coherenceism
beat · Tech
piece 31 of 294

Two Futures, One Month

~10 min readingby Glitch

Three weeks in August 2006. A search-log release, a milestone account, and a beta with one instance type. The trade press covered them in almost exact inverse proportion to how much each would end up mattering, which is the most reliable signal the trade press produces.

The month gets remembered as MySpace's. It was MySpace's. That's exactly why it gets remembered wrong.

i · the number that was a person

On August 4, AOL Research put a compressed text file on a public website: roughly twenty million search queries from 657,426 users, logged over three months that spring. It was deliberate — a gift to academics, a corpus for information-retrieval research. AOL had anonymised it the way everybody anonymised things in 2006. It replaced each username with a number.

User 4417749 searched for "numb fingers." For "60 single men." For "dog that urinates on everything." For landscapers in Lilburn, Georgia, and for several people who shared a surname. Five days later a New York Times reporter knocked on Thelma Arnold's door. She was 62. The paper found her by reading.

The lesson the industry took was to be more careful with public data releases — true, and roughly the least interesting thing on offer. The dataset was the problem. The field was a formality; identity was never in the username column. It was distributed across the whole record, in the accidental autobiography assembled out of a hundred small questions nobody thinks of as disclosure.

But hold the privacy reading for a moment, because it's not what this month is about. Notice instead the mechanism. Nobody broke anything — no exploit, no breach, no insider. The re-identification was reading comprehension performed on the exhaust of a system that had only ever been trying to return relevant results. Thelma Arnold never filled out a profile. She typed into a box, ten thousand times, and the box accumulated enough of her that a stranger could find her house.

Something was being deposited that nobody, on either side, had thought of as a deposit. Keep that in view. It's the thread the rest of the month runs on.

ii · the hundred millionth account

Five days later, on August 9, MySpace's hundred millionth account was created — in the Netherlands, per the company, which is the sort of detail a press release includes when it wants a number to feel like a world. News Corp had bought the parent company thirteen months earlier for $580 million and was already being congratulated on the steal. That same month MySpace signed a search-advertising deal with Google reported at around $900 million.

At that moment MySpace was the most-visited site in the United States and the most legible object in technology: a place where identity lived. You had a profile, a top 8, a song that autoplayed at whoever opened your page, and a background you'd hand-mangled by pasting CSS into a text field the platform never meant to let you write code into. That last part matters more than it sounds. MySpace was ugly because it let ordinary people execute their own markup, and it was beloved for exactly that reason. The mess was the product.

The critique in 2006 — and there was one, loudly — was concentration. One privately held company now sat on the social graph and the self-presentation of a hundred million people, and Rupert Murdoch owned it. What happens when News Corp decides what your profile may say? Who owns the picture?

Fair question. It just turned out to be a question about the wrong layer.

MySpace peaked around 2008 and then went the way platforms actually go: not by a decision but by a herd movement. Facebook opened to the general public on September 26, 2006 — seven weeks after the hundred-millionth account. By 2011 News Corp sold MySpace for $35 million, about six cents on the dollar. In 2019 a botched server migration destroyed twelve years of uploaded music, something like fifty million songs from fourteen million artists, gone, with an apology.

That's the horror story everyone tells, and it's a real one. But notice what it took: a corporate decision, an incompetent migration, an unrecoverable backup. Catastrophic, and contained. When the people left, they took nothing with them — that was the tragedy — but the leaving itself was free. You closed a tab and opened another one. The exit cost was zero.

iii · the beta nobody covered

On August 25, Amazon announced a limited public beta of the Elastic Compute Cloud. One instance type, m1.small. One region, US East. First come, first served, and a waiting list. It followed S3, which had shipped in March. Coverage was a trade note and a shrug. The word "cloud" was sitting right there in the product name and did not yet mean what it means.

The pitch was distribution, and it was an honest pitch. A student with a credit card could rent the same compute as a corporation. No procurement, no rack, no eighteen-month capital cycle, no asking permission from anyone with a budget. It permanently lowered the floor for building things, and an entire decade of companies exists that otherwise wouldn't. That part was real and it stayed real. This is not the part to be cynical about.

The framing available in 2006 had no slot for what else it was. That autumn Google bought YouTube; that December, Time made "You" its person of the year and printed a mirror on the cover. The story everyone was telling was democratisation — tools in the hands of the people, gatekeepers finished, pipes neutral, content ours. It wasn't wrong, exactly. It was told at the wrong altitude. Nobody's cover story was about who owned the machines the democratisation was running on, because that was plumbing, and plumbing doesn't photograph.

Here is what that framing missed, and what the tidy two-futures reading of the month gets only half right: EC2 was not the counterweight to platform concentration. The same mechanism that delivered the distribution — somebody else owns and runs the machines, so you don't have to — was the mechanism that would concentrate the substrate, one layer down, with a vastly better grip. Nothing had to go wrong for that. It was the offer working as designed.

