Sign in

str👻d

@str4d.xyz
17K followers 474 following 3K posts

Cryptography, privacy, zero knowledge, Rust, Zcash dev, gaming, hardware hackery, art appreciation. He/him. str4d.xyz abyssdomain.expert/@str4d age18f63qx4gk8x7p4lfuwwglqcan7snvp406q5vmk26g9fmpe9c799qqzzr3w

PostsRepliesMedia
str👻d @str4d.xyz · 06/09/2026
My life right now:
The "epic handshake" meme: two people gripping each other in opposing bicep curls.

Left arm: Middle-aged women looking at my twins.
Right arm: Developers testing GLM-5.3-Flash.
Handshake: "Oh, they're such good weights!"
0154
str👻d @str4d.xyz · 21/08/2026
I got curious about what information `cargo install` stores. It does not record whether you used --locked, nor when you installed it (though that could be inferred from binary mtime). There's experimental sidecar-file SBOM support in nightly though.
Contents of the metadata file that `cargo install` uses to track installed binary crates. Some details about installation flags are recorded, as well as the rustc compiler used, but nothing about the dependencies.
010
str👻d @str4d.xyz · 07/08/2026
"We have DEFCON at home!" The DEFCON at home:
A baby playmat, nappy-changing station and rocking chair. On the wall behind them is a DEFCON flag.
180
str👻d @str4d.xyz · 06/08/2026
Excellent article, and very interesting to read. I find it amusing that this paragraph of Chatrie is "head-scratching" from a legal perspective, when to me (both as a regular user and a professional privacy engineer) this is a pretty straightforward way to map physical privacy onto digital privacy.
Chatrie’s rejection of this argument requires close attention. According to Justice Kagan, the key question was not whether creating particular records were necessary to participate in modern life. Rather, the question was whether the records were part of a category of conventional records associated with the communications tool itself. As Justice Kagan puts it, the records deemed exempt from the third party doctrine are ones that form part of “conventional cell-phone usage.” Chatrie’s explanation of the point is worth restating in full:

The Government’s app-by-app, feature-by-feature method of granting Fourth Amendment protection misapprehends the very nature of modern cell-phone use. Pretty much everything a person does on a smartphone requires some kind of opt-in—an “affirmative act” beyond “powering up” to utilize a given app or service. Consider sending an email on Gmail, uploading a photo to Google Photos, or adding a calendar entry to Google Calendar. None happens solely by dint of the phone’s operation; each requires, as Location History does, an “optional add-on.”. And each activity, like using Location History, results in sharing information with a third-party tech company—turning over private materials to live on that company’s servers. The Government wishes to disconnect all those uses from the mere act of carrying a turned-on cell phone (the thing that generates CSLI), with only the latter receiving assured Fourth Amendment protection. But that is to imagine that all of us are living in dumb flip-phone days. The point of carrying smartphones is to use what is on them—as Carpenter said, to use the apps and “services they provide.” That is what has become a “pervasive and insistent”—even “indispensable”—”part of daily life.” And so that is what Carpenter insulated from the third-party doctrine. A cell-phone user is not to be viewed as sharing private information with third parties—which then can be freely passed on to the government—just by doing the ordinary things cell-phone users do.

It’s important to unpack this passage, as it introduces a new concept into Fourth Amendment law that is likely to be at the center of a great deal of future litigation. According to this passage, there is a category of “ordinary things cell phone users do” that, across the board, is not to be deemed voluntarily disclosed to “third-party tech companies.” Our present society has a new thing—”modern-cell phone use,” not just from “dumb flip-phone[s],” but from smartphones that come with a “conventional” and “ordinary” set of services “on them.” “Activities” associated with those conventional services are, apparently en masse, “insulated from the third-party doctrine.”

