The Attacker-Defender Asymmetry Test
Score a technology by which side it favours, then read off where power goes
- Difficulty
- Moderate
- Time to result
- ~ongoing to results
- Steps
- 6
- Confidence
- 63%
Most consequential technologies quietly hand an advantage to either the attacker or the defender, and that allocation predicts where power, control, identity and anonymity end up. Ridley and Naval walk the ledger together. Cannon, guns, tanks, air strikes, nuclear and biological weapons all favour the attacker; castle walls and moats favoured the defender before gunpowder; the machine gun favoured the defender, which is why trench warfare went static. Strong cryptography is, on Naval's reading, the first major defender-favouring shift since the castle wall, because an attacker can throw unlimited compute at a correctly implemented key and still fail. The test has three moves: name what the technology makes cheap, decide whether that cheapening helps the initiating or resisting side, then read off the consequence for who can be coerced. Naval uses it to separate physical privacy, already lost to cameras and recognition, from digital privacy, which cryptography can still defend.
Origin
Naval Ravikant lays out the ledger on this episode while explaining why cryptography, as distinct from cryptocurrency, matters. Ridley supplies the machine gun counterexample that keeps the ledger honest, noting it favoured the defender and produced static trench warfare.
Core principles
- 01Every consequential technology quietly allocates advantage to either the attacker or the defender.
- 02That allocation, not the technology's stated purpose, determines where power settles.
- 03Wherever power goes, control, identity and anonymity follow.
- 04The asymmetry lives in the primitive, not in the application built on top of it.
- 05A defender advantage in one domain does not transfer to another.
How to run it
- 1
Name the primitive, not the product
Separate the underlying capability from the applications built on it. Naval's distinction is cryptography, not cryptocurrency: the asymmetry lives in the encryption, and the currency is one application among many.
Pro tip If your analysis changes when the product fails, you were analysing the product, not the primitive.
- 2
Write down what the technology makes cheap
Every technology collapses the cost of one specific thing: projecting force at distance, copying information, holding a position, hiding a secret. Get this sentence right and the rest of the test is mechanical.
- 3
Place it on the attacker or defender side
Ask whether the cheapened capability helps the side initiating action or the side resisting it. Cannon, nuclear weapons and air strikes favour the attacker; machine guns, castle walls and encryption favour the defender.
Pro tip Build the historical ledger first. Placing a new technology alongside known cases is far easier than judging it in isolation.
Watch out The same technology can flip sides as the surrounding context changes. Re-run the placement when the deployment environment shifts.
- 4
Test the asymmetry's ceiling
Check whether unlimited resources on the favoured-against side can still overcome it. With correctly implemented cryptography an attacker can throw unlimited compute at the problem and still not break the key, which is what makes the asymmetry structural rather than temporary.
Watch out The ceiling assumes correct implementation. Almost every real-world break is an implementation or human failure, not a mathematical one.
- 5
Read off the power consequence
Follow the advantage to its second-order effect. Naval's chain is that whichever way power goes, that is the way control, identity and anonymity go, and governments retain leverage because they hold a monopoly on violence.
- 6
Split the defended domains from the exposed ones
State clearly which parts of life the asymmetry actually covers. Naval concludes physical privacy is dead to cameras, surveillance and recognition, while digital privacy remains defensible through a cryptographically protected identity.
Pro tip If another human can recognise you, assume a computer eventually will. Do not spend defensive effort where the asymmetry does not reach.
In the wild
Naval argues that since the cannon and the gun, the attacker has been gaining advantages while the defender has been losing them, with nuclear, biological, air and armoured weapons all favouring the attacker. Ridley interjects the exception: the machine gun favoured the defender, which is why trench warfare became so static. Naval accepts the correction and places cryptography on the same defender side, because an attacker can throw unlimited compute at a correctly secured key and still fail. He then follows the consequence, arguing you can build a cryptographically protected identity, a reputation and a business against it without anyone knowing who you are.
→ A structural reason to expect digital autonomy to hold even as physical anonymity disappears, independent of any particular crypto product succeeding.
Run the test on ubiquitous internet-connected cameras with recognition software. The primitive is cheap automated identification at scale. That cheapening helps whoever wants to locate and act on a person, which is the initiating side. The ceiling test fails for the defender: masks and disguises are defeated by a slightly better algorithm, and if another human could recognise you, a computer eventually will. The power consequence is that physical location becomes permanently legible to whoever operates the network.
→ A clear verdict that effort spent on physical anonymity is wasted, and that defensive investment belongs in the digital layer instead.
Common mistakes
Judging the application instead of the primitive
Dismissing cryptography because a token collapsed confuses the product with the capability underneath it. The asymmetry survives every failed application built on top of it.
Assuming a defender advantage transfers across domains
Cryptography defends information, not physical location. Treating one domain's asymmetry as general leads people to feel protected in exactly the domain where they are exposed.
Ignoring implementation quality
The unlimited-compute ceiling only holds if you have done your security correctly. In practice the attacker routes around the mathematics through people, endpoints and metadata.
Is it for you?
Best for
Assessing security, privacy or infrastructure technologies whose long-run effect is on the distribution of power rather than on convenience.
Not ideal for
Consumer products and business models where no adversarial dynamic is in play.
From the transcript
“What cryptography, not cryptocurrency, enables is the first asymmetric advantage for the defender against the attacker, probably since the castle wall or the moat.”
“The machine gun favored the defender, funnily enough. That's what made trench warfare so static.”
“And of course, whichever way power goes, that's the way that control, identity, and anonymity goes.”
From the episode
Matt Ridley: How Innovation Works, Part 2
Matt Ridley