The Digital Millennium
The Third Millennium was supposed to belong to everyone. It was going to be bright, glassy and open — a thousand years of machines that served the people holding them. Twenty-six years in, most of the computers on Earth run code their owners are not permitted to read, on silicon that boots a processor they cannot switch off, under a law that makes looking a crime. This page is about how that happened, how long we have to fix it, and what "fixing it" would even mean.
The Argument
Since the beginning of the Anthropocene1, one trait has separated our genus from everything else that has lived: the refusal to accept the world as issued. Homo erectus divided labour. Homo neanderthalensis buried their dead. Homo sapiens walked on the Moon, split the atom, and taught sand to do arithmetic. No obstacle has ever held permanently. That is a genuine achievement and it deserves to be said plainly.
It is also the seed of the problem. Capability breeds confidence, confidence breeds arrogance, arrogance breeds the conviction that one's own judgement need not be checked by anybody. A species that cannot be stopped from outside is eventually only ever stopped from inside — and the mechanism it uses to stop itself is division.
We stand near the start of the Third Millennium holding the most remarkable tools ever built. We have coaxed something resembling thought out of silicon and matrix multiplication. We have bent computation around quantum mechanics to search spaces faster than counting allows. And we have arranged, almost without discussing it, for nearly every one of those tools to be opaque to the person using it.
This is the part that should trouble you. Opacity is not a minor defect in a tool; it is a transfer of authority. A machine you cannot inspect is a machine whose loyalties are asserted rather than demonstrated. You are asked to accept, on the vendor's word, that it does what it claims and nothing else. Trust of that kind is not trust. It is deference with better marketing.
Why should you trust what you cannot audit? And if we cannot establish what our own instruments are doing, on what exactly do we propose to build the next nine hundred and seventy-three years?
The Digital Millennium is not lost. It is enclosed. The distinction matters, because enclosure is reversible and loss is not.
The Epochs
The millennium divides naturally along the points where our timekeeping breaks. These are not arbitrary: each boundary is a real limit in a real format, a place where a number we chose decades ago runs out of room. They are the metronome of the age. Each clock below counts down to the failure that ends its epoch.
I Unixipithocene You are here
2000.01.01 00:00:00 UTC → 2038.01.19 03:14:07 UTC
From the opening of the Digital Millennium to the end of
32-bit Unix time. The age we are living in, and the one still running on a
counter chosen when the machines it addressed filled a room. At
03:14:07 on 19 January 2038 a signed 32-bit time_t reaches
2,147,483,647 and the next second reads as December 1901.
until signed 32-bit time_t overflows
II Postunixocene
2038.01.19 03:14:08 UTC → 2038.11.20 23:59:42 UTC
The shortest epoch by an enormous margin: ten months. From the death of 32-bit Unix time to the third rollover of the GPS 10-bit week number, which counts to 1023 and then begins again. It has happened twice already — in 1999 and in 2019 — and both times receivers that had not been updated silently reported the wrong date.2
until the third 10-bit GPS week rollover
III Allocationcene
2038.11.20 23:59:43 UTC → 2107.12.31 23:59:58 UTC
Sixty-nine years named for the habit that defines them: deciding how many bits a thing deserves. It ends when the FAT filesystem runs out of calendar. FAT stores the year in seven bits counting from 1980, which reaches 2107, and stores seconds in two-second steps — so the last moment any FAT-formatted volume can represent is 23:59:58 on the final day of that year.
until the FAT 7-bit year field is exhausted
IV Nanocene
2107.12.31 23:59:59 UTC → 2262.04.11 23:47:16.854775807 UTC
A century and a half measured in billionths. Counting nanoseconds since 1970 in a signed 64-bit integer buys 292 years and change, and not one second more. Anyone who has met the outer limit of a pandas timestamp has already touched the far wall of this epoch.
until signed 64-bit nanoseconds overflow
V Exanocene
2262.04.11 23:47:16.854775808 UTC → 2554.07.21 23:34:33.709551615 UTC
Reclaiming the sign bit doubles the runway and buys another 292 years — the same arithmetic, one bit richer. Nearly three centuries bought by giving up the ability to express a moment before 1970. Every fix in this list is a trade of that shape.
until unsigned 64-bit nanoseconds overflow
VI Tacitocene
2554.07.21 23:34:33.709551616 UTC → 2999.12.31 23:59:59 UTC
Four and a half centuries with no scheduled failure in them — the silent epoch, and the longest. Nothing we have currently built is due to break here. That is either the most reassuring line on this page or the most ominous one, depending on whether you think the absence of a known deadline means the work is finished. It ends only when the millennium does.
until the close of the Third Millennium
A Timeline of the Millennium
The story of the Digital Millennium is not a decline. It is a promise, an enclosure, and an unfinished recovery — three movements that overlap and are still running concurrently.
enclosure recovery context
"Just a hobby, won't be big and professional." The proof that infrastructure could be built in the open by people who would never meet.
