5 ms·
I think I'm able to view all other gists. If I open the Gist on https://gist.github.com/ https://gist.github.com/ then go to the original gist at 'kobble-git/c
by abrussak 9y ago
I think I'm able to view all other gists.
If I open the Gist on https://gist.github.com/ https://gist.github.com/ then go to the original gist at 'kobble-git/channel-groups.json' I can navigate to all the forks and see data for other users.
- kobble 9y agoI'd just like to announce public and private repo support in Kobble. All data is now stored in a public or private repo, depending on how you log in.
- ytjohn 9y agoOh wow. Look at that. https://gist.github.com/kobble-git/87ea625d421177f9e9307c6cee259e63/forks https://gist.github.com/kobble-git/87ea625d421177f9e9307c6ce... And each fork is a link to a secret gist.
- elzi 9y agoAaaaaaaand revoked.
- mjmasn 9y agoA timely reminder that online services _have_ to prioritise security if they want to be taken seriously. I guess day one is a good day to learn that lesson though...
- zjs 9y agoOuch. It does seem as if anyone can view any users' content this way.
- kobble 9y agoI'm one of the Kobble devs. This is intentional. Please read the comments above about public and private use of Kobble. The intros on the web have been clarified also.
- stevejackson 9y agoThis isn't directly obvious, so I'll clarify. Anyone who has used this app - all of your notes are publicly available by following the link above. Everyone - revoke access to the app and manually delete all the gists it created in your account. To view anyone's notes, all you have to do is visit https://gist.github.com/kobble-git/87ea625d421177f9e9307c6cee259e63/forks https://gist.github.com/kobble-git/87ea625d421177f9e9307c6ce..., click anyone's "View fork", then follow the trail of gist links in the JSON.
- kobble 9y agoPlease read the comments above about the various uses of Kobble. Gists are for public use and sharing. Private repos are coming very soon for other use cases.
- vanderreeah 9y agoNot sure why this isn't at the top. This is crazy.
- kobble 9y agoI think we assumed that GitHub users would know that gists are not private. We added a clarification to the onboard slideshow. Support for public and private repos is coming, via GitHub Integrations.
- detaro 9y agoPeople probably would expect private gists to be reasonably private. They normally are, if you don't publish a global index of them... This is not users misunderstanding how gists work.
- kobble 9y agoWe are trying to clarify the multiple ways Kobble can be used. Gists are for public data that you want to share. Private repos (coming soon) are for private data. I think the intros on the web make this clearer now.
- danfromberlin 9y agoI quote from your website: "Don't worry if you don't know what GitHub is, you only need to create an account." You don't appear to make any assumptions that your users understand that their notes will be published and readable by anyone on the internet. Furthermore, your clarification: "Currently, Kobble stores all user data in secret GitHub Gists, under your account. Secret gists are not private." does not help because it does not explicitly state the fact that notes will be readable by anyone on the internet.
- kobble 9y agoI'm one of the devs on Kobble. Kobble is a versatile tool that can be used in a variety of ways. One way is as a content sharing platform. Gists are great for this purpose, because as you have noted, the discovery mechanisms are largely built into GitHub. Our use of gists for this purpose was entirely intentional. On top of that, we have built a flexible data model (similar to YouTube) for organizing and sharing the content. We are attempting to build an open content sharing platform where users have control over the data. For note taking, obviously you want private access. We will have support for private repos very shortly. This was stated in the intros, and we have improved the wording to make it clearer. Hope this helps.