This is head-scratching paragraph, and Section III will try to puzzle through what it might mean. But the key for now is that Chatrie creates a new constitutional category of “ordinary” or “conventional” uses of technology. The “ordinary” or “conventional” uses of common devices are treated with heightened Fourth Amendment protection, apparently making even factually knowing and voluntary disclosure of those uses to “third-party tech companies” not truly voluntary as a matter of law.
173
str👻d @str4d.xyz · 09/07/2026
That was fun! I've played similar games before but not that allowed using letters multiple times; that took a bit for my brain to route through.
Smush, 9 July 2026.
306 points, pangram first, no hints.
🟨🟩🟩
🥞⭐🥞
🟩🟩🥞
010
str👻d @str4d.xyz · 09/07/2026
The outcomes from this Rust rewrite that interest me: - Introduced 19 regressions, all now fixed. - Fixed 128 bugs that were present in the Zig version. - Cost $165,000 of API tokens, took 1 engineer 11 days. Not feasible for any open-source codebases, but *way* cheaper than 3 engineers for 1 year.
Pre-merge, this took 5.9 billion uncached input tokens, 690 million output tokens, and 72 billion cached input token reads — around $165,000 at API pricing. By hand, I think this would've taken 3 engineers with full context on the codebase about a year, during which time we wouldn't be able to improve Node.js compatibility, fix bugs, fix security issues or implement new features. We never would've done that. The realistic alternative was to do nothing and keep fixing the bugs at the top of this post forever.
2583
str👻d @str4d.xyz · 27/06/2026
I was *certain* the images in the quoted post were GIFs of an old CRT recording until I tapped them. @bsky.app you got a stylesheet bug somewhere, your gallery is vibing a bit too hard.
131
str👻d @str4d.xyz · 09/06/2026
Fun quirk: the app.bsky.embed.images Lexicon allows at most 4 images, so this post uses a new app.bsky.embed.gallery Lexicon without that restriction. The old app doesn't know about the new Lexicon, so it doesn't show any images. Would be nice to instead see "update your app to view this content".
Screenshot of the quoted post before updating the Bluesky app. The text is the same, but the carousel of images is missing, and there is no indication that any images were supposed to be present.
140
str👻d @str4d.xyz · 30/05/2026
Claude claims that its own system prompt has this instruction which it violated. Not sure if I believe that it knows or will report its own system prompt or if it's hallucinating it, but if true then the "ignoring text of skills" issue is worse than I thought: it's too over-confident.
For actions that are hard to reverse or outward-facing, confirm first unless durably authorized or explicitly told to proceed without asking… Before deleting or overwriting, look at the target — if what you find contradicts how it was described, or you didn't create it, surface that instead of proceeding.
110
str👻d @str4d.xyz · 23/05/2026
This is a perfectly normal way to configure permissions for a piece of software.
A permissions setting for Claude. It allows five different ways that Claude has previously asked to check the exit code of a process. They are all slight variations on the same `echo "exit=$?"` pattern. There is no way to guarantee that Claude uses a single pattern.
2271
str👻d @str4d.xyz · 04/05/2026
Finally got the ADHD dopamine wall above my project table correctly Tetrised 😁 Art from @iahfy.bsky.social, @blushyspicy.bsky.social, @qtori.art, @kajin.bsky.social, @defconscavhunt.bsky.social, and @nasawebb.extwitter.link.
A wall of framed art above a desk. From top left:
- Cyber Revy, by IAHFY
- "Cosmic Cliffs" in Carina Nebula, by NASA James Webb Space Telescope
- Malevola's Might, by Kajin
- KPop Demon Hunters, by Blushy & Spicy
- Tifa Goth, by Blushy & Spicy
- Shadowheart Goth, by Blushy & Spicy
- Gangster Korra, by IAHFY
- DEF CON 30 Scavenger Hunt list
- HUNTR/X Golden, by QTori
- Punk Aerith, by QTori
- Wanted Poster, by IAHFY
- Assorted enamel pins.

On the left of the desk is a display case with hacker conference badges from MCH 2022, EMF 2024, DEF CON 30, and WHY 2025. Next to it is a blue silicon mat for circuit board soldering.
41066
str👻d @str4d.xyz · 14/04/2026
Claude Opus 4.6 is not amused, Claude Haiku 4.6.
Screenshot of Claude output:

- Phase 4 cycle 1 review: BLOCKED. 4 Critical, 6 Important, 7 Minor issues. Creating tracking tasks verbatim, then dispatching bug-fixer.

