check

DHH has made this mistake before, and his precedent is a big problem. The Rails Foundation, his 2022 vehicle, is a US 501(c)(6) business league, EIN 88-2382127, filings on public record. A business league was arguable for Rails because a framework used by GitHub, Shopify, and Cookpad could be posed as a line of business. The Supreme Court actually closed that route for single-brand entities in National Muffler Dealers Assn. v. United States, 440 U.S. 472 (1979): a business league must improve an entire line of business, not promote one brand. Yet Omacom’s stated purpose is to hold the trademarks and promote the work of exactly one product. That’s textbook violation material. And the founder specifies the brand is his and personal. The system installs “by DHH.”

It’s an exact repeat of National Muffler.

The charitable route is a disaster. Let me count the ways.

Better Business Bureau v. United States, 326 U.S. 279 (1945), holds that a single substantial nonexempt purpose destroys exemption, and the nonexempt purpose here was published by the founder in the sponsorship announcement itself: the system “first has to be an amazing system for me, personally.”

An examiner does not need to infer private benefit. It is published by DHH, in the record in the first person, as the whole point.

Second, the IRS has already ruled on the category. Its May 2014 determination letter denying the Yorba Foundation, an open source Linux desktop project, held that publishing software for anyone to use, including commercially, is a substantial nonexempt purpose. If GNOME photo software failed that test after a four and a half year review, a distro whose founder announces it exists first for himself does not present anything new.

Third, do the math: under the public support test, each donor’s countable contribution is capped at two percent of total support. Fourteen donors supplying $12.6 million yields roughly 28 percent public support against a one-third threshold. Omacom defaults to private foundation status, and the “tier open to everyone, coming soon” on the foundation page reads as an attempt to artificially manufacture a claim of public support after the concentration is already being promoted as “elite” capital.

“Elite capital” on the blog post links to “oligarchy.fyi”. Three of the twelve faces here are the infamous “no politics in the workplace” authors, who are joined together now for a personally branded project to fund the man pushing hate speech essays and Nazi theory into workplaces.

Private foundation status is where the 37signals payment fails. Under section 4946, DHH is a disqualified person as substantial contributor and manager, Jason Fried is a disqualified person as substantial contributor, and 37signals, a company the two of them control, is therefore itself a disqualified person. How is this not obvious to them?

Section 4941 prohibits self-dealing between a private foundation and a disqualified person per se: no fair value defense, no good faith defense, excise tax plus mandatory unwinding.

While a pure gift from a disqualified person could be permitted, the announcement itself describes what 37signals receives: the foundation exists to promote and fund the system that, in DHH’s words, the company’s “whole technical team” already runs on.

The regulations would make an exception for benefits that are incidental or tenuous, like public recognition of a donor. But again, DHH is boasting about operating infrastructure for the donor’s business, which is precisely the benefit the exception does not cover.

Put it all together and it’s quite a problem.

  • A business league is barred by National Muffler.
  • A charity is barred by Better Business Bureau, by Yorba, and by the founder’s own published sentence.
  • A private foundation is the default classification and immediately trips self-dealing on one of its first two corporate transactions.

There is no box in the Internal Revenue Code for a tax-exempt entity whose purpose is holding and promoting the trademark of one man’s personally branded product.

So I’ll tell you what DHH means when he says “nonprofit foundation”: a marketing claim about an unincorporated pool of money, solicited over a personal email address, held by the only person named anywhere in the paperwork, because there is no paperwork.

Corrupting the Records

Criminal tax liability would be making a willfully false statement on a document signed under penalty of perjury. My guess is that Omacom has signed nothing and there is no incorporation, no exemption application, no return, nothing that yet carries a penalty of perjury.

An announcement on a website isn’t enough to hold him accountable with… yet.

It is a willfulness exhibit for filings that have not happened yet. Exemption applications and annual returns become public records by statute once they exist. Whoever eventually signs Omacom’s application or first return, and characterizes these payments as sponsorship without return benefit, signs against an August 31 document proving the drafter knew the correct legal standard and knew the facts that defeat it, because the drafter published both together.

Interestingly, willfulness is ordinarily the element hardest to document: what the signer knew, and when. Yet with the DHH post we can see clearly the knowledge and date it before the entity existed to sign anything.

1Password is Untrustworthy

Now the part that is not a tax question. 1Password is a credential security company. Its entire product is the claim that it can be trusted with the keys. That company just committed $300,000 into an unincorporated fund with no board, no charter, no disclosed jurisdiction, and no filings, run over one man’s personal email, in exchange for holding default placement inside an operating system that ships autonomous AI agents as a core feature.

