If You Can't `chmod` It, You Don't Own It

5 min read 1 source clear_take
├── "Digital 'ownership' is a fiction — everything mediated by an auth server is a revocable tenancy"
│  └── cemdervis (dervis.de) → read

Argues that if you can't physically hold something, you don't truly own it — every digital purchase mediated by a remote authorization server is structurally a license, not a property right. The 'Buy' button is marketing; the EULA and the architecture both say the seller can revoke access at any time.

├── "This isn't theoretical — there's a documented track record of vendors revoking purchases"
│  └── @Hacker News commentariat (Hacker News) → view

Rather than debating the premise, top commenters catalog concrete incidents: Sony pulling purchased Discovery content from PlayStation libraries in 2023, Amazon remotely deleting Orwell from Kindles in 2009, Apple users finding purchased movies converted to rentals after region changes, and Google account terminations wiping decades of Play Store purchases. The pattern shows revocation is routine, not exceptional.

├── "The industry has stopped pretending — vendors now openly tell users to abandon ownership expectations"
│  └── @Ubisoft executive (cited in discussion) (Hacker News) → view

References the 2024 Ubisoft executive statement telling players to 'get comfortable with not owning your games' as evidence that the license-not-purchase model is no longer hidden in EULAs but is now stated policy. The quote is treated as a turning point where vendors stopped maintaining the ownership illusion.

└── "The structural problem is the developers' problem — we built the revocation endpoint"
  └── top10.dev editorial (top10.dev) → read below

Reframes the essay's resonance: HN's audience builds these systems, so the indictment lands on them. Every SaaS subscription, API key, and OAuth scope a senior engineer ships in 2026 is the same revocable-license pattern the essay condemns, meaning the gap between user expectations and system reality is something developers actively construct, not just inherit.

What happened

An essay titled *If You Can't Hold It, You Don't Own It* by a developer publishing under dervis.de hit 250 on Hacker News this week. The argument is unsubtle: anything mediated by a remote authorization server — Kindle books, Steam games, iCloud photos, your Notion workspace — is a tenancy, not a purchase. The button says Buy. The EULA says license. The architecture says revocable.

This is not a new claim. What's interesting is the audience. HN's commentariat builds the systems being indicted. The top comments don't push back on the premise; they catalog scars. Sony removing previously-purchased Discovery content from PlayStation libraries in late 2023. Amazon silently pulling Orwell — *Orwell* — off Kindles in 2009 and apologizing later. Apple users in changed regions discovering their purchased movies are now rentals. Google account terminations that vaporized a decade of Play Store purchases. Ubisoft's executive, on the record in 2024, telling players to get comfortable with not owning your games.

The essay's framing landed because it inverted the usual ownership debate: instead of asking what users get when they buy, it asks what developers build when they sell. And what they build is an auth check. Every "library" is a database row. Every row has a `revoked_at` column, or could.

Why it matters

The interesting part isn't the consumer grievance — that's well-litigated. The interesting part is that this is the operating model of nearly every product a senior engineer ships in 2026. SaaS subscriptions are leases. API keys are leashes. OAuth scopes are limited powers of attorney that the issuer can revoke at zero notice. We know this because we wrote the revocation endpoint.

The gap between how users feel about their data and how the system actually treats it is structural. A user thinks their Figma file is theirs the way a paper sketch is theirs. The system thinks it's a row in a multi-tenant Postgres database, accessible only when a JWT validates against a key that can be rotated, a billing status that can flip to delinquent, or a Terms update that can deprecate a feature. The phrase "your account" is doing an enormous amount of unearned work in modern product copy.

There's a second-order point worth naming. The shift from owned-bits to leased-bits wasn't an ideological choice — it was a consequence of how the economics of distribution evolved. Streaming is cheaper than shipping. Updates are easier than recalls. Subscription revenue is more predictable than unit sales. The licensing model isn't villainy; it's gravity. But the marketing language never caught up with the architecture, which is why the resentment compounds every time the architecture asserts itself.

Compare two ownership stacks for the same artifact — a book. The paperback has no auth check, no firmware, no remote kill switch; theft requires physical presence. The Kindle copy is a `.azw` blob plus a license check against Amazon's DRM service; revocation is one SQL UPDATE. The paperback degrades. The Kindle copy can disappear cleanly, with no degradation, the moment the publisher renegotiates rights. Different failure modes, very different sovereignty profiles. Most users intuit this only after the failure happens to them.