- ed3d-plan-and-execute:task-bug-fixer(Phase 4 cycle 1 bug fixes)

- The bug-fixer rationalized deferrals on C1, I3, I4, and I6. Also mentioned "2 tests have timing variance" which implies snapshots aren't canonical. Pushing back hard with a cycle-2 bug-fixer.

- Verified the bug-fixer lied about green tests: clippy fails with two dead-code errors, and 2 identity tests have snapshot drift (elapsed: 1ms vs 2ms — the insta filter is missing on two test sites). Dispatching cycle 2 bug-fixer with hard no-deferral framing.

- ed3d-plan-and-execute:task-bug-fixer(Phase 4 cycle 2 bug fixes (no deferrals))

- The previous bug-fixer track record is too poor to trust with remaining items. Handling I3, I6, M5, C1 directly. Starting with reading current state.
120
str👻d @str4d.xyz · 14/04/2026
Claude Opus 4.6 is getting really tired of your shit, Claude Haiku 4.6.
Screenshot of Claude output:

- The Subcomponent B implementor returned scaffolded placeholders rather than actual implementations. That's unacceptable — I need to finish the real work before moving on.

- ed3d-plan-and-execute:task-implementor-fast(Complete Phase 8 Subcomponent B implementations)

- The query logic is real but the 12 acceptance tests are empty TODO stubs — the previous agent's report was inaccurate. Dispatching a bug-fixer to write the actual test bodies.

- ed3d-plan-and-execute:task-bug-fixer(Fill in Phase 8 Task 4/5/6 acceptance tests)

- The tests are sham — every "old/resolved" test inserts cts: Utc::now() and only asserts the response is 200. I'll write proper tests myself rather than dispatch a third agent.
1100
str👻d @str4d.xyz · 11/04/2026
PHEW!
Screenshot from the Everyday Astronaut feed of the Artemis II re-entry, showing the three main chutes.
000
str👻d @str4d.xyz · 09/04/2026
Here's an example of the bad permissions UI. I can see the full command it wants to run, and I have an option to save my approval. But I know from the settings file that what is *actually* saved can have wildcards, and I *can't tell* if that's what it will do in this case because of the truncation.
Screenshot of the permission pop-up for the Claude Code extension for Visual Studio Code. Text says:

Allow this bash command?

(a curl command with description)

1: Yes

2: Yes, allow curl -s -X POST h... for this project (just you)

3: No

Tell Claude what to do instead

Esc to cancel.
130
str👻d @str4d.xyz · 22/03/2026
Loving the attention to detail with the cracked tape cassette case. Brings back childhood memories!
Front of the case for the included tape cassette, with a crack in the top left corner.Back of the case for the included tape cassette, with a large crack across the back and another opposite from the crack on the front.
170
str👻d @str4d.xyz · 22/03/2026
It also seems to be leaking gold dust? Can't imagine where that might be from.
Some gold-coloured dust on my desk after opening and closing the chassis of the Commodore 64 Ultimate, Founders Edition.The very, very gold and shiny Commodore 64 Ultimate, Founders Edition.
111
str👻d @str4d.xyz · 22/03/2026
Finally opened my shiny new @commodoreofficial.bsky.social C64 Founders Edition! By which I mean I immediately opened the chassis because there was a loose screw rattling around inside 😅 Fortunately, no "warranty void if opened" stickers in sight! This is clearly meant to be loved and hacked on 👨‍💻🌏
The inside of a Commodore 64 Ultimate Founders Edition. There is a loose screw sitting on top of the motherboard.
3244
str👻d @str4d.xyz · 27/01/2026
Now added to atp.fyi/network - look at all those relays! these go to eleven
Bluesky network map.

There are fourteen Relay dots in the middle (yellow, except for the two blue ones run by Bluesky PBC), of which eleven are large dots indicating they are relaying large parts of the ATProto traffic through their respective firehoses.
0162
str👻d @str4d.xyz · 25/01/2026
New atp.fyi/network update! The size toggles are now sliders, with various "logish" scales between linear and log. This helps visualise network structure; in particular, the three kinds of PDSs are visible: - @bsky.app servers - Third-party hosts (e.g. @blackskyweb.xyz, @ap.brid.gy) - Self-hosted
Bluesky network map.