Yeah, that’s not trustworthy.

I get the technical part. Agents need a secrets layer. 1Password sells the secrets layer.

But this is a product placement contract described in the vocabulary of patronage, and 1Password’s own accountants will book it as marketing because, absent any exempt entity, there is nothing else to book it as.

More to the point, 1Password looked at all the evidence, all the risk, and signed up with a Nazi-promotion platform. Framework’s sponsorship of this ecosystem rightly produced a sustained backlash through late 2025, forced the company to publish a running list of everything it funds, and put every future sponsor on notice of exactly what association with this project costs. Sidekiq pulled its Ruby Central funding in September 2025 over the platforming of DHH. By the time 1Password signed, the remigration essay was seven weeks old. The swastika sale on the platform where DHH holds a board seat was eighteen months old. The citizenship review record for the Shopify founder was public. Toronto-headquartered 1Password read all of the Nazism and committed the money anyway. That is not obliviousness. A company that reads that record and still signs the deal is willfully buying into the Nazi association.

Exemption applications and annual returns become public records the moment they exist. When Omacom finally files, examiners get to read the paperwork next to an August 31 announcement that invoked the legal standard and then listed the facts that fail it.

DHH wrote the government’s case against himself. All that’s missing is his signature.

But more importantly, perhaps, DHH just published the proof that 1Password users can no longer trust it. Migration to another product should start now.

Hacker History of OPSEC

The moment armies transmitted, their operations were being exposed as unclassified observations. In theory this was a risk since the first ever conflict, yet in practice we see a turning point with modern radio because of the sheer scale of the problem. And that’s arguably where a hacker history of OPSEC starts.

August 1914 seems the foundational moment in doctrines of modern secrecy. Russia’s Second Army under General Samsonov marched into East Prussia sending its orders by radio, often in the clear, and the German staff officers under Max Hoffmann simply listened. They knew where the Russians were going before the Russians arrived, and the result was the encirclement at Tannenberg, one of the most lopsided defeats of the war.

Two months later the British Admiralty stood up its famous Room 40 to do the listening professionally, and within two years both sides had learned that an enemy transmits far more than the words in its messages. Which station talks to which, how often, from where, and in what rhythm all reveal the future of battle. That craft became known as traffic analysis, and defending against it demanded what would much later get a name: operational security, or OPSEC.

By the end of WWI all sides were using radio silence discipline, call-sign rotation, dummy traffic, as well as entire state censorship regimes, such as DORA in Britain from 1914, or the Espionage Act and Creel Committee apparatus of 1917.

Of course WWII brought it all back into practice again, analysis of one’s own operations from the view of the enemy’s eyes.

Named point-to-point Lorenz links between German command centres, each a separate teleprinter circuit Bletchley tracked and tried to read. Trout, Whiting, Perch, Squid, Stickleback, Shad, where every spoke is one link.

Deception programs were built around the observation of the enemy’s behavior, such as the unbelievably successful Allied Operation Bertram, which fed the German Panzerarmee’s intelligence staff a false picture of the timing and axis of the October 1942 attack at El Alamein; Rommel himself had left for Berlin to party with Hitler (receive a field marshal’s baton, star at a Sportpalast rally, and assure the press that Germany held the door of Egypt in its hand, before he settled into the Heereskurlazarett relaxation at the Semmering resort). Hitler’s desperate midnight phone call pulled his “fox” out of an “alpine cure” (spa treatment) as his men were being out-observed into a total rout.

Source: “Images of War: The Armour of Rommel’s Afrika Korps” by Ian Baxter. Rommel’s men give him a look of disgust; his impatient and stretched orders fall apart as Montgomery easily outsmarts him.

The London Controlling Section came by 1942 and then the American equivalent Joint Chiefs’ Joint Security Control in 1944. BODYGUARD, the 1944 deception plan covering the Normandy invasion, treated every convoy schedule, radio net, and press release as a signature to be shaped. The same war supplied the canonical failure, B-Dienst reading the convoy traffic of the Atlantic, and the state-level Office of Censorship from December 1941 and the careless-talk campaigns from 1942, evolving into posters on high-risk American defense office walls well into the 1980s. I remember seeing some still hanging in 1994 even, the genesis of my own award-winning security awareness campaigns.

The Vietnam War offers an interesting footnote. American bombers kept arriving over targets where the enemy was already waiting, both the B-52 strikes called ARC LIGHT and the long air campaign against the North called ROLLING THUNDER. In 1966 a joint investigation team codenamed Purple Dragon went looking for the spies and found none. The giveaways were all in plain view: refueling tankers launched hours ahead and circled in predictable orbits, strikes ran on stereotyped schedules, and radio warnings meant to keep friendly aircraft clear of the target also told anyone listening where the target was. The enemy just watched and counted, which is the Tannenberg lesson of WWI and the wartime method of the Joint Security Control all over again.