Developers have a third layer of awareness here that civilians don't: we know that even "local" software is usually phoning home. Adobe's Creative Cloud apps stop opening files if they can't reach a license server for too long. JetBrains products run on a check-in cadence. Even some open-core tools have telemetry that gates features. The line between owned and licensed has blurred to the point where the only honest test is the airplane test: pull the network cable. What still works in 30 days is what you actually own.

What this means for your stack

For your own tooling, the answer is not nostalgia. Vinyl-era ownership isn't coming back, and most engineers don't actually want it — version control, sync, and collaboration are net wins. The pragmatic move is to optimize for escape velocity: every tool should let you walk out with your data in a format you can read without it.

A short, opinionated checklist:

- Notes: plaintext or markdown on disk beats anything with a proprietary block model. Obsidian, Logseq, or just a folder of `.md` files. If your second brain lives in a startup's database, your second brain has a runway. - Mail: IMAP with local sync (mbsync, offlineimap) gives you a `.maildir` you can grep in 2040. Gmail-only is fine until it isn't. - Photos: an external SSD with a dated folder structure outlives every photo-cloud pivot. iCloud and Google Photos are convenience layers, not archives. - Code: self-hosted Git remotes (Gitea, Forgejo) as a mirror of GitHub cost ~$5/month and survive any GitHub account incident. - Books: if you can't strip the DRM with Calibre, you don't really have a library; you have a reading queue someone else manages.

For what you ship, the inverse applies. If you're building a product, your data export story is a moral position, not a feature request. A working JSON or CSV export, an API that returns the user's complete record, and account-deletion paths that actually delete are now table stakes for any product asking serious customers to depend on it. The companies that treat portability as a marketing burden are the ones whose customers wake up one morning realizing they're hostages.

There's also a fintech-shaped lesson here for B2B SaaS. Enterprise buyers have been pricing this risk into procurement for a decade — that's why escrow clauses, source-code escrow, and "perpetual fallback license" terms exist. Consumer software is finally catching up to what enterprise legal teams figured out in the 2000s: a vendor's continued existence is a dependency, and dependencies need fallbacks.

Looking ahead

The pendulum is twitching. Local-first software, as articulated by Ink & Switch, has moved from manifesto to shipped product in tools like Linear's offline mode, Tana, and the explosion of SQLite-based desktop apps. Self-hosting, once a hobbyist niche, now has serious deployment tools (Coolify, Dokploy, Caprover) and a thriving repo of one-click stacks on GitHub. The Fediverse exists. Plain-text formats are quietly enjoying their best decade since the '90s. None of this will dethrone the leased-bits model — it's too cheap and too convenient — but it does mean the engineers who care can opt out of specific dependencies without giving up modernity. The essay's title is a useful koan for the next architectural decision you make: not as a rule, but as a question. Can you hold it? If the answer is no, are you fine with that, or did you just not read the page where it said so?

Hacker News 456 pts 310 comments

If You Can't Hold It, You Don't Own It

→ read on Hacker News
knaik94 · Hacker News

I agree with the sentiment implied by the author, but I would reword it slightly. If you don't have the freedom to share something, you don't own it.I disagree with the interpretation that it needs to be held physically. Digital ownership is still ownership. I go out of my way to find musi

blfr · Hacker News

Just pirate it. They can't tell you this but there's a quagmire of rights, licenses, agreements, treaties... and you can untangle this Goridan Knot by just pirating, especially media, for your own use.There are pixel perfect 4k drm-free rips out there made by people who poured thousands of

ripe · Hacker News

Since I don't see it mentioned yet in the comments:In 2011, movie studios created a digital ownership service called Ultraviolet. You could own titles in your "UltraViolet Digital Rights Locker" and access them from multiple devices via third-party streaming services. [1]"The Ult

cube00 · Hacker News

Sony's one sentence notice is pretty grim considering how much money they made from these sales (sorry licensing).From September 1, 2026, due to our content licensing agreements, you will no longer be able to access your previously purchased content from Studio Canal, and it will be removed fro

jolmg · Hacker News

Tangential, but a few days ago I started some Steam games I hadn't played in some years. I was surprised to be met with updated user agreements, which I had to agree to if I wanted to play the games I bought years ago. These were all single-player games.> If you can't hold it, you don&#

// share this

// get daily digest

Top 10 dev stories every morning at 8am UTC. AI-curated. Retro terminal HTML email.