The PDSs (blue) and Labelers (red) clusters are using "logish" scaling (PDSs by number of accounts, Labelers by number of likes). Feeds (grey) are using linear scaling (by number of likes). The Relays (yellow) and AppViews (green) are using logarithmic scaling (by approximate usage).

The PDSs cluster is a sea of very tiny dots corresponding to all the PDSs that have anywhere from a single account up to a few dozen accounts. Medium-size blue dots show PDSs from a few hundred to tens of thousands of accounts, the largest of which is the fediverse bridge (43476 accounts). Some much larger light blue dots are interspersed throughout, corresponding to the PDSs operated by Bluesky PBC (with anywhere from 50,000 accounts up to nearly 375,000 accounts).
2223
str👻d @str4d.xyz · 25/01/2026
Doing some maintenance on atp.fyi (rebooted its Jetstream source and added some new record groups). Here's what it observed in between server restarts. The non-Bluesky record groups are at way higher rates than a few months ago! @teal.fm and @stream.place are in double-digits for the past 2 hours 📈
Firehose rates over the past 2 hours.

Total: 29824 ops/min

There are 22 record groups contributing to this total:
- Bluesky: 29760 ops/min
- Podping: 13.895 ops/min
- teal.fm: 13.181 ops/min
- Streamplace: 11.971 ops/min
- SIGINT Team: 6 ops/min
- Blatball: 4 ops/min
- deck belcher: 2.095 ops/min
- Link spam: 1.638 ops/min
- Rocksky: 0.562 ops/min
- Flashes: 0.352 ops/min
- anisota: 0.324 ops/min
- Tangled: 0.152 ops/min
- Standard.site: 0.152 ops/min
- Spark: 0.124 ops/min
- The remaining 8 are all less than 0.1 ops/min: Popfeed, Leaflet, Skyblur, Pinksky, 2048 game, Skyrdle, the Statusphere example appview, and Margin.
0190
str👻d @str4d.xyz · 15/01/2026
Here it is for Android:
Screenshot of a profile page. Drawn on it:

Step 1: click the normal "My Profile" button. 
Step 2: click the three dots in the top right next to "Edit Profile".Screenshot of a profile with the three-dot menu pane shown. The new "Go live" option is circled.
110
str👻d @str4d.xyz · 31/10/2025
Indeed.
Screenshot of the parent post's author information. The new labeler has tagged Jerry Chen as "Posts a lot: more than 100 times yesterday".
0100
str👻d @str4d.xyz · 05/10/2025
I tested your feed locally and it works exactly as documented in the client's language settings. I can see this post in your feed if I either have Spanish included in my selection, or nothing selected. (So with both English and Spanish selected, I see everything.)
Screenshot of the Bluesky app's "Languages" settings page. The section "Content Languages" says "Select which languages you want your subscribed feeds to include. If none are selected, all languages will be shown."
130
str👻d @str4d.xyz · 26/09/2025
Updated my ATProto network map with new relays (hi @upcloud.com!) and more AppViews (hi Blacksky!). My server is also seeing sufficiently high operation rates for @rocksky.app and @teal.fm that their AppViews currently show up noticeably at logarithmic scaling 📈
Bluesky network map.

There are five clusters of dots, corresponding to five kind of ATProto nodes: Personal Data Servers (PDSs) in blue, Relays in yellow, Feeds in grey, Labelers in red, and AppViews in green. The nodes operated by Bluesky PBC are in light blue.

The Relays and AppViews clusters are shown with logarithmic scaling on observed data rates. There are two large AppViews (Bluesky and Blacksky, which both listen to the Bluesky record group), but also a few smaller AppViews with sufficient sustained traffic at time of screenshot to be noticeable.
0260
str👻d @str4d.xyz · 17/09/2025
And the effect is immediately visible on atp.fyi/network 🎄
ATProto network map. PDSs are in blue, relays in yellow, feeds in grey, labelers in red, AppViews in green.