NSA’s own declassified history is unsparing about the causes of failure, calling it ignorance of history, and the team coined the term OPSEC precisely so the lesson would finally have a name that would land and stick. Unsurprisingly, briefings on the subject like to reach back to Washington’s letter of 26 July 1777 to Elias Dayton, on how even the smallest trifles of information are worth collecting, as evidence that nobody should be claiming novelty on a practice as old as conflict itself.

Then, fast forward to 1987, with personal computers now settled onto corporate desks, when the monthly journal of the American Society for Industrial Security, Security Management, ran an article on control selection that introduced its readers to the Department of Defense methodology of OPSEC. On page 81 of volume 31 the “operations security” pioneered by the department was made applicable to corporate control planning, and defined:

OPSEC denies information to adversaries by identifying, controlling, and protecting indicators

This was simply Defense doctrine of that period; JCS Pub 18 had set joint operations security policy on 25 October 1974. DoD Directive 5205.2 established the department-wide program in 1983 so the transition to civilian information security four years later was reasonable. NSDD 298 carried the same identifying, controlling, and protecting language into national policy a few months after the article ran, on 22 January 1988, creating the Interagency OPSEC Support Staff. The trade press was circulating the formula and then the White House standardized it. This was somewhat common knowledge within hacker circles, not least of all because of all the news about the 414s, such as the cover of Newsweek in 1983; two years after the Security Management article, “Hagbard” of the KGB hacking case disappeared, leaving only a ring of fire in a remote German forest.

The youngest member of the 414s was said to be the only one legally able to appear on the cover of Newsweek, September 5, 1983

The civilian readership was arguably prepared also by military service. The Air Force pamphlet You and OPSEC went through the U.S. Government Printing Office in 1975, fourteen pages of second-person instruction distributed to airmen. U.S. Army Intelligence and Security Command published A Road Map to OPSEC: The 902d Military Intelligence Group in 1984, seventeen pages describing the counterintelligence unit’s OPSEC survey services. Federal depository distribution put this material out in the open for everyone to see; the digitized copy of the 1984 guide is on the shelves at the University of Illinois at Urbana-Champaign, famous for its role in early Web development. The genre descends from the wartime information campaigns that had been teaching the same silence discipline to the whole population a generation earlier. Security Management’s audience in 1987 included the veterans and cleared-facility officers that this material had trained over the preceding decade. Nobody really forgets the best OPSEC training, which is the whole point.

A second commercial thread then starts to flourish in the early 1990s, oriented to that era’s fears around economic dominance and threats of espionage. Protecting Corporate America’s Secrets in the Global Economy, published by the American Institute for Business Research in 1992 (253 pages, Cornell’s depository copy), applies the acronym within a threat model of foreign intelligence services collecting U.S. business information. The surrounding institutional activity becomes an OPSEC Professionals Society formed in 1990. IOSS ran industry outreach under NSDD 298 throughout this time, and Congress passed the Economic Espionage Act in 1996. In the same way corporations were starting to adopt encryption from the military, they also adopted the OPSEC that the military ran in the original doctrine, including foreign services as a shared adversary.

Methodology as Merchandise

Promotion is an art, not a science. OPSEC is a science, not an art.

Some may remember the moment Check Point launched its partner program in 1997 under the clever OPSEC brand. It was promoted through the company’s own SEC filings as their Open Platform for Secure Enterprise Connectivity, but the appropriation wasn’t subtle. Dan Blacharski’s Network Security in a Mixed Environment, a 1998 trade manual, shows how the acronym bled into eight long and dense pages of firewall coverage, starting page 400. Even Phrack started talking like this too, looking at issue 56, May 2000, which is a reference-list pointing back at the Check Point platform instead of the OPSEC it was referring to. Through the early 2000s the acronym registers in InformationWeek as well. And Network Magazine took that marketing baton and ran with it across twenty pages in early 2003 alone, as Check Point’s partner certification exploded and made OPSEC into standard product-coverage vocabulary. Meanwhile, actual practitioners of security operations continued preserving the real meaning; JP 3-13 counted OPSEC as a capability of information operations in October 1998, and the Journal of Information Warfare was writing it into volumes 3 and 4 in 2004.

