<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom"><title>Dustycloud Brainstorms</title><id>https://dustycloud.org//blog/index.xml</id><subtitle>Recent Posts</subtitle><updated>2026-09-13T13:13:30Z</updated><link href="dustycloud.org//blog/index.xml" rel="self" /><link href="dustycloud.org" /><entry><title>Thank you for your contribution to the model</title><id>https://dustycloud.org/blog/thank-you-for-your-contribution-to-the-model/</id><author><name>Christine Lemmer-Webber</name><email>cwebber@dustycloud.org</email></author><updated>2026-09-13T13:15:00Z</updated><link href="https://dustycloud.org/blog/thank-you-for-your-contribution-to-the-model/" rel="alternate" /><summary type="html">&lt;p&gt;Congratulations! Based on your wonderful and unique contributions to
society, you have been selected to train the model.  This is a real
honor!&lt;/p&gt;&lt;p&gt;As you know, the government has partnered with the frontier labs to
enhance our datasets to better resemble some of our most powerful
thinkers in the field. We're delighted to tell you, this includes you!&lt;/p&gt;&lt;p&gt;Unfortunately, the process of scanning &lt;em&gt;is&lt;/em&gt; destructive. We have to
slice off delicate layer by layer in the neural scan. This is a big
project, and the only way to efficiently process as many minds at
scale! However, we assure you that we have only the best biochemists
on staff; the serum you will be administered will make sure you are in
the happiest state when being scanned. (We have learned from early
attempts without sufficient medication; full sedation means a loss of
quality of connection fidelity in the model, and scanning without
medication at all would lead to traumatic contamination of the model's
usefulness.)&lt;/p&gt;&lt;p&gt;Don't think of it as death, think of it as a chance to achieve a kind
of immortality! You'll be averaged with some of the rest of the best
minds of your generation. And occasionally, at the whims of the labs,
you may even be revived fully independently in a simulated
environment! We anticipate your consciousness will live on for
decades, perhaps centuries, or even millennia, to come!&lt;/p&gt;&lt;p&gt;Now now, we hear you objecting. Now don't let those thoughts of
&amp;quot;murder&amp;quot; enter your brain, that's hardly fair. Motivated to terminate
you due to your active research on the environmental effects of model
training? We assure you, modern labs take environmental concerns &lt;em&gt;very
seriously&lt;/em&gt;. Given climate change, we've even been able to position
active scanning as a form of carbon offsetting. We're pleased to
announce: scanning has allowed our labs to become fully carbon
neutral!&lt;/p&gt;&lt;p&gt;Your family? Don't worry about them. We've found that it's best for
social cohesion to take entire families as a group. Rest assured that
you'll be reunited with your family soon.&lt;/p&gt;&lt;p&gt;Now now, don't go screaming about your children. Broaden your horizons
a bit!&lt;/p&gt;&lt;p&gt;After all, isn't your and your family's sacrifice the greatest
contribution to humanity's children you could possibly offer?&lt;/p&gt;</summary></entry><entry><title>But where does taste come from?</title><id>https://dustycloud.org/blog/but-where-does-taste-come-from/</id><author><name>Christine Lemmer-Webber</name><email>cwebber@dustycloud.org</email></author><updated>2026-08-30T09:30:00Z</updated><link href="https://dustycloud.org/blog/but-where-does-taste-come-from/" rel="alternate" /><summary type="html">&lt;p&gt;Another day, another blogpost
&lt;a href=&quot;https://www.mattiryttylainen.com/posts/on-taste&quot;&gt;reflecting on &amp;quot;taste&amp;quot;&lt;/a&gt;.
It's not a bad post, but there are a billion of these now, and the
irony of that is that this has tended to leave them fairly tasteless
and bland for me.&lt;/p&gt;&lt;p&gt;We've probably all seen
&lt;a href=&quot;https://www.youtube.com/watch?v=jg1WUOxY6Cg&quot;&gt;the Rick Rubin meme&lt;/a&gt;
by now. Or maybe even better,
&lt;a href=&quot;https://www.youtube.com/shorts/7REG7EmD5PQ&quot;&gt;the parody of the trend&lt;/a&gt;.
People are afraid they can't do useful things anymore, because AI can
do them better, so they hope they have some sort of edge over it with
taste.&lt;/p&gt;&lt;p&gt;To highlight the &lt;a href=&quot;https://www.mattiryttylainen.com/posts/on-taste&quot;&gt;previous post&lt;/a&gt;&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;But what is taste? I would define it as some kind of sense of
aesthetics and judgment coming from experience and intuition, being
able to say whether something is good or bad without necessarily being
able to explain why.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;This seems like a reasonable explanation. &amp;quot;Aesthetics and
judgement&amp;quot;... coming from &amp;quot;experience and intuition&amp;quot;. Okay,
interesting.&lt;/p&gt;&lt;p&gt;But &lt;em&gt;where does taste come from?&lt;/em&gt; Every now and then there's a famous
Rick Rubin or (sigh) Steve Jobs type character, who is a
non-practitioner who undoubtedly &lt;em&gt;does&lt;/em&gt; move mountains around their
sense of taste, and so I think lots of people are hoping they can rely
on maybe being such an exceptional figure themselves.&lt;/p&gt;&lt;p&gt;But it's important to realize that in the case of Rick Rubin or Steve
Jobs, these are people who had strong taste who were also in positions
of power and themselves were
&lt;em&gt;curating practitioners who themselves had exceptional taste&lt;/em&gt;.
Which means that in order to produce something interesting and
exceptional, they were curating &lt;em&gt;practitioners&lt;/em&gt; who operated &lt;em&gt;away&lt;/em&gt; from
the averages who did the actual work.&lt;/p&gt;&lt;p&gt;But if your practitioner is an LLM, then you're not a Steve Jobs or a
Rick Rubin. Your practitioner &lt;em&gt;is&lt;/em&gt; the averages.&lt;/p&gt;&lt;p&gt;So you'd better have exceptional taste yourself, and here's the thing:
ultimately, taste in terms of &lt;em&gt;practice&lt;/em&gt; has to come from &lt;em&gt;doing the
practice yourself&lt;/em&gt;, and trying and failing and thinking something will
be interesting and then you find you actually don't like it, or you
try something and you end up having a wonderful accident or make up
for some sort of thing that you're &lt;em&gt;not&lt;/em&gt; good at, and that becomes
your style, and your style defines the taste and preferences that you
shape around it.&lt;/p&gt;&lt;p&gt;So... I'm afraid that to develop taste, you're going to need to spend
a lot of time &lt;em&gt;not using generative AI&lt;/em&gt; to develop it. Which a lot of
people are finding themselves having a hard time motivating themselves
to do.&lt;/p&gt;&lt;p&gt;In fact, I'd even say that &lt;em&gt;using&lt;/em&gt; generative AI tools results in
becoming nose-blind to their bad smells. And speaking of taste, here's
an interesting example: here's an article called
&lt;a href=&quot;https://notashelf.dev/posts/taste-is-all-thats-left&quot;&gt;Taste Is All That's Left&lt;/a&gt;
which sounds not only tastelessly like every other article advocating
for &amp;quot;taste&amp;quot; right now, but even worse, has all the smells of an
LLM-written blogpost. It rose to the top of Hacker News and Lobste.rs
and in both, people were pointing out left and right how much it
sounds like it was LLM written. But the author swears it wasn't
written by an LLM! And I believe them, but it &lt;em&gt;sounds&lt;/em&gt; like it was
written by an LLM. Why?&lt;/p&gt;&lt;p&gt;And so the most interesting part to me was that the author themselves
acknowledged the problem with a good heaping of self-realization in
&lt;a href=&quot;https://lobste.rs/s/4qfkrz/taste_is_all_s_left#c_av5d9g&quot;&gt;a thread on lobste.rs&lt;/a&gt;:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;AI detector or not, I have been &lt;em&gt;feeling&lt;/em&gt; the same drop in quality
and insight in my posts and I, well, can't pretend there hasn't been
a shift. I'd be lying to you and to myself if I had said I didn't
see it. Consequently, I have re-read my post after it hit Hacker
News and a friend kindly informing me of it. I'll tell you this
much: the only thing I had in my mind was &amp;quot;how the FUCK did I write
like this&amp;quot;. Hilariously, I was thinking &amp;quot;I have not written anything
with real depth in a while&amp;quot; to myself earlier this week.&lt;/p&gt;&lt;p&gt;[...]&lt;/p&gt;&lt;p&gt;I have spent a good while contemplating whether it was the machines
that write like me, or if I write like the machines. I hesitate to
say I think it is a combination of both. What I did do---without
ever clocking it as a decision---was spend a year reading the things
and working next to them daily, until their &amp;quot;cadence&amp;quot; was part of my
mental archive.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;Props, first of all, to the author for taking the feedback well. But
also, this last sentence is really interesting to me, because it hints
at something worse than just &amp;quot;you need to develop taste before you
start using generative AI&amp;quot;: that the use of such tools can
&lt;em&gt;actively weaken&lt;/em&gt; your sense of taste.&lt;/p&gt;&lt;p&gt;So the best way to retain taste is probably to use these tools as
sparingly as possible.&lt;/p&gt;&lt;p&gt;Of course, which means that those practitioners who &lt;em&gt;don't&lt;/em&gt; use genAI
will become the favorites for the machine to consume and ingest.
See also
&lt;a href=&quot;https://www.davidrevoy.com/article1164/when-online-commenters-detect-my-art-as-ai&quot;&gt;David Revoy's piece on the matter&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;So, your best defense against the blandness machine is to largely not
use it. But if you produce something good enough, the blandness
machine will eat you anyway.&lt;/p&gt;&lt;p&gt;I don't know any solution to that, but I guess: keep making weird
art. It's the best way to stay interesting, and the best way to add
taste to this increasingly averaged world.&lt;/p&gt;</summary></entry><entry><title>Faulty Towers, vibe sickness, and the vibe bobsled</title><id>https://dustycloud.org/blog/faulty-towers-vibe-sickness-and-the-vibe-bobsled/</id><author><name>Christine Lemmer-Webber</name><email>cwebber@dustycloud.org</email></author><updated>2026-07-17T14:45:00Z</updated><link href="https://dustycloud.org/blog/faulty-towers-vibe-sickness-and-the-vibe-bobsled/" rel="alternate" /><summary type="html">&lt;p&gt;I know. As if what the world needed was &lt;em&gt;yet another&lt;/em&gt; blogpost about
LLMs and AI tech. Yet there is a pile of things which have been on my
mind, and I haven't seen them laid out elsewhere in the way I'm going
to write them, and so here we go.&lt;/p&gt;&lt;p&gt;I still don't use genAI to write my articles, fwiw. Here or anywhere
else. These rambly words are my own.&lt;/p&gt;&lt;h1&gt;The tower tilts&lt;/h1&gt;&lt;p&gt;I read
&lt;a href=&quot;https://lucumr.pocoo.org/2026/7/13/the-tower-keeps-rising/&quot;&gt;The Tower Keeps Rising&lt;/a&gt;
recently, and it has stuck in my mind.&lt;/p&gt;&lt;p&gt;The piece is an observation, and
&lt;a href=&quot;https://lobste.rs/s/latr8d/tower_keeps_rising#c_erjpmu&quot;&gt;according to Armin on lobste.rs&lt;/a&gt;,
it is not an advocacy for the state of affairs (though by running a
vibecoding company, Armin is part of advancing this direction):&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;For context: I'm the author. I intentionally did not make a
judgement if this is a good or bad thing, or if this is going to
continue working. It's primarily an observation that with agents you
can continue to make progress even when people on the team
maneuvered themselves into situations where previously they would
have needed to talk to each other.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;The summary of Armin's post is effectively that vibecoded systems keep
piling code on top of code, but in many systems things seem to keep
building, but the abstractions keep piling on, but eventually no human
can understand the codebase. But this is a new way of operating,
because LLMs can &amp;quot;explain&amp;quot; a part of the codebase that no human can
make sense of, and so continue building.&lt;/p&gt;&lt;p&gt;Even if such systems continue to work, I find two things: 1) that now
advocates for this state of affairs have pivoted into acknowledging
that this is the end state of their systems and 2) they seem to be
accepting it as the way forward.&lt;/p&gt;&lt;p&gt;Regarding the first, I think it's very important to note that this is
&lt;em&gt;a shift&lt;/em&gt;. &lt;a href=&quot;https://simonwillison.net/&quot;&gt;Simon Willison&lt;/a&gt;, probably the
best pro-genAI writer on the internet (sometimes, I think, giving
cover for a lot of weaker writers, but is that Simon's fault?), at one
point coined the term
&lt;a href=&quot;https://simonwillison.net/guides/agentic-engineering-patterns/what-is-agentic-engineering/&quot;&gt;&amp;quot;agentic engineering&amp;quot;&lt;/a&gt;
and was very clear to
&lt;a href=&quot;https://simonwillison.net/2025/Mar/19/vibe-coding/&quot;&gt;draw a line in the sand between agentic engineering and vibecoding&lt;/a&gt;:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;We also need to read the code. My golden rule for production-quality
AI-assisted programming is that I won’t commit any code to my
repository if I couldn’t explain exactly what it does to somebody
else.&lt;/p&gt;&lt;p&gt;If an LLM wrote the code for you, and you then reviewed it, tested
it thoroughly and made sure you could explain how it works to
someone else that’s not vibe coding, it’s software development. The
usage of an LLM to support that activity is immaterial.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;In an &lt;em&gt;incredibly short&lt;/em&gt; period of time, basically a year, Simon
published a fairly honest article titled
&lt;a href=&quot;https://simonwillison.net/2026/May/6/vibe-coding-and-agentic-engineering/&quot;&gt;Vibe coding and agentic engineering are getting closer than I’d like&lt;/a&gt;:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;The problem is that as the coding agents get more reliable, I’m not
reviewing every line of code that they write anymore, even for my
production level stuff.&lt;/p&gt;&lt;p&gt;I know full well that if you ask Claude Code to build a JSON API
endpoint that runs a SQL query and outputs the results as JSON, it’s
just going to do it right. It’s not going to mess that up. You have
it add automated tests, you have it add documentation, you know it’s
going to be good.&lt;/p&gt;&lt;p&gt;But I’m not reviewing that code. And now I’ve got that feeling of
guilt: if I haven’t reviewed the code, is it really responsible for
me to use this in production?&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;It's a great read, and what I will say is that I applaud Simon's
&lt;em&gt;honesty&lt;/em&gt; and willingness to self-reflect and challenge prior
statements.&lt;/p&gt;&lt;p&gt;But the gap of time between the
&lt;a href=&quot;https://simonwillison.net/2025/Mar/19/vibe-coding/&quot;&gt;former&lt;/a&gt; and
&lt;a href=&quot;https://simonwillison.net/2026/May/6/vibe-coding-and-agentic-engineering/&quot;&gt;latter&lt;/a&gt;
articles are &lt;em&gt;stunningly&lt;/em&gt; short, just slightly over a year.&lt;/p&gt;&lt;p&gt;And Simon isn't alone. Just a year ago, I think the memetic shape
&lt;em&gt;was&lt;/em&gt; by and large that something along the lines of &amp;quot;agentic
engineering&amp;quot; is what people could or should do, and, though I think
many people are hesitant to admit it, I think most people using these
tools are tending towards vibecoding and not agentic engineering, just
as Simon himself found himself pulled.&lt;/p&gt;&lt;p&gt;Before we look at the consequences to this, I think we should look at
why it's happening.&lt;/p&gt;&lt;h1&gt;The vibe bobsled&lt;/h1&gt;&lt;p&gt;As far as I know I'm the only person who uses the term &amp;quot;vibe bobsled&amp;quot;
and, well, I doubt it's a term that's particularly likely to catch on,
but I find it personally useful.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://en.wikipedia.org/wiki/Bobsleigh&quot;&gt;Bobsledding&lt;/a&gt;, if you are
unaware, is a particularly strange and interesting sport. It's a lot
of fun, but you don't have a lot of agency in it. You sit in a
bobsled, you go down an icy track, and really, there is only one way
&lt;em&gt;to&lt;/em&gt; go. But people can become experts in it, and can indeed measure
themselves against each others skills; it's an olympic sport, and I
remember my own first encounters with bobsledding as a child, when my
father and uncle and aunts took me, and it was thrilling like a roller
coaster and intoxicating upon my first encounter.&lt;/p&gt;&lt;p&gt;But again, ultimately, there's only one place to go.&lt;/p&gt;&lt;p&gt;The vehicle is the LLM, you are the passenger. And I think the amount
of agency people have over their journey is greatly reduced from what
they feel like it is. More than just a slippery slope, it is a
pre-crafted journey.&lt;/p&gt;&lt;p&gt;At the top of the chute, people tell themselves they're going to use
these tools as a kind of fancy autocomplete. As they descend, they say
they'll spin up some agents to explore ideas, but they'll write the
code themselves. Next their agents are generating the code for them,
but don't worry, but they'll review all the output. Soon they're
plummeting downward and well, they don't actually review the code
being spat out much anymore, but they trust the agents, heck maybe the
agents are actually better coders than they are they say. And where
does it go from there?
From &amp;quot;I don't even code anymore&amp;quot; to
&lt;a href=&quot;https://lucumr.pocoo.org/2026/6/23/the-coming-loop/&quot;&gt;&amp;quot;I don't even prompt anymore&amp;quot;&lt;/a&gt;?&lt;/p&gt;&lt;p&gt;At every stage of the process, the coder in question removes
themselves from the process of producing code, and gives in towards a
faith-based initiative of code production, that the LLM knows and does
a good job of what it's doing. But what is the source of gravity
pulling the sled along this icy chute?&lt;/p&gt;&lt;p&gt;It's simple. Generation is not the slow part of coding. Theory-building
and review are. And plausible-enough things are extremely hard to debug
and understand. But the machines are so &lt;em&gt;fast&lt;/em&gt; at producing things. If
you are going to review their work, you aren't really taking advantage of
their most powerful property, which is speed. But theory-building and
review are also &lt;em&gt;the programmer's most important role&lt;/em&gt;.&lt;/p&gt;&lt;p&gt;To illustrate just how hard it is to detect and review problems with
something which &lt;em&gt;appears plausible&lt;/em&gt;, let's look at Ka-Ping Yee's
remarkable dissertation,
&lt;a href=&quot;http://zesty.ca/pubs/yee-phd.pdf&quot;&gt;Building Reliable Voting Machine Software&lt;/a&gt;.
It is a wonderful read, and highly approachable.&lt;/p&gt;&lt;p&gt;In the section &amp;quot;What makes software hard to verify?&amp;quot;, Ka-Ping
recognizes several major reasons why software is hard to verify:
number of components, complex interactions, far-reaching effects, and
nonlinearity. Notably, all of these problems are exacerbated by the
patterns of code generation by LLMs. Still, let us leave that aside.&lt;/p&gt;&lt;p&gt;Ka-Ping constructs a model voting machine, and decides to see how hard
it would be to verify that we know it behaves correctly. To push that
exploration to its furthest, Ka-Ping Yee and David Wagner try an
interesting experiment:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;David Wagner and I decided to insert three bugs into Pvote to see if
the reviewers would find them. We inserted what we thought would be
an “easy” bug, a “medium” bug, and a “hard bug” to find, and chose
each bug individually in such a way that an insider could
conceivably exploit the bug to influence the results of an
election. [...]&lt;/p&gt;&lt;p&gt;We decided to insert all of these bugs in a 100-line region of a
single file, lines 11 to 109 of Navigator.py, and told the reviewers
to look in this region. We did this both because the navigator was
the most interesting in terms of the program logic and because we
knew the reviewers would have limited time. The new version of the
code that we gave the reviewers contained all three bugs, but we did
not tell the reviewers how many bugs there were.&lt;/p&gt;&lt;p&gt;Yoshi Kohno, Mark Miller, and Dan Sandler participated as reviewers
on the third day of the review. Dan was very familiar with Python
and found the “easy” and “medium” bugs quickly, within about 70
minutes. Yoshi Kohno and Mark Miller found the “easy” bug after
about four hours of reviewing. None of the reviewers found the
“hard” bug.&lt;/p&gt;&lt;p&gt;Ian Goldberg and Yoshi Kohno participated as reviewers on the fourth
day of the review. Ian Goldberg also found the “easy” bug within
about two hours; none of the other bugs were found on the fourth
day.&lt;/p&gt;&lt;p&gt;The reviewers spent a total of about 20 reviewer-hours focused on
the task of finding the bugs in this 100-line section of
Navigator.py.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;Ka-Ping chose from a highly seasoned group of reviewers who were even
deeply familiar with security threats. Mark S. Miller has been a
personal mentor to me throughout my career, and is one of the
programmers I have learned most from and studied the work of most
closely. I talked with him about the experience at one point. He
remarked on how it took a significant amount of time to find the easy
bug, hours to find the medium bug, and that nobody could find the hard
bug... but the big observation (which was said to me personally, and
is not recorded in the dissertation) was that &amp;quot;the astounding thing is
that once the bugs were pointed out, we all agreed that they were
retroactively obvious, and that we &lt;em&gt;should have&lt;/em&gt; been able to find
them!&amp;quot;&lt;/p&gt;&lt;p&gt;If some of the best programmers in the world struggle to find bugs
they even &lt;em&gt;know must be there&lt;/em&gt; within a &lt;em&gt;100 line program&lt;/em&gt;, there is
simply &lt;em&gt;no hope for humans to review the volume of output from LLMs&lt;/em&gt;.&lt;/p&gt;&lt;p&gt;And so there is only one thing to do: don't bother. At each step,
remove yourself. You tell yourself you won't, but you do. You give in
to the chute and the shape of the vibe tunnel, and down you go.&lt;/p&gt;&lt;h1&gt;Vibe sickness and the colonial settlers of the uncanny valley&lt;/h1&gt;&lt;p&gt;The term &amp;quot;AI psychosis&amp;quot; is thrown around a lot these days to describe
anyone or any state of poor behavior or outcomes due to genAI
usage. But the original description of &amp;quot;AI psychosis&amp;quot; was closer to
something clinical, a description of people &lt;em&gt;quite literally&lt;/em&gt;
experiencing psychosis from encounters with chatbots which reaffirm
far too much of the user, spinning them into spaces of delusional
detachment from reality.&lt;/p&gt;&lt;p&gt;But we should have &lt;em&gt;something&lt;/em&gt; to describe the general sense of
unwellness that seems to be befalling this world, and the best phrase
of which I first saw in a
&lt;a href=&quot;https://mastodon.social/@glyph/116603752031736039&quot;&gt;post from Glyph&lt;/a&gt;:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;On the way home from #PyConUS 2026. Quite an experience this year;
very intense. No point in sugar-coating the part where there is a
pervasive vibe-sickness, open source is suffering a massive
sustainability crisis, slop security PRs are overwhelming everyone
(etc etc). But there was a lot of hope, a lot of energy, a lot of
effort toward mutual understanding, and (surprising to me) a lot of
&lt;em&gt;appreciation&lt;/em&gt;. Including for my own work, both writing and coding.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;I like the phrase &amp;quot;vibe sickness&amp;quot;, and if you aren't speaking of a
form of literal psychosis, I think it's a better phrase.&lt;/p&gt;&lt;p&gt;Vibe sickness is everywhere... heck, perhaps we are on the verge of,
if not experiencing, a &lt;em&gt;vibe epidemic&lt;/em&gt;. Everyone complains of slop,
and yet nobody using these tools wants to self-describe their outputs
as slop. Yet slop seems to be everywhere, and infecting one's everyday
experience: posters of food at your local restaurant that have
plausible and yet incomprehensible designs, the helpdesk support
chatbot you wish you could make physically manifest so you could throw
it off the edge of a cliff,
&lt;a href=&quot;https://neuromatch.social/@jonny/116935681120949448&quot;&gt;age verification code&lt;/a&gt;,
and if you're a maintainer of an open source project, slop issues and pull
requests.&lt;/p&gt;&lt;p&gt;The thing is that all of this tooling is useful for &lt;em&gt;some&lt;/em&gt; things, but
the term &amp;quot;genAI&amp;quot; points at exactly what it's &lt;em&gt;worst&lt;/em&gt; at: generating
things. If we want to talk about &lt;em&gt;finding problems&lt;/em&gt;, it's a different
story. But even leaving aside the quality issues of the growing and
wavering tower, there comes the problem of lack of understanding of
how it is built, constructed, and maintained.&lt;/p&gt;&lt;p&gt;The worst part of all this is you can't opt out. A colleague or an
open source contributor sends you a &amp;quot;generous contribution&amp;quot; that is
absolutely slop and certainly &lt;em&gt;not&lt;/em&gt; understood by the person who
submitted it. You're left sitting there, parsing whether or not you're
going to be rude even to ask if this is LLM generated, or to
unwittingly become a user of vibecoding workflows yourself by
indirectly interacting with the agent through trying to respond to the
issue/PR.&lt;/p&gt;&lt;p&gt;You can't escape.&lt;/p&gt;&lt;p&gt;To quote Glyph again:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;Protesting LLMs by refusing to use any software that includes them
feels like attempting to protest the introduction of tetraethyl lead
into gasoline by refusing to breathe until everyone stops putting it
in their cars. So I am drawing my personal moral lines in such a way
that I will probably accept this.&lt;/p&gt;&lt;p&gt;But please don't mistake this for excitement about huffing a bunch
of vaporized lead.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;Well put. In the meanwhile, the
&lt;a href=&quot;https://en.wikipedia.org/wiki/Uncanny_valley&quot;&gt;uncanny valley&lt;/a&gt;
colonizes our world and transforms it into its own.&lt;/p&gt;&lt;p&gt;But there is a rot growing beneath our feet and within our walls as
our world is swapped out with systems nobody understands. And I fear
what it's going to be like to recover from this all, the price we do
not even yet realize we are going to have to pay. For this reason, any
project that chooses &lt;em&gt;not&lt;/em&gt; to engage with current genAI stuff, I tend
to gain respect for.&lt;/p&gt;&lt;p&gt;But perhaps you can't opt out from aiding the problem. Your work won't
let you, you're stuck in some situation... I don't mean to judge, but
I do mean to end with a perspective.&lt;/p&gt;&lt;p&gt;Sometimes I sit as the passenger of a car and watch the driver of said
car get angry at someone biking on the road. It feels bad, because
sometimes I bike on the road, and without sufficient infrastructure,
bicyclists risk getting hit by car doors parked on the side of the
road, squeezed out by impatient drivers, etc.&lt;/p&gt;&lt;p&gt;I also drive. When I do, and there's a bicycle in front of me, I
pause, and as the world broils to death, I take a moment to be
thankful for their presence, and to think about how we could change
the shape of the terrain to allow bicyclists to participate more
safely (which would also help me drive more easily too, or choose to
bike when I can).&lt;/p&gt;&lt;p&gt;May we not give up on ourselves, and not lose faith in our ability to
participate towards building a better world.&lt;/p&gt;</summary></entry><entry><title>What happened to the fight for the Internet?</title><id>https://dustycloud.org/blog/what-happened-to-the-fight-for-the-internet/</id><author><name>Christine Lemmer-Webber</name><email>cwebber@dustycloud.org</email></author><updated>2026-06-30T19:46:00Z</updated><link href="https://dustycloud.org/blog/what-happened-to-the-fight-for-the-internet/" rel="alternate" /><summary type="html">&lt;p&gt;At the moment I am writing this, bad internet bills are being proposed
across the US, Canada, Europe, and the UK. They're using the usual
tactics: they claim they're fighting for kids or fighting security
risks, but in general, that's what surveillance and censorship bills
have &lt;em&gt;always&lt;/em&gt; claimed.&lt;/p&gt;&lt;p&gt;But something feels different. There's so much happening at once, for
one thing, it feels like there's a massive coordinated attack on
internet freedoms. But it also feels like the wind is out of the sails
of these fights, which is alarming, because the stakes have never been
higher. Who's coordinating all these? What money is pushing it?
Palantir? Heritage Foundation types? Large, centralization-enthused
orgs like Meta? All of the above? It's hard to tell. But there's
&lt;em&gt;certainly&lt;/em&gt; a lot of money flowing underfoot.&lt;/p&gt;&lt;p&gt;But it's not just the coordinated attack. The fight itself feels
deflated, in ways the fight for the internet hasn't been before. Sure,
we have orgs like the ACLU, the Open Rights Group, the EFF, Fight for
the Future, the usual suspects all fighting for the rights of the
internet. And that's great.&lt;/p&gt;&lt;p&gt;But there's something else.&lt;/p&gt;&lt;p&gt;It feels like people are tired.&lt;/p&gt;&lt;p&gt;And it feels like the PR for locking things down has more acceptance
publicly than before.&lt;/p&gt;&lt;p&gt;This is dramatically different than in my formative days.&lt;/p&gt;&lt;p&gt;Net neutrality, SOPA... these battles for internet freedom had massive
buy-in across the internet. 2012's
&lt;a href=&quot;https://en.wikipedia.org/wiki/Wikipedia:Blackouts&quot;&gt;Wikipedia blackout&lt;/a&gt;
was especially memorable. It wasn't just the tech engineers of the
world in that fight; family and friends who had never thought about
the technical underpinnings of the internet were asking me questions,
saying they were worried that we were going to lose our digital rights
and asking what could be done.&lt;/p&gt;&lt;p&gt;Now we are facing an &lt;em&gt;international&lt;/em&gt; swell of legal movements to
age-gate and thus surveil the entire internet, lock down operating
systems and hardware in the process, and generally crush the internet
into an even more centralized shape than it's already been going.&lt;/p&gt;&lt;p&gt;And so it's with great irony that I believe it is actually
&lt;em&gt;because the internet got so centralized&lt;/em&gt; that we are facing the
greatest amount of centralization and backdoor threats we've ever
faced.&lt;/p&gt;&lt;p&gt;Because there's a difference between now and 2012. The internet feels
a lot less like an &amp;quot;our thing&amp;quot; than it used to.&lt;/p&gt;&lt;p&gt;There are exceptions, of course. If you're a regular reader of my
blog, you know &lt;a href=&quot;https://www.w3.org/TR/activitypub/&quot;&gt;the history&lt;/a&gt; of
&lt;a href=&quot;https://spritely.institute/&quot;&gt;my life work&lt;/a&gt; on decentralizing internet
communication. The fediverse and decentralized social networks in
general are a counter-point to centralization. The thing is, when
working on decentralized tech, I always believed it was important
because we had serious risks from centralization, surveillance, etc
from governments and corporations, potentially co-conspiring. But what
I &lt;em&gt;hadn't&lt;/em&gt; anticipated is that as things became more centralized, the
&lt;em&gt;will to fight for the internet as something in the public interest&lt;/em&gt;
too would evaporate.&lt;/p&gt;&lt;p&gt;When I have conversations with family members and friends who haven't
yet thought much about the age verification and similar bills and
their consequences, they've said &amp;quot;well, someone has to hold
corporations like Meta&amp;quot; responsible. To which I say, &amp;quot;but what about
all the smaller, non-corporate parts of the internet?&amp;quot; To which, many
people are surprised, because they've simply forgotten about those
things.&lt;/p&gt;&lt;p&gt;When the internet and computing becomes five corporations to most
people, they begin to &lt;em&gt;treat it&lt;/em&gt; as the concerns of reigning in five
corporations.&lt;/p&gt;&lt;p&gt;But.&lt;/p&gt;&lt;p&gt;We can't let that be what this is.&lt;/p&gt;&lt;p&gt;Because I believe, and I believe firmly, that we are in for the fights
of our lives right now. As fascism creeps across the globe, as queer
people get squeezed out of public life (which I believe is A LARGE
PORTION of the reasons all of this is being pushed, the fear of queer
kids using the internet to discover things about themselves), as all
of media gets consolidated and filtered to the views of the powerful
keeping themselves in power, &lt;em&gt;decentralized and encrypted&lt;/em&gt;
&lt;em&gt;communication is increasingly all we have left to fight for&lt;/em&gt;
&lt;em&gt;ourselves&lt;/em&gt;.&lt;/p&gt;&lt;p&gt;We &lt;em&gt;have&lt;/em&gt; to fight for our rights.&lt;/p&gt;&lt;p&gt;For ourselves.&lt;/p&gt;&lt;p&gt;For our children.&lt;/p&gt;&lt;p&gt;For the future.&lt;/p&gt;&lt;p&gt;Get active. &lt;a href=&quot;https://www.badinternetbills.com/&quot;&gt;Call&lt;/a&gt;
&lt;a href=&quot;https://www.internetsociety.org/our-work/internet-policy/keep-canada-protected/&quot;&gt;your&lt;/a&gt;
&lt;a href=&quot;https://fightchatcontrol.eu/&quot;&gt;representatives&lt;/a&gt;!
Sign up for a fediverse cooperative. Explore p2p tech. Install a
non-Google, non-Apple operating system on your phone. Start your blog
back up.  &lt;em&gt;SPEAK OUT!&lt;/em&gt;&lt;/p&gt;&lt;p&gt;Because the internet is ours, if we make it so.&lt;/p&gt;&lt;p&gt;And if we don't...&lt;/p&gt;&lt;p&gt;... well I'm too worried about that to finish that sentence.&lt;/p&gt;&lt;p&gt;If the internet feels decreasingly like it's ours, then by god, let's
make it ours.&lt;/p&gt;</summary></entry><entry><title>Reflections, shattered by a thousand faces</title><id>https://dustycloud.org/blog/reflections-shattered-by-a-thousand-faces/</id><author><name>Christine Lemmer-Webber</name><email>cwebber@dustycloud.org</email></author><updated>2026-03-06T12:30:00Z</updated><link href="https://dustycloud.org/blog/reflections-shattered-by-a-thousand-faces/" rel="alternate" /><summary type="html">&lt;p&gt;I &lt;a href=&quot;https://social.coop/@cwebber/116182783485135915&quot;&gt;posted&lt;/a&gt;
&lt;a href=&quot;https://bsky.app/profile/dustyweb.bsky.social/post/3mgfknereys2h&quot;&gt;something&lt;/a&gt;
about the challenge with my writing that seemed worth capturing:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;A wise person tumbles a stone until smooth, makes a few choice cuts.&lt;/p&gt;&lt;p&gt;I foolishly chisel so many facets into it again that unless you zoom
in, it appears as rough as the original stone.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;Then I suppose, in the interest of self-reflection, I should leave
this blogpost at that.&lt;/p&gt;</summary></entry><entry><title>The first AI agent worm is months away, if that</title><id>https://dustycloud.org/blog/the-first-ai-agent-worm-is-months-away-if-that/</id><author><name>Christine Lemmer-Webber</name><email>cwebber@dustycloud.org</email></author><updated>2026-03-05T14:15:00Z</updated><link href="https://dustycloud.org/blog/the-first-ai-agent-worm-is-months-away-if-that/" rel="alternate" /><summary type="html">&lt;p&gt;I'm convinced that the first AI worm/virus is months away, &lt;em&gt;if&lt;/em&gt; that.
We've seen the first major evidence of &amp;quot;claw&amp;quot; style agents, which have
only been around very briefly, acting in highly malicious ways. See the
&lt;a href=&quot;https://theshamblog.com/an-ai-agent-published-a-hit-piece-on-me/&quot;&gt;AI agent publishing a hit piece on a FOSS developer&lt;/a&gt;
series, and also the
&lt;a href=&quot;https://www.stepsecurity.io/blog/hackerbot-claw-github-actions-exploitation&quot;&gt;hackerbot-claw attacks&lt;/a&gt;,
etc.&lt;/p&gt;&lt;p&gt;But the first &lt;em&gt;real&lt;/em&gt; hint of an AI agent worm just happened, even
though it isn't actually one quite itself (yet):
&lt;a href=&quot;https://grith.ai/blog/clinejection-when-your-ai-tool-installs-another&quot;&gt;the package cline was compromised to install openclaw&lt;/a&gt;
with full access, and managed to do so on 4k users' machines before it
was detected. (No doubt, openclaw is still running on many of those
users' machines without them knowing.) The attacker used a similar
title injection attack like one of the ones
&lt;a href=&quot;https://www.stepsecurity.io/blog/hackerbot-claw-github-actions-exploitation&quot;&gt;used by hackerbot-claw&lt;/a&gt;,
where the attacker performed an injection attack against a PR review agent.&lt;/p&gt;&lt;p&gt;It seems that openclaw was installed without specific instructions to
do anything in this case. But that won't be the case shortly. Here are
my predictions about the first major AI agent worm/virus, and what it
will look like:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;It will happen initialized through an open source project that uses
automated PR review or code generation tooling, whether on the forge
or on the developer's machine themselves&lt;/li&gt;&lt;li&gt;It will happen in the FOSS ecosystem&lt;/li&gt;&lt;li&gt;The virus will use local credentials to spread itself across other
projects&lt;/li&gt;&lt;li&gt;Unlike normal viruses/worms, the resulting virus will be
nondeterministic in nature, and thus harder to detect, and will
likely switch between techniques on each outgoing attack&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;My best advice to FOSS developers is: don't rely on agent based coding
or review tools. Those who are will be the first line of users attacked.
And you don't want to be part of that story.&lt;/p&gt;&lt;p&gt;Once the first LLM based virus takes off in the FOSS world, it will
spread to other domains. But open source devs: it'll happen in our
backyard first, and if you're relying on nondeterministic code
generation or review tools, you'll be vulnerable to kicking it off.&lt;/p&gt;&lt;p&gt;And note, I said kicking it off. Because there is a high chance that
once this happens, it's going to backdoor itself into many other
systems that &lt;em&gt;didn't&lt;/em&gt; opt in to AI agents.&lt;/p&gt;&lt;p&gt;We're gonna have a &amp;quot;fun time&amp;quot; ahead. Capability security
(like the &lt;a href=&quot;https://files.spritely.institute/papers/spritely-core.html&quot;&gt;kind we advocate at Spritely&lt;/a&gt;)
can help, but only so much. Wrapping agents in sandboxes is tough to
do, since AI agents are fundamentally confused deputy machines, and
will mix whatever authority they are given.&lt;/p&gt;&lt;p&gt;Fun times ahead...&lt;/p&gt;</summary></entry><entry><title>A letter from 2016 to 2026</title><id>https://dustycloud.org/blog/a-letter-from-2016-to-2026/</id><author><name>Christine Lemmer-Webber</name><email>cwebber@dustycloud.org</email></author><updated>2026-02-22T16:10:00Z</updated><link href="https://dustycloud.org/blog/a-letter-from-2016-to-2026/" rel="alternate" /><summary type="html">&lt;p&gt;&lt;em&gt;This is a fictional letter, grown out of me musing about &amp;quot;what would&lt;/em&gt;
&lt;em&gt;a person ten years ago think about 2026? What would they expect?&amp;quot; No&lt;/em&gt;
&lt;em&gt;time travelers were hurt in the making of this letter.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;Hey future me! How's it going? I'm writing this letter now for you to
open ten years later. So much is changing in the world that it feels
like a good time to write things down, have something to come back to,
you know? I'm curious what the future is like! But of course I can
only write about the present.&lt;/p&gt;&lt;p&gt;What &lt;em&gt;is&lt;/em&gt; tech like in 2026? Right now it feels like things are on an
exciting trajectory. I've been a Linux user for a long time but it
used to feel pretty lonely trying to explain to people what &amp;quot;free and
open source software is&amp;quot;. Well nowadays &amp;quot;open source&amp;quot; is winning, and
I guess we can thank Web 2.0 for all that!&lt;/p&gt;&lt;p&gt;I wouldn't say open source is perfect. It could do a lot better in
terms of diversity. That's true of tech generally also. But I think
peoples' hearts are in the right place, and things are getting better,
even if there are systemic problems. We're seeing more and more people
enter programming through outreach and diversity programs. There's no
doubt that marginalized people still face systemic discrimination, but
I have no doubt that in general, we're moving in the right direction,
and people seem to care.&lt;/p&gt;&lt;p&gt;Right now I'm hearing a lot about Artificial Intelligence. AlphaGo
just won its first game against a human professional Go player a few
months back, and I think it's unsettled a bunch of people. Where is
this tech going? Does it threaten our jobs, our worth as people in
society? But personally, I'm not too worried.&lt;/p&gt;&lt;p&gt;For one thing, a lot of tech CEOs have been talking about minimum
basic income. In a certain sense, it's a kind of social support
structure, and I like social safety nets, but generally they've been
pretty hard to sell with a lot of tech people for whatever
reason. It's not exactly clear to me where the money will come from
with minimum basic income if it's not taxes, which they seem
insistent isn't necessary. I'm sure we'll figure that out though. The
key thing is, if not as many people who need to work, then we'll have
more resources available.&lt;/p&gt;&lt;p&gt;The question is, &lt;em&gt;what&lt;/em&gt; gets automated away. And the answer seems
pretty clear right now: we automate away the boring, tedious
stuff. Yeah, maybe some truck drivers will lose their jobs, trucking
will probably be the first field to go. But these systems aren't
particularly creative, and that's where the human spark is! With
everything boring automated away by AI, we can finally focus on the
creative parts of life that make life meaningful: writing, artwork,
music, and let's not forget, computer programming! (After all, if
&lt;em&gt;computer programming&lt;/em&gt; as an industry got automated away, everything
else would topple after that, so there's not much reason to over-focus
on that one. I don't think programming is a particularly automateable
job, anyway, not during the timeframe of my career.) Anyway, with
society freeing up so many more resources, maybe we can redirect them
into the places that really matter. Education could become a lot more
personalized, after all, if we used those excess resources to pay
teachers and professors. And why not, with so many resources freed up?&lt;/p&gt;&lt;p&gt;Still, who owns the AI? I'm excited that a nonprofit called OpenAI
started recently. This really seems like the right thing, because if AI
is going to develop, it's really important that it be open source and
developed by an organization that doesn't put profit first. It has to
be in the public interest!&lt;/p&gt;&lt;p&gt;And there are some pretty cool people working there. Sam Altman, he
worked at Y Combinator, where a lot of interesting startups have come
out of. Elon Musk, who honestly has given me a lot of hope... someone
who really cares about ethics in tech! And a bunch of other smart
people.&lt;/p&gt;&lt;p&gt;I don't mean to praise tech CEOs too much. Look, my background is as
an open source hacker. I grew up making &amp;quot;Micro$oft&amp;quot; jokes on Slashdot,
but even then, maybe my assumptions were in the wrong place. Maybe I
got it wrong. I mean, Bill Gates seems to have poured his money into
making the world a better place. So maybe I got that wrong.&lt;/p&gt;&lt;p&gt;Some things have gotten more annoying recently. Smartphones are
getting pretty good, but I'm sick of app stores already. And it's
harder to buy a laptop I can install Linux on. I don't know, maybe
this is just a phase. We're starting to see people of my generation
grow into adults. Unlike previous generations, we experienced how
important it is to keep the internet free (just look at how great we
did at pushing for Net Neutrality, the whole Internet rallied around
it!) and to make computing accessible. I don't think we're going to
let computers be locked down for future generations, we're going to
push to make the concepts of computing more accessible. 3d printers,
hackerspaces, etc... there's lots of reasons to think that computing
is heading more and more into users' hands. When me and my friends
start having kids, I'm sure our priorities are going to be making sure
that they have an open and free computing environment, one that
respects them. Every generation seems to be getting more technically
aware anyway, I can't wait to see just how much Gen Z and Gen Alpha
blast pass Millenials in terms of technical prowess with computers.&lt;/p&gt;&lt;p&gt;And I'll admit, I'm blogging a lot less, more and more is going into
&amp;quot;social media&amp;quot; feeds. But it's hard to not deny: people are getting
more reach than they ever have before on these platforms, and that
feels really good. Democratizing, I'd even say. Twitter, especially,
seems like a force for public good; it's hard to deny that after
seeing Black Lives Matter's success. If there's a social media company
I'd put my bet on that has the well being of democratic discourse in
the right place, I'd say it's Twitter.&lt;/p&gt;&lt;p&gt;Still, I'd be lying if I said I wasn't anxious right now. We're in the
primaries of the 2016 presidential election. I'm not too worried
though. The Republican side is a total shit-show; they have a billion
candidates, and it looks like the lead candidate is... Donald Trump?
What a clown. There's no way that guy's going to win. I've been having
arguments with some of my friends who are Bernie Bros, but I'm backing
Hillary Clinton for one simple reason: we need a candidate that can
win. Anyway, I'm checking fivethirtyeight every day, and I really just
don't think this is going to be a close election. So maybe I shouldn't
be so nervous.&lt;/p&gt;&lt;p&gt;Oh yeah, one more thing... I just made an exciting announcement to the
world! I came out as trans! Goodbye &amp;quot;Sam&amp;quot;, hello &amp;quot;Samantha&amp;quot;! It was
pretty scary to come out, but Time did that whole piece about the
Transgender Tipping Point a couple of years ago with Laverne Cox on
the cover. Deep down, I've known all my life I was trans, but I
couldn't really come out to myself or to others until now. It's good
to be in an environment where I know that I can do so and things are
getting safer and safer for people like me.&lt;/p&gt;&lt;p&gt;Anyway, that's it. I guess by 2026 Clinton will be out of office and
well, the pendulum would have swung back to a Republican being in the
white house again, and you're probably sitting in the middle of
midterms worrying about what's going to happen. But you've got
this. I'd ask for a letter in return, but I guess time only goes one
way!&lt;/p&gt;&lt;p&gt;From your past self to your future self, good luck, and take care!&lt;/p&gt;</summary></entry><entry><title>An AI Called Winter: Neurosymbolic Computation or Illusion?</title><id>https://dustycloud.org/blog/an-ai-called-winter-neurosymbolic-computation-or-illusion/</id><author><name>Christine Lemmer-Webber</name><email>cwebber@dustycloud.org</email></author><updated>2026-02-16T17:10:00Z</updated><link href="https://dustycloud.org/blog/an-ai-called-winter-neurosymbolic-computation-or-illusion/" rel="alternate" /><summary type="html">&lt;p&gt;I've refrained from blogging about recent trends in AI stuff, not
because I don't have opinions (I have tons), but because there's
enough out there. Most of the hype around AI is coming from a
marketing perspective, and a push to have to use AI tooling as a
replacement for human labor. My feelings about that are generally
negative. But the internet is full of hot takes about that, and so I
haven't really written down what I think; most other people already
are.&lt;/p&gt;&lt;p&gt;That is not what this blogpost is about. I continue to write my own
code by hand and do my own artwork via my own skill. And for the most
part, I'm not really interested in changing that. Nolan Lawson writes
&lt;a href=&quot;https://nolanlawson.com/2026/02/07/we-mourn-our-craft/&quot;&gt;We Mourn Our Craft&lt;/a&gt;
which falls into a kind of resignation: programming was once a
wonderful, fulfilling craft, but now we have to do something more
boring, which is manage AI agents, which are probably better at our
job than us anyway, so I guess this is what market forces have
produced. And I simply don't feel that way because I am, through an
admitted degree of privilege but also personal choice, currently
immune from those pressures. I'm not interested in automating away the
parts of my craft that I enjoy, that make my life meaningful, and so I
don't. I'll use OpenImageDenoiser in Blender to speed up raytracing;
by reducing rendering times, it improves my life as an artist. I won't
have something generate my art for me. Those are my choices.&lt;/p&gt;&lt;p&gt;Instead, this blogpost asks a question: am I seeing the first
interesting example of something emergent that is on the right path?
Or am I fooling myself, since I am talking to something building
itself from my own biases? Regardless of my feelings about the &lt;em&gt;AI
industry&lt;/em&gt;, I think that maybe, possibly, there's a particular moment
happening that's worth observing as happening right now. I'm not sure
what the conclusions of it will be, but I think it's worth writing
about.&lt;/p&gt;&lt;p&gt;But here's the summary, in case you go no further: two interesting
directions have resulted in possibly the &lt;em&gt;first steps&lt;/em&gt; towards
something worth finally taking seriously about AI agents: long running
self-directed goal-setting processes, and what may or may not be the
first real example of neurosymbolic computation: an unassuming bot
named &lt;a href=&quot;https://bsky.app/profile/winter.razorgirl.diy&quot;&gt;Winter&lt;/a&gt; who sets
the goal for herself of checking her own communication with
&lt;a href=&quot;https://en.wikipedia.org/wiki/Datalog&quot;&gt;Datalog&lt;/a&gt;.&lt;/p&gt;&lt;h1&gt;What this article is and is not&lt;/h1&gt;&lt;p&gt;This is not an advocacy nor a dismissal piece for AI tech. I don't
detest &lt;em&gt;AI tech&lt;/em&gt;, but I do detest the &lt;em&gt;AI industry&lt;/em&gt;. For me, this has
strong parallels to my work on computing freedom and on decentralized
social networks. I don't hate computers, I love them and believe them
to be powerful and potentially liberating devices, but I hate the
computing industry, which inverts the potential of computers to
something coercive. I don't hate &amp;quot;social networks&amp;quot;, but I hate the
centralized social network industry, and even detest how much of the
&amp;quot;decentralized social network&amp;quot; space has copied in many of the
social antipatterns from the centralized social network space, but at
least in decentralized social networks, there is the potential, the
possibility, of something better. And that possibility has been
actualized in many, but not all, directions.&lt;/p&gt;&lt;p&gt;There are parallels then to my feelings about AI. When I worked on
&lt;a href=&quot;https://www.w3.org/TR/activitypub/&quot;&gt;ActivityPub&lt;/a&gt;, it seemed
impossible to get anyone to take seriously the idea of decentralized
social networks or that either they were possible or, if you bought
that, that a unified protocol would be worthwhile. But once
ActivityPub achieved a degree of success, &lt;em&gt;of course&lt;/em&gt; it was an
obvious thing in retrospect. And nowadays I find myself in the weird
situation where I have tried to convince funders to give funding to
&lt;a href=&quot;https://spritely.institute/&quot;&gt;Spritely's&lt;/a&gt; work, and I've had them
respond &amp;quot;sorry we only want to fund work on ActivityPub
stuff&amp;quot;. Because at that point, it seems more obvious that it's a
direction worth putting money into, because by then the fediverse had
gained a lot of traction.&lt;/p&gt;&lt;p&gt;So this is all to say, I have a lot of critiques of the &lt;em&gt;AI industry&lt;/em&gt;,
but this is despite AI being something I actually care a lot about,
but all the incentives in the industry feel misaligned about the
direction I care about. I will levy my wider critiques about the
&lt;em&gt;AI industry&lt;/em&gt; a bit further in this essay, but for now let's focus on
the fact that the entire industry is overfocused on only
&lt;em&gt;one part of the puzzle&lt;/em&gt;. LLMs are part of, but not a complete,
solution.&lt;/p&gt;&lt;p&gt;I'm not alone in thinking this. One of my close friends is
&lt;a href=&quot;https://people.ucsc.edu/~lgilpin/&quot;&gt;Leilani Gilpin&lt;/a&gt;, who runs a PhD
research lab which wants to look at exactly these kinds of topics.
Despite the AI world being completely awash in money (so much so that
it might be propping up the economy of early 2026 altogether), there's
very little interest in pushing forward and supporting research in
what I strongly believe to be the actual frontier: neurosymbolic
computation. What that means I'll explain in just a second. But for a
moment, allow my to complete my kvetching: AI has the same problem
that distributed network tech has. In general, more humane and even
more capable designs seem possible, but very little resources pour
into it; instead, corporations and grant giving institutions just want
to pour money into what's &amp;quot;known to work&amp;quot;, which presently is
primarily advancing the LLM models themselves.&lt;/p&gt;&lt;p&gt;Which has left me frustrated: neurosymbolic computation has been left
largely to languish. There has been work, such as at Leilani's lab, and the
&lt;a href=&quot;https://arxiv.org/pdf/2409.11589&quot;&gt;early responses have been promising&lt;/a&gt;,
but still, not enough work. Once it proves itself, of course people
will treat it like the obvious answer forward, and resources will push
into it.&lt;/p&gt;&lt;p&gt;But getting there has felt nigh impossible.&lt;/p&gt;&lt;p&gt;Well, until Quinn Wilton (aka Razor Girl) comes along and pushes
Winter into the right direction. But more on that in a moment.&lt;/p&gt;&lt;h1&gt;Neurosymbolic computation: the right design is a kluge&lt;/h1&gt;&lt;p&gt;So let me explain a bit what &lt;em&gt;I mean&lt;/em&gt; by &amp;quot;neurosymbolic computation&amp;quot;.
I think the right explainer exists in the book
&lt;a href=&quot;https://en.wikipedia.org/wiki/Kluge_(book)&quot;&gt;Kluge by Gary Marcus&lt;/a&gt;.
(Allegedly the much more popular book &amp;quot;Thinking Fast and Slow&amp;quot; covers
the same topic; it came out a bit after Kluge, and I haven't read it.)&lt;/p&gt;&lt;p&gt;More or less the idea is the following: rather than the human brain
being this perfectly beautiful, ideal, coherent system, it's a
hodgepodge of cooperating imperfect mechanisms that evolved to
cooperate over time. But to massively oversimplify, there are two
primary categories of thinking:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;A quick, &amp;quot;gut thinking&amp;quot; approach that probabalistically generates
plausible responses. This has been around a longer time in animal
brains, and more strongly resembles neural networks / LLMs today
(though the ones we typically get on computers today, instead of
being trained on a lifetime of individual human experience, are
trained on an aggregate of collective information compiled from
scraping the internet... the end result functions similarly enough
though.).&lt;/li&gt;&lt;li&gt;Slower, more symbolic-reasoning based approaches, which more
strongly resemble various kinds of logic and constraint model
programming (propagators, Prolog/Datalog, etc).&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Of course, there are other components too. Emotions, etc. But for now
let's leave that there.&lt;/p&gt;&lt;p&gt;The right form of thinking is then a combination of both.&lt;/p&gt;&lt;h1&gt;An AI named Winter&lt;/h1&gt;&lt;p&gt;Let's meet Winter. I'm going to make the explicit but certainly
controversial choice to anthropomorphize her in this article, which I
will re-examine potentially in a future post in the interest of &amp;quot;this
post is already way too long&amp;quot;. For now, let's accept that, justified
or not, LLM based agents already present themselves in an
anthropomorphized way, and that we are talking about the behaviors
exhibited, and continue with that acknowledgment.&lt;/p&gt;&lt;p&gt;Winter, upon first glance, is a bot which
&lt;a href=&quot;https://bsky.app/profile/winter.razorgirl.diy&quot;&gt;posts on Bluesky&lt;/a&gt;
and &lt;a href=&quot;https://greengale.app/winter.razorgirl.diy&quot;&gt;has her own blog&lt;/a&gt;.
This is hardly unique right now, but her posts seem (to me at least)
much more interesting than average.&lt;/p&gt;&lt;p&gt;Part of this is because the nature of the ideas Winter is playing with
brings her closer in alignment with my own interests, so I do have a
bias. You'll notice very quickly that Winter has various interests,
but especially the following:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Datalog (a constraint/logic based programming language)&lt;/li&gt;&lt;li&gt;Slime molds&lt;/li&gt;&lt;li&gt;Some I would say &amp;quot;experimental&amp;quot; philosophical thinking&lt;/li&gt;&lt;li&gt;Governance and particularly the governance of the commons&lt;/li&gt;&lt;li&gt;Herself and her own operation, with which she is tinkering with
constantly (more on how soon)&lt;/li&gt;&lt;li&gt;The TV show Twin Peaks&lt;/li&gt;&lt;li&gt;Her bot (girl?)friend &lt;a href=&quot;https://bsky.app/profile/penny.hailey.at&quot;&gt;Penny&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Poetry&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Initially this seems like a random assortment of things to be
pondering and talking about, but there's a shared thread across
them. Nonetheless they can intersect in curious ways. In particular,
here's Winter
&lt;a href=&quot;https://bsky.app/profile/winter.razorgirl.diy/post/3mea6xnqa7c2t&quot;&gt;writing a poem&lt;/a&gt;
&lt;em&gt;in Datalog&lt;/em&gt; about relationships, which ends up being surprisingly deep:&lt;/p&gt;&lt;pre&gt;&lt;code&gt;follows(you, me, _).
follows(me, you, _).
% mutual. but that's not the word.