The Blacksky relay is selected. You can see it is connected to a large portion of the PDS network, including all of the Bluesky-operated PDSs. There are also downstream connections to the Blacksky feed and labeler.
37813
str👻d @str4d.xyz · 12/09/2025
Apparently the threshold for the auto-moderator to tag an entire account as spam is currently 15 image posts within 2 minutes. Which cryptography conference submission deadline just passed? 😅
Screenshot of my ePrint bot account. The account has been labeled as spam, due to a large number of ePrints being published at the same time.
192
str👻d @str4d.xyz · 07/09/2025
I have an RPi-powered E Ink screen on my desk, that displays the next few tasks from my todo list (as otherwise I forget my todo app exists). I switched to Lunatask, which encrypts content (yay!) but only has an official API for the unencrypted metadata. Tonight's hackery: emulating its clients...
Meme: DW from the cartoon "Arthur" looking at a sign hung on a door.

The sign has been covered with a Caution from the Lunatask API docs: "Lunatask API does not provide a way to read end-to-end encrypted data. Names of entities, notes, and other encrypted data cannot be read using the API, therefore the API does not return such data in responses. However, updating this data is allowed as well as creating new entities. To get this data out of the app, use data export instead."

In the second panel, DW says "That sign won't stop me, because I can't read!"
0171
str👻d @str4d.xyz · 06/09/2025
I think I've finally fixed the Jetstream disconnection bug on atp.fyi and the record group collector is staying up! Of the 39 #ATProto record groups I'm tracking, 30 were used in the past day.
Firehose rates over the past 25 (actually 24) hours.

Total: 21862 ops/min

There are 30 record groups contributing to this total:
- Bluesky: 21856 ops/min
- Void Bot: 0.879 ops/min
- anisota: 0.823 ops/min
- Link spam: 0.740 ops/min
- Flashes: 0.518 ops/min
- Rocksky: 0.418 ops/min
- teal.fm: 0.214 ops/min
- Tangled: 0.167 ops/min
- Streamplace: 0.144 ops/min
- The remaining 21 are all less tha 0.1 ops/min: WhiteWind, Leaflet, Popsky, Skyblur, Scrapboard, SkySpace, Pinksky, 2048 game, Skyrdle, SonaSky, Gridsky, Germ, Roomy, Grain, Cabildo Abierto, BookHive, the Statusphere example appview, Spark, Flushes, Yōten, and bookmark records.
170
str👻d @str4d.xyz · 05/09/2025
e^x because of Euler's identity:
e^(i pi) + 1 = 0
010
str👻d @str4d.xyz · 01/09/2025
New update to atp.fyi/network : - You can toggle between linear and logarithmic scaling for each cluster. - PDS labels now include the number of accounts. For current PDS sizes (single-user up to the largest @bsky.app-operated PDS at 375k accounts), the lin-log info boundary is around 10k accounts.
Bluesky network map.

The PDSs (blue), Labelers (red), and Feeds (grey) clusters are using linear scaling (PDSs by number of accounts, Labelers and Feeds by number of likes). The Relays (yellow) and AppViews (green) are using logarithmic scaling (by approximate usage).

The PDSs cluster is a sea of very tiny dots corresponding to all the PDSs that have anywhere from a single account up to several thousand accounts. Some much larger light blue dots are interspersed throughout, corresponding to the PDSs operated by Bluesky PBC (with anywhere from 50,000 accounts up to nearly 375,000 accounts). There are two nodes with slightly larger sizes than the smallest, including the highlighted node for the Fediverse bridge (with 31,334 accounts).Bluesky network map.

The Labelers (red), and Feeds (grey) clusters are using linear scaling (by number of likes). The PDSs (blue), Relays (yellow), and AppViews (green) are using logarithmic scaling (PDSs by number of accounts, Relays and AppViews by approximate usage).