Hacker publications of course talked about the practice of hiding tracks, yet they tended to not adopt large institutional military vocabulary. Agent Steal’s guide to federal prosecution, bylined in the text “From Federal Prison, 1997” and published in Phrack 52 in January 1998, covers source protection, informants, wiretaps, and sentencing without sounding like it’s from the government. The term had been in continuous commercial print for a quarter century by the time a hacker conference speaker started promoting it as being novel at Ekoparty in September 2012, while also admitting he had overheard ex-government hackers (e.g. NSA) using the term. Phrack finally absorbed this all in issue 69 of 2016, as if it had been there all along.

And so the oldest discipline, re-branded after multiple military lessons of the first half of the 20th century, was known as OPSEC in computer hacking circles since the 1980s. This blog was writing about “Ctrl-Alt-Del when you leave your seat” in January 2006, not because it was ahead but because it was so late. Usage simply depended on how much someone wanted to reveal knowledge/alignment with state-based military culture, like a civilian who says FUBAR, klicks instead of kilometers, or asks for a SITREP instead of an update. For many, it’s poor OPSEC to say OPSEC.

Socrates Warned You About Dean Burnett Books

I was surprised, but not really, to find a book about the harms of information technology is pushing bad history. The history wasn’t written by a historian, in other words. Take this bit, for example.

Source: “Why Your Parents Are Hung-Up on Your Phone and What To Do About It” by Dean Burnett

First, Socrates wrote nothing. He feared that writing would misrepresent ideas. Ironic, given we know of him from Plato, who put the critique of writing in writing, framed as a myth in a dialogue. We read that “Socrates genuinely feared” writing, as a claim made through a literary character.

Second, “words on paper” is anachronistic; think papyrus and wax or carved stone. Stuff that’s very hard to change when it’s wrong.

Third, the quote the footnote mentions is a documented fabrication: the famous “youth today are lazy and disrespect their elders” line comes from Kenneth John Freeman’s 1907 Cambridge dissertation, where he paraphrased general ancient complaints about the young. Later writers added Socrates’ name, without evidence. The author says “there’s a different Socrates quote in my previous book” and my guess is the fake one.

The bottom line is Socrates is far more nuanced and useful. Phaedrus 275d–e expressed that written words cannot defend themselves, and they drift to readers they were never meant for. Those are true problems; a critique of static text versus live dialogue, which remains a fairly sharp point in debates about media that simulate understanding without possessing it. Did I mention the irony, yet? This book is wrong about Socrates, exactly as Socrates had warned us.

To be fair, the author is known for light-hearted handling of subjects. Still, it’s useful to know his book about information technology risk ended up proving the whole point unintentionally.

Related:

Source: unknown

Trump Targets Yosemite Where Buffalo Soldiers Stood

On April 20, 1871, President Grant signed the Ku Klux Klan Act. Within six months he had suspended habeas corpus in nine South Carolina counties and sent federal troops into the upcountry to break the Klan. On March 1, 1872, he signed the Yellowstone Act, declaring the land…

reserved and withdrawn from settlement, occupancy, or sale under the laws of the United States, and dedicated and set apart as a public park or pleasuring-ground for the benefit and enjoyment of the people.

Ten months separate the two signatures because they are related. Both rested on the same premise that federal authority, once asserted, would be enforced against private interests that considered themselves above the law. Fifty years later those interests marched under the banner America First, when the second Klan claimed the slogan as its own, advertised itself as the only America First society, and asserted a copyright it never held.

Enforcement continued past the appropriation. Congress paid Yellowstone’s first superintendent nothing for five years, then in 1886 eliminated the civilian budget entirely, and the Army took the duty. Cavalry patrols reached Yosemite and Sequoia in 1891. In the seasons of 1899, 1903, and 1904 the duty fell to Buffalo Soldiers of the 24th Infantry and 9th Cavalry, who evicted the sheep herders and timber cutters. Captain Charles Young of the 9th, acting superintendent of Sequoia in 1903, completed the wagon road into the Giant Forest that a decade of civilian administration had failed to build.

Fast forward to the Trump “America First” administration, which has spent more than a year discussing a land exchange with Kingsbarn Realty Capital. The Nevada firm holds property on Yosemite’s western edge, where it plans upscale single-family homes. These developers want to pave a road from those homes to the park to reduce 28 miles to 11. A previous owner tried to develop the same parcel and win road access, and a court stopped him a decade ago. Kingsbarn’s lawyer says the exchange would avoid the legal obstacles that stopped that owner in court. A loophole, in plainer words. Interior says no final decision has been made.

No statute needs repeal. An exchange of equal value, papered by counsel, targets what the Congress that armed Grant against the Klan withdrew from sale.

A slogan first printed in the 1880s, marched as a Klan banner by the 1920s
The Economist/The New Yorker weren’t wrong