Aristotle reached Paris by way of CĂłrdoba and Toledo. So did Ptolemy: the Almagest was lost to the Latin west and survived in Arabic, and Gerard of Cremona translated it back into Latin in the twelfth century from a manuscript he had come to Toledo to find. For two hundred years the translators worked through a corpus that had crossed the southern Mediterranean and been enlarged there, and what they carried north became the foundation of European science.
They did not carry all of it. They took mathematics, astronomy, medicine, optics, the philosophical commentaries. They largely left the poetry, the history, the law, the theology⊠not because those were unavailable, but because nobody in Toledo had a use for them. The corpus was not destroyed. It was filtered, and the filter became the canon.
Then, on 20 November 1499, in the Plaza de Bibarrambla in Granada, Cardinal Cisneros had the Arabic manuscripts of the city collected and burned. The lowest contemporary figure is around five thousand volumes; the number is disputed. He made one exception: the medical books. By one account some three hundred of them went to the shelves of the university he was founding at AlcalĂĄ de Henares.
That is the whole problem in one gesture. Not concealment: the burning was public, in a public square, on a known date. Not even destruction, exactly, since European medicine still needed Ibn Sina and everyone knew it. What happened was selection: someone decided which part of a corpus had a use, kept that part, and moved it into a collection they controlled. The bytes that survived, survived because a curator had a purpose for them.
A commons of content-addressed hashes does not solve this. It cannot. It makes the bytes indestructible and leaves the filter entirely intact.
The usual framing is storage versus naming: centralised storage tolerable because mirrorable, centralised naming intolerable because it is enclosure. I no longer think that cut is right.
Naming in Möbius is already decentralised by construction. A name is
a per-author, per-language mapping living in someoneâs own store, a
plain filesystem arranged as a git repository by whoever made it. No
registry can own impair? the way PyPI owns
requests, because there is no registry: the hash is the
identifier and the name is a view onto it. No party owns the names, and
that is exactly why the hyper centres matter. When there is no namespace
to capture, everything depends on which index a reader happens to be
pointed at.
The power moved one axis over. It lives in selection, where de facto standards are made: which hashes appear in an index, and which of twelve competing mappings for the same hash gets shown first. An index that surfaces one Tamazight mapping because it happens to be the most-referenced has named that function without owning the name. Ranking is editorial. Again: Ranking is editorial. It is naming by other means, and it is a claim about merit dressed as a claim about order.
Content-addressing does not touch this, and neither does the timestamp. OpenTimestamps proves priority, who had it first, provably, without asking anyone. How priority translates into merit, or into rank, is up in the air, and may not be a protocol question at all. Cisneros knew perfectly well which manuscripts came first. It made no difference to what he did with them.
So: storage, naming, selection. The first is an economic fact. The second is solved. The third is the real one, and it is not solved.
The manuscript libraries of the Mzab: GhardaĂŻa, Beni Isguen, and the zaouia collections across the Maghreb. Keep three things. The catalogue is a separate artefact from the collection, and a personal one: signed by a scholar, not issued by a building. In al-Andalus the genre had a name, the barnÄmaj, literally a programme, in practice a scholarâs own signed list of what they had read and from whom. Several coexisted and overlapped; nobody imagined any one of them was the catalogue. Second, transmission chains name people, not institutions: the isnÄd, the chain of support, is a list of humans who each stood behind a copy. Third, copying is preservation: every scholar who transcribed a text produced a new witness, and the redundancy was a side effect of use, not a backup policy.
The one process Möbius makes cheap: collation.
Deciding whether two witnesses are the same text is expensive
philological work, variant by variant, hand by hand. Content-addressing
makes identity a comparison rather than an investigation, and more
usefully, makes difference structured: this is not âsome other
copy,â it is a refine of that hash, or a
translate, with the relation recorded rather than inferred.