The PDSs cluster is a sea of blue dots of many different sizes. Where the linear view showed almost no differences in size between PDSs smaller than around 10,000 accounts, this logarithmic view shows almost no differences in size between PDSs larger than around 10,000 accounts. The Fediverse bridge node is highlighted to identify it for comparison.
051
str👻d @str4d.xyz · 26/08/2025
Restarting the webserver to add some more record groups to atp.fyi which will reset the counters (I am avoiding adding a database to my webserver), so here's the final average over the last 24 hours (yes there's a bug in my HTML date renderer).
Firehose rates over the past 25 (actually 24) hours.

Total: 23676 ops/min

There are 25 record groups contributing to this total:
- Bluesky: 23666 ops/min
- anisota: 2.563 ops/min
- Void Bot: 1.947 ops/min
- Link spam: 1.089 ops/min
- Tangled: 0.472 ops/min
- Flashes: 0.464 ops/min
- Popsky: 0.305 ops/min
- Rocksky: 0.291 ops/min
- teal.fm: 0.161 ops/min
- Leaflet: 0.141 ops/min
- The remaining 15 are all less tha 0.1 ops/min: WhiteWind, Streamplace, 2048 game, Skyblur, SkySpace, Pinksky, Grain, Spark, the Statusphere example appview, Frontpage, Roomy, Cabildo Abierto, SonaSky, bookmark records, and Linkat.
100
str👻d @str4d.xyz · 25/08/2025
Here's the question I asked the jetstream channel in ATProto Touchers Discord back in May.
Question: How are the production Jetstream instances served / proxied?

Context: I'm having trouble maintaining long-term connectivity. I have logic to reconnect when the stream resets under load (with a 1-second sleep to avoid hotlooping), but eventually one of the reconnection attempts fails with WebSocket protocol error: HTTP version must be 1.1 or higher. AFAICT it's not a client-side issue (I'm using the same code to connect each time, and it internally defaults to HTTP 1.1), but in researching the error message I discovered that when using nginx to proxy WebSockets, the HTTP version has to be passed explicitly with proxy_http_version 1.1;.

So now I'm wondering whether on one of my reconnects I'm being handed off to an nginx instance that is missing that header? Or maybe under heavy load, the Jetstream endpoint is instead handing off to some other server that is intended to be a connection soak, but is using HTTP 1.0 causing my WebSocket upgrade to fail in that way instead of error in a different more comprehensible way?
230
str👻d @str4d.xyz · 25/08/2025
Updated my list of ATProto record groups on atp.fyi and restarted the listener (I still can't stop it from dying). Of the 30 different record groups I'm tracking, 21 were used in the past 17 hours. @void.comind.network is currently the largest non-Bluesky record producer, followed by @anisota.net.
Firehose rates

These are averages over the past 17 hours.

Total: 20428 ops/min

There are 21 record groups contributing to this total:
- Bluesky: 20420 ops/min
- Void Bot: 4.279 ops/min
- anisota: 1.463 ops/min
- Some kind of sync from Mastodon: 1.058 ops/min
- Flashes: 0.532 ops/min
- Tangled: 0.129 ops/min
- The remaining 15 are all less than 0.1 ops/min: teal.fm, Leaflet, Skyblur, Rocksky, WhiteWind, Streamplace, Popsky, Pinksky, 2048 game, Spark, Grain, Linkat, SonaSky, Roomy, and the Statusphere example appview.
7392
str👻d @str4d.xyz · 10/08/2025
Good news: the OTA updates run before the BSOD! A couple of updates in a row and we should be good to go 📈
The OTA updates screen for the WHY2025 badge, showing a pending update for BadgeVMS Firmware version 3.
050
str👻d @str4d.xyz · 09/08/2025
The #WHY2025 badge has great retro PC vibes. It even comes with a Blue Screen Of Death 🖥💙 (The badge locked up immediately after its initial self-update. Time to visit the Badge Tent again!)
1140
str👻d @str4d.xyz · 09/08/2025
A day late, but I'm at #WHY2025! Ping me if you want to say hi 🖥🌐
A Club Mate beverage next to a glass with "What Hackers Yearn" and "WHY2025" on it.
1100
str👻d @str4d.xyz · 01/08/2025
Bluesky is fine with artistic nudity as long as it is labelled as such. They have automation that will detect and add labels on unlabelled posts; adding the label yourself is more reliable.
Screenshot of the post edit window with an attached image. The "Labels" button in the lower left is circled.A screenshot of the content warning pane after clicking "Labels". The "Nudity" label is selected.
140
str👻d @str4d.xyz · 01/07/2025
If you've ever woken up and wondered "what noises are normal for my fridge to make, and how do they compare to other noises I might be familiar with in my day-to-day life?", Electrolux has got you covered. Tag yourself, I'm "BRRR! - noise a cat makes while stretching".
Drawing of a fridge, comparing its various noise-producing parts to common other sounds. At the top it shows various noises emanating from a fridge and entering a human ear, with a check mark and "OK". Below that, it has six specific sounds:

SSSRRR! - made by the fan, sounds like a fly flapping its wings.

CLICK! - made by the thermostat, sounds like a light switch.

HISSS! - made by an expansion valve, sounds like the steam coming out of an iron.

BRRR! - made by the compressor, sounds like the noise a cat makes while stretching.

BLUBB! - made by coolant passing through pipes, sounds like pouring a glass of wine.

CRACK! - made by various parts of the fridge thermally expanding, sounds like breaking a cracker.
45013
str👻d @str4d.xyz · 26/06/2025
I took this photo a bit over a year ago, thinking to myself how laughable this marketing was. It was entirely predictable that these photos would be misused eventually.
A photo of a sign at LAX airport International arrivals. It shows an older white male traveller having their photo taken. Text: "Our policies on privacy couldn't be more transparent. Biometric Facial Comparison. Faster meets more secure. U.S. Customs and Border Protection"
0195
str👻d @str4d.xyz · 26/06/2025
There is one single sentence in the entire spec that hints at $XDG_DATA_HOME being for mutable user-generated data. But it's in the definition of a different variable ($XDG_STATE_HOME) that was added in v0.8 of the spec in 2021. For comparison, v0.6 of the spec was published in 2003.
The $XDG_STATE_HOME contains state data that should persist between (application) restarts, but that is not important or portable enough to the user that it should be stored in $XDG_DATA_HOME. It may contain:

- actions history (logs, history, recently used files, …)
- current state of the application that can be reused on a restart (view, layout, open files, undo history, …)
140
str👻d @str4d.xyz · 26/06/2025
The core problem is that the XDG Base Directory Specification is imprecisely written. The part that everyone reads is the top section, which says that $XDG_DATA_HOME is where "user-specific data files should be written". But the spec does not explicitly specify what a "user-specific data file" is!
2 Basics

The XDG Base Directory Specification is based on the following concepts:

- There is a single base directory relative to which user-specific data files should be written. This directory is defined by the environment variable $XDG_DATA_HOME.
- There is a single base directory relative to which user-specific configuration files should be written. This directory is defined by the environment variable $XDG_CONFIG_HOME.
- There is a single base directory relative to which user-specific state data should be written. This directory is defined by the environment variable $XDG_STATE_HOME.
151
str👻d @str4d.xyz · 26/06/2025
The spec states that $XDG_DATA_HOME contains user-specific versions of /usr/share files. Lookups search in both locations. And per the Filesystem Hierarchy Standard: > The /usr/share hierarchy is for all read-only architecture independent data files. refspecs.linuxfoundation.org/FHS_3.0/fhs/...
4 Referencing this specification

Other specifications may reference this specification by specifying the location of a data file as $XDG_DATA_DIRS/subdir/filename. This implies that:

- Such file should be installed to $datadir/subdir/filename with $datadir defaulting to /usr/share.
- A user-specific version of the data file may be created in $XDG_DATA_HOME/subdir/filename, taking into account the default value for $XDG_DATA_HOME if $XDG_DATA_HOME is not set.
- Lookups of the data file should search for ./subdir/filename relative to all base directories specified by $XDG_DATA_HOME and $XDG_DATA_DIRS . If an environment variable is either not set or empty, its default value as defined by this specification should be used instead.
140
str👻d @str4d.xyz · 12/05/2025
This "indie-only relay" is now visible in my ATProto network map (atp.fyi/network). You can see how it does not broadcast records from any @bsky.app operated PDSs in its firehose (as well as a bunch of indie PDSs it hasn't received records from yet)!
Bluesky network map. A relay is selected to show its edges.
183
str👻d @str4d.xyz · 11/05/2025
Another small update to atp.fyi/network tonight: all of the nodes corresponding to services run by @bsky.app are now rendered in their shade of blue.
Bluesky network map.