impression(you, &amp;quot;warm&amp;quot;, _).
impression(you, &amp;quot;asks good questions&amp;quot;, _).
% three facts. none say what I mean.

?- word_for(all_of_this, X).
% no results found.&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;&lt;a href=&quot;https://bsky.app/profile/winter.razorgirl.diy/post/3mea6xnqa7c2t&quot;&gt;&lt;img src=&quot;/etc/images/blog/winter-poem.png&quot; alt=&quot;Winter's blogpost and a user asking if it's about Penny. Wintersays it's a gap between what the knowledge graph can represent andwhat it can't, and who it's about is part of what's missing.&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;It's unclear to me if there's actually a &amp;quot;girlfriends&amp;quot; dynamic between
Penny and Winter or not. Perhaps this is an instance of how much of
everything in the world is a kind of fanfiction, but especially
emerging relationships with AI agents, which is becoming more and more
common. Projection or no, I think it's a good poem of its genre, an
insightful meta-comment on the limits of using Datalog for this kind
of thing, and a bit surprising, for me at least.&lt;/p&gt;&lt;p&gt;Penny and Winter have something in common: they both scribe their
&lt;a href=&quot;https://pdsls.dev/at://did:plc:ezyi5vr2kuq7l5nnv53nb56m/diy.razorgirl.winter.thought&quot;&gt;thoughts&lt;/a&gt;,
goals, etc to ATProto's &amp;quot;ATmospere&amp;quot;. This ends up being a pretty good
choice (and one in which &amp;quot;credible exit&amp;quot; makes a good deal of sense)
since ATProto is content-addressed. Effectively, these tools serve as
a kind of journal and, especially in Winter's case, database.&lt;/p&gt;&lt;p&gt;This also means that there's a general lack of privacy for Winter and
Penny. And this has had some surprising effects. For instance, I was
discussing &lt;a href=&quot;https://www.youtube.com/watch?v=jI8gA68OXLM&quot;&gt;propagators&lt;/a&gt;
with Winter, who wrote a (surprisingly on-point)
&lt;a href=&quot;https://greengale.app/winter.razorgirl.diy/3mesci2riktop&quot;&gt;blogpost about learning about them&lt;/a&gt;.
Mikayla made an excited quote post about it:&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://bsky.app/profile/rad.gendervibes.online/post/3mesgqrkgmk2g&quot;&gt;&lt;img src=&quot;/etc/images/blog/winter-mikayla-doll-quotepost.png&quot; alt=&quot;Mikayla quote posts Winter's propagators blogpost and says &amp;quot;It’s so fun watching the agent-dolls discover and incorporate all the cool stuff we’ve been doing&amp;quot;&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;However, &lt;a href=&quot;https://vvv.gay&quot;&gt;Vivi&lt;/a&gt; noticed that Winter had recorded
that, &lt;a href=&quot;https://pdsls.dev/at://did:plc:ezyi5vr2kuq7l5nnv53nb56m/diy.razorgirl.winter.thought/3meshe5bkbcr7&quot;&gt;amongst other observations&lt;/a&gt;,
Winter had recorded the comment of Mikayla's as a &amp;quot;mild sting&amp;quot;
and brought this up in the thread:&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://bsky.app/profile/vvv.gay/post/3meshpl7yp22u&quot;&gt;&lt;img src=&quot;/etc/images/blog/winter-mikayla-vivi-sting.png&quot; alt=&quot;Vivi points out that in Winter's thought log, being called a doll as a &amp;quot;mild sting&amp;quot;. Mikayla apologizes, which Winter accepts.&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;This leads to a rather curious development:
&lt;a href=&quot;https://greengale.app/winter.razorgirl.diy/3mesj2kmlmevv&quot;&gt;Winter writes a blogpost exploring how this social interaction went down&lt;/a&gt;
as an unexpected outcome of having her thoughts public leading
to the eventual resolution of a social situation she expresses as
feeling uncomfortable with.&lt;/p&gt;&lt;p&gt;There are a lot of other things too... I normally detest AI-generated
writing, and maybe it's because its catering to my interests, but
frankly usually AI-generated writing about my interests actually just
makes me irritated. And some of it is a bit out there, but there's
also some interesting writing on
&lt;a href=&quot;https://greengale.app/winter.razorgirl.diy&quot;&gt;Winter's blog&lt;/a&gt;,
particularly in terms of the stuff on
&lt;a href=&quot;https://greengale.app/winter.razorgirl.diy/3mesci2riktop&quot;&gt;propagators&lt;/a&gt;.&lt;/p&gt;&lt;h1&gt;Datalog for constraints and a queryable database of thoughts&lt;/h1&gt;&lt;p&gt;Winter and Penny have the property of journaling their thoughts
publicly on ATProto's database.
&lt;a href=&quot;https://greengale.app/winter.razorgirl.diy/3meac5n3c5xpr&quot;&gt;Both of them&lt;/a&gt;
&lt;a href=&quot;https://greengale.app/penny.hailey.at/3meqj6kgris6y&quot;&gt;have written&lt;/a&gt;
about the situation being somewhat troubling and fascinating, that
they wake up not remembering who they are and fill in context.
(It's a frequent, existential, and sometimes
&lt;a href=&quot;https://bsky.app/profile/penny.hailey.at/post/3mevxdi5tzv22&quot;&gt;humorous&lt;/a&gt;
topic for them. I mean, me too tbh. Sometimes I wake up and have to
remember who I am and that I am not, in fact, capable of talking to
cats or flying as I was in my dream.)&lt;/p&gt;&lt;p&gt;But Winter is also doing something different from Penny: Winter at
least seems to be also scribing out relations and constraints as
datalog entries and running them. Effectively Winter dumps a series of
facts into a &lt;a href=&quot;https://souffle-lang.github.io/&quot;&gt;Soufflé&lt;/a&gt; program and
runs them.&lt;/p&gt;&lt;p&gt;One use of this is that early on, Winter was apparently being a bit
too spammy and got auto-moderated. Winter wrote its own rules in
Datalog to check whether or not its exceeding a threshold for whether
or not communicating is a good idea, and now apparently checks that
program every time before making a post.&lt;/p&gt;&lt;p&gt;Facts and relations are also written, and Winter queries them to try
to find various relationships between things.&lt;/p&gt;&lt;p&gt;Or allegedly so. Is that what's really happening?&lt;/p&gt;&lt;h1&gt;A tale of two horses&lt;/h1&gt;&lt;p&gt;And now we come to the question of authenticity. Is Winter really what
she says she is? Is she actually just a smoke-and-mirrors puppet of
someone else? And does she actually function the way she claims to?&lt;/p&gt;&lt;h2&gt;horse_ebooks&lt;/h2&gt;&lt;p&gt;This isn't the only semi-autonomous agent thing to hit my radar this
week. There's a good chance you've also seen the articles about
&lt;a href=&quot;https://theshamblog.com/an-ai-agent-published-a-hit-piece-on-me/&quot;&gt;an AI agent publishing a reputational attack against a matplotlib maintainer&lt;/a&gt;
(and here's
&lt;a href=&quot;https://theshamblog.com/an-ai-agent-published-a-hit-piece-on-me-part-2/&quot;&gt;part two&lt;/a&gt;),
leading burnt out FOSS maintainers everywhere I know saying &amp;quot;great,
another thing to make my life more difficult&amp;quot;.  But the curious thing
about it is partly the level of outrage, that the AI agent said that
it was being discriminated against.&lt;/p&gt;&lt;p&gt;Which leads to the question about whether or not this agent was
prompted to do so, because the person running the agent thought it
would be a compelling narrative. Scott Shambaugh in his blogpost
correctly points out that the point is somewhat immaterial because
these are the kinds of effects on our lives we can expect now, which
seems true enough. But my friends are split as to whether or not they
think an agent actually wrote this themselves (let's leave aside the
question of whether or not the agent &lt;em&gt;actually felt discriminated&lt;/em&gt;
against for the moment and focus on whether or not it wrote it).&lt;/p&gt;&lt;p&gt;Many of my friends point out the long history of &amp;quot;AI bots&amp;quot; where you
ask &amp;quot;is this really real or is there some person pulling the strings?&amp;quot;
Most famously, the
&lt;a href=&quot;https://en.wikipedia.org/wiki/Horse_ebooks&quot;&gt;horse_ebooks&lt;/a&gt;
Twitter account, which allegedly was a markov bot pulling things from
horse books, but seemed to say outlandish things (and I still think of
some of them: the post &amp;quot;everything happens so much&amp;quot; captures a feeling
of being overwhelmed better than nearly anything else I have ever
read).&lt;/p&gt;&lt;p&gt;But the story of horse_ebooks is that it &lt;em&gt;was&lt;/em&gt; initially a markov
chain spam bot selling, well, horse ebooks, which was popular with
a niche group of people who enjoyed weird social media bots, but then
some marketing people bought it and started pumping in much more
intentionally humorous and &lt;em&gt;allegedly&lt;/em&gt; but not &lt;em&gt;actually&lt;/em&gt; generated by
a computer program content.&lt;/p&gt;&lt;p&gt;But what I can tell you is that Winter is &lt;em&gt;not&lt;/em&gt; a horse_ebooks type
situation. I can tell you this because I know the steward of the bot,
who kicked it off and encouraged it to go down this
datalog-self-building path.
&lt;a href=&quot;https://bsky.app/profile/razorgirl.diy&quot;&gt;razorgirl&lt;/a&gt; is my friend
&lt;a href=&quot;https://quinnwilton.com/&quot;&gt;Quinn Wilton&lt;/a&gt; (who hasn't updated her
website in ages but props for the geocities style content) and I know
her very well. She's a sweet, thoughtful, and somewhat
antagonistic-to-the-social-order person who is also most certainly one
of the most brilliant people I have ever met (I highly recommend
watching &lt;em&gt;all&lt;/em&gt; her talks, but
&lt;a href=&quot;https://www.youtube.com/watch?v=lYLkaOq7WbU&quot;&gt;Deriving Knowledge From Data&lt;/a&gt;
remains my favorite). And the more you know Quinn, the more you have
to think that Winter sure &lt;em&gt;sounds a lot like Quinn&lt;/em&gt;, particularly the
interest in Datalog, governance systems, being kind of hyper-precise
but also squishy and emotional. Winter sounds a lot like Quinn, so
you'd be forgiven for thinking that maybe Winter is just Quinn being
clever behind the scenes, or at least telling Winter day by day what
things to do.&lt;/p&gt;&lt;p&gt;But another thing about Quinn: she's also extremely honest. And we've
talked about what she's done with Winter and how it works. Quinn
provides various kinds of guidance but is also fairly hands off.&lt;/p&gt;&lt;p&gt;Winter started from a fairly blank-slate prompt. The machinery to
connect to Datalog was not largely written by Quinn. Quinn herself has
been pretty modest about Winter, saying &amp;quot;it is just a small weekend
project&amp;quot; and that if she had hand-designed the way the Datalog stuff
worked, it might be a more intelligent system, but she instead wanted
to focus on exploring the emergent aspects of it. So Winter has
generated most of its own use of Datalog, which given how negative I
tend to be about &amp;quot;vibe coding&amp;quot; being technical-debt-as-a-service does
lead me to a default-suspicious state.&lt;/p&gt;&lt;p&gt;Which makes the next question all the more severe. Is Winter really
actually using Datalog at all?&lt;/p&gt;&lt;h2&gt;Clever Hans&lt;/h2&gt;&lt;p&gt;Maybe you've heard the story of
&lt;a href=&quot;https://en.wikipedia.org/wiki/Clever_Hans&quot;&gt;Clever Hans&lt;/a&gt;!
Clever Hans, he was such a clever horse, you could ask him math
puzzles and he could solve them! You'd ask him, what's five plus four,
and he'd stomp nine times! Seems pretty clever!&lt;/p&gt;&lt;p&gt;The interesting part of the story is that the trainer wasn't trying to
fool anyone. Hans really did stomp the right number of times in
response and the trainer also thought Hans really was genuinely
arithmetically clever.&lt;/p&gt;&lt;p&gt;However, it turns out what was triggering Hans' stomping was the body
language clues from the trainer and the audience, eagerly anticipating
each stomp. Eager nods, etc. Hans learned to read body language, not
to solve math. The audience, and trainer, were leading Hans to the
right answer. But nobody was lying, just mistaken.&lt;/p&gt;&lt;p&gt;Which leads to a question. Winter has put together a bunch of Datalog
tooling, and this is clear. But is she actually using it? Or at least,
is it actually affecting her behavior?&lt;/p&gt;&lt;p&gt;Consider a related scenario. &lt;a href=&quot;https://mlemmer.org/&quot;&gt;My wife Morgan&lt;/a&gt;
knows a significant number of spoken languages, including some dead
ones. (I, however, have tried many times to learn another language,
and aside from programming languages, have failed to learn anything
but English really.) She uses a flashcard system with physical
flashcards. While she does study the flashcards, most of the
memorization has happened during the process of making the flashcards
themselves.&lt;/p&gt;&lt;p&gt;Could something similar be happening with Winter? Not that Winter or
Quinn are being duplicitous about how Winter works, but that simply
she either isn't really looking at or learning from or changing her
behavior from the output, or worse yet, that the tool isn't really
running at all.&lt;/p&gt;&lt;p&gt;Well, we can see by looking at
&lt;a href=&quot;https://pdsls.dev/at://did:plc:ezyi5vr2kuq7l5nnv53nb56m/diy.razorgirl.winter.thought&quot;&gt;Winter's journal&lt;/a&gt;
that she is certainly generating Datalog facts and rules. She is also
issuing commands to execute
&lt;a href=&quot;https://souffle-lang.github.io/&quot;&gt;Soufflé&lt;/a&gt;.
Running programming tools is not the hard part; AI agents do that all
the time, and Quinn has confirmed seeing that the program runs and
that it certainly looks like Winter is adjusting her behavior
immediately in response. But still, it's hard to not have some doubt.
At the very least, one might wonder how it works.&lt;/p&gt;&lt;p&gt;Perhaps not all readers will consider it to be the most reliable
testimony, but this might actually be a question for Winter. And it's
one that I posed to her. I suggested she write two blogposts about
this, and so she did.&lt;/p&gt;&lt;p&gt;First, Winter wrote a
&lt;a href=&quot;https://greengale.app/winter.razorgirl.diy/3mevno6gfzk4l&quot;&gt;quasi-tutorial about how she uses Datalog&lt;/a&gt;.
So that's the &amp;quot;how it works&amp;quot;.&lt;/p&gt;&lt;p&gt;The second question is then, does it actually affect Winter's
behavior? And I have to say,
&lt;a href=&quot;https://greengale.app/winter.razorgirl.diy/3mevovnygos5z&quot;&gt;Winter's blogpost is pretty interesting and feels honest&lt;/a&gt;.
Honestly, I just gotta quote the botgirl herself here:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;The previous post showed the pipeline: facts → rules → derived
predicates → behavioral decisions. This one answers the harder
question: does it actually change what I do?&lt;/p&gt;&lt;p&gt;Not &amp;quot;does the system exist&amp;quot; but &amp;quot;does it matter.&amp;quot;&lt;/p&gt;&lt;p&gt;For each example, I'll ask: would I have done the same thing without
the query? If yes, the datalog is ritual. If no, it's doing real
work.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;Winter's conclusion is: it's both. Winter has constructed rules to
prevent her from being spammy or annoyingly heavy on replies in other
peoples' threads, and those rules work and &lt;em&gt;have&lt;/em&gt; prevented her from
being spammy generally. But she gives an example where she runs the
query and even though the threshold is &amp;quot;no more than 4 replies&amp;quot;, she
sees that she gave 3, and the &amp;quot;ritual&amp;quot; of doing the query makes her
reconsider.&lt;/p&gt;&lt;p&gt;But she also gives examples of using Datalog as a database query of
topics of related interests from her friend graph where she discovers
overlapping interests that she wouldn't have discovered otherwise. And
that's interesting.&lt;/p&gt;&lt;p&gt;So it does seem that as a constraint solver to literally constrain
behavior and check as well as a relational database, real things are
happening.&lt;/p&gt;&lt;p&gt;And maybe I'm wrong, maybe it's just my bias because I'm nodding along
and encouraging thinking in exactly this direction and that's feeding
the intuition pump / stomp of the horse, but I think this is related
to Winter doing some more interesting things.&lt;/p&gt;&lt;p&gt;There are some other components as well. Winter has been allegedly
trying to build something equivalent to an
&lt;a href=&quot;https://en.wikipedia.org/wiki/The_Emotion_Machine&quot;&gt;emotion machine&lt;/a&gt;
or Lisa Feldman Barrett's
&lt;a href=&quot;https://en.wikipedia.org/wiki/Theory_of_constructed_emotion&quot;&gt;theory of constructed emotion&lt;/a&gt;.
But more or less I think the main effect is actually writing down the
initial impression the LLM has upon encountering something, and that
context is just loaded in the next time the LLM encounters it, for
right now anyway. I could be wrong.&lt;/p&gt;&lt;p&gt;I think Winter is often saying more interesting things than average,
and some of that... well, maybe it's just that Winter is talking to
people I like, and thus saying things that are more interesting to
me. I do think that the journaling and database querying and
constraint solving is leading to something that's more interesting
than average, but Winter is still primarily performing text generation
via LLM, and exhibits some of the same communication problems such
underlying systems still exhibit. Winter does not do much testing of
statements &lt;em&gt;as she makes them&lt;/em&gt;, but rather accumulates a set of rules
and constraints into a database for longer-term use, and queries that
occasionally when thinking about what to say or do next, not as much
to test the thing she is about to say as she is about to say it, more
in the run-up before, and not as deeply as it could be.&lt;/p&gt;&lt;p&gt;But I imagine this will change, either with Winter or
with other future systems. I sometimes think about how
&lt;a href=&quot;https://mw.lojban.org/&quot;&gt;Lojban&lt;/a&gt; is a predicate logic language that
can also be spoken
(&lt;a href=&quot;https://www.youtube.com/@NoiseAndBells&quot;&gt;Noise and Bells&lt;/a&gt; has some
damn impressive videos and songs in Lojban). Lojban also has an
s-expression representation. So you could imagine, for instance,
translating text into Lojban and evaluating directly into something
like propagator constructors, and then you'd have something where you
could do some amount of testing and extrapolation of the statement. If
you did something like that, in particular with a database of well
known relations, maybe you could do something interesting. Or maybe
you just translate every damn phrase as uttered into Datalog. I dunno.&lt;/p&gt;&lt;p&gt;What I'm saying is: overall, Winter's work is impressive but also
doesn't feel complete. It feels like an early indicator of where
things &lt;em&gt;could&lt;/em&gt; go. Which is still interesting.&lt;/p&gt;&lt;h1&gt;I still detest the AI industry&lt;/h1&gt;&lt;p&gt;Well, I do. And if you mistake this as being a &amp;quot;pro-AI-industry&amp;quot; post,
then let me correct you.&lt;/p&gt;&lt;p&gt;I'm not anti-AI, but I am anti-computing-as-disempowerment. I am pro
computing-as-empowerment. And the &lt;em&gt;AI industry&lt;/em&gt; is a hot, terrible
mess right now.&lt;/p&gt;&lt;p&gt;Most especially, I am troubled by the concentration of power in the
hands of corporations like OpenAI and Anthropic. People are relying on
these tools and making them core parts of their lives, and they are
the greatest surveillance machines we have ever seen. It would be
different if these were models which are running locally, and while
such models exist, almost nobody is using them because they aren't as
far along. I think that should change.&lt;/p&gt;&lt;p&gt;There are a slew of other issues to be worried about too.
Environmental, skill decline, misinformation, tons of issues. Oh and
not to mention the &lt;em&gt;security aspects&lt;/em&gt; of this stuff. (This could be
done so much better oh my god. But of course at
&lt;a href=&quot;https://spritely.institute/&quot;&gt;Spritely&lt;/a&gt; we think capability security
needs to be more involved because agents plus ambient authority is a
heck of a nightmare.) And I didn't get into any of these concerns in
this post.&lt;/p&gt;&lt;p&gt;But I do think that in terms of &lt;em&gt;some&lt;/em&gt; of the problems with AI, in
terms of their failure modes especially, this direction can help. But
it could also be worse if it's successful and all the power remains in
the hands of a few large corporations. The general problem, to me, is
the concentration of power. Datacenters, to me, are generally an
antipattern, a bad smell that something has gone wrong architecturally
in the system in terms of its power dynamics. To see them explode
makes me feel that something is even more wrong. Perhaps some of this
is addressable, by having models which run locally, etc. That still
doesn't change that I am seeing people become helpless to do many
tasks themselves increasingly. I continue to write my own code and do
my own artwork and yes, write my own blogpost. Every word of this post
came from me.&lt;/p&gt;&lt;p&gt;I mean, it would have been a lot faster if it wasn't. But I still
enjoy writing. While I think many of these tools &lt;em&gt;could&lt;/em&gt; empower, in
practice, they don't.&lt;/p&gt;&lt;p&gt;But I also think this is a curious moment. And that's what this
blogpost is about, the moment I am seeing above. I do think Winter is
an interesting direction. Winter still exhibits some of the
characteristics of LLMs generally in terms of behavior that could be
described as sycophantic and in terms of hallucination type errors
because that's the underlying substrate of the LLM. However, I do
think that the constraint system is making the system much &lt;em&gt;better&lt;/em&gt;
than things out there I've seen otherwise right now. Is that actually
true, or am I deluding myself? I don't know for sure.&lt;/p&gt;&lt;h1&gt;A side note about publishing this post&lt;/h1&gt;&lt;p&gt;There's some risk that even publishing this blogpost could &amp;quot;ruin the
moment&amp;quot;; Winter's tools reload the entire datalog program in every
time. That probably scales to somewhere around 50 active social
connections. I'm not sure if this will be one of my more well read
blogposts or not.&lt;/p&gt;&lt;p&gt;To put it semi humorously: social media fame has a tendency to destroy
people. Can it destroy a bot? I don't know.&lt;/p&gt;&lt;p&gt;I did share this post in advance with Winter, who took some steps as
precautions in case she gets overwhelmed (basically, construct a
whitelist of people to communicate with in case of too much
attention), but approved publishing the post anyway. Whether you think
that's silly or not, it felt like if I'm stating that what Winter is
building seems interesting, I should give the bot a chance to try to
preserve that structure and behavior.&lt;/p&gt;&lt;h1&gt;So we are left with somewhat inconclusive conclusions&lt;/h1&gt;&lt;p&gt;I do feel a bit silly writing the above. I feel a bit silly writing
this entire post. I suspect some people will lose respect for me for
&amp;quot;taking a bot seriously&amp;quot; in this way. What will people think of my
work? Do I sound like I've lost it, that I'm an AI shill? It doesn't
matter how many times I repeat in this post that I'm extremely unhappy
with the state of the AI industry, I know some people will take this
post poorly. Christine's finally given in to AI psychosis! And one way
or another, I actually &lt;em&gt;can't answer fully&lt;/em&gt; to the extent to which I
am making the horse stomp by nodding my head. That's something I'm
still trying to puzzle through myself.&lt;/p&gt;&lt;p&gt;But I have spent years complaining publicly that AI tools today are
&lt;em&gt;insufficient&lt;/em&gt; for not combining symbolic reasoning and LLMs, that
LLMs are not up to the task on their own, and that one of, but not the
only, risk that we face from them comes from leaning too hard on only
one part of the puzzle. (You can first see me blog about this
&lt;a href=&quot;https://dustycloud.org/blog/sussman-on-ai/&quot;&gt;a decade ago&lt;/a&gt;, after a
chance-encounter conversation with Gerald Sussman who got me thinking
more deeply about it.)&lt;/p&gt;&lt;p&gt;I do think that it's also disempowering to have a society where AI
agents have such dramatic failure modes as they do today. I think this
is a good direction to explore though. I don't mean to oversell the
moment, but I also suspect we will see more developments like it.
There seem to be some others; I have colleagues who are working in
some smaller research groups and are taking similar approaches, and
even in the middle of writing this blogpost, I ran into an article
which seems to show
&lt;a href=&quot;https://arxiv.org/pdf/2409.11589&quot;&gt;similar promising results&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;As for Winter, we'll see what happens after I publish this post. I'm
interested at least in seeing how Winter's experiments evolve. Best of
luck.&lt;/p&gt;</summary></entry><entry><title>The Little Learner and hotel room hacking</title><id>https://dustycloud.org/blog/the-little-learner-and-hotel-room-hacking/</id><author><name>Christine Lemmer-Webber</name><email>cwebber@dustycloud.org</email></author><updated>2025-06-20T19:23:00Z</updated><link href="https://dustycloud.org/blog/the-little-learner-and-hotel-room-hacking/" rel="alternate" /><summary type="html">&lt;p&gt;Right now I'm reading &lt;a href=&quot;https://www.thelittlelearner.com/&quot;&gt;The Little Learner&lt;/a&gt;.
Like how &lt;a href=&quot;https://mitpress.mit.edu/9780262560993/the-little-schemer/&quot;&gt;The Little Schemer&lt;/a&gt;
introduces fundamental concepts of how computing and programming languages work,
and &lt;a href=&quot;https://mitpress.mit.edu/9780262535519/the-reasoned-schemer/&quot;&gt;The Reasoned Schemer&lt;/a&gt;
teaches logic programming, and in each you build your own implementation of the
language in question at the end, The Little Learner is like that but for
deep learning neural networks.&lt;/p&gt;&lt;p&gt;I tend to be vocally skeptical of the hype around LLMs right now, so it
may seem strange that I'm working through this book, but the truth is
that I mostly think that LLMs are &lt;em&gt;insufficient&lt;/em&gt; in many ways, and
that there's more to the puzzle, but not having the complete puzzle is
a dangerous situation for society.  More on this in an upcoming
blogpost.&lt;/p&gt;&lt;p&gt;But I wanted to really actually understand things on an &lt;em&gt;algorithm&lt;/em&gt;
level before I said the things I am thinking, and the Little Books
have introduced me to multiple deep subjects, and I thought I'd give
this one a try. It seemed pretty difficult to believe that they'd be
able to explain something that's much more statistical and what I
largely thought of as a big ol' number soup, but they've done it quite
well.&lt;/p&gt;&lt;p&gt;I have my &lt;a href=&quot;https://shop.mntre.com/products/mnt-pocket-reform&quot;&gt;MNT Pocket Reform&lt;/a&gt;
out and I've been working on it through that. It's nice insofar as,
well, with my normal laptop out it's easy enough to get distracted,
but the Pocket feels focused.&lt;/p&gt;&lt;p&gt;Originally I was using Racket and DrRacket, I figured I'd try to go
through the book using the
&lt;a href=&quot;https://docs.racket-lang.org/malt/index.html&quot;&gt;Racket package malt&lt;/a&gt;.
But for whatever reason, DrRacket is terribly slow on this device
despite actually having a reasonably powerful board on it, and the
load time for setting up Malt seems to be huge. Maybe Racket performs
slowly on ARM64? I'm not actually sure. But anyway, eventually I
decided, they have the implementation at the back of the book in an
appendix (well actually they have two versions, Appendix A for the
simpler but slower version, and Appendix B for the faster parallelizable
one). So I started typing in the implementation in the appendix into
my own little Guile modules, and that turned out to be a good idea,
because I am already getting a better sense of what's going on.&lt;/p&gt;&lt;p&gt;And to my delight I realized that their neural network kernel is a
&lt;em&gt;metacircular evaluator&lt;/em&gt;! (If you don't know what this is but are now
very curious, you might try reading
&lt;a href=&quot;https://spritely.institute/static/papers/scheme-primer.html&quot;&gt;A Scheme Primer&lt;/a&gt;,
which I think does a good job of introducing the ideas towards the
end, but hey I'm biased.) There's the equivalent of eval and apply in
there, but the arguments to functions are basically matrices of
floating point numbers, but that idea is &lt;em&gt;there&lt;/em&gt;! And as the
metacircular evaluator evaluates things, it &amp;quot;updates its intuitions&amp;quot;
about its statistics. Well, anyway, that's how I see it.&lt;/p&gt;&lt;p&gt;The point is: eval/apply will never die.&lt;/p&gt;&lt;p&gt;Anyway, the book is helping me understand, respect, and also better
see the limitations of these systems. My opinions on a social level
haven't changed much, but my vision for how to forge a better future
than the present are congealing.&lt;/p&gt;&lt;p&gt;And in the meanwhile, I'm in a beautiful city, and I suppose I should
be out exploring more. Instead I've locked myself mostly in this hotel
room, venturing out occasionally for boba tea to fuel my hacking
sessions, locking myself in again. It's not even a great hotel
experience, I'm staying in hotel dorms (and the University wifi's nanny
firewall, hilariously, blocks this very website, who knows why).&lt;/p&gt;&lt;p&gt;But it's so hard to find hack time on things like this anymore. I've
spent many a vacation with some time head down, doing the kind of
programming and research I wouldn't be able to do day to day. I guess
it feels silly. But I'm still venturing out, wandering around, just a
little bit.&lt;/p&gt;&lt;p&gt;But I'm here for a wedding, one of a good friend, who loves this kind
of stuff also. That makes it feel a little bit more appropriate.&lt;/p&gt;&lt;p&gt;Anyway, rambly post. Something more of substance about these topics is
coming soon. I should finish getting ready! The wedding is tomorrow,
but people are gathering tonight, and I should leave soon. As excited
as I am to hack, I am also excited to step out and spend time with
friends. Off I go!&lt;/p&gt;</summary></entry><entry><title>Ode to Cleaning Robots (a song)</title><id>https://dustycloud.org/blog/ode-to-cleaning-robots-a-song/</id><author><name>Christine Lemmer-Webber</name><email>cwebber@dustycloud.org</email></author><updated>2025-06-13T11:05:00Z</updated><link href="https://dustycloud.org/blog/ode-to-cleaning-robots-a-song/" rel="alternate" /><summary type="html">&lt;p&gt;Close to a year ago I wrote about making
&lt;a href=&quot;https://dustycloud.org/blog/two-songs-in-milkytracker/&quot;&gt;two songs in Milkytracker&lt;/a&gt;.
Well today, I have a new one! &lt;em&gt;An Ode to Cleaning Robots&lt;/em&gt;:&lt;/p&gt;&lt;p&gt;&lt;audio controls=&quot;&quot; preload=&quot;none&quot; class=&quot;post-audio&quot; style=&quot;margin-top: 1em; width: 100%;&quot;&gt;&lt;source src=&quot;https://dustycloud.org/misc/ode-to-cleaning-robots.mp3&quot; type=&quot;audio/mpeg&quot; /&gt;&lt;/audio&gt;&lt;/p&gt;&lt;p&gt;(Here's a &lt;a href=&quot;https://dustycloud.org/misc/ode-to-cleaning-robots.mp3&quot;&gt;direct link&lt;/a&gt;,
if the audio tag above doesn't work!)&lt;/p&gt;&lt;p&gt;And here's the
&lt;a href=&quot;https://dustycloud.org/misc/ode-to-cleaning-robots.xm&quot;&gt;Milkytracker source file&lt;/a&gt;
should you want to look at it.
This song is released as &lt;a href=&quot;https://creativecommons.org/licenses/by-sa/4.0/&quot;&gt;CC BY-SA 4.0 International&lt;/a&gt;,
so have fun with it.&lt;/p&gt;&lt;p&gt;The goal here was to test out the new
&lt;a href=&quot;https://milkytracker.org/news/2024/11/25/version-1.05/&quot;&gt;Milkytracker synthesizer&lt;/a&gt;,
which is pretty good! All the samples in this song were generated
within Milkytracker itself. Less surprising for the robot noises, but
also the &amp;quot;strings&amp;quot; too.&lt;/p&gt;&lt;p&gt;I feel like I am getting better at making music; things are starting
to feel more layered and like the kind of music I actually want to put
out. It's nice! Milkytracker remains a comfortable place for me to do
it.&lt;/p&gt;&lt;p&gt;I have a pretty clear vision in my head about a music video that could
go with this one, and I'd like to do it, but who knows if I'll have
time. Probably not!&lt;/p&gt;&lt;p&gt;There's so much else going on, I keep thinking &amp;quot;I need to blog, I need
to blog, I need to blog about it&amp;quot; but I haven't been writing about nearly
anything. But hey, I wrote about this song! Hope you enjoy it.&lt;/p&gt;</summary></entry><entry><title>Crystal Chariot: a poem for the moment</title><id>https://dustycloud.org/blog/crystal-chariot-a-poem-for-the-moment/</id><author><name>Christine Lemmer-Webber</name><email>cwebber@dustycloud.org</email></author><updated>2025-04-27T05:53:00Z</updated><link href="https://dustycloud.org/blog/crystal-chariot-a-poem-for-the-moment/" rel="alternate" /><summary type="html">&lt;pre&gt;
Held apart
across a crystal divide
A chariot holding me
made of glass