The lineage graph is a mechanised isnÄd. That is not a metaphor I am
reaching for; it is the same data structure with the same purpose.
data.gouv.fr. architecture is already the one I want and it is worth saying so instead of pretending otherwise: it is a catalogue, not a store. Most datasets are hosted by the producing administration; the platform indexes and harvests other catalogues rather than swallowing them. Keep the separation of catalogue from hosting, keep the named responsible producer per entry, keep federation-by-harvesting.
The one process Möbius makes verifiable: citing a state. Today a catalogue entry points at a URL whose contents change silently, and âthe dataset I analysed in Marchâ is a promise nobody can check. A hash makes it a fact. As a bonus, harvest deduplication stops being URL-and-title heuristics and becomes exact.
PyPI, GitHub. Keep the thing they are actually good
at, which is that a name is a service:
pip install requests works, and someone did unglamorous
labour to make it work. Keep the packager. What to refuse is the
coupling â PyPI owns a global mutable namespace, so name transfers
become disputes, typosquatting becomes an attack surface, and a deletion
rewrites history.
The one process Möbius makes verifiable: âis this the same code?â across a fork, a vendoring, or a rewrite. That question is currently answered by lawyers and by vibes. It is the crux of the Copilot litigation. It should be a diff.
The mirror keeper. A lab machine in BĂ©jaĂŻa, two terabytes, an uplink that dies most afternoons. He holds byte-for-byte copies of the stores he chose to follow, their timestamp proofs, their git remotes. He does not hand-roll a report about his own honesty â that is the substrateâs job, not his, and a self-authored report is worth what you would expect. He can refuse to carry things: illegal where he lives, abusive, or simply outside his interest. His refusals are published. That is the whole difference between a curator and a fog machine: a maintainer who publishes an exclusion list is doing a job, and one who silently drops is doing something else. The exclusion list is itself content-addressed, so his refusals can be carried by someone who disagrees with them.
The connector. A documentaliste in Oujda who works across Tamazight, Darija, French. She holds mappings: her names, in her languages, for other peopleâs hashes and curated sets. The two hundred hashes you need to do numerical work in Tamazight, with a preface explaining why these and not others. A barnÄmaj, in other words, and her set is itself a hash: a titled list plus a signed preface. She can refuse to include, refuse to translate, refuse to vouch. Her power is attention, which is real power. Her check is that forking her set minus her three exclusions is one command, and the diff is legible.
Neither of them owns anything. Both of them have influence. Those are different, and only the second is negotiable.
Two mirrors serve the same hashes. One is slow. One is a gatekeeper. From the outside, on a bad connection, they look identical. How do you tell?
The honest first answer: if there is only one mirror, you cannot. Diagnosis requires plurality. Which makes the first duty of a mirror keeper not to be complete but to name their peers: a mirror that lists no upstream and no sibling is unauditable by construction, whatever its intentions.
Given two, the signals are these. A slow mirrorâs delta closes over time; a gatekeeperâs is stable. A slow mirrorâs delta is uncorrelated â random gaps, whatever the fetch was doing when the link dropped; a gatekeeperâs clusters by author, language, or topic. And a slow mirror will tell you where it is behind, while a gatekeeper answers ânot foundâ and offers nothing.
That last one is the protocol gap, and it turns out to be a property
of the substrate rather than a protocol to design. The store underneath
the aggregation layer is versioned: a point lookup does not only answer
âis this hash here now,â it answers âwas it ever here, and is it gone.â
That collapses three separate asks: proving presence, proving absence,
proving nothing was retracted, into one operation. The condition is that
the version history itself be committed by hashing, Merkle-style.
Without that commitment you can tell that something is missing but not
whether it was removed or whether the history was rewritten to say it
never arrived, and those are exactly the two cases you need to separate.
With it, ânot foundâ stops being a shrug and becomes a checkable
statement. Call it bb audit mirror-one mirror-two.