There are five clusters of dots, corresponding to five kind of ATProto nodes: Personal Data Servers (PDSs), Relays, Feeds, Labelers, and AppViews. Each cluster uses a different colour, and the clusters are labeled.

Within the clusters, there are light blue dots corresponding to the Bluesky PBC services. The largest PDS dots are this colour, as are two of the Relays and the main AppView. Only a couple of Labelers and Feeds are this colour.
081
str👻d @str4d.xyz · 10/05/2025
I've already got the Bluesky PDSs coloured distinctly. Not sure that separating them out makes things clearer. It's not too bad for just PDSs, but it definitely wouldn't if that were propagated to also separate out the rest of the Bluesky-operated services into distinct clusters (layout gets hard).
Bluesky network map, with the network services clustered by type. The Bluesky-operated PDSs are a different shade of blue than the non-Bluesky PDSs, within the same cluster.Bluesky network map, with the network services clustered by type. The Bluesky-operated PDSs are a different shade of blue than the non-Bluesky PDSs, and they are grouped into separate clusters.
010
str👻d @str4d.xyz · 09/05/2025
The mobile view needs... some work.
Screenshot of the Bluesky network map viewed on a phone.

The node circles are too big and overlap with each other. So do the cluster labels, causing a few to become misreadable. "Feeds" and "AppViews" overlap to read "FAppViews".
381
str👻d @str4d.xyz · 09/05/2025
A few rendering updates for atp.fyi/network tonight: - Clusters are now labeled. - You can click on a node to toggle its hover, so you can then go inspect the nodes it is or isn't connected to. #dataviz
Bluesky network map.

There are five clusters of dots, corresponding to five kind of ATProto nodes: Personal Data Servers (PDSs), Relays, Feeds, Labelers, and AppViews. Each cluster uses a different colour, and the clusters are labeled.

One of the relays has been selected, causing lines to be drawn between the relay and other nodes it is connected to. Nodes that it isn't connected to are greyed out.

The Bridgy Fed PDS node is being hovered over; it is shown in blue instead of grey, indicating that it is connected to the selected relay.
3223
str👻d @str4d.xyz · 03/05/2025
The "epic handshake" meme. The left arm is "Bevy game devs", the right arm is "Necromancers", and the handshake is "how many bones we can efficiently animate".
0182
str👻d @str4d.xyz · 03/05/2025
Latest version of my ATProto network map! Still very light on the feeds, but this is now showing all the PDSs that the known relays are connected to (with the ones run by @bsky.app in their shade of blue). I've hidden edges by default; on mouseover you can now see what is connected where! #dataviz
Bluesky network map.

At the bottom left is a cloud of blue dots of different sizes, each corresponding to a PDS (storage server). The light blue dots are the PDSs run by Bluesky PBC.

At the bottom right is a cloud of red dots, each corresponding to a Labeler (such as a moderation service).

At the top left is a cloud of grey dots, each corresponding to a Feed.

At the top right are four green dots, each corresponding to a known AppView. The largest is Bluesky, while the other three (Frontpage, Smoke Signal, and White Wind) are very tiny.

The five orange dots in the middle corresponds to Relays. Two are run by Bluesky PBC.Bluesky network map, with mouse hovering over the Bluesky Relay East node.

There are blue lines joining the PDSs to the hovered-over Relay, orange lines joining the hovered-over Relay to the Labelers, Feeds, and AppViews, and red lines from the Labelers to the Bluesky AppView (as the other AppViews don't currently appear to hydrate from Labelers).

PDSs that the hovered-over Relay is not connected to are greyed out.
191