Later renamed coreboot. The first serious argument that the firmware beneath the operating system should also belong to the owner.
Y2K passes without catastrophe — not by luck, but because a very large number of people spent years auditing code. A demonstration, immediately forgotten, that inspectable systems can be repaired.
Gloss, water, skies, glass, green grass behind clean chrome. Named only in hindsight, but it encoded a real belief: that computing was heading somewhere bright, humane and shared. The aesthetic outlived the belief.
The millennium was enclosed fourteen months before it began. Section 1201 makes circumventing an access control unlawful in itself, severed from whether the underlying use was lawful. Reading your own device becomes an offence not because of what you do with what you learn, but because you looked. Every three years the Librarian of Congress grants temporary permission to perform specific acts of curiosity.
A major label ships software that hides itself on customer machines to enforce copy protection, and weakens those machines in the process. Copyright enforcement is established as a legitimate reason to conceal code from the person running it.
A separate processor on the die with its own firmware, its own memory access and its own network path, running before the main CPU starts and continuing while the machine is nominally off. Not auditable, not removable, not optional.
NIST SP 800-90A blesses a random number generator with a structure that permits whoever chose its constants to predict its output. It is the default in RSA's BSAFE library for nine years. NIST withdraws it in 2014, eight years after publishing it.
A technician's disclosure describes a splitter cabinet in a San Francisco switching centre, copying backbone traffic wholesale. Not a targeted warrant — a mirror.
Researchers demonstrate the Management Engine as an execution environment beneath every privilege level the owner can reach. The rings run deeper than the architecture manual admits: −1 for the hypervisor, −2 for system management mode, −3 for the coprocessor answering to somebody else.
A genuinely good mechanism — cryptographic verification of the boot chain — shipped with the keys held by the vendor rather than the owner. The technology is sound. The custody is the problem, and the two are persistently conflated.
An ARM TrustZone core placed on the die, with the same posture as Intel's. The last mainstream alternative closes. There is now no high-performance consumer CPU whose owner controls everything executing on it.
Disclosures reveal a sustained programme to weaken the cryptographic standards everyone else was told to rely on. The damage is not any single intercept; it is that "follow the published standard" stopped being sufficient advice.
An instruction set architecture nobody owns. Not a product — a removal of the assumption that the foundation must be somebody's property.
coreboot with the remaining binary blobs stripped out, on the machines where that is achievable. A small list of models, honestly stated, that boot on code you can read end to end.
A tool that strips the Management Engine firmware to the minimum the hardware will tolerate. The following year an undocumented "High Assurance Platform" bit is found that disables most of it — a capability that existed all along, for customers who were considered to merit it.
POWER9 workstations with auditable boot firmware and no equivalent coprocessor. Expensive, niche, and proof that the closed arrangement was a choice rather than a physical necessity.
Right-to-repair legislation begins reversing, piecemeal, the principle that buying a device does not entitle you to understand it.
An operating system written from scratch, and language models trained and published with every token count and failed run disclosed. Small contributions, deliberately. The argument is not that KMOS or OpenCerebral will displace anything. It is that the alternative has to exist, be readable, and be built in the open by somebody — and that the somebody may as well be us.
The clock at the top of this site is counting to it.
What Restoration Requires
Not nostalgia. The Frutiger Aero millennium was mostly an aesthetic, and the freedom it implied was never actually delivered — the enclosure was already law before the gloss arrived. There is no earlier state to return to.
What is owed is narrower and harder: that a person who buys a computer be permitted to know what it is doing. That verification be possible rather than promised. That no processor in a machine answer to somebody other than its owner. That examining a device you possess not be an offence. Every one of those is achievable with technology that already exists, and every one of them is currently obstructed by a decision somebody made and could unmake.
Nine hundred and seventy-three years remain. The clocks above are not a countdown to doom; they are a reminder that these systems were designed by people with limited foresight, and are therefore still ours to redesign. The Digital Millennium is enclosed, not lost.
1 "Anthropocene" denotes the period in which the genus Homo has had a measurable effect on the Earth itself — megafaunal extinction, deforestation, and everything since.
2 The GPS rollover is quoted here as 2038.11.20 23:59:42 UTC. The week counter rolls at the start of 2038.11.21 in GPS time, which falls on the previous day in UTC because GPS runs ahead by the accumulated leap seconds — 18 at present. In 2022 the CGPM resolved to stop inserting leap seconds by 2035, so that offset is expected to be frozen at 18 by the time this arrives. If it is not, the moment shifts by the difference.
3 This page dates the Third Millennium from 2000.01.01 rather than the strictly correct 2001.01.01. The Digital Millennium is reckoned from the rollover that mattered to the machines.