Eight shapes that name or locate something, gathered because they fail in the same way: they can be flawless as strings and still lead nowhere useful. The thesis behind that sits on what a shape proves.
Every card in this family documents a string whose only job is to designate. Each one stands in for a place, a record or a person, so that the place, record or person can be reached later, filed, or mentioned in a sentence without being described in full. That is the thread holding the eight cards together, and it is the reason they are worth reading side by side rather than one at a time.
Designation is a thin act, and the thinness is why this family exists at all. A pointer is correctly built or it is not; past that it makes no promise. The onion host printed above this text names a service. Naming is not the same as the service being there, being the one you had in mind, or answering at the moment you read the name. An order reference stands in for a record kept somewhere you cannot see. A username stands in for an account, and an account is a row in a table, not a person.
Two kinds of rule are mixed together here, and separating them before you read makes the cards easier to trust. Five of the shapes follow public formats that anyone can state in full: the current onion address, the older sixteen character form, the layout of a link, the percent escapes that can appear inside one, and the local part, at sign and domain of an email shaped string. Those rules hold whatever any particular site would prefer. The other shapes are house rules. An order reference is whatever the market decided it should be. A username is whatever the sign up form accepted. Where the rules are private, the card says so plainly instead of inventing a length.
This family is also where substitution would have to land, for the simple reason that substitution needs a target small enough to swap. Nobody rewrites a paragraph of prose to redirect you. They change the string that decides where you go next, or the string you paste into a payment field. That is not an argument for treating every broken pointer as an attack. Stale notes, careless copying, a chat client that swallowed the tail of a line, and a screenshot read at the wrong zoom account for far more malformed strings than anything deliberate ever will. Each card puts that in its own terms, because the balance of causes differs from shape to shape.
The remaining card, the host built from lookalike characters, is the odd one out. It documents a shape by documenting how a shape can be mimicked, and it turns out narrower than its reputation, because the alphabet available inside an onion host removes most of the classic imitation tricks before anyone can reach for them.
- The onion addressOne length, one alphabet, no punctuation inside, and a fixed suffix at the end
- The sixteen character onion addressThe older short form, and what meeting one says about the age of a note
- A mirror link that carries a pathScheme, host, path and query, and the one slash that separates two of them
- A host built from lookalike charactersConfusables, and why the onion alphabet deletes most of them before anyone can use them
- Percent encoding inside a linkA percent sign plus exactly two hex digits, and the shapes that hides
- An order referenceA shape whose rules are private, and how to read one anyway
- A usernameCasing, punctuation, invisible characters, and two names one character apart
- A string shaped like an email addressLocal part, one at sign, a domain with a dot, and the display name trap
What this family leaves to other families
Pointing is not the only thing a string can do, and the four other families collect the strings that do something else. Knowing where the borders run saves you hunting for a card in the wrong place.
Proof lives under keys. A fingerprint also identifies something, so at first glance it belongs here, but it identifies by standing in a fixed arithmetic relationship to key material rather than by being registered as a name. That difference changes every question you can usefully ask about it, so it is filed with the proof shapes.
Payment strings live under money. A Bitcoin address or a Monero address is a pointer in the purest sense, and it would sit comfortably in this family were it not for two things: the failure mode is a payment rather than a page, and those alphabets carry their own internal check digits, which changes the eye procedure completely.
Strings that point but expire live under session. The border between that family and this one is worth stating exactly, because two cards look similar from a distance. A mirror link that carries a path is filed here because the path is the interesting part. A link with a token inside it is filed there because the token is the interesting part, and because it stops meaning anything after a while. If the string in your hand loses value as time passes, look under session first.
Names given to blobs of bytes live under files. A filename names something too, but it names inside a container that somebody else controls, and the traps around it concern what a name conceals rather than where a name sends you.
One subject sits in no family, because it is not a shape. This reference holds no view on whether any address answers, and it runs no test of any kind against any of them. The three strings printed above every page are printed and nothing more; the addresses page says the same at greater length.