The thread began with a developer questioning whether custom domains for Go modules are a good idea because vanity domains can disappear, leaving imports broken, and noted that Go already records the hash of each module in go.sum files, so a content‑addressable fetch would restore reproducibility as long as the module’s bits can be found somewhere; the remaining difficulty is supporting module evolution, i.e., declaring that a name like github.com/company/someproject now refers to company.com/someproject for all dependents, a task that replace directives solve only on a per‑package basis and do not scale. The signal attracted 77 comments. The concrete fact that the language stores a cryptographic digest of each module’s source tree points to a deeper pattern: projects rely on mutable identifiers as proxies for immutable content, and when the identifier’s referent changes or vanishes the proxy breaks, while a direct binding to the content’s hash would survive any renaming, relocation, or disappearance of the naming authority. This pattern recurs whenever a system substitutes a convenient label for the thing it labels, creating a coupling that is fragile to the label’s instability.
In the Go ecosystem the label is a URL‑like import path. The author of a module chooses a domain they control, pushes code to a repository under that domain, and records the module’s hash in the go.sum of every downstream build. Downstream consumers trust that the hash matches the source they will fetch, but they obtain the source by performing a GET request to the import path. If the domain expires, is transferred, or the repository is moved, the GET fails even though the hash in go.sum still validates the original bits. The developer’s proposal is to replace the GET with a lookup that uses the hash as the primary key: given a hash, query any known mirror or cache for the matching blob, retrieve it, and verify the hash locally. The import path would then serve only as a human‑readable hint, not as a mandatory retrieval key. The remaining obstacle is expressing evolution: when a project wants to change its import path without breaking existing dependents, it must publish a mapping from the old path to the new one. In Go today this mapping is expressed with a replace directive in each dependent’s go.mod file, which must be edited individually; the developer notes that this does not scale because each consumer must be updated. A content‑addressable system would eliminate the need for such mappings: the hash remains constant, so the old path can simply redirect to the new location, or be ignored entirely, while the hash continues to locate the exact bits.
The same tension between mutable names and immutable content appears in many other technical and social arrangements. In medieval Europe, guilds stamped their wares with a hallmark that identified the maker and attested to purity. The hallmark was a trusted label, but it was only as reliable as the guild’s authority to enforce standards. When a guild dissolved or its hallmarks were forged, buyers could no longer rely on the mark to guarantee the metal’s fineness, even though the actual alloy of a particular object remained unchanged. The solution that eventually emerged was assay offices that tested the metal itself and applied a mark whose validity depended on the test result, not on the continued existence of the originating guild. The hallmark’s fragility stemmed from its reliance on a social institution that could disappear, whereas the metal’s composition is an intrinsic property that can be verified directly.
A comparable episode occurred in the United States during the late nineteenth‑century patent medicine boom. Manufacturers advertised remedies under distinctive brand names—Lydia Pinkham’s Vegetable Compound, Dr. Kilmer’s Swamp Root, Chamberlain’s Cough Remedy—promising cures that were often unverified. Consumers learned to associate the brand name with efficacy and safety, but the name itself was detached from any measurable property of the preparation. When a company went out of business, its formula could be lost or altered, yet the brand name lingered in advertising, leading consumers to purchase products that no longer matched the original claims. The Pure Food and Drug Act of 1906 responded by requiring that the actual ingredients be listed on the label, shifting trust from the brand name to the verifiable composition of the contents. The brand name remained useful for marketing, but it no longer served as the sole guarantee of the product’s identity.
In telecommunications, the North American Numbering Plan assigned geographic area codes and subscriber numbers as labels for telephone endpoints. For decades, changing a physical line meant changing the number, because the number was tightly coupled to the switch port. When number portability was introduced in the 1990s, the coupling was broken: subscribers could retain their numeric label while moving to a different provider or technology, because the network began to resolve the label to a routing identifier stored in a database, rather than to a fixed physical path. The label’s persistence now depends on a database lookup, not on the immutability of the underlying hardware, mirroring the shift from import‑path‑based fetches to hash‑based lookups in Go.