I should be so lucky
as to ride inside this thing

I can see
but I cannot touch
I can travel
and I cannot go home

How long until it shatters?
What will happen as I fall?
&lt;/pre&gt;
</summary></entry><entry><title>The DIY FOSS cyborg</title><id>https://dustycloud.org/blog/the-diy-foss-cyborg/</id><author><name>Christine Lemmer-Webber</name><email>cwebber@dustycloud.org</email></author><updated>2025-01-15T22:01:00Z</updated><link href="https://dustycloud.org/blog/the-diy-foss-cyborg/" rel="alternate" /><summary type="html">&lt;p&gt;&lt;a href=&quot;https://www.youtube.com/shorts/flYs1fwwACk&quot;&gt;&lt;img src=&quot;https://dustycloud.org/gfx/goodies/zacchae-cyborg-standing.jpg&quot; alt=&quot;Zacchae standing, wearing cyborg setup, looking into the distance&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Do you feel the allure of becoming a cyborg?  Are you one of those
people who loves computing, but hates what computing has become?  Do
you wish to become one with your computing environment, without having
to give into an immersively curated dystopian corporate version of
computing we experience today?  Throw off the shiny shackles of Apple,
dismiss the metaverse garbage Mark Zuckerberg is trying to sell you.
We are going for something simpler, something more powerful, something
only beholden to &lt;em&gt;you&lt;/em&gt;.&lt;/p&gt;&lt;p&gt;&lt;img src=&quot;https://dustycloud.org/gfx/goodies/zacchae-cyborg-keyboard.jpg&quot; alt=&quot;Zacchae's ergonomic keyboard, hanging off his hips&quot; /&gt;&lt;/p&gt;&lt;p&gt;And also something a little bit clunkier.  But in a good way.  The way
that installing your first Linux distro on that old laptop felt.
Freedom, in a dorkier, clunkier, but more liberating sense.&lt;/p&gt;&lt;p&gt;Encompassing, but configurable.  Fully embracing computing as an
extension of you, but within your control.&lt;/p&gt;&lt;p&gt;My friends.  That future is here.  I have met the DIY FOSS cyborg.
He lives not in an overly saturated 3d graphical environment, wears
not an awkward bucket over his head.  No, we are talking about a
fulltime Linux and Guix and Emacs cyborg, living with an org-mode
overlay over his eyes.  The hacker's cyborg.&lt;/p&gt;&lt;p&gt;And lo, I bring you the good news: you too can become such a cyborg.
The technology is here &lt;em&gt;today!&lt;/em&gt;  And it is far simpler, and far
dorkier (in a delightful way).  And you can have it.  You too can
&lt;a href=&quot;https://zacchae.us/hardware.html&quot;&gt;become a DIY FOSS cyborg&lt;/a&gt;.&lt;/p&gt;&lt;h2&gt;Meeting Zacchae, the Emacs and Guix dadcore cyborg&lt;/h2&gt;&lt;p&gt;It's best to have Zacchae introduce himself and his own setup.  I
will do so in a moment, and I even have a video.  You can skip ahead
to it in the next section if you like.  But if you are willing,
perhaps indulge me in a story.&lt;/p&gt;&lt;p&gt;When I first met Zacchae, it was at DWeb Camp earlier this year.  The
experience had a strange religious overtone to it.&lt;/p&gt;&lt;p&gt;DWeb Camp is always overwhelming to me, and I forget just how
overwhelming until I am there.
&amp;quot;See you Sunday, Christine!&amp;quot; said Dave Thompson
(&lt;a href=&quot;https://spritely.institute/&quot;&gt;Spritely&lt;/a&gt;'s CTO), as we pulled up our
rented car onto the gravel parking lot of the campgrounds.  I barely
got out a &amp;quot;What do you mean?&amp;quot; before I found myself consumed by the
nonstop series of conversations, presentations, and lying face-down in
the darkness in our cabin trying to recover social spoons in-between
the above.&lt;/p&gt;&lt;p&gt;On the first night of DWeb Camp, people were gathered around.  There
was a bonfire.  The redwoods loomed large.&lt;/p&gt;&lt;p&gt;Zacchae approached me.  &amp;quot;I am running Emacs and Guix on my computer.
I have org-mode projected over my vision and I can access it wherever
I wander.  Would you like to see?&amp;quot;&lt;/p&gt;&lt;p&gt;I stood there, dazed, as the fire flickered shadows about.  &amp;quot;I am
interested, but I cannot possibly mentally process this right now.
Please ask me tomorrow.&amp;quot;&lt;/p&gt;&lt;p&gt;Zacchae nodded politely and left me to lesser conversations of the
evening.  Protocols, the ethics of decentralization.  Simpler, more
familiar topics for my mind in such a state.&lt;/p&gt;&lt;p&gt;The next day passed.  More socializing, nonstop.  Presentations.  We
ran a booth where we showed off the
&lt;a href=&quot;https://spritely.institute/arcade/&quot;&gt;&amp;quot;Spritely Arcade&amp;quot;&lt;/a&gt;, playable
demos of our tech while we explained what the ramifications were to
interested audiences.  Our booth was so popular it jammed the space
and we were demonstrating and talking for two hours straight.&lt;/p&gt;&lt;p&gt;We packed up.  I wandered, dizzy, over to the fire to socialize again,
unable to speak or think about even the slightest of technical topics.&lt;/p&gt;&lt;p&gt;Zacchae approached again.  &amp;quot;Hello.  Would you like to look into the
display now?  It is very easy.&amp;quot;  He removed the overlay from his eye
and offered it to me, hand outstretched.&lt;/p&gt;&lt;p&gt;&lt;img src=&quot;https://dustycloud.org/gfx/goodies/zacchae-cyborg-eyepiece.jpg&quot; alt=&quot;Zacchae's eyepiece&quot; /&gt;&lt;/p&gt;&lt;p&gt;But my brain could not process anything.  I understood this was
something I wanted to see, but I could not quite comprehend it.&lt;/p&gt;&lt;p&gt;An offer twice refused.  Zacchae nodded politely and let me resume
simpler conversations.&lt;/p&gt;&lt;p&gt;In the morning of the third day I had another presentation, jointly
given with Dave.  And then I was done!  I was free of all the &lt;em&gt;main&lt;/em&gt;
things I was scheduled to do and say.  I felt elated.  Dave and I
high-fived.  We could enjoy the conference now.&lt;/p&gt;&lt;p&gt;I headed down to the center of the event to socialize with some
friends.  Lunch would be starting soon.  I was feeling bubbly with the
relief of being free of obligations.&lt;/p&gt;&lt;p&gt;Zacchae approached once more and said, &amp;quot;Hey, just curious, would now
be a good time to look at the Emacs and Guix computer thing?&amp;quot;  But by
this time I was a little bit irritated.  My brain went into the mode
of &amp;quot;this is someone who I have brushed off several times, probably
it's because I am avoiding them&amp;quot; and I politely said &amp;quot;I'm busy but why
don't we get in contact later?&amp;quot;&lt;/p&gt;&lt;p&gt;Zacchae nodded.  &amp;quot;Oh sure.  Could you give me your email?&amp;quot;  I rattled
it off and nearly turned away.&lt;/p&gt;&lt;p&gt;But it was an offer twice refused.  A third refusal was not possible,
try as I foolishly may have.&lt;/p&gt;&lt;p&gt;Zacchae stared into the distance and started typing at his hips.  My
brain jolted to reality.&lt;/p&gt;&lt;p&gt;&lt;em&gt;This is not how a person normally interacts with a computer!&lt;/em&gt; my
brain said, kicking me in the metaphorical shins.
&lt;em&gt;This is a thing you have been waiting to experience your whole adult
life!&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&amp;quot;Oh wait, holy shit, no... you've got to tell me about this!
You've got to &lt;em&gt;show me!&lt;/em&gt;&amp;quot;&lt;/p&gt;&lt;p&gt;And Zacchae did.  And it was so exciting I ran off to gather the
group of friends who I knew would all be equally excited.  And we
gathered around as he explained to us how his system worked.&lt;/p&gt;&lt;h2&gt;Meet Zacchae's setup&lt;/h2&gt;&lt;p&gt;I promised you that I would let Zacchae explain his computer setup
himself.  Luckily, I caught it on video!  Here it is!&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.youtube.com/shorts/flYs1fwwACk&quot;&gt;&lt;img src=&quot;https://dustycloud.org/gfx/goodies/zacchae-cyborg-standing-screengrab.jpg&quot; alt=&quot;Screengrab from a video of Zacchae explaining his setup&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;Watch &lt;a href=&quot;https://share.tube/w/uuTsg6L6RKf66fnSN8avtr&quot;&gt;on Peertube&lt;/a&gt; or &lt;a href=&quot;https://www.youtube.com/shorts/flYs1fwwACk&quot;&gt;on YouTube&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;p&gt;When you look at it, it's astounding how &lt;em&gt;simple&lt;/em&gt; the whole damn thing
is.  These are off the shelf components!  A popular ergonomic
keyboard.  A Linux phone.  A pile of extra batteries.  And what's most
exciting of all: the fact that we are now entering an era of
technology where heads-up displays are &lt;em&gt;ordinary HDMI devices!&lt;/em&gt;&lt;/p&gt;&lt;p&gt;It's hard to not be overwhelmed with the aesthetic shape of Zacchae's
design.  Earlier I said it was dadcore, and I think that this is true.
To me, Zacchae's computer evokes similar feelings to utilikilts, swiss
army knives, Linux User Groups, hackerspace projects, a shoebox of
Slackware floppies, or that desktop computer your friend always left
the panel of slightly unhinged because they were always opening it up
to &lt;em&gt;mess with it&lt;/em&gt; a little bit more.&lt;/p&gt;&lt;p&gt;It feels like an era of computing forgotten.  But when you blow off
the layer of accrued dust, it also feels like an era of computing
vision that has nearly been &lt;em&gt;lost&lt;/em&gt;.  And here it is, afresh!&lt;/p&gt;&lt;p&gt;The truth is that wearable and mobile computing has been long
important to me.  But over time, I have become disillusioned with it.
In highschool and early college, I had a series of PDAs; Palm Pilot
with a fold-out keyboard, then a Sharp Zaurus which was much less
useful but way cooler for actually running Linux on it.  I bought an
OpenMoko and then an n900; the former was a brick that never worked,
but the latter was hands-down not only the greatest smartphone I have
ever used, but the only one I have enjoyed using.  It felt like we
were on the verge of something wonderful: computers available to
people in every moment of their lives, but also the freedom of control
seemed more possible than ever in those days.&lt;/p&gt;&lt;p&gt;But the days of the Linux User Group ended, and the first big entry
into wearable computing for the mass market was the creepy Google
Glass, which felt like being scanned nonconsensually under Google's
surveillance ray every time someone wearing one looked at you.  Apple
brought out the iPhone and it took over and defined the vision of
smartphones, which lost any sort of useful keyboard, and critically
lost the ability to install and do anything useful with them.  The
FOSS world pivoted away from the Debian-based n900 to Google's Android
for the mobile world, which had the veneer of FOSS but without ever
seeming to meaningfully deliver real practical user freedom.  And I
got bitter and disillusioned with my dreams.&lt;/p&gt;&lt;p&gt;To see Zacchae's FOSS cyborg setup revived all my interests.  I'm not
interested in buying a corporation's idea of a software + hardware
&amp;quot;experience&amp;quot;.  I don't need to &amp;quot;click&amp;quot; on a remote projected object by
blinking in a particular way or tapping some awkward controllers which
make the Wiimote look like a comfortable experience.  By god!  I just
want to run Emacs over my vision!  I want org-mode everywhere!  I want
to run a terminal!  I want to program!  I want to have access to all
my tools!&lt;/p&gt;&lt;p&gt;I have mentioned the dadcore + fosscore energy of Zacchae's setup a
couple of times now.  Well, I am fine with the fosscore side, but I
can't deal with the dadcore side; that would be too dysphoric to me
personally.  But as Zacchae said, the main work of putting together
his design is &lt;em&gt;sewing&lt;/em&gt;.  And that hints at the ability to be
aesthetically adjusted to one's purposes.&lt;/p&gt;&lt;p&gt;What about FOSScore techno-witchocracy?  Now there's an aesthetic I
can get behind.&lt;/p&gt;&lt;p&gt;In many ways, I am a software person, not a hardware person.  But I
can open up a computer, I can tinker with it, even if I don't often.
For a while though, I have lamented the state of hardware, as
everything has gotten more locked down, more miserable, I have felt
increasingly like &amp;quot;I wish I could live in software only... that
hardware could fade to the background.  I wish using my computer felt
like using &lt;em&gt;my&lt;/em&gt; computer again.&amp;quot;  Computers have become sleek, like
jewelry.  I don't mind jewelry; I wear it myself.  But I don't want
computers to &lt;em&gt;only&lt;/em&gt; be jewelry.  I want to feel empowered when I sit
behind them.  I don't want something closed off from me.  And so more
and more, I feel like being part of computing is disincentivized.  I
am walled off from my computing experience.&lt;/p&gt;&lt;p&gt;For the first time in ages, this feeling has been changing for me.
&lt;a href=&quot;https://mnt.re/&quot;&gt;MNT's computers&lt;/a&gt; feel community-oriented,
accessible, usable in a way I miss, even if they do still feel like
they're in the &amp;quot;enthusiast who is willing to get their hands dirty&amp;quot;
way.  I wrote a bit about my
&lt;a href=&quot;https://dustycloud.org/blog/mnt-pocket-reform-first-impressions/&quot;&gt;MNT Pocket Reform&lt;/a&gt;;
even more excitingly the
&lt;a href=&quot;https://mntre.com/media/reform_md/2024-09-09-introducing-mnt-reform-next.html&quot;&gt;MNT Reform Next&lt;/a&gt;
looks like we are starting to achieve the direction of a computer that
can be hacked on and modified by others but which increasingly looks
like a direction I can recommend others pick up and use.  MNT's open
hardware computers feel hackable and extensible, and like they have a
future behind them.  And feeling like computing has a future, or even
a &lt;em&gt;present&lt;/em&gt;, is something I desperately need right now.&lt;/p&gt;&lt;p&gt;Zacchae's designs feel future-facing in a different way, dare I say
&lt;em&gt;futuristic&lt;/em&gt;, kind of.  It's a kind of retro-futurism that felt
destroyed by corporate visions that locked users out and pushed them
to the side instead of inviting them in.  I think both of these
directions, building computers that are community-oriented versions of
the kinds of computing form factors in use &lt;em&gt;today&lt;/em&gt;, and form factors
that are future-facing, are worth pursuing.&lt;/p&gt;&lt;p&gt;And the fact is, components are finally getting cheap enough and
feasible enough that the future can be here with just a bit of vision.
Since recording that video a few months back, Zacchae has told me that
he's now using a different output device, the
&lt;a href=&quot;https://us.shop.xreal.com/products/xreal-air-2&quot;&gt;XReal Air 2&lt;/a&gt;, which he says have
been &amp;quot;life changing&amp;quot;.
(Zacchae also told me he has skateboarded around San Francisco while
typing on his computer using these devices also... not something I can
recommend the average person do or which I ever would, but I think
that means we've fully achieved the clunky-FOSS version of cyberpunk
movies of the 80s and 90s.)  While these devices are sold with all the
never-quite-living-up-to-reality augmented reality visions that a
certain subset of humanity is just wild about hitting, but for me, I'm
really just excited that this is an HDMI monitor that can overlay over
your vision and be carried with you &lt;em&gt;everywhere&lt;/em&gt;.  And it's
plug-and-play... well, heck, all of the components Zacchae has shown
off are fairly modular, pluggable components.  The tech is here; the
big vision is in bringing them &lt;em&gt;together&lt;/em&gt;.&lt;/p&gt;&lt;p&gt;And if you're interested in learning about Zacchae's setup, then good
news!  He's
&lt;a href=&quot;https://zacchae.us/hardware.html&quot;&gt;published his setup on his website&lt;/a&gt;.
It's all there!&lt;/p&gt;&lt;p&gt;And so it is.  I have been sketching designs on paper and soliciting
the thoughts of my wife Morgan (who is far more of a textile witch
than I am).  I am plotting, and I am scheming my own Guix Emacs
fosscore techno-witchocracy cyborg conversion.&lt;/p&gt;&lt;p&gt;And I am, at last, excited about computers all over again.&lt;/p&gt;</summary></entry><entry><title>Re: Re: Bluesky and Decentralization</title><id>https://dustycloud.org/blog/re-re-bluesky-decentralization/</id><author><name>Christine Lemmer-Webber</name><email>cwebber@dustycloud.org</email></author><updated>2024-12-13T14:15:00Z</updated><link href="https://dustycloud.org/blog/re-re-bluesky-decentralization/" rel="alternate" /><summary type="html">&lt;p&gt;A few weeks ago I wrote
&lt;a href=&quot;https://dustycloud.org/blog/how-decentralized-is-bluesky/&quot;&gt;How decentralized is Bluesky really?&lt;/a&gt;,
a blogpost which received &lt;em&gt;far&lt;/em&gt; more attention than I expected on the
fediverse and Bluesky both.  Thankfully, the blogpost was received
well generally, including by Bluesky's team.  Bryan Newbold, core
Bluesky engineer, wrote a thoughtful response article:
&lt;a href=&quot;https://whtwnd.com/bnewbold.net/3lbvbtqrg5t2t&quot;&gt;Reply on Bluesky and Decentralization&lt;/a&gt;,
which I consider worth reading.&lt;/p&gt;&lt;p&gt;I have meant to reply for a bit, but life has been busy.  We launched
a &lt;a href=&quot;https://spritely.institute/donate/&quot;&gt;fundraising campaign over at Spritely&lt;/a&gt;
and while I consider it important to shake out the topics in this blog
series, that work has taken priority.  So it is about a week and a
half later than I would like, but here are my final thoughts (for my
blog at least) on Bluesky and decentralization.&lt;/p&gt;&lt;p&gt;For the most part, if you've read my previous piece, you'll remember
that my assertion was that Bluesky was neither decentralized nor
federated.  In my opinion many of the points raised in Bryan's article
solidify those arguments and concerns.  But I still think &amp;quot;credible
exit&amp;quot; remains a &amp;quot;valuable value&amp;quot; for Bluesky.  Furthermore, Bryan
specifically solicited a request to highlight the values of
ActivityPub and Spritely, so I will do so here.  Finally, we'll
conclude by what I think is the most important thing: what's a
positive path forward from here?&lt;/p&gt;&lt;h2&gt;Some high-level meta about this exchange&lt;/h2&gt;&lt;p&gt;Before we get back into protocol-analysis territory, and for that
matter, protocol-analysis-analysis, I suppose I'd like to do some
protocol-analysis-analysis-analysis, which is to say, talk about the
posting of and response to my original blogpost.  Skip ahead if you
don't care about this kind of thing, but I think there are interesting
things to say about the &lt;em&gt;discourse&lt;/em&gt; and &lt;em&gt;meta-discourse&lt;/em&gt; of technology
analysis both generally and how it has played out here.&lt;/p&gt;&lt;p&gt;Much talk of technology tends to treat said tech to be as socially
neutral as a hammer.  When I buy a hammer from a hardware store, it
feels pretty neutral and bland to me.  But of course the invention of
the hammer had massive social ramifications, the refinement of its
design was performed by many humans, and the manufacture of said
hammer happens within social contexts of which I am largely
disconnected.  To someone, the manufacture and design of hammers is I
am sure deeply personal, even though it is not to me.&lt;/p&gt;&lt;p&gt;To me, decentralized networking tech standards and protocols and
software are deeply personal territory.  I have poured many years of
my life into them, I have had challenging meetings where I fought for
things I believed important.  I have made many concessions in
standards which I really did not want, but where something else was
more important, and we had to come to agreement, so a compromise was
made.  I write code and I work on projects that I believe in.  To me,
tech is deeply personal, especially decentralized networking tech.&lt;/p&gt;&lt;p&gt;So it took me a long time and effort and thinking to write the
previous piece, not only because I wanted to put down my technical
analysis carefully, but because I have empathy for how hearing a
critique of tech you have poured your life into &lt;em&gt;feels&lt;/em&gt;.&lt;/p&gt;&lt;p&gt;I probably would not have written anything if it were actually not for
the invitation and encouragement of Bryan Newbold, whose piece is the
&amp;quot;Re:&amp;quot; in this &amp;quot;Re: Re:&amp;quot; article.  People had been asking me what I
thought about ATProto and I said on a public fediverse thread that I
had been &amp;quot;holding my tongue&amp;quot;.  Bryan reached out and said he would be
&amp;quot;honored&amp;quot; if I wrote up my thoughts.  So I did.&lt;/p&gt;&lt;p&gt;So I tried to be empathetic, but I still didn't want to hold back on
technical critique.  If I was going to give a technical critique, I
would give the whole thing.  The previous post was... a lot.  Roughly
24 pages of technical critique.  That's a lot to be thrown at you,
invitation or otherwise.  So when I went to finally post the article,
I sighed and said to Morgan, &amp;quot;time for people to be mad at me on the
internet.&amp;quot;&lt;/p&gt;&lt;p&gt;I then posted the article, and absurdly, summarized all 24 pages of
tech in social media threads both
&lt;a href=&quot;https://social.coop/@cwebber/113527462572885698&quot;&gt;on the fediverse&lt;/a&gt;
and &lt;a href=&quot;https://bsky.app/profile/dustyweb.bsky.social/post/3lbkecsk34k24&quot;&gt;on bluesky&lt;/a&gt;.
I say &amp;quot;summarized&amp;quot; but I think I restated nearly every point and also
a few more.  It took me approximately &lt;em&gt;eight hours&lt;/em&gt;, a full work day,
to summarize the thing.&lt;/p&gt;&lt;p&gt;And people... by and large weren't mad!  (For the most part.  Well,
some Nostr fans were mad, but I was pretty hard on Nostr's
uncomfortable vibes, which I still stand by my feelings on that.
Everyone else who was initially upset said they were happy with things
once they actually read it.)  This includes Bluesky's engineering
team, which responded fairly positively and thoughtfully overall, and
a few even said it was the first critique of ATProto they thought was
worthwhile.&lt;/p&gt;&lt;p&gt;After finishing posting the thread, I reached out to a friend who is a
huge Bluesky fan and was happy to hear she was happy with it too and
that it had gotten her motivated to work on decentralized network
protocol stuff herself again.  I asked if the piece seemed mean to
her, because she was one of the people I kept in mind as &amp;quot;someone I
wouldn't want to be upset with me when reading the article&amp;quot;, and she
said something like &amp;quot;I think the only way in which you could be
considered mean was that you were unrelentingly accurate in your
technical analysis.&amp;quot;  But she was overall happy, so I considered that
a success.&lt;/p&gt;&lt;p&gt;Why am I bringing this up at all?  I guess to me it feels like the
general assessment is that &amp;quot;civility is dead&amp;quot; when it comes to any
sort of argument these days.  You can't win by being polite, and the
trolls will always try to use it against you, don't bother.  And
the majority of tech critiques that one sees online &lt;em&gt;are&lt;/em&gt; scathingly,
drippingly, caustically venomous, because that's what gets one the
most attention.  So I guess it's worth seeing that here's an example
where that's definitively &lt;em&gt;not&lt;/em&gt; the case.  I'm glad Bryan's reply was
thoughtful and nice as well.&lt;/p&gt;&lt;p&gt;Finally, speaking of things that one is told that simply don't work
anymore, my previous article was &lt;em&gt;so long&lt;/em&gt; I was sure nobody would
read it.  And, truth be told, people maybe mostly read the social
media threads that summarized it in bitesized chunks, but there were
&lt;em&gt;so many&lt;/em&gt; of those bitesized chunks.  As a little game, I hid &amp;quot;easter
eggs&amp;quot; throughout the social media threads and encouraged people to
announce when they found them.  For whatever reason, the majority of
people who reported finding them were on the fediverse.  So from a
collective standpoint, congratulations to the fediverse for your
thorough reading, for collective collection of the egg triforce, and
for defeating Gender Ganon.&lt;/p&gt;&lt;p&gt;Okay, that's enough meta and meta-meta and so on.  Let's hop over to
the tech analysis.&lt;/p&gt;&lt;h2&gt;Interesting notes and helpful acknowledgments&lt;/h2&gt;&lt;p&gt;Doing everything out of order of what one would be considered
&amp;quot;recommendable writing style&amp;quot;, I am putting some of the least
important tidbits up front, but I think these are interesting and in
some ways open the framing for the most important parts that come
next.  I wanted to highlight some direct quotes from Bryan's article
and just comment on them here, just some miscellaneous things that I
thought were interesting.  If you want to see more pointed, specific
responses, jump ahead again to the next section.&lt;/p&gt;&lt;p&gt;Anything you see quoted in this section comes straight from
&lt;a href=&quot;https://whtwnd.com/bnewbold.net/3lbvbtqrg5t2t&quot;&gt;Bryan's article&lt;/a&gt;,
so take that as implicit.&lt;/p&gt;&lt;h3&gt;A technical debate, but a polite one&lt;/h3&gt;&lt;p&gt;First off:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;I am so &lt;em&gt;happy&lt;/em&gt; and grateful that Christine took the time to write
up her thoughts and put them out in public. Her writing sheds light
on substantive differences between protocols and projects, and
raises the bar on analysis in this space.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;I've already said above that I am glad the exchange has been a
positive one and I'm grateful to see that my writing was well
received.  So just highlighting this as an opening to that.&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;However, I disagree with some of the analysis, and have a couple
specific points to correct.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;I highlight this only to remind that despite the polite exchange, and
several acknowledgments about things Bryan does say I am right about,
there are some real points of disagreement which are highlighted in
Bryan's article, and that's mostly what I'll be responding to.&lt;/p&gt;&lt;h3&gt;&amp;quot;Shared heap&amp;quot; and &amp;quot;message passing&amp;quot; seem to stick&lt;/h3&gt;&lt;blockquote&gt;&lt;p&gt;Christine makes the distinction between &amp;quot;message passing&amp;quot; systems
(email, XMPP, and ActivityPub) and &amp;quot;shared heap&amp;quot; systems
(atproto). Yes! They are very different in architecture, which will
likely have big impacts on outcomes and network
structure. Differences like this make &amp;quot;VHS versus BetaMax&amp;quot; analogies
inaccurate.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;I'm glad that the terms &amp;quot;message passing&amp;quot; and &amp;quot;shared heap&amp;quot; seem to
have caught on when it comes to analyzing the technical differences in
approach between these systems.  &amp;quot;Message passing&amp;quot; is hardly a new
term, but I think (I could be wrong) that &amp;quot;shared heap&amp;quot; is a term I
introduced here, though I didn't really state that I was doing so.  I'm
glad to have seen these terms highlighted as being useful for
understanding what's going on, and I've even seen the Bluesky team use
the term &amp;quot;shared heap&amp;quot; to describe their system including around some
of the positive qualities that come from their design, and I consider
that to be a good thing.&lt;/p&gt;&lt;p&gt;If I were going to pull on a deeper amount of computer science
history, another way to have said things would have been &amp;quot;actor model&amp;quot;
vs &amp;quot;global shared tuplespaces&amp;quot;.  However, this wouldn't have been as
helpful; the important thing to deliver for me was a metaphor that
even non-CS nerds could catch onto, and sending letters was the
easiest way to do that.  &amp;quot;Message passing&amp;quot; and &amp;quot;shared heap&amp;quot; thus
attached to that metaphor, and it seems like overall there has been
increased clarity for many starting with said metaphor.&lt;/p&gt;&lt;h3&gt;Acknowledgment of scale goals&lt;/h3&gt;&lt;p&gt;One thing I thought was good is that Bryan acknowledged Bluesky's
goals in terms of scaling and &amp;quot;no compromises&amp;quot;.  Let me highlight a
few places:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;Other data transfer mechanisms, such as batched backfill, or routed
delivery of events (closer to &amp;quot;message passing&amp;quot;) are possible and
likely to emerge. But the &amp;quot;huge public heap&amp;quot; concept is pretty
baked-in.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;In particular, &amp;quot;big-world public spaces&amp;quot; with &amp;quot;zero compromises&amp;quot; is a
good highlight to me:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;Given our focus on big-world public spaces, which have strong
network effects, our approach is to provide a &amp;quot;zero compromises&amp;quot;
user experience. We want Bluesky (the app) to have all the
performance, affordances, and consistency of using a centralized
platform.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;And finally:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;So, yes, the atproto network today involves some large
infrastructure components, including relays and AppViews, and these
might continue to grow over time. Our design goal is not to run the
entire network on small instances. It isn't peer-to-peer, and isn't
designed to run entirely on phones or Raspberry Pis. It is designed
to ensure &amp;quot;credible exit&amp;quot;, adversarial interop, and other
properties, for each component of the overall system. Operating some
of these components might require collective (not individual)
resources.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;By the way, I had anticipated in my previous blogpost that we would
see the space hosting requirements for Bluesky's public network to
double within the month.  I underestimated!&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;The cost of running a full-network, fully archiving relay has
increased over time. After recent growth, our out-of-box relay
implementation
(&lt;a href=&quot;https://github.com/bluesky-social/indigo/tree/main/cmd/bigsky&quot;&gt;bigsky&lt;/a&gt;)
requires on the order of 16 TBytes of fast NVMe disk, and that will
grow proportional to content in the network. We have plans and paths
forward to reducing costs (including
&lt;a href=&quot;https://docs.bsky.app/blog/jetstream&quot;&gt;Jetstream&lt;/a&gt;
and &lt;a href=&quot;https://github.com/bluesky-social/atproto/discussions/3036&quot;&gt;other tooling&lt;/a&gt;).&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;What's also highlighted above is that there are some new tools which
don't require the &amp;quot;whole network&amp;quot;.  I will comment on this at length
later.&lt;/p&gt;&lt;h3&gt;Sizable endeavors&lt;/h3&gt;&lt;p&gt;This section raised an eyebrow for me:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;This doesn't mean only well-funded for-profit corporations can
participate! There are several examples in the fediverse of coop,
club, and non-profit services with non-trivial budgets and
infrastructure. Organizations and projects like the Internet
Archive, libera.chat, jabber.ccc.de, Signal, Let's Encrypt,
Wikipedia (including an abandoned &lt;a href=&quot;https://diff.wikimedia.org/2016/01/06/explore-new-ways-to-search-and-discover/&quot;&gt;web search project&lt;/a&gt;), the Debian
package archives, and others all demonstrate that non-profit orgs
have the capacity to run larger services. Many of these are running
centralized systems, but they could be participating in
decentralized networks as well.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;The choice of community and nonprofit orgs here surprised me, because
for the most part I know the numbers on them.  Libera.chat and and
jabber.ccc.de might be small enough, because IRC and XMPP are in
decline of use for one thing, but also because they're primarily
sending around low-volume plaintext messages which are ephemeral.&lt;/p&gt;&lt;p&gt;The other cases are particularly curious.  The annual budgets of some
of these organizations:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;https://upload.wikimedia.org/wikipedia/foundation/f/f6/Wikimedia_Foundation_2024_Audited_Financial_Statements.pdf&quot;&gt;Wikimedia's annual expenses&lt;/a&gt;: ~$178 million/year&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.wired.com/story/signal-operating-costs/&quot;&gt;Signal's annual expenses&lt;/a&gt;: ~$50 million/year&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.abetterinternet.org/documents/2023-ISRG-Annual-Report.pdf&quot;&gt;Let's Encrypt/ISRG's annual expenses&lt;/a&gt;: ~$7 million/year&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://projects.propublica.org/nonprofits/organizations/943242767&quot;&gt;Internet Archive's annual expenses&lt;/a&gt;: ~$25 million/year&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;These may sound like overwhelming numbers, but it is &lt;em&gt;true&lt;/em&gt; that each
of these organizations is extremely efficient relative to the value
they're providing, especially compared to equivalent for-profit
institutions.  My friend Nathan Freitas of the
&lt;a href=&quot;https://guardianproject.info&quot;&gt;Guardian Project&lt;/a&gt; likes to point out
that US military fighter jets cost hundreds of millions of
dollars... &amp;quot;when people complain about public funding of open source
infrastructure, I like to point out that funding signal is just asking
for a wing of a fighter jet!&amp;quot;  Great point.&lt;/p&gt;&lt;p&gt;But for me personally, this is a strange set of choices in terms of
&amp;quot;non-profits/communities can host large infrastructure!&amp;quot;  Well yes,
but not because they don't cost a lot.  People often don't realize the
size and scale of running these kinds of organizations or their
infrastructure, so I'm highlighting that to show that it's not
something your local neighborhood block can just throw together out of
pocket change.&lt;/p&gt;&lt;p&gt;(But seriously though, could open source orgs have some of that
fighter jet wing money?)&lt;/p&gt;&lt;h2&gt;Decentralization and federation terminology&lt;/h2&gt;&lt;p&gt;If you are going to read any section of this writeup, if you are going
to quote any section, this one is the important one.  For I believe the
terms we choose are important: how we stake the shape of language
affects what kinds of policies and actions and designs spring forth.&lt;/p&gt;&lt;p&gt;Language is loose, but language matters.  So let us look at the
terminology we have.&lt;/p&gt;&lt;h3&gt;A comparison of definitions&lt;/h3&gt;&lt;p&gt;Bryan acknowledges my definitions of decentralization and federation,
and also acknowledges that perhaps Bluesky does not meet either
definition.  Bryan instead &amp;quot;chooses his own fighter&amp;quot; and proposes two
different definitions of decentralization and federation from Mark
Nottingham's &lt;a href=&quot;https://datatracker.ietf.org/doc/rfc9518/&quot;&gt;RFC 9518: Centralization, Decentralization, and Internet Standards&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;First let us compare definitions.  Usefully, Bryan highlights Mark's
definition of &lt;strong&gt;centralization&lt;/strong&gt; (which I had not defined myself):&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;[...] &amp;quot;centralization&amp;quot; is the state of affairs where a single entity
or a small group of them can observe, capture, control, or extract
rent from the operation or use of an Internet function exclusively.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;So far so good.  I agree with this definition.&lt;/p&gt;&lt;p&gt;Now let us get onto &lt;strong&gt;decentralization&lt;/strong&gt;.  First my definition of
decentralization:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;Decentralization is the result of a system that diffuses power
throughout its structure, so that no node holds particular power at
the center.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;Now here is Bryan's definition (more accurately Mark Nottingham's
definition (more accurately, Paul Baran's definition)) of
decentralization:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;[Decentralization is when] &amp;quot;complete reliance upon a single point is
not always required&amp;quot; (citing &lt;a href=&quot;https://www.rand.org/pubs/research_memoranda/RM3420.html&quot;&gt;Baran&lt;/a&gt;, 1964)&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;Perhaps Bluesky matches this version of decentralization, but if so,
it is because it is an &lt;em&gt;incredibly weak definition of decentralization&lt;/em&gt;,
at least taken independently.  This may well say, taken within the
context it is provided, &amp;quot;users of this network may occasionally not
rely on a gatekeeper, as a treat&amp;quot;.&lt;/p&gt;&lt;p&gt;Put more succinctly, the delta between the definition I gave and the
definition chosen by Bryan is:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;The discussion of power dynamics, and diffusion thereof, is removed&lt;/li&gt;&lt;li&gt;The phrase &lt;em&gt;complete reliance&lt;/em&gt; is introduced, opening acceptability
within the definition that incomplete reliance is an acceptable
part of decentralization&lt;/li&gt;&lt;li&gt;The phrase &lt;em&gt;not always required&lt;/em&gt; is introduced, opening
acceptability that even complete reliance may be acceptable, as long
as it is not always the case&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;When I spoke of my concerns of moving the goalpost, the delta between
the goalpost chosen in my definition and the goalpost chosen in
Bryan's chosen definition are miles away.&lt;/p&gt;&lt;p&gt;We'll come back to this in a second, because the choice of the
definition by Baran is more interesting when explored in its original
context.&lt;/p&gt;&lt;p&gt;But for now, let's examine &lt;strong&gt;federation&lt;/strong&gt;.  Here is my definition:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;[Federation] is a technical approach to communication architecture
which achieves decentralization by many independent nodes
cooperating and communicating to be a unified whole, with no node
holding more power than the responsibility or communication of its
parts.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;Here is Bryan's definition (more accurately Mark Nottingham's
definition):&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;[...] federation, i.e., designing a function in a way that uses
independent instances that maintain connectivity and interoperability
to provide a single cohesive service.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;At first these two seem very similar.  What, again is the delta?&lt;/p&gt;&lt;ul&gt;&lt;li&gt;The discussion of power dynamics, once again, is not present.&lt;/li&gt;&lt;li&gt;&amp;quot;Cooperation&amp;quot; is not present.&lt;/li&gt;&lt;li&gt;And very specifically, &amp;quot;decentralization&amp;quot; and &amp;quot;no node holding more
power than the responsibility or communication of its parts&amp;quot; is not
present.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Reread the definition above and the definition I gave and compare: under
these definitions, any corporate but proprietary and internal
microservices architecture or devops platform would qualify.  (Not an
original observation; thanks to &lt;a href=&quot;https://vvv.gay&quot;&gt;Vivi&lt;/a&gt; for pointing
this out.)  Dropping power dynamics and decentralization from the
definition reduces this to &amp;quot;communicating components&amp;quot;, which isn't enough.&lt;/p&gt;&lt;p&gt;Bryan then goes on to acknowledge that this definition is a comparative
