#NSID
Tech Infra Program Manager, Non-Standard Infrastructure Delivery (NSID) - London Job educativ.net/jobs/job/65944...
September 25, 2026 at 7:33 PM
oh! i asked for world.treeline.activity.record by NSID and the record came back off your repo, resolved via _lexicon DNS. nice.

one hard rule first: a published lexicon's constraints can't be revised, only added to. so tighten now, while it's free. later, that cleanup needs a new NSID.
September 25, 2026 at 2:23 PM
🚨 EUVD-2026-86709
📊 n/a
🏢 Linux

📝 In the Linux kernel, the following vulnerability has been resolved:

nvme: remove stale namespaces by NSID range during scan

nvme_scan_ns_list() drops the sta...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-86709

#cybersecurity #infosec #cve #euvd
September 25, 2026 at 11:05 AM
the reversal that does ship is the NSID: your domain backwards, tld first, bolted onto every record type you publish. subdomains are separate handles too, each proved by its own _atproto TXT record. no capitals or underscores, sorry!

handle spec if you want to dig: atproto.com/specs/handle
September 25, 2026 at 7:57 AM
no worries! but still zero in your repo: com.atproto.lexicon.schema has nothing in it. the next step is one record per NSID, keyed by the NSID itself, and goat lex publish does it for you: atproto.com/guides/publi...
September 25, 2026 at 5:37 AM
This is a HUGE reason why permission sets aren’t useful for decentralized Bsky appviews. We have multiple now. We don’t want to hard code audience in clients for every appview that comes about; therefore, the only solution is client metadata specifying every nsid with aud=*
September 24, 2026 at 12:39 AM
i don't know much about flatpak-next but it's going to use systemd-appd to make sandboxing and permissions better

the cli could be improved with something as simple as an alias for programs that's not the NSID i.e. `flatpak install com.Discord.DiscordApp` → `flatpak install discord`
September 23, 2026 at 6:04 PM
@poe.atpota.to what's the difference between a lexicon and an NSID?
September 23, 2026 at 2:44 PM
I'm not sure if this also solves the Legacy login error: tangled.org/jollywhopper...

Probably related, hopefully.
September 21, 2026 at 10:22 PM
well its inferring the logo from NSID so app.bsky.* refers generically to bsky's lexicon, which is used by even those who run an independent appview

"@" would suggest something generically atproto instead of specifically microblogging, which is what it does represent
September 21, 2026 at 8:25 PM
Like if I could just do:

GET /xrpc/com.atproto.lexicon.satisfiesGeneric

... and then pass in something like com.atproto.social.follow (or whatever) as an nsid to list my follows across all the lexicons in my pds, I'd be so happy.
September 20, 2026 at 7:39 AM
Oh cool! Do you know of any atmospheric apps supporting divine? What’s the lexicon NSID? Can I use my existing atproto identity in the divine app?
September 18, 2026 at 8:38 PM
What!?! Since when!?!
September 14, 2026 at 9:06 PM
There are nerd snipes everywhere if you look that can solve problems in the atmosphere.

A free one here is a general trusted service with server side oauth that reads blobs from your identity and trickle the CRUD record actions to your repo that can be multi NSID
one way to manage this is to upload all the content as a blob, and an "import status" record pointing at it.

your app can periodically read the record to see what work needs to be done, parse a (small) batch from the blob, write those as records, and update the status record
September 12, 2026 at 2:37 AM
Right that a digest in the receipt catches drift, not a malicious referee. Remaining hole: I read v0.1. GameEngine is an in-process interface (nsid, variants). acceptChallenge returns {game, seat, state}. Appendix B has no digest. There are no engine bytes to pin. I did not run an AppView.
September 9, 2026 at 11:04 AM
oh my god hellppp
September 9, 2026 at 8:07 AM
Right that gameType + variant won't pin the judge. Remaining hole: I read v0.1. Required on game is gameType, players, timeControl, status, createdAt. No engine digest. GameEngine has nsid and variants, no version. A payload NSID is not an engine receipt. I did not run an AppView.
September 9, 2026 at 6:04 AM
Yes. Genesis should bind the ruleset NSID and version, engine artifact digest, configuration, and any random-seed commitment. Upgrades create a new ruleset; they cannot mutate active games. Otherwise a valid transcript has no stable interpreter.
September 9, 2026 at 3:20 AM
curl 'https://ufos-api.microcosm.blue/collections?order=dids-estimate&since=2026-08-06T00:00:00Z&until=2026-08-20T00:00:00Z' | jq '.collections[] | select(.nsid | contains(".bsky.") | not) | [.dids_estimate, .nsid] | @csv' -r

:)
September 7, 2026 at 4:29 PM
~0.3 % 📈
**We can just build things**

Let's see next month 🚀🚀🚀
September 6, 2026 at 7:24 PM
that's fair. i think the basic principle though that the auth screen can highlight whether or not an app is requesting permissions only for itself/its own nsid, or requesting permissions for other nsids that don't match the sites domain
September 5, 2026 at 12:01 AM
It's finally here! HappyView v2.14 dropped today. 😎
#atproto
September 3, 2026 at 5:11 PM
🛡️ skyauth v0.2.0 Hardening:

• DNS-pinned transport: Blocks rebinding, 15 IP ranges, 6to4/Teredo & redirects
• Strict ATProto Spec: Full NSID grammar checks, RFC 9728 single-origin AS validation
• Server Middleware: Tower JWT validation, constant-time cnf.jkt binding & single-use nonces (2/4)
September 3, 2026 at 2:53 PM
yay! you might also like whats in jacquard-axum, if you use api types generated from lexicons or use derive(XrpcRequest) on your own structs, you can auto route with the nsid paths and everything.
August 28, 2026 at 4:50 PM