Library classification offers another illustration. Before the adoption of the International Standard Book Number (ISBN) in 1970, libraries relied on call numbers derived from the Dewey Decimal Classification or the Library of Congress Classification to locate books on shelves. Call numbers are convenient for browsing, but they are subject to revision when a library reclassifies its collection or when a book’s subject matter is reinterpreted. If a library changes its shelving scheme, the call number no longer points to the correct location without a massive re‑labeling effort. The ISBN, by contrast, binds a unique identifier to the physical embodiment of a text, independent of its subject categorization. Libraries can retain the ISBN as a stable key while freely altering call numbers for shelving or display purposes, just as a Go project can retain its import path as a hint while depending on the hash for retrieval.
In finance, stock tickers serve as short labels for securities on exchanges. Historically, ticker symbols were assigned by the exchange and could be reassigned when a company changed its name, merged, or delisted. Traders who relied on the ticker as a shorthand for a firm’s economic exposure faced risk when the symbol was recycled, because the new entity might have a completely different balance sheet. The introduction of the International Securities Identification Number (ISIN) in 1981 provided a fixed, ISO‑standard identifier tied to the security’s issuing entity and its terms, unaffected by ticker changes. Market data systems now use the ISIN as the primary key for pricing and risk calculations, while the ticker remains a human‑readable convenience, analogous to using a module’s hash as the core identifier and its import path as a optional hint.
Biological databases confront a similar problem. Genetic sequences are submitted to repositories such as GenBank with accession numbers that act as labels. Early versions of the database allowed accession numbers to be changed when a sequence was updated or when a submission was corrected, which broke downstream analyses that had cached the old label. Later versions introduced immutable versioned accession numbers (e.g., NM_001301717.1) where the numeric part remains constant and a version suffix tracks modifications, ensuring that any reference to the base accession always retrieves the same underlying sequence. The versioned accession functions like a content‑addressable hash: the label’s persistence is guaranteed by the immutability of the referenced data, while the version suffix safely records evolution without breaking existing links.
Across these examples, a recurring mechanism emerges: a system adopts a mutable, human‑friendly label as a proxy for an immutable piece of content or state; the label is convenient for communication, indexing, or trust, but it introduces a failure mode when the label’s binding to the content can be altered by the disappearance, transfer, or manipulation of the labeling authority. The failure manifests as broken links, misattributed trust, or the need for costly global updates whenever the label changes. The remedy is to decouple the label from the retrieval or verification process by anchoring the reference directly to the content’s intrinsic, tamper‑evident property—a cryptographic hash, an assay result, a serial number tied to the object's physical attributes, or a database key that is immutable by design. The label may still be retained for readability or legacy compatibility, but it no longer governs access to the underlying artifact.
The Go module ecosystem illustrates this mechanism in a contemporary software supply chain. The import path is the mutable label; the go.sum hash is the immutable content identifier. The current workflow requires the label to resolve the content, which creates a vulnerability when the label’s host disappears. Shifting resolution to the hash eliminates that vulnerability while preserving the ability to evolve the label through redirection or aliasing, because the hash remains constant across renamings. The scaling problem with replace directives is simply a symptom of trying to manage label evolution through per‑consumer edits rather than through a universal, content‑based lookup.
Because the mechanism is independent of any particular technology, it can be observed wherever a society or engineering team substitutes a name for a thing. The persistence of the name depends on the stability of the naming institution; when that institution falters, the name ceases to be a reliable pointer. Recognizing the coupling allows designers to replace it with a direct reference to the thing’s invariant signature, thereby removing the single point of failure that has repeatedly undermined reproducibility, safety, and trust across centuries and disciplines. The lesson is not that names are useless, but that they must never be the sole conduit for accessing the thing they denote.