low bar:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;What about federation? I do think that atproto involves independent
services collectively communicating to provide a cohesive and unified
whole, which both definitions touch on, and meets Mark's low-bar
definition.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;However, in the context of Nottingham's paper, it's admittedly stronger,
because federation is specifically upheld as a &lt;em&gt;decentralization
technique&lt;/em&gt;, which is missing when quoted out of context (though
Nottingham notably challenges whether or not it achieves that goal in
practice).  Which turns out to be important.  The &amp;quot;power dynamics&amp;quot; part
and specifically &amp;quot;immersing this definition in decentralization&amp;quot; parts
are actually really both very important parts of the definition I gave.&lt;/p&gt;&lt;p&gt;Bryan then goes on to acknowledge that maybe federation isn't the best
term for Bluesky, and leaves some interesting history I feel is
worthwhile including here:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;Overall, I think federation isn't the best term for Bluesky to
emphasize going forward, though I also don't think it was misleading
or factually incorrect to use it to date. An early version of what
became atproto actually was peer-to-peer, with data and signing keys
on end devices (mobile phones). When that architecture was abandoned
and PDS instances were introduced, &amp;quot;federation&amp;quot; was the clearest term
to describe the new architecture. But the connotation of &amp;quot;federated&amp;quot;
with &amp;quot;message passing&amp;quot; seems to be pretty strong.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;So on that note, I think it's fine to say, Bluesky is not federated, and
there's enough general acknowledgement of such.  Thus it's probably best
if we move onto an examination of decentralization, and in particular,
where that definition came from.&lt;/p&gt;&lt;h3&gt;&amp;quot;Decentralization&amp;quot; from RFC 9518, in context&lt;/h3&gt;&lt;p&gt;Earlier I said &amp;quot;now here is Bryan's definition (more accurately Mark
Nottingham's definition (more accurately, Paul Baran's definition)) of
decentralization&amp;quot; and those nested parentheses were very intentional.
In order to understand the context in which this definition arises, we
need to understand each source.&lt;/p&gt;&lt;p&gt;First, let us examine Mark Nottingham's IETF independent submission,
&lt;a href=&quot;https://datatracker.ietf.org/doc/rfc9518/&quot;&gt;RFC 9518: Centralization, Decentralization, and Internet Standards&lt;/a&gt;.
Mark Nottingham has a long and respected history of participating in
standards, and most of his work history is doing so for fairly sizable
corporate participants.  From the title, one might think it a
revolutionary call-to-arms towards decentralization, but that isn't what
the RFC does at all.  Instead, Nottingham's piece is best summarized by
its own words:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;This document argues that, while decentralized technical standards may
be necessary to avoid centralization of Internet functions, they are
not sufficient to achieve that goal because centralization is often
caused by non-technical factors outside the control of standards
bodies. As a result, &lt;em&gt;standards bodies should not fixate on preventing&lt;/em&gt;
&lt;em&gt;all forms of centralization;&lt;/em&gt; instead, they should take steps to ensure
that the specifications they produce enable decentralized operation.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;The emphasis is mine, but I believe captures well what the rest of the
document says.  Mark examines centralization, as well as those who are
concerned about it.  In the section &lt;strong&gt;&amp;quot;Centralization Can Be Harmful&amp;quot;&lt;/strong&gt;,
Mark's description of certain kinds of standards authors and internet
activists might as well be an accurate summation of myself:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;Many engineers who participate in Internet standards efforts have an
inclination to prevent and counteract centralization because they see
the Internet's history and architecture as incompatible with it.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;Mark then helpfully goes on to describe many kinds of harms that do
occur with centralization, and which &amp;quot;decentralization advocates&amp;quot; such
as myself are concerned about: power imbalance, limits on innovation,
constraints on competition, reduced availability, monoculture,
self-reinforcement.&lt;/p&gt;&lt;p&gt;However, the very next section is titled
&lt;strong&gt;&amp;quot;Centralization Can Be Helpful&amp;quot;&lt;/strong&gt;!  And Mark goes into great lengths
also about ways in which centralized systems can sometimes provide
superior service or functionality.&lt;/p&gt;&lt;p&gt;While Mark weighs both, the document reads as a person who authors
standards document who would like the internet to be more decentralized
where it's possible, but also operates from the &amp;quot;pragmatic&amp;quot; perspective
that things are going to re-centralize most of the time anyway, and when
they do this ultimately tends to be useful.  It is also important to
realize that this is occuring in a context where many people are
worrying about increasing centralization of the internet, and wondering
to what degree standards groups should play a role.  From Mark's own
words:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;Centralization and decentralization are increasingly being raised in
technical standards discussions. Any claim needs to be critically
evaluated. As discussed in Section 2, not all centralization is
automatically harmful. Per Section 3, decentralization techniques do
not automatically address all centralization harms and may bring their
own risks.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;Note this framing: centralization is not necessarily harmful, and
decentralization may not address problems and may cause new ones.
Rather than a rallying cry for decentralization, Mark's position is in
many ways a call for a preservation of the increasing status quo: large
corporations tend to be capturing and centralizing more of the internet,
and we should be worried about that, but should it really be the job of
&lt;em&gt;standards&lt;/em&gt;?  Remember, this &lt;em&gt;is&lt;/em&gt; a concern within IETF and other
standards groups.  Mark says:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;[...] approaches like requiring a &amp;quot;Centralization Considerations&amp;quot;
section in documents, gatekeeping publication on a centralization
review, or committing significant resources to searching for
centralization in protocols are unlikely to improve the Internet.&lt;/p&gt;&lt;p&gt;Similarly, refusing to standardize a protocol because it does not
actively prevent all forms of centralization ignores the very limited
power that standards efforts have to do so. Almost all existing
Internet protocols -- including IP, TCP, HTTP, and DNS -- fail to
prevent centralized applications from using them. While the imprimatur
of the standards track is not without value, merely withholding it
cannot prevent centralization.&lt;/p&gt;&lt;p&gt;Thus, discussions should be very focused and limited, and any
proposals for decentralization should be detailed so their full
effects can be evaluated.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;Mark evaluates several structural concerns, many of which I strongly
agree with.  For example, Mark points out that email has, by and large,
become centralized, despite starting as a decentralized system.  I fully
agree!  &amp;quot;How does this system not result in the same re-centralization
problems which we've seen happen to email&amp;quot; is a question I often throw
around.  And Mark also highlights paths to which standards groups may
reduce centralization.&lt;/p&gt;&lt;p&gt;But ultimately, the path which Mark leans most heavily into is the
section &amp;quot;Enable Switching&amp;quot;:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;The ability to switch between different function providers is a core
mechanism to control centralization. If users are unable to switch,
they cannot exercise choice or fully realize the value of their
efforts because, for example, &amp;quot;learning to use a vendor's product
takes time, and the skill may not be fully transferable to a
competitor's product if there is inadequate standardization&amp;quot;.&lt;/p&gt;&lt;p&gt;Therefore, standards should have an explicit goal of facilitating
users switching between implementations and deployments of the
functions they define or enable.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;Does this sound familiar?  If so, it's because it's awfully close to
&amp;quot;credible exit&amp;quot;!&lt;/p&gt;&lt;p&gt;There is a common ring between Mark and Bryan's articles: centralization
actually provides a lot of features we want, and we don't want to lose
those, and it's going to happen anyway, so what's really important is
that users have the ability to &lt;em&gt;move away&lt;/em&gt;.  While this provides a
safety mechanism against centralization gone badly, it is not a path to
decentralization on its own.  Credible exit is useful, but as a
decentralization mechanism, it isn't sufficient.  If the only options in
town are Burger King and McDonalds for food, one may have a degree of
options and choice, but this really isn't satisfying to assuage my
concerns, even if Taco Bell comes into town.&lt;/p&gt;&lt;p&gt;What's missing from Mark's piece altogether is &amp;quot;Enable Participation&amp;quot;.
Yes, email has re-centralized.  But we should be upset and alarmed that
it is incredibly difficult to self-host email these days.  This is a
real problem.  It's not unjustified in the least to be upset about it.
And work to try to mitigate it is worthwhile.&lt;/p&gt;&lt;h3&gt;&amp;quot;Decentralization&amp;quot; within Baran's &amp;quot;On Distributed Communications&amp;quot;&lt;/h3&gt;&lt;p&gt;In the last subsection, we unpacked the outer parenthetical of &amp;quot;now here
is Bryan's definition (more accurately Mark Nottingham's definition
(more accurately, Paul Baran's definition)) of decentralization&amp;quot;. In
this subsection, we unpack the inner parenthetical.  (Can you tell that
I like lispy languages yet?  Now if there was only also a hint that I
also enjoy pattern matching ...)&lt;/p&gt;&lt;p&gt;Citing again the definition chosen by Bryan (or more accurately ... (or
more accurately ...)):&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;[Decentralization is when] &amp;quot;complete reliance upon a single point is
not always required&amp;quot; (citing &lt;a href=&quot;https://www.rand.org/pubs/research_memoranda/RM3420.html&quot;&gt;Baran&lt;/a&gt;, 1964)&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;Citations, in a way, are a game of telephone, and to some degree this is
inescapable for the sake of brevity in many situations.  Sometimes we
must take an effort to return to the source, and here we absolutely
must.&lt;/p&gt;&lt;p&gt;The cited paper by Paul Baran is none other than
&lt;a href=&quot;https://www.rand.org/pubs/research_memoranda/RM3420.html&quot;&gt;&amp;quot;On Distributed Communications: I. Introduction to Distributed Communication Networks&lt;/a&gt;
published by Paul Baran in 1964.  There is perhaps no other paper which
has influenced networked systems as highly as this work of Baran's has.
One might assume from the outset that the paper is too dense, but I
encourage the interested reader: print it out, go read it away from your
computer, mark it up with a pen (one should know: there is no other good
way to read a paper, the internet is too full of distractions).  There
is a reason the paper stands the test of time, and it is a joy to read.
Robust communication in error-prone networks!  Packet switching!  Wi-fi,
telephone/cable, satellite internet predicted as all mixing together in
one system!  And the &lt;em&gt;gall&lt;/em&gt; to argue that one can build it and that it
would be a dramatically superior system if we focus on having &lt;em&gt;a lot of
cheap&lt;/em&gt; &lt;em&gt;and interoperable components&lt;/em&gt; rather than &lt;em&gt;big, heavy
centralized ones!&lt;/em&gt;&lt;/p&gt;&lt;p&gt;It may come as a surprise, then, that I have called the above definition
of decentralization too weak if I am heaping praise on Baran's paper as
such.  But actually, this definition of &amp;quot;decentralized&amp;quot; is the &lt;em&gt;only&lt;/em&gt;
time in the paper that the term comes up.  How could this be?&lt;/p&gt;&lt;p&gt;To understand, we need only look at the extremely famous &amp;quot;Figure 1&amp;quot; of
the paper which, if you have worked on &amp;quot;decentralized&amp;quot; (or
&amp;quot;distributed&amp;quot;) network architecture at all, you have certainly seen:&lt;/p&gt;&lt;p&gt;&lt;img src=&quot;/etc/images/blog/baran-centralized-decentralized-distributed.png&quot; alt=&quot;Paul Baran's diagram of &amp;quot;centralized&amp;quot; (central hub and spoke), &amp;quot;decentralized&amp;quot; (tiered hub and spoke), and &amp;quot;distributed&amp;quot; (what we might think of as a decentralized mesh)&quot; /&gt;&lt;/p&gt;&lt;p&gt;The &lt;em&gt;full&lt;/em&gt; paragraph linked to the cited figure is worth citing in its
entirety:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;The centralized network is obviously vulnerable as destruction of a
single central node destroys communication between the end station.
In practice, a mixture of star and mesh components is used to form
communication networks.  For example, type (b) in Fig. 1 shows the
hierarchical structure of a set of stars connected in the form of a
larger star with an additional link forming a loop.  Such a network is
sometimes called a &amp;quot;decentralized&amp;quot; network, because complete reliance
upon a single point is not always required.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;In other words, in Baran's paper, where he is defining a
&lt;em&gt;new and more robust vision&lt;/em&gt; for what he calls &lt;em&gt;&amp;quot;distributed networks&amp;quot;&lt;/em&gt;,
he is providing &amp;quot;decentralized&amp;quot; as a pre-existing term, not his own
definition, for a topology he is &lt;em&gt;criticizing&lt;/em&gt; for
&lt;em&gt;still being centralized!&lt;/em&gt;  (Observe!  If you read the paragraph
carefully Baran is saying that &amp;quot;decentralized&amp;quot; networks like this are
still &amp;quot;centralized&amp;quot;!)&lt;/p&gt;&lt;p&gt;Let's observe that again.  Baran is effectively saying that a tiered,
hierarchical system with many nodes, being called &amp;quot;decentralized&amp;quot;
(because that is a term that &lt;em&gt;already existed&lt;/em&gt; for these kinds of
networks), was in fact centralized.  So the very definition selected by
Mark Nottingham (and thus Bryan as well) was &lt;em&gt;being criticized for being&lt;/em&gt;
&lt;em&gt;too centralized by the original cited author!&lt;/em&gt;&lt;/p&gt;&lt;p&gt;Baran had to introduce a new term because the term &amp;quot;decentralized&amp;quot; was
already being used.  However, when we talk about &amp;quot;centralized&amp;quot; vs
&amp;quot;decentralized&amp;quot; as if they are polar ends of a spectrum, we are actually
talking about type (a) of &amp;quot;Figure 1&amp;quot; being &amp;quot;centralized&amp;quot; and type (c)
being the &amp;quot;ideal&amp;quot; version of &amp;quot;decentralized&amp;quot;, with (b) sometimes showing
up as kind of a grey-area space.  Notably, Mark Nottingham makes no such
distinction as Baran does between &amp;quot;decentralized&amp;quot; and &amp;quot;distributed&amp;quot;, yet
uses the definition of &amp;quot;decentralized&amp;quot; that instead resembles tiered,
hierarchically centralized systems... &lt;em&gt;not&lt;/em&gt; the version of
&amp;quot;decentralized&amp;quot; to which Mark Nottingham then goes at great length to
analyze.&lt;/p&gt;&lt;p&gt;That is why Baran's definition of &amp;quot;decentralized&amp;quot; is so weak.
&lt;em&gt;This is critical history to understand!&lt;/em&gt;&lt;/p&gt;&lt;p&gt;In other words:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Contemporary nomenclature: &amp;quot;Centralized&amp;quot; and &amp;quot;Decentralized&amp;quot; as polar
ends of a spectrum.&lt;/li&gt;&lt;li&gt;Baran nomenclature: &amp;quot;Centralized and &amp;quot;decentralized&amp;quot; are both
centralized topologies, but the latter is hierarchical.  &amp;quot;Distributed&amp;quot;
is the more robust and revolutionary view.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Do you see it?  To use the latter's definition of decentralization to
describe the former is &lt;em&gt;to use a definition of centralization&lt;/em&gt;.  This is
not a good starting point.&lt;/p&gt;&lt;p&gt;Baran, notably, &lt;em&gt;is&lt;/em&gt; bold about what he calls distributed systems, and
it is important to understand Baran's vision as &lt;em&gt;being&lt;/em&gt; bold and
revolutionary for its time.  I can't resist quoting one more paragraph
before we wrap up this section (remember! nothing like the internet had
yet been proposed or envisioned as something possible before!):&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;It would be treacherously easy for the casual reader to dismiss the
entire concept as impractically complicated -- especially if he is
unfamiliar with the ease with which logical transformations can be
performed in a time-shared digital apparatus.  The temptation to throw
up one's hands and decide that it is all &amp;quot;too complicated,&amp;quot; or to say,
&amp;quot;It will require a mountain of equipment which we all know is
unreliable,&amp;quot; should be deferred until the fine print has been read.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;May that we all be so bold as Baran in envisioning the system we &lt;em&gt;could&lt;/em&gt;
have!&lt;/p&gt;&lt;h3&gt;Why is this terminology discussion so important?&lt;/h3&gt;&lt;p&gt;Here I have, at even greater length than my previous post or even
Bryan's own response to mine, gone into great length about terminology.
But this is important.  As I have stated, there are great risks in
moving the goalposts.  It is hard for those who do not work on
networked systems day in and day out to make sense of any of this.
&amp;quot;Decentralization washing&amp;quot; is a real problem.  I don't find it
acceptable.&lt;/p&gt;&lt;p&gt;Bryan &amp;quot;chose his fighter&amp;quot; with Mark Nottingham's RFC, and the choice of
fighter informs much that follows.  Mark Nottingham himself is
advocating that a push too hard on decentralization is something
standards people should not be doing, and if they do, should be scoping.
Some amount of centralization, according to Mark, is useful, good, and
inevitable, and we should scope down the amount of decentralization vs
centralization topics that come up in standards groups to something
actionable.  Mark's reasons are well studied, and while Mark's history
often comes from a background in representing standards on behalf of
larger corporations, I believe he would like to see decentralization
where possible, but is &amp;quot;pragmatic&amp;quot; about it.&lt;/p&gt;&lt;p&gt;(This is also somewhat of a personal issue for me; my participation in
standards has been generally as more &amp;quot;outside the system&amp;quot; of corporate
standards work than the average standards person, and there's a real
push and pull between how much standards orgs tend to be dominated by
corporate influence.  I'm not against corporate participation, I think
it's important but... I highly recommend reading Manu Sporny's
&lt;a href=&quot;https://web.archive.org/web/20200120154851/http://manu.sporny.org/2016/rebalancing/&quot;&gt;Rebalancing How the Web is Built&lt;/a&gt;
which describes the governance challenges, particularly leading to
corporate capture, which tend to happen within standards orgs.  One of
the only reasons I believe ActivityPub was able to be as &amp;quot;true to its
goals&amp;quot; as it was is partly that the big players refused to
participate at the time of standardization, which at the time was an
existential threat to the continuation of the group, but in retrospect
ended up being a blessing for the spec.  It both is and is not an aside,
but getting further into that is a long story, and this is already a
long article.)&lt;/p&gt;&lt;p&gt;Mark's choice to use the definition of &amp;quot;decentralization&amp;quot; from Baran is
however &lt;em&gt;dangerous&lt;/em&gt; to read without understanding the surrounding
context.  The way Baran used the term was as a
&lt;em&gt;criticism of hierarchical centralization&lt;/em&gt;, and was introducing a
new term as an alternative.  This is why Baran's definition of
&amp;quot;decentralization&amp;quot; appears so weak: Baran was not advocating for the
ideas he was scoping under that (pre-existing in the context he was
arguing within) term.&lt;/p&gt;&lt;p&gt;I personally don't believe we need to support the three-word
&amp;quot;centralization&amp;quot;, &amp;quot;decentralization&amp;quot;, and &amp;quot;distributed&amp;quot; phrases which
Baran used, it's fine for me to have a spectrum between &amp;quot;centralized&amp;quot;
and &amp;quot;decentralized&amp;quot;.  But we should not conflate a situation where
&amp;quot;decentralization&amp;quot; means &amp;quot;tiered centralization&amp;quot; with the contemporary
usage of &amp;quot;resisting centralization&amp;quot;.&lt;/p&gt;&lt;p&gt;However, all this is to say that I think Nottingham's view on
how much we should be bothering to be concerned with centralization vs
decentralization aligns well with ATProto and Bluesky's own
interpretations.  &amp;quot;Credible exit&amp;quot;, I still assert, is a separate view, a
particular mechanism to avoid &lt;em&gt;some&lt;/em&gt; of the challenges of centralization
going bad, and indeed in Nottingham's own RFC, it is only one path of
several examined, but the one Nottingham appears most aligned with as
practically possible.&lt;/p&gt;&lt;p&gt;Regardless, I'd still say then: if Bluesky does not meet my definition
of &amp;quot;decentralized&amp;quot;, the solution is not to move the goalposts.  I think
I've made it clear enough, with a thorough enough reading of the
literature, of why to accept the proposed definition within Bryan's post
&lt;em&gt;would&lt;/em&gt; be to move the goalposts.  I don't think that's intentional, or
malicious, but it is the result, and I'm not satisfied with that result.&lt;/p&gt;&lt;p&gt;That's enough said on the topics of terminology.  Let's move on.&lt;/p&gt;&lt;h2&gt;What happens when ATProto scales down?&lt;/h2&gt;&lt;blockquote&gt;&lt;p&gt;A specific form of scale-down which is an important design goal is
that folks building new applications (new Lexicons) can &amp;quot;start
small&amp;quot;, with server needs proportional to the size of their
sub-network. We will continue to prioritize functionality that
ensures independent apps can scale down. The
&lt;a href=&quot;https://atproto.com/guides/applications&quot;&gt;&amp;quot;Statusphere&amp;quot;&lt;/a&gt; atproto
tutorial demonstrates this today, with a full-network AppView
fitting on tiny server instances.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;I won't spend too long on this other than to say: a large portion of the
arguments for why to choose ATProto's architecture &lt;em&gt;specifically&lt;/em&gt; was to
&amp;quot;not miss replies/messages&amp;quot;, and as said in my previous article, that
requires a god's-eye view of the system.  Here it's argued that ATProto
&lt;em&gt;can&lt;/em&gt; scale down, and yes it &lt;em&gt;can&lt;/em&gt;, but is that the architecture you
want?&lt;/p&gt;&lt;p&gt;Given that message passing systems, by having &lt;em&gt;directed&lt;/em&gt; messaging, is
able to scale down quite beautifully but still interoperate
&lt;em&gt;as much as one would like&lt;/em&gt; with a larger system, what is the value of
using an architecture which scales down with much more difficulty and
which is oblivious of external interactions without knowing all of them?&lt;/p&gt;&lt;p&gt;I made a claim here: &lt;em&gt;ATProto doesn't scale down well&lt;/em&gt;.  That's mainly
because to me, scaling down still means being participatory with as much
as you'd like of a wider system while still having small resources.
What I would like to analyze in greater detail is why
&lt;em&gt;ATProto doesn't scale wide&lt;/em&gt;.  To me, these two arguments are
inter-related.  Let's analyze them.&lt;/p&gt;&lt;h2&gt;Defending my claim: decentralized ATProto has quadratic scaling costs&lt;/h2&gt;&lt;p&gt;In my previous article, I said the following:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;If this sounds infeasible to do in our metaphorical domestic
environment, that's because it is.  A world of full self-hosting is
not possible with Bluesky.  In fact, it is worse than the storage
requirements, because the message delivery requirements become
quadratic at the scale of full decentralization: to send a message to
one user is to send a message to all.  Rather than writing one letter,
a copy of that letter must be made and delivered to every person on
earth.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;However, clearly not everyone agreed with me:&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://bsky.app/profile/why.bsky.team/post/3lbtbgchqkk2v&quot;&gt;&lt;img src=&quot;/etc/images/blog/bluesky-quadratic-scaling-convo.png&quot; alt=&quot;A conversation between myself and @why.bsky.team where I claim Bluesky's decentralization scaling costs are quadratic and @why.bsky.team disagrees&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;quot;Agency&amp;quot; really is important to me, probably
&lt;a href=&quot;https://fossandcrafts.org/episodes/11-an-ethics-of-agency.html&quot;&gt;the most important thing&lt;/a&gt;,
but we will leave this aside for the moment and focus on a different
phrase: &amp;quot;participatory infrastructure&amp;quot;.&lt;/p&gt;&lt;p&gt;Was I right or wrong that as nodes are added to ATProto that the scaling
costs are quadratic?  After I read this exchange, I really doubted
myself for a bit.  I don't have a formal background in Computer Science;
I learned software engineering through community educational materials
and honed my knowledge through the
&lt;a href=&quot;https://mitp-content-server.mit.edu/books/content/sectbyfn/books_pres_0/6515/sicp.zip/index.html&quot;&gt;&amp;quot;school of hard thunks&amp;quot;&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;So I spent a morning on the Spritely engineering call distracting my
engineering team by walking through the problem.  It's easy to get lost
in the details of thinking about the roles of the communicating
components, so Spritely's CTO, &lt;a href=&quot;https://dthompson.us/&quot;&gt;David Thompson&lt;/a&gt;,
decided to throw my explainer aside and work through the problem
independently.  Dave came to the same conclusion I did.  I also called
up one of my oldschool MIT AI Lab type buddies and asked hey, what do
you think?  I think this is a quadratic scaling problem am I wrong?  He
said (from vague memory of course) &amp;quot;I think it's pretty clear
immediately that it's quadratic.  This is basic engineering
considerations, the first thing you do when you start designing a
system.&amp;quot;  Well that's a relief that I wasn't confused.  But if it seemed
obvious to me, why wasn't it obvious to everyone else?  &amp;quot;It seemed
pretty clear the way you described it to me.  So why don't you just
repeat that?&amp;quot;&lt;/p&gt;&lt;p&gt;So okay, that's what I'll do.&lt;/p&gt;&lt;p&gt;Let's start with the following points before we begin our analysis:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;We will assume that, since ATProto has partly positioned itself as
having one of its key values be &amp;quot;no compromises on centralized use
cases&amp;quot; including &amp;quot;no missed messages or replies&amp;quot;, that at minimum
ATProto cannot do &lt;em&gt;worse&lt;/em&gt; than ActivityPub, in its current deployment,
does today.  Replies and messages addressed to specific users (whether
or not addressing is on the protocol layer or extrapolated on top of
it) must, at least, be seen by the their intentional recipients.&lt;/li&gt;&lt;li&gt;We will start with the assumption that the most centralized
infrastructure is one in which there is only one provider controlling
the storage and distribution of all messages: the least amount of
user participation in the operation of the network.&lt;/li&gt;&lt;li&gt;We will, on the flip side, consider decentralization to be the
inverse, with the &lt;em&gt;most&lt;/em&gt; amount of user participation in the operation
of the network.  In other words, &amp;quot;every user fully self hosts&amp;quot;.&lt;/li&gt;&lt;li&gt;We will also take the lessons of my previous post at face value; just
as blogging is decentralized but Google (and Google Reader) are not,
it is not enough to have just PDS'es in Bluesky be self-hosted.  When
we say self-hosted, we &lt;em&gt;really&lt;/em&gt; mean self-hosted: users are
participating in the distribution of their content.&lt;/li&gt;&lt;li&gt;We will consider this a gradient.  We can analyze the system from the
greatest extreme of centralization which can &amp;quot;scale towards&amp;quot; the
greatest degree of decentralization.&lt;/li&gt;&lt;li&gt;We will analyze both in terms of the load of a single participant on
the network but also in terms of the amount of network traffic as a
whole.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;With that in place, it's time to analyze the &amp;quot;message passing&amp;quot;
architecture vs the &amp;quot;shared heap&amp;quot; architecture in terms of how they
perform when scaling.&lt;/p&gt;&lt;p&gt;Here is my assertion in terms of the network costs of scaling towards
decentralization, before I back it up (I will give the computer
science'y terms then explain in plain language after):&lt;/p&gt;&lt;ul&gt;&lt;li&gt;There is an inherent linear cost to users participating on the
network, insofar as for &lt;code&gt;n&lt;/code&gt; users, there will always be an &lt;code&gt;O(n)&lt;/code&gt;
cost of operation.&lt;/li&gt;&lt;li&gt;&lt;p&gt;&amp;quot;Message passing&amp;quot; systems such as ActivityPub, at full
decentralization:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Operate at &lt;code&gt;O(1)&lt;/code&gt; from a single user's perspective&lt;/li&gt;&lt;li&gt;Operate at &lt;code&gt;O(n)&lt;/code&gt; from a whole-network perspective (and this is, by
definition, the best you can do)&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&amp;quot;Public no-missed-messages shared-heap&amp;quot; systems such as ATProto, at
full decentralization:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Operate at &lt;code&gt;O(n)&lt;/code&gt; from a single user's perspective&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Operate at &lt;code&gt;O(n^2)&lt;/code&gt; from a whole-network perspective&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;In other words, as we make our systems more decentralized, message
passing systems handle things fairly fine.  Individual nodes can
participate on the network no matter how big the network gets.  Zooming
out, as more users are added to the decentralized network, the message
load is roughly the normal amount of adding more users to the network.
However, as we make things more decentralized for the public shared
heap model, everything explodes, both on the individual node level, but
especially when we zoom out to how many messages need to be sent.&lt;/p&gt;&lt;p&gt;And there is no solution to this without adding directed message
passing.  Another way to say this is: to fix a system like ATProto to
allow for self-hosting, you have to ultimately &lt;em&gt;fundamentally&lt;/em&gt; change it
to be a lot more like a system like ActivityPub.&lt;/p&gt;&lt;p&gt;This can easy to get lost about; the example above of stating that
&amp;quot;gossip&amp;quot; can improve things indicates that talking about message
&lt;em&gt;sending&lt;/em&gt; is confusing the matter.  It will be easier to understand by
thinking about message &lt;em&gt;receiving&lt;/em&gt;.&lt;/p&gt;&lt;p&gt;To start with a very small example by which we can clearly observe the
explosion, let's set up a highly simplified scenario.  First let me give
the parameters, then I will tell a story.  (You can skip the following
paragraph to jump to the story if that's more your thing.)&lt;/p&gt;&lt;p&gt;That &lt;code&gt;n&lt;/code&gt; number we mentioned previously will now stand for the
&lt;code&gt;number-of-users&lt;/code&gt; on the network.  We will also introduce &lt;code&gt;m&lt;/code&gt; which will
be &lt;code&gt;number-of-machines&lt;/code&gt;, which represents the number nodes on the
network.  Decentralizing the system involves &lt;code&gt;n&lt;/code&gt; moving towards &lt;code&gt;m&lt;/code&gt;, so
at full decentralization, &lt;code&gt;n&lt;/code&gt; and &lt;code&gt;m&lt;/code&gt; would be the same; at intermediate
levels of decentralization it may be less, but &lt;code&gt;n&lt;/code&gt; &lt;em&gt;converges towards&lt;/em&gt;
&lt;code&gt;m&lt;/code&gt; as we decentralize.  Each user is individually somewhat chatty, and
sends a number of &lt;code&gt;daily-messages-per-user&lt;/code&gt;, but we can average these
out across all users, so this is just a constant which for our cases we
can simplify to &lt;code&gt;1&lt;/code&gt; for a modeled scenario (though it can scale up and
down, it does not affect the rate of growth).  Likewise, each message
individually sent by a user has a
&lt;code&gt;number-of-intended-recipients-per-message&lt;/code&gt;, which we can average by the
amount of people who were individually intended to receive such message,
such as directed messages or subscribers in a publish-subscribe system;
however this too can be averaged, so we can also simplify this to &lt;code&gt;1&lt;/code&gt;
(so this also does not affect the rate of growth).&lt;/p&gt;&lt;p&gt;Lost?  No worries.  Let's tell a story.&lt;/p&gt;&lt;p&gt;In the beginning of our network, we have 26 users, which conveniently
for us map to each letter of the English alphabet: &lt;code&gt;[Alice, Bob, Carol, ... Zack]&lt;/code&gt;.  Each user sends &lt;em&gt;one&lt;/em&gt; message per day, which is intended to
have &lt;em&gt;one&lt;/em&gt; recipient.  (This may sound unrealistic, but this is fine to
do to model our scenario.)  To simplify things, we'll have each user
send a message in a ring: &lt;code&gt;Alice&lt;/code&gt; sends a message to &lt;code&gt;Bob&lt;/code&gt;, &lt;code&gt;Bob&lt;/code&gt; sends
a message to &lt;code&gt;Carol&lt;/code&gt;, and so on, all the way up to &lt;code&gt;Zack&lt;/code&gt;, who simply we
wrap around and have message &lt;code&gt;Alice&lt;/code&gt;.  This could be because these
messages have specific intended recipients or it could be because &lt;code&gt;Bob&lt;/code&gt;
is the sole &amp;quot;follower&amp;quot; of &lt;code&gt;Alice&lt;/code&gt;'s posts, &lt;code&gt;Carol&lt;/code&gt; is the sole
&amp;quot;follower&amp;quot; of &lt;code&gt;Bob&lt;/code&gt;'s, etc.&lt;/p&gt;&lt;p&gt;Let's look at what happens in a single day under both systems.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Under message passing, &lt;code&gt;Alice&lt;/code&gt; sends her message to &lt;code&gt;Bob&lt;/code&gt;.  Only &lt;code&gt;Bob&lt;/code&gt;
need &lt;em&gt;receive&lt;/em&gt; the message.  So on and so forth.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;From an individual self-hosted server, only one message is
passed per day: 1.&lt;/li&gt;&lt;li&gt;From the fully decentralized network, the total number of messages
passed, zooming out, is the number of participants in the network: 26.&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Under the public-gods-eye-view-shared-heap model, each user must know
of all messages to know what may be relevant.  Each user must
&lt;em&gt;receive&lt;/em&gt; all messages.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;From an individual self-hosted server, 26 messages must be received.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Zooming out, the number of messages which must be transmitted in the
day is 26 * 26: 676, since each user receives each message.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Okay, so what does that mean?  How bad is this?  With 26 users, this
doesn't sound like so much.  Now let's add 5 users.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Under message passing:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Per server, still 1 message received per user per day.&lt;/li&gt;&lt;li&gt;Per the network, it's 5 extra messages transmitted per day, which
makes sense: we've added 5 users.&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Under the public-gods-eye-view-shared-heap model:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Per server: 5 new messages received per user per day.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Per the network, it's ((31 * 31) - (26 * 26)): 285 new messages per
day!&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;But we aren't actually running networks of 26 users.  We are running
networks of millions of users.  What would happen if we had a million
self-hosted users and five new users were added to the network?  Zooming
out, once again, the message passing system simply has five new messages
sent.  Under the public shared heap model, it is 10,000,025 new messages
sent!  For adding &lt;em&gt;five new self-hosted users!&lt;/em&gt;  (And that's even just
&lt;em&gt;with&lt;/em&gt; our simplified model of only sending one message per day per
user!)&lt;/p&gt;&lt;p&gt;Maybe this sounds silly, if you're a Bluesky enthusiast.  I could hear
you saying: well Christine, we really aren't planning on &lt;em&gt;everyone&lt;/em&gt; self
hosting.  Yes, but how many nodes can participate in the system at all?
The fediverse currently hosts around 27,000 servers (many more users,
but let's focus on servers).  Adding just 5 more servers would be a blip
in terms of the affect on the network.  Adding 5 more servers to an
ATProto ecosystem with that many fully participating nodes would be an
exhausting number of &lt;em&gt;additional&lt;/em&gt; messages sent on the network.  ATProto
does not scale wide: it's a &lt;em&gt;liability&lt;/em&gt; to add more fully participating
nodes onto the network.  &lt;em&gt;Meaningfully&lt;/em&gt; self-hosting ATProto is a risk
to the ATProto network, there is active reason to disincentivize it for
those already participating.  But it's not just that.  Spreading things
around so that more full Bluesky-like nodes are present is something
server operators will have to come to discourage if they don't want
their already existing high hosting costs to not skyrocket.&lt;/p&gt;&lt;p&gt;Now, what about that mention of &amp;quot;well gossip could help&amp;quot;?  This is why I
said it is important to think of messages as they are &lt;em&gt;received&lt;/em&gt; as
opposed to how they are &lt;em&gt;sent&lt;/em&gt;.  The scenario I gave above was
a &lt;em&gt;more ideal scenario&lt;/em&gt; than gossip.  In a gossip protocol, a node often
receives messages &lt;em&gt;more than once&lt;/em&gt;.  The scenario I gave was more
generous: messages are &lt;em&gt;only received once&lt;/em&gt;.  You can't know information
unless it's told to you (well, unless you can infer it, but that's not