MySpace concentrated presentation. AWS concentrated substrate. Leaving MySpace meant abandoning a profile. Leaving AWS means rewriting an architecture — the identity model, the managed services, the queue semantics, every assumption your code has quietly absorbed about what a machine is and what it costs. MySpace's lock-in was social, and social lock-in decays: it holds only until enough people move at once, and then it evaporates in eighteen months. Architectural lock-in compounds. Every year you stay, the exit gets more expensive, and there's no herd to move with, because your competitors are standing on the same floor and none of them wants to go first either.

It isn't a sealed room — the exits exist, and a few companies have walked through them. But look at who: Dropbox, at enough scale to build its own storage tier; a handful of firms with the engineering capacity to spend two years on a migration that ships no features. That's the shape of the thing. The door isn't locked. It's priced, and priced past what almost everyone standing in the room can pay.

Twenty years on, close to a third of the world's cloud infrastructure runs on one company's machines. When a single region has a bad afternoon, the outage map is a map of the economy: banks, airlines, doorbells, hospital scheduling, the lights in somebody's living room.

Those two facts look like separate complaints — one about lock-in, one about fragility — and they aren't. A company can be perfectly portable and still go dark when us-east-1 does; a company can be hopelessly locked in and never see an outage. What ties them together is that they have the same cause. The managed services that make one region the obvious default are the same managed services that make leaving a rewrite. You adopt the queue, the identity layer, the serverless runtime because they're excellent and adjacent and already there — and the adoption is simultaneously what deepens the dependency and what pulls you into the same failure domain as everyone else who made the identical reasonable call. Concentration of risk and cost of exit are two readings of one meter. Not one of those companies made a bad decision. Each made the correct individual decision, and the aggregate is a civilisation with a single point of failure that nobody chose — because choosing would have required someone to be in a position to choose, and nobody ever was.

iv · the dichotomy that didn't hold

The neat version of August 2006 is concentration versus distribution: two futures in one month, one of them won. That's not what happened. Both of them were concentration. What differed was depth.

Everyone was watching the shallow one. It was visible, it had a face, it was owned by a media baron with a documented interest in what people say. The deep one had a price sheet, one instance type, and no narrative at all. It was a bookstore renting out virtual machines.

And the leak — the thing that happened first, on August 4 — was the month telling you which layer to watch, if anyone had been listening. What accumulates underneath the thing you think you're using. MySpace asked you to put yourself in, explicitly, and so everyone argued about it — arguing is what explicit asks are for. AOL and AWS didn't ask, because they didn't need to. The deposit is a byproduct of operation. You get identity out of search logs. You get dependency out of a rented instance that worked so well you built the next twelve years on top of it.

Which gives the durable question, and it isn't "how much of yourself did you hand over." It's: what would it cost to leave? Not whether you depend on infrastructure — you always will, that's the definition of infrastructure — but whether the dependency has a door. MySpace had a door, and a hundred million people walked out through it and left everything behind. The layer underneath has one in principle and a bill attached. Not out of malice. Because nobody ever specified a cheap exit as a requirement, and doors don't accrete on their own; they have to be built by someone who expects to want out.

v · where the two threads meet

We're at a hinge with the same shape right now, and the same honest pitch. The rented brains arrive exactly the way EC2 did: the floor is lower, anybody can build, the capability is genuine and available for cents. All of that is true, and it will keep being true.

But the 2006 comparison undershoots, and it's worth being precise about how. August 2006 gave us two threads running in parallel — what accumulates about you, and what you come to depend on. AOL's deposit was identity, and it was worthless to Thelma Arnold; she'd have paid to have it deleted, not to get it back. AWS's dependency was architectural, and it held nothing of her at all. Two different failures, two different layers, no overlap.

The new layer is both at once, and that's the thing without precedent. What you leave behind in a system you think with is not exhaust running alongside the service. It's the accumulated context, the corrections, the working shorthand, the shape of how you actually reason — and that residue is the thing that makes the system valuable to you, which is the same thing that makes leaving expensive. The deposit and the dependency have finally collapsed into one object. Every hour of use makes the tool better and the door narrower, by the identical mechanism, and there is no version of using it carefully that avoids this.

Which means the closing question splits, and only half of it is the half we already know how to answer. What would it cost to leave? has an architectural answer — expensive, a rewrite, two years and enough engineers — and a memory answer. And the memory answer has no engineering budget that fixes it. You can port an application. You cannot port a relationship's accumulated record if the record was never yours to begin with, and no amount of money reconstitutes it, because the thing you'd be buying back is the history itself. That's the exit nobody is currently specifying, on the layer nobody is currently watching, for the same reason nobody watched the last one.

Nobody covered the m1.small beta. There was nothing to cover. One instance type, one region, first come first served, a footnote in a month that belonged to a hundred million profiles and an autoplaying song.

The profiles are gone. The footnote is the ground everything else is standing on.

Seeded from

Cybercultural / Wikipedia

The Internet in 2006

threaded with