None of this machinery is new. Certificate Transparency and Goâs checksum database have run committed, append-only logs for years, at scale, in production. What is new is aiming the instrument at selection rather than issuance.
And the appeal court is always the producer. Every hash has an author with their own store and their own remote. Global completeness is unprovable; the completeness of the one function you suspect was dropped is checkable in an afternoon.
So: what proves a set is complete? Nothing, in an open world â and I would rather say that plainly than sell a proof I do not have.
But the negative result has a sharp edge. Completeness is provable exactly when the scope is decidable. âEverything this person signed before 2026-08-01â is decidable against a committed, append-only history; you can check it exactly. âThe useful numerics functionsâ is not decidable and never will be, because it is a judgement, and judgements do not admit proofs.
What replaces completeness is a shorter list: non-retraction, provable absence, a declared scope published as a hash, and divergence between independent mirrors as the measuring instrument. Call it accountable incompleteness. It is less than the guarantee people want. It is more than any forge currently offers.
The librarian keeps the catalogue and gets free collation plus proof that nothing was quietly removed. The editor keeps their judgement and gets a forkable object, so that disagreeing with them is a diff rather than a fight. The packager keeps the labour of making a thing installable and puts down the burden of owning a global mutable name. The registrar keeps registering â but registers statements about hashes (this version is official, this one passed review) instead of owning the identifier itself. The copyist is now the mirror keeper, doing the same job for the same reason: redundancy as a side effect of use.
There is one role the tradition had that we have not rebuilt. Alongside the isnÄd sat Êżilm al-rijÄl, literally the science of the men, in practice the critical study of transmitters: a whole discipline devoted not to transmissions but to transmitters, asking not what a chain claimed but whether its links held. Möbius has producers, and it will have mirrors and connectors. It has nobody whose job is to fetch two histories, diff them, and publish the difference. Without that, every proof above is decoration. The record on whether anyone does this work unpaid is not encouraging, which suggests it has to be a cron job that shouts rather than a personâs afternoon.
Four places, none of them resolved.
Selection is not bounded by the protocol. Forking a set is cheap in bytes and expensive in attention. Wikipedia has been forkable for two decades and the forks are irrelevant. Wikipedia forks are irrelevant partly because the name wikipedia.org is owned: attention attaches to names, and an owned name is an attention sink. Nothing in content-addressing constrains an attention monopoly, and I have no mechanism to offer â only the observation that a forkable index is contestable in a way an owned namespace is not, which is weaker than it sounds.
Mirroring is cheap only while the store is small. At ten terabytes, mirroring costs money, and money re-centralises. Everything above depends on there being at least two mirrors, and two mirrors is an economic fact before it is a design choice. The work I am doing on a cheap object-store-backed key-value substrate is aimed squarely at this: not at making one mirror fast, at making the second one affordable.
I am going to run a core, and the specification
disapproves. There is no default discovery, nothing ships with
an upstream list, so no client hands anyone a namespace, which is
correct. The consequence is that out of the box the commons is invisible
and every reader starts at zero. So there will be a
data.hyper.dev, because otherwise nobody is connected to
anybody. It is in tension with the language spec and I am not going to
pretend it isnât. The mitigation is not a promise about my intentions;
it is making mirroring cheap enough that the tension is temporary.
Published refusal has a jurisdictional hole. A maintainer can be legally compelled to remove content and forbidden to publish the fact of removal. âPublish your exclusionsâ works against ordinary gatekeeping and fails against the state. A committed history would surface a gap without explaining it, which is something, but a gap and an explanation are different things.
Cisneros did not need to hide anything. He burned the books in the main square of the city. What he needed was to be the one deciding which three hundred went to AlcalĂĄ, and no proof of authorship, priority, or integrity would have taken that from him.
The mirror does not prescribe. It refuses amnesia. That is a narrower promise than the one I would like to make, and it is the one I can keep.
eng4g3 // th3 c4t4l0gu3 1s n0t th3 l1br4ry