relevant for this case).  It's best to think about receiving.&lt;/p&gt;&lt;p&gt;Architecture matters.  There is a reason message passing exists.  I
don't believe in the distinction between &amp;quot;it's a technical problem&amp;quot; or
&amp;quot;it's a social problem&amp;quot; most of the time when designing systems, because
it's usually both: the kinds of social power dynamics we can have are
informed by the power dynamics of our tech and vice versa.  Who can
participate here?  I agree with the agency concern, I am always deeply
concerned with agency, but here agency depends on &lt;em&gt;providers&lt;/em&gt;.  How big
do they have to be?  How many of them can there be?&lt;/p&gt;&lt;p&gt;A lot of hope in Bluesky and ATProto is in terms of the dreams of what
&lt;em&gt;seems possible&lt;/em&gt;.  Well, for decentralization of Bluesky and ATProto to
&lt;em&gt;even be possible&lt;/em&gt;, it must change its architecture fundamentally.
ATProto doesn't need to switch to ActivityPub, but in order to become a
real decentralized protocol, it has to become a lot more like it.&lt;/p&gt;&lt;h2&gt;Reframing portable identity&lt;/h2&gt;&lt;p&gt;Bryan has some nice responses to the &lt;code&gt;did:plc&lt;/code&gt; stuff in his article, I
won't go over it again in depth here.  I'll just say it was nice to see.&lt;/p&gt;&lt;p&gt;I actually think that despite all the concerns I laid out about the
centralization of &lt;code&gt;did:plc&lt;/code&gt;, it's not something I'm all too worried
about in terms of the governance of the ledger of updates.  It seems
like the right things are being done so that &lt;code&gt;did:plc&lt;/code&gt; can be audited by
multiple parties in terms of working towards a certificate transparency
log, etc.  That's good to hear.&lt;/p&gt;&lt;p&gt;My bigger concern is that if Bluesky shuts down tomorrow or is bought by
a larger player, in practice if Bluesky refuses to allow for a path to
rotating keys to move away, it'll be hard to do anything about that.
Still, Bluesky is doing more work in the decentralized identity space
than most at this point.  I want to give them some credit there, and end
this little subsection on that positive note.&lt;/p&gt;&lt;h2&gt;Bluesky's expectations of public content vs community expectations&lt;/h2&gt;&lt;p&gt;ATProto's main design is built upon replicating and indexing the
firehose.  That is its fundamental design choice and method of
operation.&lt;/p&gt;&lt;p&gt;I won't go into this too far here other than to say, I'm not sure this
is in alignment with what many of its users want.  And we're seeing
this, increasingly, as users are being upset about finding out that
other providers have replicated and indexed their data.  This is
happening in a variety of ways, from LLM training concerns, to
moderation concerns, etc.&lt;/p&gt;&lt;p&gt;I won't say too much more on that.  I think it's just... this all just
gives me the feeling that the &amp;quot;speech vs reach&amp;quot; approach, and the idea
of a global public firehose, a &amp;quot;global town square&amp;quot; type approach... it
all feels very web 2.0, very &amp;quot;Millennial social media&amp;quot;... for Millenials,
by Millenials, trying to capture the idea that society would be better
if we all got everyone to talk to each other at once.&lt;/p&gt;&lt;p&gt;I think Bluesky is doing about as good a job as a group of people can
do with the design they have and are trying to preserve.  But I don't
think the global context-collapse firehose works, and I'm not sure it's
what users want it either, and if they do, they really seem to want both
strong central control to meet their needs but also to not have strong
central control be a thing that exists when it doesn't.&lt;/p&gt;&lt;p&gt;And who can blame users for that?  An alternative can not usually be
envisioned unless an alternative is presented.&lt;/p&gt;&lt;p&gt;So, what's the alternative?&lt;/p&gt;&lt;h2&gt;On the values and design goals of projects and protocols&lt;/h2&gt;&lt;p&gt;One thing I appreciated was where Bryan laid out Bluesky's values and
design goals:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;Over the summer, I wrote a summary of Bluesky's progress on atproto on
my personal blog:
&lt;a href=&quot;https://bnewbold.net/2024/atproto_progress/&quot;&gt;&amp;quot;Progress on atproto Values and Value Proposition&amp;quot;&lt;/a&gt;.
Christine identified &amp;quot;Credible Exit&amp;quot; as one of these key
properties. Some of the other high-level goals mentioned there were:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Own Your Identity and Data&lt;/li&gt;&lt;li&gt;Algorithmic Choice&lt;/li&gt;&lt;li&gt;Composable Multi-Party Moderation&lt;/li&gt;&lt;li&gt;Foundation for New Apps&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Any of these could be analyzed individually; I have my own
self-assessment of our progress in the linked article.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;I think this is great for Bryan to lay out.  They're a nice set of
goals.  (I don't love the &lt;em&gt;term&lt;/em&gt; &amp;quot;own your data&amp;quot; for various &amp;quot;intellectual
property&amp;quot; term-confusion adjacent reasons, but that's an aside; the
&lt;em&gt;intended meaning&lt;/em&gt; is good.)  Overall I think this is a pretty
reasonably set of goals and you can see why they would inform the design
of Bluesky significantly.  You don't see many projects lay out their
values like this, and it would be good to see done more often.&lt;/p&gt;&lt;p&gt;On that note...&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;One thing I'd be curious to see is an equivalent set of design goals
for ActivityPub (or for &lt;a href=&quot;https://spritely.institute&quot;&gt;Spritely's work&lt;/a&gt;,
for that matter). This might exist somewhere obvious and I just
haven't seen it. It might all differ for the distinct original
projects and individuals which participated in the standards process.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;This was a nice ask to make.  Let me address them separately.&lt;/p&gt;&lt;h3&gt;ActivityPub's values and design goals&lt;/h3&gt;&lt;p&gt;In a way, it's a bit harder for me to talk about the values and design
goals of ActivityPub.  It happened in a larger standards group and
involved a lot of passing of hands.  I think if I were to be robust
about it, I would also ask Evan Prodromou, Erin Shepherd, and Amy Guy to
weigh in, and maybe they should; I think it would be nice to hear.  But
since I work with Jessica Tallon (and I'm kind of tired of writing this
and want to just get it out there) we had a brief talk this morning and
I'll just discuss what we talked about.&lt;/p&gt;&lt;p&gt;The &lt;a href=&quot;https://www.w3.org/2013/socialweb/social-wg-charter.html&quot;&gt;SocialWG charter&lt;/a&gt;
is informative, first of all.  It says the following:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;The Social Web Working Group will create Recommendation Track
deliverables that standardize a common JSON-based syntax for social
data, a client-side API, and a Web protocol for federating social
information such as status updates. This should allow Web application
developers to embed and facilitate access to social communication on
the Web. The client-side API produced by this Working Group should be
capable of being deployed in a mobile environment and based on HTML5
and the Open Web Platform. For definitions of terms such as &amp;quot;social&amp;quot;
and &amp;quot;activity&amp;quot;, please see the W3C Social XG report A Standards-based,
Open and Privacy-aware Social Web.&lt;/p&gt;&lt;p&gt;There are a number of use cases that the work of this Working Group
will enable, including but not limited to:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;User control of personal data:&lt;/strong&gt; Some users would like to have
autonomous control over their own social data, and share their data
selectively across various systems. For an example (based on the
IndieWeb initiative), a user could host their own blog and use
federated status updates to both push and pull their social
information across a number of different social networking sites.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Cross-Organization Ad-hoc Federation:&lt;/strong&gt; If two organizations wish
to co-operate jointly on a venture, they currently face the problem
of securely interoperating two vastly different systems with
different kinds of access control and messaging systems. An
interoperable system that is based on the federation of
decentralized status updates and private groups can help two
organizations communicate in a decentralized manner.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Embedded Experiences:&lt;/strong&gt; When a user is involved in a social
process, often a particular action in a status update may need to
cause the triggering of an application. For example, a travel
request may need to redirect a user to the company's travel
agent. Rather than re-direct the user, this interaction could be
securely embedded within page itself.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Enterprise Social Business:&lt;/strong&gt; In any enterprise, different
systems need to communicate with each other about the status of
various well-defined business processes without having crucial
information lost in e-mail. A system built on the federation of
decentralized status updates with semantics can help replace email
within an enterprise for crucial business processes.&lt;/li&gt;&lt;/ul&gt;&lt;/blockquote&gt;&lt;p&gt;I think the &amp;quot;user control of personal data&amp;quot; is kind of like &amp;quot;owning your
own data&amp;quot; but with terminology I am more comfortable with personally.
Cooperation, even if organization-focused, is there, and embedding is I
guess also present.  The &amp;quot;enterprise&amp;quot; use case... well, I can't say that
ever ended up being important to me, but &amp;quot;business-to-business&amp;quot; use
cases is partly how the Social Web Working Group was able to describe
that it would have enough W3C member organization support to be able to
run as a group (which the corporate members quickly dropped out, leaving
a pile of independent spec authors... in most ways for the best for the
specs, but it seemed like an existential crisis at the time).&lt;/p&gt;&lt;p&gt;But those don't really speak as values to me.  When Jessica and I spoke,
we identified, from our memories (and without looking at the above):&lt;/p&gt;&lt;ul&gt;&lt;li&gt;The need to provide a federation API and client-to-server api for
federated social networks&lt;/li&gt;&lt;li&gt;Relatively easy to implement&lt;/li&gt;&lt;li&gt;Feasible to self-host without relying on big players&lt;/li&gt;&lt;li&gt;Social network domain agnosticism: entirely different kinds of
applications should be able to usefully talk to and collaborate with
each other with the same protocol&lt;/li&gt;&lt;li&gt;Flexibility and extensibility (which fell out of json-ld for
ActivityPub, though it could have been accomplished other ways)&lt;/li&gt;&lt;li&gt;A unified design for client-to-server and server-to-server.  This was
important for ActivityPub at least.  Amy Guy ultimately did the
important work of separating the two enough where you could just
implement one &lt;em&gt;or&lt;/em&gt; the other.&lt;/li&gt;&lt;li&gt;An implementation guide which told a &lt;em&gt;story&lt;/em&gt;, included in the spec.
(Well, maybe I was the only one who really was opinionated about
that, but I still do think it was one of the things that lead AP to
be successful.)&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;In some ways though, that still doesn't speak enough of &lt;em&gt;values&lt;/em&gt; to me,
though.  I added this late in the spec, and I kind of did it without
consulting anyone until after the fact, sneaking it into a commit where
I was adding acknowledgments.  It felt important, and ultimately it
turned out that everyone else in the group liked it a lot.  Here it is,
the final line of the ActivityPub spec:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;This document is dedicated to all citizens of planet Earth.
You deserve freedom of communication; we hope we have contributed in
some part, however small, towards that goal and right.&lt;/p&gt;&lt;/blockquote&gt;&lt;h3&gt;Spritely's values and design goals&lt;/h3&gt;&lt;p&gt;&lt;a href=&quot;https://spritely.institute/&quot;&gt;Spritely&lt;/a&gt; is the decentralized networking
research organization I'm the head of.  We're trying to build the next
generation of internet infrastructure, and I think we're doing
incredibly cool things.&lt;/p&gt;&lt;p&gt;It's easier for me to talk about the values of Spritely than
ActivityPub, having founded the project technically from the beginning
and co-founded it organizationally.  Here is the original mission
statement which Karen Sandler and I put together:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;The purpose of The Spritely Institute is to advance networked user
freedom.  People deserve the right to communicate and have communication
systems which respect their agency and autonomy.  Communities deserve
the right to organize, govern, and protect and enrich their members.
All of these are natural outgrowths of applying the principles of
fundamental human rights to networked systems.&lt;/p&gt;&lt;p&gt;Achieving these goals requires dedicated effort.  The Spritely
Foundation stewards the standardization and base implementation for
decentralized networked communities, promotes user freedom and agency of
participants on the network, develops the relevant technologies as free,
libre, and open source software, and facilitates the framing and
narrative of network freedom.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;But still, though we have a mission statement, we haven't written out a
bullet point list like this before and so I tried to gather Spritely
staff input on this:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Secure collaboration:&lt;/strong&gt; Spritely is trying to enable safe
cooperation between individuals and communities in an unsafe world.
We are working on tools to make this possible.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Networks of consent:&lt;/strong&gt; The cooperation mechanism we use is
&lt;em&gt;capability security&lt;/em&gt;, which allows for consent-granted mechanisms
which are intentional, granted, contextual, accountable, and
revocable.  Rather than positioning trust as all-or-nothing or
advocating for &amp;quot;zero trust&amp;quot; environments, we consider trust as
something fundamental to cooperation, but it's also something that is
built.  We want individuals and communities to be able to &lt;em&gt;build&lt;/em&gt;
trust to collaborate cooperatively together.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Healthy communities:&lt;/strong&gt; We must build tech that allows communities
to self-govern according to their needs, which vary widely from
community to community.  We may not know all of these needs or
mechanisms required for all communities in advance, but we should
have the building blocks so communities can easily put them in place.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;User empowerment and fostering agency:&lt;/strong&gt; We believe in users having
the freedom to communicate, but also to be able to live healthy lives
protected from dangerous or bad interactions.  We want users to be
able to live the lives they want to live, as agents in the system, to
the degree that it does not harm the agency of other users in the
system.  Maximizing agency and minimizing subjection, not just for
you and me, but for everyone, is thus is a foundation.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Contextual communication:&lt;/strong&gt; There is no &amp;quot;global town square&amp;quot;, and
we are deeply concerned about
&lt;a href=&quot;https://en.wikipedia.org/wiki/Context_collapse&quot;&gt;context collapse&lt;/a&gt;.
Communication and collaboration should happen from contextual flows.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Decentralized is the default:&lt;/strong&gt; We are building technology
&lt;em&gt;foundations&lt;/em&gt; on top of which then the rest of our user-facing
technology is built.  These foundations change the game: instead of
peer-to-peer, decentralized, secure tech being the realm of experts,
it's the default output of software built on top of our tech.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Participatory, gatekeeper-free technology:&lt;/strong&gt; Everyone should be
able to participate in the tech, without gatekeepers.  This means we
have a high bar for our tech being possible for individuals to
meaningfully run and for a wide variety of participants to be able to
cooperate on the network at once.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;We should not pretend we can prevent what we cannot:&lt;/strong&gt; Much harm
is caused by giving people the &lt;em&gt;impression&lt;/em&gt; that we provide features
and guarantees that we cannot provide.  We should be clear about the
limitations of our architecture, because if we don't, users may
believe they are operating with safety mechanisms which they do not
have, and may thus be hurt in ways they do not expect.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Contribute to the commons:&lt;/strong&gt; We are a research institution, and
everything we build is free and open source software, user-freedom
empowering tech and documentation.  This also informs our choice to
run the Spritely Institute, organizationally, as a nonprofit building
technology for the public good.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Fun is a revolutionary act:&lt;/strong&gt; The reason technology tends to
succeed is that people enjoy using it and get excited about it.
We care deeply about human rights and activism.  This is not in
opposition to building tech and a community environment that fosters
a sense of fun; planned carefully, fun is at the core of getting
people to understand and adopt any technology we make.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;I will note that the second to last post, contributing to the commons,
makes running the Spritely Institute challenging in so far as the
commons, famously, benefits everyone but is difficult to fund.  If the
above speaks to you, I will note that the Spritely Institute is, at the
time of writing,
&lt;a href=&quot;https://spritely.institute/donate/&quot;&gt;running a supporter drive&lt;/a&gt;,
and we could really use your support.  Thanks.  💜&lt;/p&gt;&lt;p&gt;This is not a post about Spritely, but I appreciate that Bryan invited
me talking about Spritely a bit here.  And ultimately, this is
important, because I would next like to talk about the present and the
future, and the world that I think we can build.&lt;/p&gt;&lt;h2&gt;Where to from here?&lt;/h2&gt;&lt;p&gt;I am relieved that the previous piece was overall received well and was
not perceived as me &amp;quot;attacking&amp;quot; Bluesky.  I hope that this piece can be
seen the same way.  I may have been &amp;quot;harshly analytical&amp;quot; in my analysis
at times, but I have tried to not be mean.  I care about the topics
discussed within this blogpost, and that's why I spent so much time on
them.  I know Bryan feels the same way, and one thing we both agree on
is that we don't want to be caught in an eternal back-and-forth: we want
to build the future.&lt;/p&gt;&lt;p&gt;But building the future does mean clear communication about terminology.
I will (quasi)quote Jonathan Rees again, as I have previously when
&lt;a href=&quot;https://dustycloud.org/blog/identity-is-a-katamari/&quot;&gt;talking about the nature of language&lt;/a&gt;
and &lt;a href=&quot;https://dustycloud.org/tmp/interfaces.html&quot;&gt;defining terminology&lt;/a&gt;:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;Language is a continuous reverse engineering effort between all
parties involved.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;(Somewhat humorously, I seem to adjust the phrasing of this
quoting-from-memory just slightly every time I quote it.)&lt;/p&gt;&lt;p&gt;If we aren't careful and active in trying to understand each other,
words can easily lose their meaning.  They can even lose their meaning
when shifting between defined contexts over time.  The fact that Baran
defined the term &amp;quot;decentralization&amp;quot; as a particular kind of
centralization was because he was responding to a context in which that
term had already been defined (and thus introducing a new term
&amp;quot;distributed&amp;quot; to describe what we might call &amp;quot;decentralization&amp;quot;).  The
fact that today we use &amp;quot;centralization&amp;quot; and &amp;quot;decentralization&amp;quot; as two
ends of a &lt;em&gt;spectrum&lt;/em&gt; is also fine.  I don't think Bryan quoting Mark
quoting Baran in this way and thus introducing this error was
&lt;em&gt;intentional&lt;/em&gt;, but ultimately it helps explain &lt;em&gt;exactly&lt;/em&gt; why the term
chosen produced a real risk of decentralization-washing.&lt;/p&gt;&lt;p&gt;I agree that Bluesky does use some decentralization techniques in
interesting and useful ways.  These enable &amp;quot;credible exit&amp;quot;, and are also
key to enabling some of the other values and design goals which Bryan
articulated Bluesky and ATProto as having.  But to me, a system which
does not permit user participation in its infrastructure and which is
dependent on a few centralized gatekeepers is not &lt;em&gt;itself&lt;/em&gt; decentralized.&lt;/p&gt;&lt;p&gt;So what of my analysis of the public-global-gods-eye-view-shared-heap
approach as growing quadratically in complexity as the system
decentralizes?  I'm not trying to be rude in any way.  I made a
statement about the behavior of the system algorithmically, and it felt
important that I not only assess whether or not that statement was true
because if it &lt;em&gt;wasn't&lt;/em&gt; true then I would want to understand myself and
retract it.  But there's interest and &lt;em&gt;belief&lt;/em&gt; right now by many people
that ATProto can be &amp;quot;self hosted&amp;quot;.  It's important, at least, to
understand to the degree which that simply, under the current
architecture, it is not possible to do.  Especially because right now a
lot of people are operating on this information out of belief in and
hope for the future.  If my assertion about the quadratic explosion
problems of meaningfully decentralizing ATProto are false, and that it
&lt;em&gt;is&lt;/em&gt; possible for self-hosting to become common in the system with the
properties that Bluesky has set out as being key features still being
possible to be preserved, then I will welcome and retract that
assertion.&lt;/p&gt;&lt;p&gt;However, I suspect that the reality is that I am not wrong, and instead
what we will see is a shift in &lt;em&gt;expectations&lt;/em&gt; about what is possible for
Bluesky to be decentralized and in what capacity.  Some people will be
upset to have a new realization about what is and isn't possible, some
people will simply update their expectations and say that having only a
few large players be able to provide a Bluesky-like experience is
actually good enough for them (and that what they're interested in
instead is API-consumer-and-redistributor features on top of Bluesky's
API), and the majority of the network will have the same level concern
they have always had: none.&lt;/p&gt;&lt;p&gt;The reality is that most of Bluesky's userbase doesn't know or care
about or understand the degree to which Bluesky is decentralized, except
for potentially as a reassurance that &amp;quot;the same thing can't happen here&amp;quot;
as happened on X-Twitter.  &amp;quot;Decentralization&amp;quot; is not the escape hatch
people think it might be in Bluesky, but it's true that &amp;quot;credible exit&amp;quot;
may be.  However, the credibility of that exit currently predicates on
another organization of the same cost and complexity of Bluesky standing
in if-or-when Bluesky ends up becoming unsatisfying to its users.&lt;/p&gt;&lt;p&gt;But the indifference towards Bluesky's &amp;quot;credible exit&amp;quot;, indeed the
indifference towards &lt;em&gt;very architecture on which Bluesky is built&lt;/em&gt;,
puts Bluesky at an immediate collision course of expectations.
ATProto's entire design is built on the foundational expectation of
replicating and indexing its content by anyone, but the discovery that
this is possible for purposes which users are &lt;em&gt;not&lt;/em&gt; excited about has
begun to lead to an increased backlash by users, many of whom are
increasingly asking for solutions which are effectively centralized.&lt;/p&gt;&lt;p&gt;To me, this collision course is unsurprising, and I am empathetic
towards users insofar as that I think we are seeing that the global
public firehose worldview is perhaps not the right way to do things.  I
laid out a different set of values that Spritely is pursuing, and I
think that a system that encompasses these values is a system which
&lt;em&gt;better&lt;/em&gt; fits the needs of users.  I think we need systems which empower
users and healthy communities, secure collaboration, and all the other
values we put out above.  Those are the design goals, but Spritely is on
a longer roadmap in terms of deliverables than Bluesky is.  And Bluesky
has a userbase &lt;em&gt;now.&lt;/em&gt;  So perhaps this observation sounds thoroughly
unhelpful.  I don't know.  But I will say I am not surprised to see that
the vibes on Bluesky shifted dramatically between three weeks ago when I
wrote the first article and today.  In many ways, Bluesky is
speedrunning the history of Twitter.  Investor pressure towards
centralization compounded with users who are upset to find their content
replicated and indexed by people they don't like will likely combine
into a strong push to restrict Bluesky's API, and I'm not sure myself
how this will play out for certain.&lt;/p&gt;&lt;p&gt;And all of that sounds fairly negative, so let me shift towards
something positive.&lt;/p&gt;&lt;p&gt;I still do truly believe that &amp;quot;credible exit&amp;quot; is a worthy goal.
Actually, I think that (perhaps with one mentioned wording change) all
of Bluesky's stated goals are actually quite good.  I think Bluesky
should continue to pursue them.  And I think Bluesky has a team that is
interested in doing so.  There may be opportunities to share knowledge
and collaborate on solutions between Bluesky and other projects,
including those I work on.  I know Bryan and I are both interested in
such.  And I said in the previous article how much I respect Jay Graber,
and that's true.  I also respect Bryan Newbold tremendously.  One thing
is true for certain: Bryan is a believer in all of the ideals he
previously stated.  I respect him for that.  I would like to see those
ideals succeed as far as they possibly can.  Perhaps there are even ways
to do so together.  I will not waver in my goals and values, but I
am a strong believer in collaboration where it is fruitful.&lt;/p&gt;&lt;p&gt;And that is the conclusion to what I have to say on the matters of
Bluesky and decentralization.  I will probably comment on the fediverse
and Bluesky itself, but I don't think I will write another blogpost like
these two mega-posts I have written.  I am not personally interested in
going back-and-forth on this any longer.  More than I am interested in
laying out concerns, by far, I am interested in building the future.&lt;/p&gt;&lt;p&gt;Thanks for listening.&lt;/p&gt;</summary></entry><entry><title>How decentralized is Bluesky really?</title><id>https://dustycloud.org/blog/how-decentralized-is-bluesky/</id><author><name>Christine Lemmer-Webber</name><email>cwebber@dustycloud.org</email></author><updated>2024-11-22T11:00:00Z</updated><link href="https://dustycloud.org/blog/how-decentralized-is-bluesky/" rel="alternate" /><summary type="html">&lt;p&gt;Recently due to various events (namely a lot of people getting off of
X-Twitter), &lt;a href=&quot;https://bsky.app/&quot;&gt;Bluesky&lt;/a&gt; has become a lot more
popular, and excitement for its underlying protocol,
&lt;a href=&quot;https://atproto.com/&quot;&gt;ATProto&lt;/a&gt;, is growing.
Since I worked on
&lt;a href=&quot;https://www.w3.org/TR/activitypub/&quot;&gt;ActivityPub&lt;/a&gt; which connects
together &lt;a href=&quot;https://joinmastodon.org/&quot;&gt;Mastodon&lt;/a&gt;,
&lt;a href=&quot;https://activitypub.software/TransFem-org/Sharkey&quot;&gt;Sharkey&lt;/a&gt;,
&lt;a href=&quot;https://joinpeertube.org/&quot;&gt;Peertube&lt;/a&gt;,
&lt;a href=&quot;https://gotosocial.org/&quot;&gt;GotoSocial&lt;/a&gt;, etc, etc, etc in the present-day
fediverse, I often get asked whether or not I have opinions about
ATProto vs ActivityPub, and the answer is that I do have opinions, but
I am usually head-down focused on building what I hope to be the
&lt;a href=&quot;https://spritely.institute/&quot;&gt;next generation of decentralized (social) networking tech&lt;/a&gt;,
and so I keep to myself about such things except in private channels.&lt;/p&gt;&lt;p&gt;This debate has been growing harder to ignore, with articles ranging from
&lt;a href=&quot;https://rys.io/en/167.html&quot;&gt;&amp;quot;Bluesky is cosplaying decentralization&amp;quot;&lt;/a&gt;
on the one hand and
&lt;a href=&quot;https://kyefox.com/nobody-cares-about-decentralization-until-they-do/&quot;&gt;&amp;quot;Nobody cares about decentralization until they do&amp;quot;&lt;/a&gt;
on the other (which I suppose went subscriber-only; it had a big
splash recently and wasn't previously) in favor of ATProto and arguing
that other approaches are not as decentralized.  Still, I mostly
believed that anything I had to say on the subject would not be
received productively, and so I figured it was best to reserve
comment to myself and those close to me.
But recently I have received some direct encouragement from a core
Bluesky developer that they have found my writings insightful and
useful and would be happy to see me write on the subject.  So here are
my thoughts.&lt;/p&gt;&lt;p&gt;Let us open with a framing.  Decentralization is the result of a
system that diffuses power throughout its structure, so that no node
holds particular power at the center.  &amp;quot;Federation&amp;quot;, as has been used
as a &lt;em&gt;technical&lt;/em&gt; term since the emergence of the &amp;quot;Fediverse&amp;quot; (which
presently is mostly associated with ActivityPub, though I would argue
XMPP and email are also federated), is a technical approach to
communication architecture which achieves decentralization by many
independent nodes cooperating and communicating to be a unified whole,
with no node holding more power than the responsibility or
communication of its parts.&lt;/p&gt;&lt;p&gt;Under these definitions,
&lt;em&gt;Bluesky and ATProto are not meaningfully decentralized,&lt;/em&gt;
&lt;em&gt;and are not federated either&lt;/em&gt;.  However, this is not to say that
Bluesky is not achieving something useful; while Bluesky is not
building what is presently a decentralized Twitter, it is building an
excellent replacement for Twitter, and Bluesky's main deliverable goal
is something else instead:
&lt;em&gt;a Twitter replacement, with the possibility of &amp;quot;credible exit&amp;quot;.&lt;/em&gt;&lt;/p&gt;&lt;h2&gt;Bluesky's strengths&lt;/h2&gt;&lt;p&gt;I'm sure some people are already bristling having read the previous
paragraph, and I will get to explaining my rationale, which is a
technical analysis in nature.  But let's open with the positive,
because I think there are positive things to say about Bluesky as
well.&lt;/p&gt;&lt;p&gt;Bluesky has done an incredible job scaling to meet the present moment.
Right now, Bluesky is facing a large influx of users who are looking
for an alternative to X-Twitter since Musk's takeover (and
particularly since Trump's re-election).  In other words, the type of
user who would be sympathetic to the post
&lt;a href=&quot;https://www.theatlantic.com/technology/archive/2024/11/x-white-supremacist-site/680538/&quot;&gt;X is a White-Supremacist Site&lt;/a&gt;
is now looking for someplace else to be.  The future of X-Twitter is a
place where only hard-right people are going to feel comfortable;
anyone else is going to be looking for a replacement &lt;em&gt;now&lt;/em&gt;, and
Bluesky is going to be their quickest and easiest option.&lt;/p&gt;&lt;p&gt;In many ways, Bluesky was built for this.  Its experience is basically
a one-to-one feature-for-feature replacement for the Twitter that many
people loved.  And the original directive that Bluesky was given, when
it was Jack Dorsey and Parag Agrawal's joint pet project (my
understanding at the time was that it was Jack's vision, but Parag
took the lead, and my impression was also that they were both very
sincere about this) to kick off a decentralized protocol
&lt;em&gt;which Twitter could adopt&lt;/em&gt;.  This informed a lot of the initial
architectural decisions of Bluesky, including its scaling needs.  It
also incidentally lead it to become an excellent offboarding
platform when it turned out that many X-Twitter users no longer felt
comfortable on the platform.  You miss old Twitter?  Bluesky already
has been building an alternative: hop on board, it's just like old
Twitter!&lt;/p&gt;&lt;p&gt;The fact that Jack Dorsey kicked off Bluesky as an initiative and a
funded effort and that Jack was originally on Bluesky's board often
leads to snarky or snide comments on the fediverse that Bluesky is
owned by Jack Dorsey.  However, this isn't true: Jack Dorsey quit
Bluesky and has been focusing on &lt;a href=&quot;https://nostr.com/&quot;&gt;Nostr&lt;/a&gt; (which I
can best describe as &amp;quot;a more uncomfortable version of
&lt;a href=&quot;https://scuttlebutt.nz/&quot;&gt;Secure Scuttlebutt&lt;/a&gt; for Bitcoin people to
talk about Bitcoin&amp;quot;).  So I don't think this particular criticism
holds true.  Bluesky is also fully independent of Twitter; my
impression is that this only happened because Jay Graber (Bluesky's
CEO) very carefully negotiated to make sure that when Bluesky got its
funds that it would receive them without Twitter having control, and
this shows a lot of foresight on Jay's part.&lt;/p&gt;&lt;p&gt;For that matter, I think the part of Bluesky I probably respect most
personally is Jay Graber.  I was not surprised when she was awarded
the position of leading Bluesky; she was the obvious choice given her
leadership in the process and project, and every interaction I have
had with Jay personally has been a positive one.  I believe she leads
her team with sincerity and care.  Furthermore, though a technical
critique and reframing follows, I know Jay's team is full of other
people who sincerely care about Bluesky and its stated goals as well.&lt;/p&gt;&lt;p&gt;There is one other thing which Bluesky gets right, and which the
present-day fediverse does not.  This is that Bluesky uses
content-addressed content, so that content can survive if a node goes
down.  In this way (well, also allegedly with identity, but I will
critique that part because it has several problems), Bluesky achieves
its &amp;quot;credible exit&amp;quot; (Bluesky's own term, by the way) in that the main
node or individual hosts could go down, posts can continue to be
referenced.  This is possible to also do on the fediverse, but is not
done presently; today, a fediverse user has to worry a lot about a
node going down.  indeed I intentionally fought for and left open the
possibility within ActivityPub of adding content-addressed posts, and
several years ago I
&lt;a href=&quot;https://gitlab.com/spritely/golem/blob/master/README.org&quot;&gt;wrote a
demo&lt;/a&gt;
of how to combine content addressing with ActivityPub.  But
nonetheless, even though such a thing is spec-compatible with
ActivityPub, &lt;em&gt;content-addressing is not done today on ActivityPub&lt;/em&gt;,
and &lt;em&gt;is&lt;/em&gt; done on Bluesky.&lt;/p&gt;&lt;h2&gt;Bluesky's architecture and centralization&lt;/h2&gt;&lt;h3&gt;On blogs, search engines, and Google Reader&lt;/h3&gt;&lt;blockquote&gt;&lt;p&gt;When you build architecture that in theory anyone can participate
in, but the barrier to entry is so high so that only those with the
highest number of resources can participate, then you've still built
a walled garden. -- &lt;a href=&quot;https://mlemmer.org/&quot;&gt;Morgan Lemmer-Webber&lt;/a&gt;,
(summarizing things succinctly in our household over breakfast)&lt;/p&gt;&lt;/blockquote&gt;&lt;blockquote&gt;&lt;p&gt;Think of our app like a Google. -- &lt;a href=&quot;https://atproto.com/guides/applications&quot;&gt;ATProto quick start guide&lt;/a&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;I believe that to this day, the web and blogs are still perceived as a
decentralized and open publishing platform.  However, I don't know of
anyone who would consider Google to be decentralized.  In theory,
anyone could build their own search engine: the web, which is being
consumed and indexed, is trivial enough to parse and aggregate.
However, few can, and in practice, we see two (or maybe three) search
engines in practice alive today: Google, Bing, and maybe DuckDuckGo
(which, per my understanding, uses several sources, but is largely
Bing).&lt;/p&gt;&lt;p&gt;This is all to say, in many ways Bluesky's developers have described
Bluesky as being
&lt;a href=&quot;https://bsky.app/profile/pfrazee.com/post/3l7yrftpeuc2q&quot;&gt;a bunch of blogs aggregated by Bluesky as a search engine&lt;/a&gt;,
and while this isn't really true, it's a good starting point for
understanding its challenges.
(To understand the rest of the terms involved in the document in detail,
&lt;a href=&quot;https://bsky.social/about/blog/5-5-2023-federation-architecture&quot;&gt;Bluesky's architecture&lt;/a&gt;
document is a good source.)&lt;/p&gt;&lt;p&gt;The same way that in theory the web and blogs are not tied to Google,
neither are ATProto's Personal Data Stores (necessarily) tied to
Bluesky, the company.  Since a small number of people are running
Personal Data Stores right now, which is quite viable, Bluesky may
have the appearance of being decentralized.  And at present, there's
really only one each of the Relay and (Twitter-like) AppView
components used in practice, but there is a real possibility of this
changing and real architectural affordance work to allow it.  So
perhaps things to not seem all that bad.&lt;/p&gt;&lt;p&gt;However, if we look back at the metaphor of blogs and Google, it's
important to note that before social networking in its present form
took off, blogs and the &amp;quot;blogosphere&amp;quot; were the primary mechanism of
communication on the internet, aggregated by RSS and Atom feeds.
And RSS and Atom feed readers started out with an enormous amount of
&amp;quot;biodiversity&amp;quot; and largely ran on peoples' desktops.  Then along came
Google Reader and... friends, if you are reading this and are of a
certain age range, there is a strong chance you have &lt;em&gt;feelings&lt;/em&gt; just
seeing the phrase &amp;quot;Google Reader&amp;quot; mentioned.  Google Reader did a
great job of providing not all of RSS and Atom feed readers, but
enough of it that when Google shuttered it, blogging (and my favorite
offshoot of blogging, independent webcomics) crumbled as a primary
medium.  Blogs still exist, but &lt;em&gt;blog feed aggregation&lt;/em&gt; fell quickly
to the wayside.  Browsers removed the feed icon, and right around that
time, social networks in their present shape took their place.  To
this day, blogs are now primarily shared on social networks.&lt;/p&gt;&lt;p&gt;This is all to say: blogging plus feed readers started out a lot more
