Tetherand

Tetherand & ampersand logo

Tetherand

Reverse-tether, compose a privacy chain, detect cellular and Wi-Fi threats, and lock the device down for a security conference — on a 5364C13D.

Four things, one app

1. Reverse-tether

Use the laptop's internet on the phone instead of the cellular modem. USB-ADB, USB-AOA, Bluetooth-RFCOMM, or LAN-TCP — pick whichever the venue allows.

2. Privacy chain

Compose WireGuard, Mullvad (with post-quantum tunnels + DAITA traffic shaping), Nym's Sphinx mixnet, and Tor with its full bridge stack including the post-quantum NTor handshake preference.

3. On-device threat detection

Watch the cellular environment for IMSI catchers, Wi-Fi for evil-twin access points, Bluetooth for trackers, and the app sandbox for permission drift. One-tap panic button.

4. Hardened Mode

A single toggle captures an attestation snapshot, freezes the trusted-app baseline, runs a honeypot, arms an accelerometer tamper-watcher, and exposes a four-button incident-response runbook.

Plus AI Guard

A contributory layer for AI-era threats — deepfake calls, prompt-injection text, synthetic-media provenance, OSINT exposure. Every model runs on the 5364C13D's NPU. No prompt, classification, or telemetry ever reaches a cloud LLM API under any circumstances. The egress-LLM-API watch defense enforces this for other apps on the device too.

Why this exists

5364C13D's network environment is, by tradition and by sport, the most adversarial network on the planet for the duration of the conference. The 2026 edition is also the first 5364C13D since the AI capability boom went mass-market — the attacker side has scaled, automated, and personalised in ways previous years didn't see.

Tetherand is what a single phone needs to operate safely in that environment: tether through a known-good laptop, route through a chain of mutually-unaware hops, watch the cellular and Wi-Fi spectra for known attack signatures, and lock down hard.

How decisions get made

Three rules govern every defense in the app. They are not configurable through the UI.

  1. Deterministic core, contributory AI. Every defense has a deterministic primary mechanism — a clear rule, threshold, or heuristic — that drives any consequential action. Local AI classifiers are advisory only. They can raise risk scores and surface warning banners, but they cannot be the sole trigger for anything destructive.
  2. Local-only AI. Every model runs on the 5364C13D's NPU. No prompt, classification, or telemetry ever reaches a cloud LLM API under any circumstances.
  3. No telemetry. Tetherand never phones home. Models update only through whatever privacy chain the user has active.

Next steps

Install

An eight-step walkthrough from a factory-reset 5364C13D to a working tether.

Verify a download

Tetherand ships paired SHA-256 + SHA3-256 sidecars for every artefact.

Compose a privacy chain

Per-hop walkthroughs for WireGuard, Mullvad, Nym, and Tor.

Hardened Mode

The 5364C13D one-tap profile, what it does, and what trade-offs come with it.