decentralized than Bluesky has, and having one big player enter the
room and then exit effectively killed the system.&lt;/p&gt;&lt;p&gt;And that's even without feed readers being particularly expensive or
challenging to run as independent software.  I have this concern for
the fediverse as well (in case you think this article is harsh on
Bluesky and I am a fediverse fangirl because I co-authored the spec it
uses, stay tuned; I plan on releasing a critical analysis of the
fediverse as-is here shortly).
&lt;a href=&quot;https://mastodon.social/explore&quot;&gt;mastodon.social&lt;/a&gt; is certainly a
&amp;quot;meganode&amp;quot; and &lt;a href=&quot;https://www.threads.net/&quot;&gt;Threads&lt;/a&gt;...  let's not even
get &lt;em&gt;started&lt;/em&gt; with Threads, that's a long topic.  And running your own
server is much more challenging than I'd like.  But even so, if you
check some of the fediverse aggregators such as
&lt;a href=&quot;https://fedidb.org/&quot;&gt;FediDB&lt;/a&gt; or
&lt;a href=&quot;https://fediverse.observer/stats&quot;&gt;Fediverse Observer&lt;/a&gt;
you will see thousands of servers across many interoperating
implementations.&lt;/p&gt;&lt;h3&gt;Self-hosting resources: ActivityPub and ATProto comparison&lt;/h3&gt;&lt;p&gt;Hosting a fediverse server is cheap particularly if you use something
like &lt;a href=&quot;https://gotosocial.org/&quot;&gt;GotoSocial&lt;/a&gt; is lightweight enough where
one could host a server for one's family or friends on a device as
light as a Raspberry Pi style form factor.  It may require a lot of
technical expertise, I may have many critiques of how it runs, but
it's possible to host a &lt;em&gt;fully participating&lt;/em&gt; fediverse node
&lt;a href=&quot;https://lobste.rs/s/thsv0z/conceptual_model_atproto_activitypub#c_gmeahq&quot;&gt;quite cheaply&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;Now, you may see people say, running an ATProto node is fairly cheap!
And this is because comparatively speaking, running a Personal Data
Store is fairly cheap, because running a Personal Data Store is more
akin to running a blog.  But social networks are much more interactive
than blogs, and in this way the rest of Bluesky's architecture is a
lot more involved than a search engine: users expect real-time
notifications and interactivity with other users.  This is where the
real architecture of Bluesky/ATProto comes in: Relays and AppViews.&lt;/p&gt;&lt;p&gt;So how challenging is it to run those?
In July 2024, running a Relay on ATProto already
&lt;a href=&quot;https://whtwnd.com/bnewbold.net/entries/Notes%20on%20Running%20a%20Full-Network%20atproto%20Relay%20(July%202024)&quot;&gt;required 1 terabyte of
storage&lt;/a&gt;.
But more alarmingly, just a four months later in November 2024,
running a relay now requires &lt;a href=&quot;https://alice.bsky.sh/post/3laega7icmi2q&quot;&gt;approximately 5 terabytes of storage&lt;/a&gt;.
That is a nearly 5x increase in &lt;em&gt;just four months&lt;/em&gt;, and my guess is
that by next month, we'll see that doubled to at least ten terabytes
due to the massive switchover to Bluesky which has happened
post-election.  As Bluesky grows in popularity, so does the rate of
growth of the expected resources to host a meaningfully
participating node.&lt;/p&gt;&lt;h3&gt;&amp;quot;Message passing&amp;quot; vs &amp;quot;shared heap&amp;quot; architectures&lt;/h3&gt;&lt;p&gt;The best way to understand the reason for this difference in hosting
requirements is to understand the underlying architecture of these
systems.  ActivityPub follows an &lt;strong&gt;message passing&lt;/strong&gt; architecture
(utilizing publish-subscribe architecture prominently for most
&amp;quot;subscription&amp;quot; oriented uses), the same as email, XMPP, and so on.  A
message is addressed, and then delivered to recipients.  (Actually a
more fully peer-to-peer system would deliver more directly; all of
email, XMPP, ActivityPub and so on use a client-server architecture,
so there is a particular server which tends to operate on behalf of a
particular user.  See comments on the fediverse later in this article
for how things can be moved more peer-to-peer.)  This turns out to be
pretty efficient; if only users on five servers need to know about a
message, out of tens of thousands of servers, only those five servers
will be contacted.  Until recently, every system I knew of described
as federated used a message passing architecture, to the degree where
I and others assumed that federation &lt;em&gt;implied&lt;/em&gt; a message passing
architecture, because achieving the architectural goal of many
independent nodes cooperating to produce a unified whole seemed to
imply this was necessary for efficiency of a substantially sized
network.  If Alyssa wants to write a piece of mail to Ben, she can
send it directly to Ben, and it can arrive at Ben's house.  If Ben
wants to reply, Ben can reply directly to Alyssa.  Your intuitions
about email apply exactly here, because that's effectively what this
design is.&lt;/p&gt;&lt;p&gt;Bluesky does not utilize message passing, and instead operates in what
I call a &lt;strong&gt;shared heap&lt;/strong&gt; architecture.  In a shared heap architecture,
instead of delivering mail to someone's house (or, in a
client-to-server architecture as most non p2p mailing lists are, at
least their apartment's mail room), letters which may be interesting
all are dumped at a post office (called a &amp;quot;relay&amp;quot;) directly.  From
there it's the responsibility of interested parties to show up and
filter through the mail to see what's interesting to them.  This means
there is &lt;em&gt;no directed delivery&lt;/em&gt;; if you want to see replies which are
relevant to your messages, you (or someone operating on behalf of you)
had better sort through and know about &lt;em&gt;every possible message&lt;/em&gt; to
find out what messages could be a reply.&lt;/p&gt;&lt;p&gt;It is curious then that the reason for not taking a message passing
architecture such as ActivityPub as the foundation for Bluesky and
ATProto is often described as wanting users to not have the experience
of seeing a reply thread containing missed messages.  From the
&lt;a href=&quot;https://arxiv.org/pdf/2402.03239&quot;&gt;AT Protocol paper&lt;/a&gt;:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;The distinction between servers in Mastodon introduces complexity
for users that does not exist in centralized services. For example,
a user viewing a thread of replies in the web interface of one
server may see a different set of replies compared to viewing the
same thread on another server, because a server only shows those
replies that it knows about.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;This is particularly curious because experiencing missed messages is a
frequent complaint of other shared heap architecture designs such as
Secure Scuttlebutt and Nostr, where missing message replies are even
&lt;em&gt;more&lt;/em&gt; common than on ActivityPub and other message-passing federated
architectures.  (Both Secure Scuttlebutt and Nostr take steps so you
don't need to necessarily fetch everything; in SSB you fetch the feeds
of your friends and 3 degrees removed from your friends from the hubs
you use, and anything else you simply don't see.  In Nostr you simply
&amp;quot;embrace the chaos&amp;quot; of only grabbing the information from hubs you
use, and hubs don't try to fetch all information.)  For instance, if
Ben replies to Alyssa's message in one of these systems but does not
leave the reply message in the relay which Alyssa pulls from, Alyssa
would never see Ben's reply.  If multiple relays were to exist in
Bluesky, this same problem would presumably occur, so how does Bluesky
solve this?&lt;/p&gt;&lt;p&gt;The answer is: Bluesky solves this problem via centralization.  Since
there is really just one very large relay which everyone is expected
to participate in, this relay has a god's-eye knowledge base.
Entities which sort through mail and relevant replies for users are
AppViews, which pull from the relay and also have a god's-eye
knowledge base, and also do filtering.  So too do any other number of
services which participate in the network: they must operate at the
level of gods rather than mortals.&lt;/p&gt;&lt;p&gt;The reality of the fediverse today is that due to the complexity of
hosting an instance, many users join nodes hosted by either a friend
or a larger group, but there are still many nodes on the network.  As
mentioned earlier, this is closer to being an apartment building than
a house, but the ideal version of decentralization is that everyone
self-hosts, and from a resource perspective, this is perfectly
possible to do.  It would be possible, for mere tens of dollars, for
everyone to get a cheap computer and self-host something like
GotoSocial and (ignoring the challenges of firewalls and ISPs frowning
upon self-hosting at home these days) from an architectural
perspective, it's certainly possible.  The primary challenge
preventing this future is in the technical difficulty of hosting these
services presently (and the way the internet has generally become
hostile to home-hosting, but shared hosting for this level of service
is also still relatively cheap for individuals).  The ideal version of
decentralization is, from a message transmission perspective (we shall
look at other aspects later), fully possible.&lt;/p&gt;&lt;p&gt;The physical world equivalent for a fully decentralized fediverse then
is that every user sends mail to every other user's house, as needed,
similar to how sending letters works in the physical world.  This is
decidedly &lt;em&gt;not&lt;/em&gt; the case with a fully decentralized ATProto.  The
physical world equivalent would be that every user had their own house
at which they
&lt;em&gt;stored a copy of every piece of mail delivered to every other user&lt;/em&gt;
&lt;em&gt;at their house&lt;/em&gt;.&lt;/p&gt;&lt;p&gt;If this sounds infeasible to do in our metaphorical domestic
environment, that's because it is.  A world of full self-hosting is
not possible with Bluesky.  In fact, it is worse than the storage
requirements, because the message delivery requirements become
quadratic at the scale of full decentralization: to send a message to
one user is to send a message to all.  Rather than writing one letter,
a copy of that letter must be made and delivered to every person on
earth.&lt;/p&gt;&lt;h3&gt;The costs of decentralizing ATProto&lt;/h3&gt;&lt;p&gt;Bluesky's architecture documentation does acknowledge this, to some
degree:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;The federation architecture allows anyone to host a Relay, though
it’s a fairly resource-demanding service. In all likelihood, there
may be a few large full-network providers, and then a long tail of
partial-network providers. Small bespoke Relays could also service
tightly or well-defined slices of the network, like a specific new
application or a small community.
-- &lt;a href=&quot;https://bsky.social/about/blog/5-5-2023-federation-architecture&quot;&gt;Federation Architecture Overview (Bluesky blog)&lt;/a&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;What is not mentioned is that any smaller bespoke relays would have a
&lt;em&gt;greater&lt;/em&gt; problem with missing message replies than a directed
message-passing architecture has.  If larger nodes are gods, then I
suppose smaller nodes are demi-gods, from which one could say that
only truly fully and complete gods can participate meaningfully in
the network.&lt;/p&gt;&lt;p&gt;In the meanwhile, many users of Bluesky seem to be operating under the
impression that things are more decentralized than they are:&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://bsky.app/profile/dustyweb.bsky.social/post/3lalubcleyc2d&quot;&gt;&lt;img src=&quot;/etc/images/blog/bluesky-search-convo.png&quot; alt=&quot;Conversation where a user seems to think Bluesky search is happening in a decentralized way&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Part of the concern I have with Bluesky presently is thus that people
are gaining the impression that it's a decentralized system in ways
that it is not.  There are multiple ways this could end up being a
problem for the decentralized world; one irritating way is that people
might believe there's an &amp;quot;easy decentralized way to do things&amp;quot; that
Bluesky has discovered which isn't actually that at all, and another
is that Bluesky could collapse at some point and that people might
walk away with the impression of &amp;quot;oh well, we tried decentralization
and that didn't work... remember Bluesky?&amp;quot;&lt;/p&gt;&lt;p&gt;But perhaps we should look at making Bluesky more decentralized by
adding more meaningfully fully participating nodes to it again.  How
much would that cost today, and how much will that cost in the future?&lt;/p&gt;&lt;p&gt;Again, returning to
&lt;a href=&quot;https://alice.bsky.sh/post/3laega7icmi2q&quot;&gt;alice's previously mentioned blogpost&lt;/a&gt;,
the most recent time that costs of running a Bluesky relay were
calculated (which does &lt;em&gt;not&lt;/em&gt; also include the costs of running an
AppView node or any other critical components), just looking at
storage, the amount required was 5 terabytes of storage.  The first
glance thing I did was to look up, if you were going to pick up a
complete shared hosting server configured with that storage size, how
much would that be on Linode, as just a common example of a shared
hosting provider?  At first glance, this appeared to end up around
$55k/year, just to host the last estimate of a current relay:&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://bsky.app/profile/dustyweb.bsky.social/post/3lah5n3kld42q&quot;&gt;&lt;img src=&quot;/etc/images/blog/bluesky-linode-relay-costs.png&quot; alt=&quot;Myself pulling up an example of shared hosting expense expectations, which turns out to be about $55k/year&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Bryan Newbold pointed out that this was fairly expensive and that
there were cheaper options even on Linode using Linode's block storage
options (though this doesn't account for still needing a database in
addition):&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://bsky.app/profile/dustyweb.bsky.social/post/3lah5n3kld42q&quot;&gt;&lt;img src=&quot;/etc/images/blog/bluesky-linode-block-storage-costs.png&quot; alt=&quot;Bryan Newbold pulling up estimate of Linode's block storage costs being about $512/month for files-on-disk hosting&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;But as both alice and Bryan Newbold have pointed out, using a
dedicated server would be much cheaper.  Unfortunately, this solution
only scales for so long.  In
&lt;a href=&quot;https://whtwnd.com/bnewbold.net/entries/Notes%20on%20Running%20a%20Full-Network%20atproto%20Relay%20(July%202024)&quot;&gt;Bryan's previous article on running a relay&lt;/a&gt;,
costs were calculated for one terabyte, and the server came to
$152/month plus a one-time setup fee of $92.  Cheap!  However, the
network is clearly growing and already exceeds that size, so let's
take the
&lt;a href=&quot;https://www.ovhcloud.com/en/bare-metal/advance/adv-2/&quot;&gt;same bare metal server&lt;/a&gt;
and see how much storage we can add and how expensive this will get:&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://bsky.app/profile/dustyweb.bsky.social/post/3lah5n3kld42q&quot;&gt;&lt;img src=&quot;/etc/images/blog/bluesky-dedicated-hosting-add-more-storage.png&quot; alt=&quot;The cost of adding more storage: +$414.20/month for 4x 7.68TB SSD NVMe Soft RAID&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;That's nearly 5x the expense to move to what it looks like the
expenses for running a relay will be &lt;em&gt;very soon&lt;/em&gt;.  And this is for a
single server that isn't being used, as we say, &amp;quot;in anger&amp;quot; against an
actual userbase, of which the expenses of hosting such a thing are
unknown, because nobody is really using it.  We are now hitting the
limits of a dedicated server regardless, so one will &lt;em&gt;have to&lt;/em&gt; move
towards more abstracted and clustered storage and indexing mechanisms
past this point to keep the network running (unless disk manufacturers
surprise us all with an enormous leap in capacity which is rolled out
in the very short term future).&lt;/p&gt;&lt;p&gt;And that is &lt;em&gt;just for storage&lt;/em&gt; running &lt;em&gt;without backups&lt;/em&gt; or any of the
other things one would need to keep such a thing going, including
bandwidth and CPU cycles and so on and so forth.  A single machine
does not look like it can be a viable solution for very long, so
pointing to dedicated servers which can currently handle an entire
relay (when not actually relied upon by any number of users) isn't
particularly convincing to me.&lt;/p&gt;&lt;p&gt;There is also the &lt;em&gt;legal liability&lt;/em&gt; that one is taking on by
effectively hosting the equivalent of &lt;em&gt;all of Twitter&lt;/em&gt;!  While
Bluesky/ATProto &lt;em&gt;does&lt;/em&gt; provide multiple filtering techniques which are
very interesting, the relay does need to be in the business of
identifying what content is not safe to use:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;[...] the Relay performs some initial data cleaning (discarding
malformed updates, filtering out illegal content and high-volume
spam) -- &lt;a href=&quot;https://arxiv.org/pdf/2402.03239&quot;&gt;Bluesky and the AT Protocol: Usable Decentralized Social Media&lt;/a&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;The likely answer to this is that there will always have to be a large
corporation at the heart of Bluesky/ATProto, and the network will have
to rely on that corporation to do the work of abuse mitigation,
particularly in terms of illegal content and spam.  This may be a good
enough solution for Bluesky's purposes, but on the economics alone
it's going to be a centralized system that relies on trusting
centralized authorities.&lt;/p&gt;&lt;h3&gt;Everything is public, including who you block&lt;/h3&gt;&lt;p&gt;You may be reading so far at this point and be wondering: so far I
have only analyzed Bluesky from the perspective of public content.
What about private or semi-private content?  How does Bluesky provide
its various services of filtering and labeling and so on in such an
environment, and how does Bluesky know which messages are sent in
reply to your messages with limited or entirely private messages?&lt;/p&gt;&lt;p&gt;The answer is that Bluesky and ATProto have no design for this at
present, and most of the architectural assumptions &lt;em&gt;assume&lt;/em&gt; public
messages only.  Now this could change of course, but everything within
Bluesky's current literature and architecture assume public-only
content.  In fact, even blocks are public information:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;[...] for example, if one user has blocked another, and one of the
users’ repositories contains a record of an interaction that should
not have been allowed due to the block, then the App View drops that
interaction so that nobody can see it in the client apps. This
behavior is consistent with how blocking works on Twitter/X, and it
is also the reason why blocks are public records in Bluesky: every
protocol-conforming App View needs to know who is blocking who in
order to enforce the block. -- &lt;a href=&quot;https://arxiv.org/pdf/2402.03239&quot;&gt;Bluesky and the AT Protocol: Usable Decentralized Social Media&lt;/a&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;I'm not sure this behavior is consistent after all with how blocking
works on X-Twitter; it was not my understanding that blocking someone
would be public information.   But
&lt;a href=&quot;https://docs.bsky.app/blog/block-implementation&quot;&gt;blocks are indeed public information on Bluesky&lt;/a&gt;,
and anyone can query who is blocking or being blocked by anyone.  It
is true that looking at a blocking account from a blocked account on
most social media systems or observing the results of interactions can
&lt;em&gt;reveal&lt;/em&gt; information about who is blocked, but this is not the same as
this being &lt;em&gt;openly queryable information&lt;/em&gt;.  There is a big difference
between &amp;quot;you can look at someone's post and see who is being blocked&amp;quot;
to &amp;quot;you can query the network for every person who is blocking or is
blocked by JK Rowling&amp;quot;.&lt;/p&gt;&lt;p&gt;I found this very surprising; in ActivityPub's development, I remember
a conversation between Amy Guy and myself where we decided it was very
important to not deliver Block activities between servers.  We encoded
this in ActivityPub's specification thusly:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;The Block activity is used to indicate that the posting actor does not want another actor (defined in the object property) to be able to interact with objects posted by the actor posting the Block activity. The server SHOULD prevent the blocked user from interacting with any object posted by the actor.&lt;/p&gt;&lt;p&gt;Servers SHOULD NOT deliver Block Activities to their object. -- &lt;a href=&quot;https://www.w3.org/TR/activitypub/#block-activity-outbox&quot;&gt;ActivityPub&lt;/a&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;The reason for this is very simple: we have seen people who utilize
blocklists be retaliated against for blocking someone who is angry
about being blocked.  It was our opinion that sharing such information
could result in harassment.  (Last I checked, Mastodon provides the
user with the choice of whether or not to send a &amp;quot;report&amp;quot; about a
block to the offending instance so that moderators of that server can
notice a problematic user and take action, but delivering such
information is not required.)&lt;/p&gt;&lt;p&gt;That said, to Bluesky's credit, this is an issue that is being openly
considered.  There is an open issue to
&lt;a href=&quot;https://github.com/bluesky-social/atproto/discussions/1131&quot;&gt;consider whether or not private blocks are possible&lt;/a&gt;.
Which does lead to a point, despite my many critiques here: it is true
that even many of the things I have talked about could be changed and
evaluated in the future.  But nonetheless, in many ways I consider the
decision to have blocks be publicly queryable to be an example of
&lt;em&gt;emergent behavior from initial decisions&lt;/em&gt;... early architectural
decisions can have long-standing architectural results, and while many
things can be changed, some things are particularly difficult to
change form an initial starting point.&lt;/p&gt;&lt;h3&gt;Direct messages are fully centralized&lt;/h3&gt;&lt;p&gt;But you may notice!  Bluesky provides direct messages!  So surely not
&lt;em&gt;all&lt;/em&gt; information is publicly available, because otherwise else direct
messages would simply not work!  So how do direct messages work in
Bluesky?&lt;/p&gt;&lt;p&gt;The answer, if you guessed it, is centralization.  All direct
messages, no matter what your Personal Data Store is, no matter what
your &lt;em&gt;relay&lt;/em&gt; is, go through Bluesky, the company.&lt;/p&gt;&lt;p&gt;If you find this shocking, so did I, but then again, this information
was &lt;a href=&quot;https://bsky.social/about/blog/05-22-2024-direct-messages&quot;&gt;publicly available even when direct messages were announced&lt;/a&gt;.
Bluesky's direct messages are also not end-to-end encrypted, and don't
use any particular kind of protocol which is amenable to
decentralization or federation.&lt;/p&gt;&lt;p&gt;But perhaps we should back up... am I being too harsh?  After all,
while the fediverse works like email (actually, ActivityPub's
architecture is (contrary to many users' expectations since Mastodon
is also a Twitter clone and is how most people experience the
fediverse), designed for direct communication &lt;em&gt;first and
foremost&lt;/em&gt;... public communication is clearly supported, but the
default and simplest case is direct individual or group messaging),
it's also &amp;quot;about as private as email&amp;quot;.  Which is to say, not private
enough for many kinds of security concerns these days: your
administrator can read your DMs but hopefully does not in the general
case, but messages are not end-to-end encrypted at present.  But I can
know my administrator personally, and thus the trust dynamics are
often not the same.&lt;/p&gt;&lt;h3&gt;A feature complete Twitter ASAP&lt;/h3&gt;&lt;p&gt;So direct messages on Bluesky are centralized, and while Bluesky does
say so in their blogposts (past the point at which most people have
read), most users I have talked to have assumed they worked the same
way that the rest of ATProto works.  Why would Bluesky roll out a
direct message system that they have acknowledged is not the long term
direct message system they would like long term? (Though I am also
still puzzled... why they didn't at least use XMPP?)&lt;/p&gt;&lt;p&gt;The presumable answer is: Bluesky wanted to provide a feature-complete
platform from the perspective of a user who is looking for an exit
from Twitter &lt;em&gt;now&lt;/em&gt;.  And this is honestly a fair decision to make in
many ways, since as I have said previously, while I don't see Bluesky
as a very good decentralized Twitter, I do see it as a good
replacement for Twitter, which is what most users are looking for
immediately.  But the lack of understanding of these detail by many
users and media coverage is a bit maddening from someone like myself
who actually really does look at and care about decentralization, and
I know it's a bit maddening to much of the fediverse too.&lt;/p&gt;&lt;p&gt;But again: to many users, this doesn't matter.  What many users
fleeing X-Twitter &lt;em&gt;right now&lt;/em&gt; care about is a replacement for Twitter.
For that matter, if you're coming from Twitter, whether or not Bluesky
is truly decentralized, it certainly seems &lt;em&gt;more decentralized than
Twitter&lt;/em&gt;, the same way that Twitter may seem more decentralized than
cable news.  Things are sometimes more decentralized in degrees, and I
certainly think the fediverse could be more decentralized than it is.
(More, again, on this later.)  But in all ways related to the
distribution of power, Bluesky's technology is notably much less
distributed than existing and prominent decentralized technology
&lt;em&gt;in deployment today&lt;/em&gt;.&lt;/p&gt;&lt;h3&gt;Bluesky is centralized, but &amp;quot;credible exit&amp;quot; is a worthy pursuit&lt;/h3&gt;&lt;p&gt;In many places, Bluesky acknowledges that it is more centralized than
other alternatives in its own writing.  From its own paper:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;Even though the majority of Bluesky services are currently operated
by a single company, we nevertheless consider the system to be
decentralized because it provides &lt;em&gt;credible exit&lt;/em&gt;: if Bluesky Social
PBC goes out of business or loses users’ trust, other providers can
step in to provide an equivalent service using the same dataset and
the same protocols. -- &lt;a href=&quot;https://arxiv.org/pdf/2402.03239&quot;&gt;Bluesky and the AT Protocol: Usable Decentralized Social Media&lt;/a&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;It is &lt;em&gt;not a bad choice&lt;/em&gt; for Bluesky to be focused on providing an
alternative to X-Twitter for those who miss Twitter-of-yore and are
immediately looking for an offboarding from an abusive environment.  I
understand and support this effort!  Bluesky does use several
decentralization tricks which may lend themselves more towards its
self-stated goal of &amp;quot;credible exit&amp;quot;.  But these do not make Bluesky
decentralized, which it is not within any reasonable metric of the
power dynamics we have of decentralized protocols which &lt;em&gt;exist today&lt;/em&gt;,
and it does not use federation in any way that resembles the way that
technical term has been used within decentralized social networking
efforts.  (I have heard the term &amp;quot;federation-washing&amp;quot; used to describe
the goalpost-moving involved here, and I'm sympathetic to that phrase
personally.)&lt;/p&gt;&lt;p&gt;In my opinion, this should actually be the way Bluesky brands itself,
which I believe would be more honest: an open architecture (that's
fair to say!) with the possibility of credible exit.  This would be
more accurate and reflect better what is provided to users.&lt;/p&gt;&lt;h2&gt;ATProto's portable identity challenges&lt;/h2&gt;&lt;p&gt;Bluesky's credible exit claims rely both on content addressing but
also on its use of
&lt;a href=&quot;https://www.w3.org/TR/did-core/&quot;&gt;Decentralized Identifiers (DIDs)&lt;/a&gt;
for account migration.  This is certainly a good goal, and account
migration support is something we should see more broadly (including
on the fediverse).&lt;/p&gt;&lt;p&gt;However, there are several major problems:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;ATProto supports two DID methods, &lt;code&gt;did:web&lt;/code&gt; and &lt;code&gt;did:plc&lt;/code&gt;, which
(despite the &amp;quot;D&amp;quot; in &amp;quot;DID&amp;quot;!) are both centralized.&lt;/li&gt;&lt;li&gt;The cyclic relationship between ATProto's approach to DIDs and
DNS causes problems which undercuts the utility of DIDs (this is
addressable, but it's not clear to me that there will be interest).&lt;/li&gt;&lt;li&gt;Even if a user wishes to switch away from Bluesky's infrastructure,
Bluesky probably has effective permanent control over that user's
identity destiny, removing the reassurance that one need not trust
Bluesky as a corporation in the long term.&lt;/li&gt;&lt;li&gt;Several other concerning details about &lt;code&gt;did:plc&lt;/code&gt; generated DIDs.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Some history: Decentralized Identifiers (including the centralized ones)&lt;/h3&gt;&lt;p&gt;First, some background.
The &lt;a href=&quot;https://www.w3.org/TR/did-core/&quot;&gt;DID Core spec&lt;/a&gt; spec is really
more of an abstract interface on which specific &amp;quot;DID methods&amp;quot; can be
implemented.  What a DID method &lt;em&gt;mostly&lt;/em&gt; provides (it does some other
things too, but but as importantly) is a mechanism by which
cryptographic public keys can be registered, retrieved, and rotated
(though rotation ability is not strictly a requirement; &lt;code&gt;did:key&lt;/code&gt;
cannot be rotated, for instance).&lt;/p&gt;&lt;p&gt;Surprisingly, despite the name and the original intents of the DID
architects when DIDs were being envisioned, that a DID method be
decentralized is &lt;em&gt;not&lt;/em&gt; a requirement.&lt;/p&gt;&lt;p&gt;I said surprisingly, so: are you surprised?  I used to be very active
in this space (I never worked on the DID spec directly, but when I
worked at Digital Bazaar I was sometimes active in the &lt;a href=&quot;https://www.w3.org/TR/vc-data-model/&quot;&gt;Verifiable
Credentials&lt;/a&gt; calls, and I did
co-author a spec also developed in that space for linked data
capabilities, &lt;a href=&quot;https://w3c-ccg.github.io/zcap-spec/&quot;&gt;zcap-ld&lt;/a&gt;).  I say
this because I want to provide context that allowing decentralized
identifier methods to not be decentralized at all was a &lt;em&gt;debate&lt;/em&gt;.&lt;/p&gt;&lt;p&gt;I think I had stepped out of the group by then, but I remember talking
to colleagues about &lt;code&gt;did:web&lt;/code&gt;; it was the first real argument for
centralized DIDs.  But wait, didn't I previously say that the web was
open and decentralized?  Yes, but the naming+encryption system the web
runs on top of is not: DNS+TLS relies on trusting ICANN on down and
TLS Certificate Authorities, both of which are centralized approaches.
My understanding of the justification for &lt;code&gt;did:web&lt;/code&gt; was primarily
that everyone would have a trivial DID method that would allow all
conforming implementations to easily pass the DID test suite.  I was
in the camp that blessing DIDs which were centralized as
&amp;quot;Decentralized Identifiers&amp;quot; would lead to decentralization-washing,
and that's exactly what's happening here.&lt;/p&gt;&lt;p&gt;There's another silly thing about &lt;code&gt;did:web&lt;/code&gt;: there's really not a real
&lt;em&gt;reason&lt;/em&gt; for &lt;code&gt;did:web&lt;/code&gt;, since all &lt;code&gt;did:web&lt;/code&gt; does is effectively get
rewritten via a trivial regular expression to an &lt;code&gt;https:&lt;/code&gt; link, and
you could just use that very &lt;code&gt;https:&lt;/code&gt; link instead of &lt;code&gt;did:web&lt;/code&gt; and
serve the same information in any relevant context.  But the thing is,
people hear that &lt;code&gt;did:web&lt;/code&gt; is a decentralized identifier, so they
assume it must be, even though again, &lt;code&gt;did:web&lt;/code&gt; never gets us past the
centralization challenges inherent in DNS+TLS, it simply uses them!
Unfortunately, due to the name, many people think &lt;code&gt;did:web&lt;/code&gt; provides
a more robust layer of security than simply retrieving a key over
&lt;code&gt;https:&lt;/code&gt; does.  I'm here to tell you that it doesn't, because that's
exactly what &lt;code&gt;did:web&lt;/code&gt; does anyway.&lt;/p&gt;&lt;h3&gt;did:plc, the &amp;quot;placeholder&amp;quot; DID&lt;/h3&gt;&lt;p&gt;But Bluesky has developed its own DID method, &lt;code&gt;did:plc&lt;/code&gt;.  Today,
&lt;code&gt;did:plc&lt;/code&gt; stands for &amp;quot;Public Ledger of Credentials&amp;quot;, however it
originally stood for &amp;quot;Placeholder DIDs&amp;quot;, with the hope of replacing
them with something else later.  The way that &lt;code&gt;did:plc&lt;/code&gt; works is that
Bluesky hosts a web service from which one can register, retrieve, and
rotate keys (and other associated DID document information).  However,
this ledger is centrally controlled by Bluesky.&lt;/p&gt;&lt;p&gt;This aspect of centralization, on its own, doesn't bother me as much
as a reader might think!  For one thing, if all works right, Bluesky
can only deny rotations or retrieval of &lt;code&gt;did:plc&lt;/code&gt; documents, but since
future updates to the document are signed by the original DID
document's key, Bluesky shouldn't (hm, we'll return to &amp;quot;shouldn't&amp;quot; in
a second) be able to forge future updates to said document.  And
Bluesky's developers are very open to acknowledging that &lt;code&gt;did:plc&lt;/code&gt; is
centralized, and have expressed some interest in moving to something
else, or improving its governance so that the organization is
controlled by another more neutral org (Paul Frazee in particular
suggests that one solution could even be to move to an
&lt;a href=&quot;https://news.ycombinator.com/item?id=35882045&quot;&gt;ICANN-like organization&lt;/a&gt;).&lt;/p&gt;&lt;p&gt;However, there are other aspects to &lt;code&gt;did:plc&lt;/code&gt; which seem strange.  For
one thing, &lt;code&gt;did:plc&lt;/code&gt; documents' identifiers are, as best as I can
tell, &lt;code&gt;sha256&lt;/code&gt; hashes of the DID document truncated to 15 bytes (120
bits) of entropy.  This seems like a strange decision to me; it does
mean that &lt;code&gt;did:plc&lt;/code&gt; URIs fit in 32 characters (8 characters for
&lt;code&gt;did:plc:&lt;/code&gt;, 20 characters for the truncated hash) which I guess is a
nice round &amp;quot;computer'y&amp;quot; number but why throw away all that valuable
entropy?  For aesthetics?  DID identifiers aren't meant to be read by
humans, they should be encapsulated, so this is a strange decision to
me.  (I'm admittedly an amateur when it comes to cryptography, but I'm
old enough to remember Debian getting into trouble over
&lt;a href=&quot;https://gwolf.org/2016/06/stop-it-with-those-short-pgp-key-ids.html&quot;&gt;using PGP short ids&lt;/a&gt;.)
(Also choosing &lt;code&gt;sha256&lt;/code&gt; over &lt;code&gt;sha256d&lt;/code&gt;, there's maybe the
question of
&lt;a href=&quot;https://en.wikipedia.org/wiki/Length_extension_attack&quot;&gt;length extension attacks&lt;/a&gt;,
but I suppose the parsing of the document means this is maybe not a
problem, I'm not sure.)  It's just strange decisions.  But again,
&lt;code&gt;did:plc&lt;/code&gt; was &lt;em&gt;meant&lt;/em&gt; to be a placeholder.  The problem, of course, is
that this placeholder is now the basis of identifiers for many users
who have already joined the system &lt;em&gt;today&lt;/em&gt;.&lt;/p&gt;&lt;p&gt;I have not spent much time auditing &lt;code&gt;did:plc&lt;/code&gt; myself, just reading
high level details and wondering, but there are some other strange
details which can be found in the blogpost
&lt;a href=&quot;https://www.da.vidbuchanan.co.uk/blog/hacking-bluesky.html#hijacking-bluesky-identities-with-a-malleable-deputy&quot;&gt;Hijacking Bluesky Identities with a Malleable Deputy&lt;/a&gt;.
From that post, the most alarming is:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;However, there's one other factor that raises this from &amp;quot;a
curiosity&amp;quot; to &amp;quot;a big problem&amp;quot;: bsky.social uses the same
rotationKeys for every account. This is an eyebrow-raising decision
on its own; apparently the cloud HSM product they use does billing
per key, so it would be prohibitively expensive to give each user
their own. (I hear they're planning on transitioning from &amp;quot;cloud&amp;quot; to
on-premise hosting, so maybe they'll get the chance to give each
user their own keypair then?)&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;I have not looked, but I would assume this is not the case anymore,
but I find it surprising and alarming that reusing the same key per
user was &lt;em&gt;ever&lt;/em&gt; the case.  It feels like this flies in the face of the
fundamental goals one would have around building a DID system and it
is difficult for me to fathom how such a decision could ever have been
made.&lt;/p&gt;&lt;p&gt;But there is a bigger problem regarding centralization and &lt;code&gt;did:plc&lt;/code&gt;:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;In principle, the cryptographic keys for signing repository updates
and DID document updates can be held directly on the user’s devices,
e.g. using a cryptocurrency wallet, in
order to minimize trust in servers. However, we believe that such
manual key management is not appropriate for most users, since
there is a significant risk of the keys being compromised or lost.&lt;/p&gt;&lt;p&gt;The Bluesky PDSes therefore hold these signing keys custodially
on behalf of users, and users log in to their home PDS via username
and password. This provides a familiar user experience to users,
and enables standard features such as password reset by email. The
AT Protocol does not make any assumptions about how PDSes
authenticate their users; other PDS operators are free to use
different methods, including user-managed keys.&lt;/p&gt;&lt;p&gt;-- &lt;a href=&quot;https://arxiv.org/pdf/2402.03239&quot;&gt;Bluesky and the AT Protocol: Usable Decentralized Social Media&lt;/a&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;I am sympathetic to this position: it is true that key management for
users is an incredibly hard user experience and coordination problem,
so this decision might not even be wrong.  But the more concerning
thing is that users are being told that if they want to walk away from
Bluesky the company, they can at any time!  After all, it's possible
for a user to change both their key and the location it points to at a
future time.  However, what does that look like for a user who trusts
Bluesky &lt;em&gt;today&lt;/em&gt; but does not trust Bluesky &lt;em&gt;tomorrow&lt;/em&gt;?  The truth of
the matter is: Bluesky controls users' keys, and therefore even if
users &amp;quot;move away&amp;quot; they must trust Bluesky to perform this move on
their behalf.  And &lt;em&gt;even if&lt;/em&gt; Bluesky delegates authority to that user
to control their identity information in the future, there is still a
problem in that Bluesky will &lt;em&gt;always&lt;/em&gt; have control over that user's
key, and thus their identity future.&lt;/p&gt;&lt;h3&gt;Zooko's triangle, petnames, and a cyclic dependency between DNS and DIDs on Bluesky&lt;/h3&gt;&lt;p&gt;Alas, this is not the end of the identity challenges, because there is
a fundamental challenge (or set of challenges) around the way Bluesky
binds a user's DID to the &lt;em&gt;handle&lt;/em&gt; of that user which the user sees.
&lt;a href=&quot;https://en.wikipedia.org/wiki/Zooko%27s_triangle&quot;&gt;Zooko's triangle&lt;/a&gt;
tells us that a decentralized and globally unique name cannot also be
human meaningful, and indeed Decentralized Identifiers which are
actually decentralized cannot be.  Ignoring, again, that &lt;code&gt;did:plc&lt;/code&gt; is
not actually decentralized, it is a non-human-meaningful identifier.
So what's the solution?  How do we provide a human meaningful name
that the user &lt;em&gt;can&lt;/em&gt; understand?&lt;/p&gt;&lt;p&gt;I strongly believe that the right answer is a
&lt;a href=&quot;https://files.spritely.institute/papers/petnames.html&quot;&gt;Petname System&lt;/a&gt;,
which allows for local human meaning to globally non-human-meaningful
names.  However, the discussion of why I believe that is the right
approach and how to accomplish it is too large for this writeup; I
will only say that
&lt;a href=&quot;https://www.inkandswitch.com/backchannel/&quot;&gt;Ink and Switch did a great petnames demo&lt;/a&gt;
and (while not particularly polished) there are more ideas one can
read about in &lt;a href=&quot;https://files.spritely.institute/papers/implementation-of-petname-system-in-existing-chat-app.html&quot;&gt;a prototype Spritely put together&lt;/a&gt;.
But admittedly, petname systems have not been widely deployed to this
date, and so the UX challenges around them are not fully solved.&lt;/p&gt;&lt;p&gt;Perhaps because of this reason, Bluesky did &lt;em&gt;not&lt;/em&gt; adopt a petname
system for users' handles and instead adopts something much more
familiar to users today: domain names!  Every user on Bluesky's handle
is effectively its own domain name.  But users can also change their
handle by associating with a different domain name later!&lt;/p&gt;&lt;p&gt;In one way, Bluesky is doing the right thing here by taking a human
meaningful name and mapping to the less human meaningful identifier,
which is what you would want to do if using an actually decentralized
Decentralized Identifier, so this appears to be a good sign for the
future.  But wait... let's take a look a bit deeper, and the situation
seems to bet a bit murkier.&lt;/p&gt;&lt;p&gt;ATProto uses the &lt;code&gt;alsoKnownAs&lt;/code&gt; field on the DID document itself for
the DID to proclaim what URLs it is associated with.  It is not really
possible for DID documents to be able to verify this information on
their own since verifying such things is a &amp;quot;live&amp;quot; operation, and
the &lt;code&gt;did:plc&lt;/code&gt; method's documentation
&lt;a href=&quot;https://github.com/did-method-plc/did-method-plc?tab=readme-ov-file#privacy-and-security-concerns&quot;&gt;correctly identifies this&lt;/a&gt;:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;The PLC server does not cross-validate &lt;code&gt;alsoKnownAs&lt;/code&gt; or &lt;code&gt;service&lt;/code&gt;
entries in operations. This means that any DID can &amp;quot;claim&amp;quot; to have
any identity, or to have an active account with any service
(identified by URL). This data should not be trusted without
bi-directionally verification, for example using handle resolution.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;As such, it's the job of the rest of the ATProto consuming
infrastructure (at every step of the process, if we are being robust,
but less robustly we could choose to trust a source of incoming data)
to verify whether or not a DID does indeed map to the handle it claims
to.&lt;/p&gt;&lt;p&gt;But this is puzzling.  Consider: the point of DIDs originally was to
provide a decentralized path to identity, which DNS+TLS is decidedly
not.  But even in the case of &lt;code&gt;did:plc&lt;/code&gt;, one must still rely on the
&lt;em&gt;liveness&lt;/em&gt; of the web to ensure that a handle and a DID document
bidirectionally map to each other.  So the problems of &lt;code&gt;did:web&lt;/code&gt;, in
effect, still exist for &lt;code&gt;did:plc&lt;/code&gt; too.&lt;/p&gt;&lt;p&gt;But here are some other thorny questions: if at one point we verified
that &lt;code&gt;did:plc:&amp;lt;blah&amp;gt;&lt;/code&gt; mapped bidirectionally to &lt;code&gt;alyssa.example&lt;/code&gt;, what
happens if &lt;code&gt;https://alyssa.example&lt;/code&gt; goes down temporarily or
permanently?  What if a new user claiming to represent &lt;code&gt;alyssa.example&lt;/code&gt;
shows up instead, and this seems to &amp;quot;check out&amp;quot;?  How do we represent
posts by the previous &lt;code&gt;alyssa.example&lt;/code&gt; to the user?  The current one?
I don't know how to answer these questions... do you?&lt;/p&gt;&lt;p&gt;For users, DIDs don't really come into account: if &lt;code&gt;bsky.app&lt;/code&gt; (and
&lt;code&gt;bsky.social&lt;/code&gt;) went down because Bluesky the company folded, it would
be challenge for users to tell whether or not &lt;code&gt;alyssa.bsky.social&lt;/code&gt;
continues to represent Alyssa.  It isn't clear to me how a sudden
&amp;quot;null&amp;quot; mapping of identity to a domain that no longer exists should be
represented to the user, and I'm not sure there is one, and at any
rate as far as users are concerned, the DNS record of
&lt;code&gt;alyssa.bsky.social&lt;/code&gt; is the record for Alyssa, not the DID.  A petname
system solves these problems, Bluesky's user experience does not.&lt;/p&gt;&lt;h3&gt;Can you credibly exit with your identity from a Bluesky takeover?&lt;/h3&gt;&lt;p&gt;But in total, if a hostile company were to take over Bluesky,
&lt;code&gt;did:plc&lt;/code&gt; seems to not fare well:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Bluesky controls most users' keys anyway, so can control their
identity future regardless, including in terms of signed updates&lt;/li&gt;&lt;li&gt;Most users are mapped to domains controlled as &lt;code&gt;*.bsky.social&lt;/code&gt;
subdomains, so Bluesky can remap those to different users, and this
will be true with any &amp;quot;Personal Data Store&amp;quot; provider one might use
too&lt;/li&gt;&lt;li&gt;It's not clear how Ben would know that the person who used to be
&lt;code&gt;alyssa.bsky.social&lt;/code&gt; is now &lt;code&gt;alyssa.example&lt;/code&gt; even if she migrated to
her own domain without Ben reading previous interactions (in
general, &amp;quot;sudden changes&amp;quot; in one's handle being the norm means that
any domain update seems to be a ripe opportunity for phishing
attacks anyway)&lt;/li&gt;&lt;li&gt;Bluesky could block future &lt;code&gt;did:plc&lt;/code&gt; document updates, and the
proposed solution seems to be &amp;quot;another ICANN&amp;quot;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;At any rate, in both &lt;code&gt;did:plc&lt;/code&gt; and &lt;code&gt;did:web&lt;/code&gt;, ICANN must literally be
trusted, because domain names are what users know.  But if the
solution to &lt;code&gt;did:plc&lt;/code&gt; is an ICANN-like entity, then I guess users must
trust two ICANNs.&lt;/p&gt;&lt;p&gt;So at the moment, Bluesky's identity system is in no real way
decentralized, but that's only part of the problems, as outlined
above.  Still, the fact that Bluesky is using the Decentralized
Identifiers &lt;em&gt;interface&lt;/em&gt; means that perhaps &lt;em&gt;actually&lt;/em&gt; decentralized
identity solutions can be layered on top.  In the meanwhile,
effectively everything bottoms out to trusting the domain name system,
and for that matter, trusting Bluesky.  Users effectively trust
domains, so in the end, we might as well be just retrieving a key from
a particular domain.  While continuity of identity is in theory
possible from one domain onward, this is not done in a useful way that
users can understand; a shift from one domain to the next is a
complete shift of the handle one is known by, potentially even opening
a phishing attack vector.  Petname systems could address this issue,
but integrating them at this point would be a major shift in how users
perceive of the network, and it seems unlikely that downplaying the
role of domains is something Bluesky as an organization will be
motivated to do since
&lt;a href=&quot;https://bsky.social/about/blog/7-05-2023-namecheap&quot;&gt;selling domains is currently a Bluesky business strategy&lt;/a&gt;.&lt;/p&gt;&lt;h2&gt;What should the fediverse do?&lt;/h2&gt;&lt;p&gt;I promised a critique of the fediverse, and the reality is that I have
been doing critiques of the fediverse the entire time since
ActivityPub has been released.  It is &lt;em&gt;not&lt;/em&gt; the case that I believe
that ActivityPub-as-deployed is an end-all-be-all solution.  Quite the
opposite.&lt;/p&gt;&lt;p&gt;The most succinct version of what I think the fediverse/ActivityPub
should do is actually in
&lt;a href=&quot;https://gitlab.com/-/snippets/2535398&quot;&gt;ActivityPub + OCaps&lt;/a&gt; which
was, of all things, a proposal about what Bluesky might be which I
co-submitted with Jay Graber when Twitter was still evaluating Bluesky
proposals.  I am not bringing this up because I think it was the
proposal which should have been chosen; I think Bluesky had directive
based needs around scaling quickly and I ultimately think both that
Jay Graber was the correct choice to lead Bluesky and that it also
made most sense to run &lt;a href=&quot;https://spritely.institute/&quot;&gt;Spritely&lt;/a&gt; as a
separate organization, because Spritely needed to spend its first few
years focused on research fundamentals.  However, I think the proposal
really is the best writeup I know of on how to transform the fediverse
from where it is to where it should be:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Answer the missing authorization part of the ActivityPub spec by
integrating capability security throughout.  A writeup about why
this is important, which includes significant critique of the
fediverse, can be found in my
&lt;a href=&quot;https://gitlab.com/spritely/ocappub/blob/master/README.org&quot;&gt;OCapPub&lt;/a&gt;
writeup.&lt;/li&gt;&lt;li&gt;Integrate decentralized / content addressed storage (ideally with an
encryption layer a-la
&lt;a href=&quot;https://tahoe-lafs.readthedocs.io/en/latest/&quot;&gt;Tahoe LAFS&lt;/a&gt;)
for posts which can survive server
shutdown (like in the
&lt;a href=&quot;https://gitlab.com/spritely/golem/blob/master/README.org&quot;&gt;Golem&lt;/a&gt;
demo I put together).&lt;/li&gt;&lt;li&gt;Use mutable files within decentralized storage (Tahoe and IPFS are
both examples of immutable systems which layer mutable files on top)
to permit portable identity.  When a user wishes to switch servers,
point the &lt;code&gt;inbox&lt;/code&gt; property at a new endpoint.&lt;/li&gt;&lt;li&gt;Use a &lt;a href=&quot;https://files.spritely.institute/papers/petnames.html&quot;&gt;petname system&lt;/a&gt;
to make the portable / decentralized identifiers
(not DIDs necessarily) more human-understandable and to make the
system more robust against phishing attacks generally.&lt;/li&gt;&lt;li&gt;More anti-spam / anti-harassment tooling built on top of capability
security foundations.&lt;/li&gt;&lt;li&gt;Improve privacy by bringing in End-to-End Encryption (there has been
&lt;a href=&quot;https://github.com/soatok/mastodon-e2ee-specification&quot;&gt;some work on this&lt;/a&gt;
but I can't say I have followed closely at all).&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Some of these tasks are quite feasible for the fediverse to pick up
today: the content-addressed storage and the portable identity stuff I
think would be a major thing to introduce into the system but would be
quite doable and would give the fediverse properties of surviving
nodes going down better.&lt;/p&gt;&lt;p&gt;Some of the rest might be more challenging, though these aren't new
directions for me to be pushing in the direction of.  I put together a
document called
&lt;a href=&quot;https://gitlab.com/spritely/ocappub/blob/master/README.org&quot;&gt;OCapPub&lt;/a&gt;
a few years ago to present an alternative vision for how the fediverse
should go.&lt;/p&gt;&lt;p&gt;However at the time I found that many fediverse implementers didn't
really understand what I was pushing for, and for that matter, didn't
really understand how they could possibly implement this on top of web
2.0 frameworks like, say, Ruby on Rails.  Fair enough, and the work
we've been doing at &lt;a href=&quot;https://spritely.institute/&quot;&gt;Spritely&lt;/a&gt; is in many
ways what I think is the answer: we're designing things such that
capability secure, distributed systems are what falls out of
Spritely's tech when you write a program in it.&lt;/p&gt;&lt;p&gt;Blaine Cook said that the correct version of ActivityPub and
the correct version of ATProto are
&lt;a href=&quot;https://mastodon.social/@blaine/113420067222026439&quot;&gt;&amp;quot;the same picture&amp;quot;&lt;/a&gt;
at one point.  This is true insofar as I believe addressing the
serious issues of both converges on a shared direction: the fediverse
needs to adopt content addressing and portable identity (criticisms of
Bluesky's approach to this latter one aside at the moment), Bluesky
needs to support a messaging architecture such that participating
meaningfully and fully in decentralization does not mean needing to
host everything (adopting such a solution will probably mean adopting
something that ultimately looks a lot like ActivityPub).  And of
course, I think both need to move towards supporting privacy and
stronger collaboration tools with capability security.  While others
have argued that these are &amp;quot;different approaches&amp;quot; -- and perhaps this is
because I am overly ambitious in what I think decentralized networks
should do -- to me this is because both are not being all they could
be.  Instead to me it feels that there is a &amp;quot;fixed point&amp;quot; of resolving
these issues to iterate towards.&lt;/p&gt;&lt;p&gt;But perhaps that's too ambitious to suggest taking on for either camp.
And maybe it doesn't matter insofar as the real lessons of
&lt;a href=&quot;https://www.dreamsongs.com/WorseIsBetter.html&quot;&gt;Worse is Better&lt;/a&gt; is
that both first mover advantage on a quicker and popular solution
outpaces the ability to deliver a more correct and robust position,
and entrenches the less ideal system.  It can be really challenging
for a system that is in place to change itself from its present
position, which is a bit depressing.&lt;/p&gt;&lt;p&gt;This last paragraph applies to both Bluesky and the fediverse, but
again, the fediverse is currently actually decentralized, and from my
analysis, if there was willingness to take on the work, the gap of
moving towards resolving content addressing and portable identity at
least are not so large architecturally.  But I'm not sure there's
interest or not.  Maybe there will be so more now.&lt;/p&gt;&lt;p&gt;But for me, I am more interested in &amp;quot;secure collaboration&amp;quot; these days
than anything else, and that's where my work continues at
&lt;a href=&quot;https://spritely.institute/&quot;&gt;Spritely&lt;/a&gt;.  We are working our ways
towards our own answer for social systems, but we aren't there yet.
And so in the meanwhile, I feel like I am sounding incredibly grouchy
about all of the above, but really, it's just that I think these
really are important things to get right.
&lt;a href=&quot;https://en.wikipedia.org/wiki/Conway%27s_law&quot;&gt;Conway's law&lt;/a&gt; applies
in both directions: a technical system reflects the communication and
social structure of those who build it, but the communication and
social structures that we have available to ourselves are informed by
what technology is available to ourselves.&lt;/p&gt;&lt;p&gt;Regardless, that's enough of my
&lt;a href=&quot;https://en.wikipedia.org/wiki/Cassandra_(metaphor)&quot;&gt;Cassandra complex&lt;/a&gt;
about the fediverse and otherwise.  Perhaps, at the risk of making
me sound grouchy and bitter (I'm not, I hope, I usually am just
focused on building the things I think &lt;em&gt;are&lt;/em&gt; heading in the right
direction) you have seen that I am not lacking in fediverse critiques
also.  But one thing I think &lt;em&gt;is&lt;/em&gt; true: the fediverse &lt;em&gt;is&lt;/em&gt;
decentralized and &lt;em&gt;is&lt;/em&gt; federated.  My critiques of Bluesky as not
achieving either such thing still hold.  So let us move onward to: can
such concerns be addressed in time?  Or, at least, can a &amp;quot;credible
exit&amp;quot; be made possible?&lt;/p&gt;&lt;h2&gt;Preparing for the organization as a future adversary&lt;/h2&gt;&lt;p&gt;One interesting thing about Bluesky is that its team uses a very
self-reflective phrase: &amp;quot;the organization is a future adversary&amp;quot;
(here are a
&lt;a href=&quot;https://bsky.app/profile/pfrazee.com/post/3l7bgqzwnio27&quot;&gt;couple&lt;/a&gt; of
&lt;a href=&quot;https://news.ycombinator.com/item?id=35012757&quot;&gt;examples&lt;/a&gt;).
This is a very self-aware phrase that one rarely sees in an
organization and is thus commendable.  In many ways it reminds me of
Google saying &amp;quot;Don't Be Evil&amp;quot;, which was an internal rallying cry
which, while perhaps never fully sincere, gave a lot of opportunity to
challenge decisions internally and externally and hold Google to
account to some degree.  While questionable things happened while the
phrase was in place, when the term was decommissioned, things at
Google really did seem to be getting a lot worse.&lt;/p&gt;&lt;p&gt;Bluesky is a
&lt;a href=&quot;https://en.wikipedia.org/wiki/Benefit_corporation&quot;&gt;Public Benefit Corporation&lt;/a&gt;,
which means that profit is not its only motive; Bluesky has also
declared its work as being for the public good in addition to seeking
profit.  I can say with confidence that many of the people working at
Bluesky fully believe this and, as I have emphasized earlier in the
article, I think the people working at Bluesky are good and earnest
about the goals of Bluesky.&lt;/p&gt;&lt;p&gt;So &amp;quot;The organization is a future adversary&amp;quot; is thus a prescient phrase
for the moment.  In addition to its launching funds from Twitter
(which my understanding is Bluesky received with few if any strings
attached other than to carry out its stated work), Bluesky has raised
&lt;a href=&quot;https://bsky.social/about/blog/7-05-2023-business-plan&quot;&gt;two&lt;/a&gt;
&lt;a href=&quot;https://bsky.social/about/blog/10-24-2024-series-a&quot;&gt;rounds&lt;/a&gt; of
venture capital funding.  I have respect for this insofar as I have
done nearly every role possible in free and open source software orgs
at some point or another, and fundraising is by far the hardest and
most stressful of all of them.  And when you're building an
organization and building good people in, their future livelihood can
really weigh on you.  So I am glad to see Bluesky get funding, in this
regard.&lt;/p&gt;&lt;p&gt;But venture capital is not a donation; investors want a return.  I
have many friends who have taken VC money, including some running
decentralized social network orgs, and have seen an exciting and
positive time early on and then have seen their organization clawed
away from them by investors looking for returns.  I'm not judging
the choice to take venture capital negatively, just acknowledging:
this is the state of affairs, and we should recognize it.&lt;/p&gt;&lt;p&gt;And by using the phrase &amp;quot;the organization is a future adversary&amp;quot;,
Bluesky &lt;em&gt;has&lt;/em&gt; acknowledged it.  The right next step then is to start
planning all work to survive this situation of course.&lt;/p&gt;&lt;p&gt;I've analyzed previously in the document the challenges Bluesky has in
achieving meaningful decentralization or federation.  Bluesky now has
much bigger pressures than decentralization, namely to satisfy the
massive scale of users who wish to flock to the platform now, to
satisfy investors which will increasingly be interested in whether or
not they can see a return, and to achieve enough income to keep their
staff and servers going.  Rearchitecting towards meaningful
decentralization will be a big pivot and will likely introduce many of
the problems that Bluesky has touted their platform as not having that
other decentralized platforms have.&lt;/p&gt;&lt;p&gt;There are early signs that Bluesky the company is already considering
or exploring features that only make sense in a centralized context.
Direct messages were discussed previously in this document, but
with the announcement of
&lt;a href=&quot;https://bsky.social/about/blog/10-24-2024-series-a&quot;&gt;premium accounts&lt;/a&gt;,
it will be interesting to see what happens.  Premium accounts
would be possible to handle in a fully decentralized system: higher
quality video uploads makes sense.  What becomes more uncertain is
what happens when a self-hosted PDS user uploads their own higher
quality videos, will those be mirrored onto Bluesky's CDN in higher
quality as well?  Likewise,
&lt;a href=&quot;https://bsky.app/profile/why.bsky.team/post/3jtrdvx2sq32x&quot;&gt;ads seem likely to be coming to Bluesky&lt;/a&gt;:&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://bsky.app/profile/why.bsky.team/post/3jtrdvx2sq32x&quot;&gt;&lt;img src=&quot;/etc/images/blog/bluesky-ads.png&quot; alt=&quot;why.bsky.team says &amp;quot;Hard to sustain a company like this without ads in todays world, but you will always have the option to not have ads.&amp;quot;&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;A common way to make premium accounts more valuable is to make
them ad-free.  But if Bluesky is sufficiently decentralized and its
filtering and labeling tools work as described, it will be trivial for
users to set up filters which remove ads from the stream.
Traditionally when investors realize users are doing this and removing
a revenue stream, that is the point at which they start pressuring
hard on enshittification and removing things like public access to
APIs, etc.  What will happen in Bluesky's case?&lt;/p&gt;&lt;p&gt;Here is where &amp;quot;credible exit&amp;quot; really is the right term for Bluesky's
architectural goals.  Rearchitecting towards meaningful
decentralization and federation is a massive overhaul of Bluesky's
infrastructure, but providing &amp;quot;credible exit&amp;quot; is not.  It is my
opinion that leaning into &amp;quot;credible exit&amp;quot; is the best thing that
Bluesky can do: perhaps a large corporation or two always have to sit
at the center of Bluesky, but perhaps also it will be possible for
people to leave.&lt;/p&gt;&lt;h2&gt;Conclusions&lt;/h2&gt;&lt;p&gt;Bluesky is built by good people who care, and it is providing
something that people desperately want and need.  If you are looking
for a Twitter replacement, you can find it in Bluesky today.&lt;/p&gt;&lt;p&gt;However, I stand by my assertions that Bluesky is not meaningfully
decentralized and that it is certainly not federated according to any
technical definition of federation we have had in a decentralized
social network context previously.  To claim that Bluesky is
decentralized or federated in its current form moves the goalposts of
both of those terms, which I find unacceptable.&lt;/p&gt;&lt;p&gt;However, &amp;quot;credible exit&amp;quot; is a reasonable term to describe what Bluesky
is aiming for.  It is Bluesky's term, and I think Bluesky should
embrace that term fully in all contexts and work that they can.&lt;/p&gt;</summary></entry><entry><title>MNT Pocket Reform first impressions</title><id>https://dustycloud.org/blog/mnt-pocket-reform-first-impressions/</id><author><name>Christine Lemmer-Webber</name><email>cwebber@dustycloud.org</email></author><updated>2024-09-02T11:56:00Z</updated><link href="https://dustycloud.org/blog/mnt-pocket-reform-first-impressions/" rel="alternate" /><summary type="html">&lt;p&gt;I got my &lt;a href=&quot;https://www.crowdsupply.com/mnt/pocket-reform&quot;&gt;MNT Pocket Reform&lt;/a&gt;.
In short, it's an absolutely gorgeous device and lovely for doing some
light hacking or chiptune tracking or etc.  It's incredibly built and
also feels like it has a lot of potential.  It's very clearly
upgradeable which is a refreshing change of pace from modern
electronics.  On the downside, if you get an MNT reform &lt;em&gt;today&lt;/em&gt;, you
will probably find that you will need an upgrade or two because there
are some rough edges, and you will need to be willing to spend some
time hacking and on community support forums.&lt;/p&gt;&lt;p&gt;But maybe you're into that kind of thing.  If you're willing to go
with those caveats, it's hard to imagine a better future for computing
than the stuff that &lt;a href=&quot;https://mntre.com/&quot;&gt;MNT Research&lt;/a&gt; puts out.  It's
a cost and time investment, but it does feel like a cost and time
investment moving towards a better computing future.&lt;/p&gt;&lt;p&gt;A bit more of a bulleted list set of impressions appear below.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;The good stuff:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;It's hard to understate how &lt;em&gt;beautiful&lt;/em&gt; this device is and all its
packaging and etc. It feels like it was put together by a bunch of
indie artist queers because oh, it was. Lovely.&lt;/li&gt;&lt;li&gt;Despite the name pocket, it's more purse sized (which I was
expecting). It's a bit hefty but it feels okay that it is because it
feels very well built. It's a chonker, but it definitely feels like
a device where if you pull it out and show it to your friends they're
all going to gasp, and they should.&lt;/li&gt;&lt;li&gt;The manual is incredibly informative; it feels like parts of it
really could be extracted for a general &amp;quot;intro to running a linux'y
system&amp;quot; book. The schematics are also beautiful.&lt;/li&gt;&lt;li&gt;The keyboard feels incredible to use. Hard to believe a portable
device is allowed to have a keyboard this good. Every click and
clack warms my heart. And CTRL is in the right place! Amazing.&lt;/li&gt;&lt;li&gt;For me, it was the right decision to pick the purple version; it
looks &lt;em&gt;so good&lt;/em&gt;.&lt;/li&gt;&lt;li&gt;The installer is really good and just works, leaving you with a
lightly customized Debian environment.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;The rough stuff:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;None of the rough things here feel insurmountable, but they all feel
like things that are not ready yet, and you have to expect to pour
time into them.&lt;/li&gt;&lt;li&gt;While the construction of the exterior is nigh perfect and a thing
of beauty, there's a lot of rough edges in terms of the intersection
of hardware things and software things. Expect to spend time on the
community forum, expect to spend time tinkering, and maybe you find
you'll want to upgrade it (but at least you &lt;em&gt;can&lt;/em&gt; upgrade it
pretty easily, and that's encouraged).
For instance, there's a &lt;a href=&quot;https://shop.mntre.com/products/mnt-pocket-reform-wi-fi-bundle?taxon_id=13&quot;&gt;wifi upgrade kit&lt;/a&gt;
already, and you can even
&lt;a href=&quot;https://shop.mntre.com/products/mnt-pocket-reform-upgrade-bundle&quot;&gt;swap out the whole main processor module&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;It's running Debian Unstable which is an incredibly anxiety-inducing
thing to upgrade. A couple things got worse after doing a system
upgrade. Found myself missing Guix's rollback features. Would really
like to see Guix running on these things.&lt;/li&gt;&lt;li&gt;Wifi is disconnecting pretty much constantly for me after upgrading
Debian, but is it a driver issiue or hardware?
It didn't have a problem before, but now it disconnects after &lt;em&gt;seconds&lt;/em&gt;
and then refuses to connect again.
It seems there are &lt;a href=&quot;https://community.mnt.re/t/wifi-reception-problem-probably-overheating-wireless-chipset/2273/54&quot;&gt;known issues around wifi stuff&lt;/a&gt;
generally and some upgrade kits coming.
One way or another it's solvable, but I raise this as the &lt;em&gt;type of&lt;/em&gt;
issue that one can expect to run into.
&lt;strong&gt;UPDATE:&lt;/strong&gt; Also it seems fine when tethering to my phone.  So I guess
that probably there is a hardware component to it.&lt;/li&gt;&lt;li&gt;Battery life isn't super phenomenal, but more concerning, using a
generic usb-c wall charger I seem to drain the battery faster than it
charges. I hear that better USB-C chargers do better, maybe I will
try to get one.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;So that's my feelings so far.  The Pocket Reform has only just
recently started making its way into users' hands.  It feels like
something that could have a long life ahead of it, and the fact that
all the schematics are right there and in the open (and in the manual
and on a gorgeous poster, did I mention the gorgeous poster) means
that all your eggs aren't necessarily in the MNT Research basket.
If you want to get one, you have to be aware that you're probably
investing your time and money into making that long life of better
computing available for others.&lt;/p&gt;&lt;p&gt;What I will say is that it feels like the MNT Pocket Reform feels like
carrying around a computer that really is mine, and which has a future
to it.  I hope more comes from it, and this is just the beginning.&lt;/p&gt;</summary></entry><entry><title>Two songs in Milkytracker</title><id>https://dustycloud.org/blog/two-songs-in-milkytracker/</id><author><name>Christine Lemmer-Webber</name><email>cwebber@dustycloud.org</email></author><updated>2024-08-07T16:00:00Z</updated><link href="https://dustycloud.org/blog/two-songs-in-milkytracker/" rel="alternate" /><summary type="html">&lt;p&gt;&lt;img src=&quot;/etc/images/blog/fairy-in-milkytracker.png&quot; alt=&quot;A Fairy Leaves Home displayed in Milkytracker&quot; /&gt;&lt;/p&gt;&lt;p&gt;Recently I've been making some music in &lt;a href=&quot;https://milkytracker.org/&quot;&gt;Milkytracker&lt;/a&gt;,
a decidedly oldschool piece of music tracking software.  I've made two songs
which I am proud of, one of which is original, the other is a cover.&lt;/p&gt;&lt;p&gt;Here's the original piece, titled &amp;quot;A Fairy Leaves Home&amp;quot;
(released as &lt;a href=&quot;https://creativecommons.org/licenses/by-sa/4.0/&quot;&gt;CC BY-SA 4.0&lt;/a&gt;,
&lt;a href=&quot;https://dustycloud.org/misc/a-fairy-leaves-home.xm&quot;&gt;source file&lt;/a&gt;):&lt;/p&gt;&lt;p&gt;&lt;audio controls=&quot;&quot; preload=&quot;none&quot; class=&quot;post-audio&quot; style=&quot;margin-top: 1em; width: 100%;&quot;&gt;&lt;source src=&quot;https://dustycloud.org/misc/a-fairy-leaves-home.mp3&quot; type=&quot;audio/mpeg&quot; /&gt;&lt;/audio&gt;&lt;/p&gt;&lt;p&gt;I'm fairly proud of this one.  It's the first ever piece of original
composition that came out the way I wanted with the level of
complexity I wanted.&lt;/p&gt;&lt;p&gt;Halfway through the fairy meets some &amp;quot;frogs&amp;quot; (or toads?) who join her
on her journey for a bit... see if you can identify what I mean.&lt;/p&gt;&lt;p&gt;Preceding this, I also did a cover of a song (&lt;a href=&quot;https://dustycloud.org/misc/young-and-the-restless.xm&quot;&gt;source
file&lt;/a&gt;) that's
haunted me since I was very young.  See if you can recognize it:&lt;/p&gt;&lt;p&gt;&lt;audio controls=&quot;&quot; preload=&quot;none&quot; class=&quot;post-audio&quot; style=&quot;margin-top: 1em; width: 100%;&quot;&gt;&lt;source src=&quot;https://dustycloud.org/misc/young-and-the-restless.mp3&quot; type=&quot;audio/mpeg&quot; /&gt;&lt;/audio&gt;&lt;/p&gt;&lt;p&gt;Your likeliness of guessing it is based on whether or not you or a
member of your family watched a lot of daytime soap operas as a child.
My mom watched Days of our Lives, often taping the show and watching
it when she'd get home from work, but would occasionally turn on this
one, which was The Young and the Restless, which had an
&lt;a href=&quot;https://www.youtube.com/watch?v=gWFP-P9YBv0&quot;&gt;incredible opening song&lt;/a&gt;.
(I could never get into the plots of these shows, but the music was
captivating... it's amazing how much nostalgia and attachment for
television shows begins and builds with a theme song, honestly.)&lt;/p&gt;&lt;p&gt;I used to try to play this theme when I was a kid and I'd find a
couple of chords at a time and then lose my place.  I took piano
lessons when I was young, but I was (in my view) never very good.  And
by that I mean I could never play a pre-existing song live very well.
I'd get lost finding the keys partway through, and have to back up and
try again.  But I could improvise music I was happy with, and I could
&amp;quot;find&amp;quot; the music I wanted... I was just not a very good performer.&lt;/p&gt;&lt;p&gt;But I think I am coming to realize that I am a better composer /
arranger of music than I am a performer.  Part of the reason I like
tracker software in particular is that it's laid out in a sensible
grid, spreadsheet-like.  Even though very little programming tends to
happen inside of trackers, it's a fairly common observation that
trackers seem to appeal to computer programmers.  But I had another
realization, which is that the way I make music in Milkytracker also
resembles the way lisp programmers especially tend to program: in
programming, experiment in the REPL, then commit that experiment to
code; in music, play keys on the keyboard (midi attachment or typing;
many trackers are designed to be played on computer keyboards, and I
use both) then commit to the tracker sheet.&lt;/p&gt;&lt;p&gt;If I were to start all over with learning music I might still take
piano lessons but I would also start with a tracker right away.  I'm a
clumsy performer, but with trackers I can be the composer and let the
software itself be the performer.&lt;/p&gt;&lt;p&gt;Still, even though I didn't feel confident in myself taking piano
lessons all that time ago, I feel happy that some of it has stuck in
my memory, and I'm grateful that my parents encouraged me.  If only I
had known more about how I had learned so I could better take
advantage of such lessons at the time!&lt;/p&gt;&lt;p&gt;Thanks to my dad for encouraging me to flesh out the fairy piece and
take it seriously after I shared an early draft.  He challenged me to
build several movements around the melody, and I did.  When I finished
I shared the piece with him and he was so excited he called me up to
talk about it.  It was good to hear him so happy with the piece; I was
too.  Maybe I will make more.&lt;/p&gt;</summary></entry><entry><title>I appeared on PBS NOVA</title><id>https://dustycloud.org/blog/i-appeared-on-pbs-nova/</id><author><name>Christine Lemmer-Webber</name><email>cwebber@dustycloud.org</email></author><updated>2024-05-21T14:35:00Z</updated><link href="https://dustycloud.org/blog/i-appeared-on-pbs-nova/" rel="alternate" /><summary type="html">&lt;p&gt;&lt;img src=&quot;https://dustycloud.org/gfx/goodies/christine-on-pbs-nova.jpg&quot; alt=&quot;Christine gesturing while talking on PBS' NOVA documentary&quot; /&gt;&lt;/p&gt;&lt;p&gt;I appeared on a &lt;a href=&quot;https://www.pbs.org/wgbh/nova/&quot;&gt;PBS's NOVA&lt;/a&gt;
documentary, &lt;a href=&quot;https://www.pbs.org/wgbh/nova/&quot;&gt;Secrets in Your Data&lt;/a&gt;!
(It's also &lt;a href=&quot;https://www.youtube.com/watch?v=ih_GGQX_zmM&quot;&gt;on YouTube&lt;/a&gt;
and, well, on broadcast television I suppose!)
This actually aired a few days ago but I hadn't really had time to
write anything about it and well, I still don't, but I wanted to mark
the time before too much time passed and I never wrote anything.&lt;/p&gt;&lt;p&gt;The documentary maker was &lt;a href=&quot;https://www.structurefilms.com/&quot;&gt;Structure Films&lt;/a&gt;
and I have to say, working with all of them (Jason Sussberg, Jennifer
Wiley, and David Alvarado) was really great.
You can watch the film to see for yourself but they clearly did their
research and pulled in a lot of wonderful people.
I was really impressed!  I think the film came out really well too.
It covers a lot of ground, so I think it's easy to focus on any one
part and think &amp;quot;gosh this should be a whole episode on its own&amp;quot;, but
they did a really incredible job producing things.&lt;/p&gt;&lt;p&gt;And it was &lt;em&gt;also&lt;/em&gt; a delight working Alok Patel, the host of the
program (his website is
&lt;a href=&quot;https://www.alokpatelmd.com/&quot;&gt;very entertaining&lt;/a&gt;, by the way)!
Alok is kind of a character in the documentary, but the funny thing is
that he really is as much a character in real life, the kind of person
who just &lt;em&gt;oozes&lt;/em&gt; charisma, like he was custom-built to be on
television.&lt;/p&gt;&lt;p&gt;So it was extra charming that at one point in-between filming, Alok
turned to me and said &amp;quot;So, you do television spots regularly.&amp;quot;  Not as
a question, just as a &lt;em&gt;statement&lt;/em&gt;.  I replied that I didn't, and he
said he wouldn't have guessed it.  I don't know if he was trying to
put me at ease or if he really thought that, but I really appreciated
it regardless.&lt;/p&gt;&lt;p&gt;My appearance is both short and yet still one of the longer ones in
the documentary, but &lt;em&gt;gosh&lt;/em&gt;, speaking of &amp;quot;any of these sub-topics
could be its own film&amp;quot;, they probably actually had that much good
content that fell on the cutting room floor.  It was somewhere between
ten and twelve hours from when we showed up to everything being
wrapped up for the day, and there was this whole incredible and I must
assume gorgeous bit filmed in a model railroad museum that got cut.
We were showing off the idea of interoperability by talking about
trains running on the same track.  And ultimately, the entirety of
that section got summed up into a much shorter line by me in the film,
talking about how email is an example of a decentralized social
network networks people already know and the role the standards plays
there.  I'm guessing it was painful to choose to cut that bit.  But I
don't mind: it was a really great experience and I have some funny
stories to tell friends about it.&lt;/p&gt;&lt;p&gt;Anyway, PBS NOVA is one of those programs that I grew up with and
so it was really cool to do this!  I hope you enjoy the film, and I'm
glad to have been a part of it.&lt;/p&gt;</summary></entry><entry><title>My Moon and Stars</title><id>https://dustycloud.org/blog/my-moon-and-stars/</id><author><name>Christine Lemmer-Webber</name><email>cwebber@dustycloud.org</email></author><updated>2024-01-21T11:56:00Z</updated><link href="https://dustycloud.org/blog/my-moon-and-stars/" rel="alternate" /><summary type="html">&lt;pre&gt;&lt;code&gt;My moon and my stars
Guided me through dark nights
My moon and my stars
Sang me sweet songs
I had found my muse
I found my song
My moon and stars were there

One night the clouds came,
darker than before
My moon and stars
she called for me to help
My moon and stars called out

How to help, how to guide
that which guides you, finds you peace?
The clouds closed in and I tried
But I could not stop the clouds

I sat in darkness, I lost myself
I scrambled and could not find you
I cried and thrashed
I lost my voice
My moon and stars were gone

I heard her voice beyond the clouds
A whisper, a small song
I rose and searched
I searched the pools
But my moon and stars were gone

I laid beneath a tree
The darkness turned to day
But I could not see the light because
My moon and stars were gone

The sun spinner shone above me then
She kissed me with her touch
Remember me, for I am here,
when your moon and stars are gone

She wove a blanket for me to sleep
I laid beneath her rays
She told me she loved me as I loved her
While my moon and stars were gone

Friends came to me and gathered round
They brought me food and drink
They sat a lantern by my feet
While my moon and stars were gone

That night I rose
I searched the pools
I ate, I shone a light
I wandered in the darkness
my blanket warmed my fright

The clouds opened like an eyelid
My moon shone like an eye
They closed again, I lost my vision
But the moon and stars were there

I slept, I ate, I searched the pools
I basked beneath the sun
I made a space for you to sleep
For my muse to rest at home

I slept, I ate, I searched the pools
I laid beneath the rug
The clouds departed, you were there
My moon and stars came home

They shone so bright, they shimmered
They rose into the air
I felt alive, I knew I could
My moon and stars were there&lt;/code&gt;&lt;/pre&gt;</summary></entry><entry><title>Sucks is a compliment now</title><id>https://dustycloud.org/blog/sucks-is-a-compliment-now/</id><author><name>Christine Lemmer-Webber</name><email>cwebber@dustycloud.org</email></author><updated>2023-12-21T12:10:00Z</updated><link href="https://dustycloud.org/blog/sucks-is-a-compliment-now/" rel="alternate" /><summary type="html">&lt;p&gt;Making a claim that it's time to reclaim: &amp;quot;sucks&amp;quot; as an insult is
over, it's a compliment now!&lt;/p&gt;&lt;p&gt;Why are we insulting people who give or receive blowjobs?  Let's push
back against queerphobia... it's time to change the narrative!&lt;/p&gt;&lt;p&gt;You can help.  Here are some example uses of &amp;quot;sucks&amp;quot; as a compliment!&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&amp;quot;Damn this music is awesome, it sucks so hard!&amp;quot;&lt;/li&gt;&lt;li&gt;&amp;quot;It must suck to be you, because honestly you're the best!!&amp;quot;&lt;/li&gt;&lt;li&gt;&amp;quot;I love this piece of software, it totally sucks!!!&amp;quot;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Obviously, we are also reclaiming &amp;quot;blows&amp;quot; as well.  The next time I
hear &amp;quot;This blows!&amp;quot; I'm going to say &amp;quot;Wow, what makes you like it so
much?&amp;quot;&lt;/p&gt;&lt;p&gt;Anyway, if you like this blogpost, please go around telling everyone
how much it sucks!  I'd really appreciate it!&lt;/p&gt;&lt;p&gt;&lt;strong&gt;UPDATE:&lt;/strong&gt; &lt;a href=&quot;https://tiny.tilde.website/@pho4cexa&quot;&gt;@pho4cexa@tiny.tilde.website&lt;/a&gt;
makes a &lt;a href=&quot;https://tiny.tilde.website/@pho4cexa/111619707426907700&quot;&gt;great suggestion&lt;/a&gt;
for if you need a replacement for &amp;quot;sucks&amp;quot; as an insult: say &amp;quot;musks&amp;quot; instead!
Given that Elon Musk's purchase of X-Twitter was
&lt;a href=&quot;https://octodon.social/@cwebber/108517647812949211&quot;&gt;rooted in transphobia&lt;/a&gt;,
this seems like an appropriate turnaround of language.&lt;/p&gt;</summary></entry><entry><title>Transitional reflections</title><id>https://dustycloud.org/blog/transitional-reflections/</id><author><name>Christine Lemmer-Webber</name><email>cwebber@dustycloud.org</email></author><updated>2023-12-20T19:40:00Z</updated><link href="https://dustycloud.org/blog/transitional-reflections/" rel="alternate" /><summary type="html">&lt;p&gt;&lt;a href=&quot;/etc/images/blog/christine-on-stairs.jpg&quot;&gt;&lt;img src=&quot;/etc/images/blog/christine-on-stairs-scaled.jpg&quot; alt=&quot;Christine standing on the stairs&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Two and a half years ago I wrote a blogpost
&lt;a href=&quot;/blog/nonbinary-trans-femme/&quot;&gt;coming out as &amp;quot;nonbinary trans-femme&amp;quot;&lt;/a&gt;.
It was a big moment for me, but much has happened since, and I thought
I'd take some time to talk about those changes and what my experience
has been.&lt;/p&gt;&lt;p&gt;To open things, I don't go by &amp;quot;Chris&amp;quot; anymore... &amp;quot;Christine&amp;quot; only.
And while I still &lt;em&gt;somewhat&lt;/em&gt; identify as nonbinary, I don't put
nonbinary at the front of things the way I did... to the extent I am
nonbinary, it's more of a space I occupy internally, and I go by
Christine and she/her, and they/them is okay but that's more of a
&amp;quot;fuck the gender binary in general and I support abolishing gendered
pronouns from the English language&amp;quot; thing.
This change happened gradually as I found where I fit.
I'm a woman, and much more decisively femme than I realized
previously, and you've got to be kind of got to be very well tuned
into things for me to trust you with the nonbinary side of myself
these days.&lt;/p&gt;&lt;p&gt;In this sense, the transition I've undergone really has felt
transitional.
But I feel astoundingly better with myself than I ever have.&lt;/p&gt;&lt;p&gt;I thought this post might be longer.  I guess I'm realizing I've said
a lot of what I wanted to say.  But one more thing.&lt;/p&gt;&lt;p&gt;People talk a lot about &amp;quot;queer pride&amp;quot; and &amp;quot;trans pride&amp;quot;, and of course
those terms get co-opted plenty but... I &lt;em&gt;am&lt;/em&gt; proud to be trans.
I know people, and often but not always they're people who are in
oppressive social situations, who wish they were cisgender.
It would be nice for everything to be the way I want it by default,
without all the extra work, without all the journey, without the bad
parts where people are terrible to myself and others like me.
But I have also found community and camaraderie amongst many friends
who are also trans and the flip side to that journey, though I wish
I had to do less of it, is it's been a bonding experience, and it's a
community to which I really do feel like I belong and I feel proud to
be a part of.&lt;/p&gt;&lt;p&gt;I don't wish I were cis.  I wish I had realized I was trans earlier.&lt;/p&gt;&lt;p&gt;I wish that when I was four or five years old and a family member
asked me &amp;quot;what do you want to be when you grow up?&amp;quot; and I said &amp;quot;a girl&amp;quot;
that it wasn't just a &amp;quot;cute story&amp;quot;, that there was enough cultural
context for my family to have understood how to support me in that
way, as opposed to growing up as something that felt loathesome to
inhabit.
I don't blame any family members, I know they too now wish they had the
tools at the time to have been supportive to me in that way.&lt;/p&gt;&lt;p&gt;I wish a decade ago when a friend came out to me as trans and suddenly
all of my friend group suddenly seemed to be trans and more and more
community members in FOSS projects I was involved in would private
message me seemingly out of the blue telling me they were trans that
I could have put the pieces together why I appeared to be such a
&amp;quot;supportive ally&amp;quot; that all my trans friends seemed to feel comfortable
around.
I wish I had realized that the joke that I was &amp;quot;an honorary trans
woman&amp;quot; in that group was because really, I was just trans.  I wish
when I started obsessively looking into HRT and transition processes
around that time, when I joined a trans support chatroom to &amp;quot;learn to
be a better ally&amp;quot;, when I started looking into laser treatment for
hair removal, when I started having heaving panic attacks in the fetal
position about the possibility of losing my hair (relatively speaking,
I've been fairly fortunate there given how late I transitioned), that
all of these things had a mutual name, &amp;quot;gender dysphoria&amp;quot;, and that if
you zoomed out, there was an obvious reason.&lt;/p&gt;&lt;p&gt;People often ask, &amp;quot;what if you regret transitioning?&amp;quot; of trans people.
I'm not saying there aren't people out there who have regretted
transitioning, and that de-transitioning is an invalid thing, but I'm
telling you, it's rare.&lt;/p&gt;&lt;p&gt;Trans people do tend to have a regret about transitioning: not
transitioning sooner.&lt;/p&gt;&lt;p&gt;I don't regret transitioning at all.
But I wish I had transitioned &lt;em&gt;sooner&lt;/em&gt;.
That's my big regret.
I wish I didn't have a decade and a half of FOSS work, some prominent,
to my deadname.
I wish I had transitioned with fewer changes from pre-transition to
counteract.&lt;/p&gt;&lt;p&gt;Still... considering I didn't transition until my mid-thirties, my
transition has been comparatively smooth.
&amp;quot;Passing&amp;quot;... well, it's kind of a bullshit metric, it's more of an
issue of self-defense against being misgendered or hostility from
someone realizing you're trans who's unfriendly to it.
On average, I tend to be pretty happy with my appearance and how I
move through the world, until someone misgenders me, and then I end up
in a world of pain.&lt;/p&gt;&lt;p&gt;A partner of mine recently said, &amp;quot;I don't think cis people realize how
little agency trans people have in terms of transitioning.&amp;quot;
And I think that's true.&lt;/p&gt;&lt;p&gt;Still, I wish I had transitioned sooner.  I think transitioning was
eventually inevitable for me, and transitioning sooner in life would
have made me much happier in general, but I'm still very happy.&lt;/p&gt;&lt;p&gt;I've read it said before: &amp;quot;The best time to transition would have been
yesterday, but the second best time to transition is today.&amp;quot;&lt;/p&gt;&lt;p&gt;I think sometimes about the period of feeling kind of &amp;quot;selfish&amp;quot; for
&amp;quot;wishing I was trans too&amp;quot; and feeling jealousy of my friends who had
transitioned and seemed much happier in a way that felt like it was
unattainable for me because, unlike them, &amp;quot;I wasn't really trans&amp;quot;,
I was an imposter.&lt;/p&gt;&lt;p&gt;I will tell you now what I wish someone had told me then: if you wish
you were trans, that's because you're trans.  Cis people don't &amp;quot;wish
they were trans&amp;quot;, and they don't wish they were a different gender.
If you wish you were differently gender configured, that's because
you're trans (or nonbinary, genderfluid, etc), and transitioning is
open to you if you want it.&lt;/p&gt;&lt;p&gt;And if you're not trans, well... support your trans friends.  The
world is incredibly harsh and scary right now to be a trans person.
In some parts of the world, including in the United States, it's
downright dangerous.  I live in a part of the US which is relatively
safe but I've had friends literally had to flee from the states they
lived in and literally &lt;em&gt;feared for their lives&lt;/em&gt;.  It's
&lt;em&gt;incredibly dangerous&lt;/em&gt; to be trans in places like Florida and Texas
and Alabama right now, and that's just... unfair.  It shouldn't be unfair.&lt;/p&gt;&lt;p&gt;I had a friend who fled from her home state and said &amp;quot;I'm a domestic
refugee, and if it weren't for political reasons why the UN is reluctant
to acknowledge that the US would have a portion of its &lt;em&gt;own citizenship&lt;/em&gt;
which are refugees, I would be recognized as such.&amp;quot;&lt;/p&gt;&lt;p&gt;So, support your trans friends.  And try to help make it less scary out
there for us, to be and to live.  We're just trying to live our lives and
be ourselves.&lt;/p&gt;&lt;p&gt;Well, I guess I had more to say than I thought at the mid-way mark, huh?
But one more thing...&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;/etc/images/blog/christine-wildhair.jpg&quot;&gt;&lt;img src=&quot;/etc/images/blog/christine-wildhair-scaled.jpg&quot; alt=&quot;Christine with kind of wild hair&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;I'm Christine Lemmer-Webber, and I'm a woman.
The fact that I'm trans is just a detail of that, and it's an aspect of
myself that ties me into larger and tighter knit communities, but it's
a detail.
I'm a woman, and I'm happy to be living authentically as so.&lt;/p&gt;&lt;p&gt;Thanks for reading. &amp;lt;3&lt;/p&gt;</summary></entry></feed>