4 ms·
The current implementation will look up any URL you visit so that it can populate the "number of comments" text that appears over the button. The data only goes
by jdormit 9y ago
The current implementation will look up any URL you visit so that it can populate the "number of comments" text that appears over the button. The data only goes to 1 server - hn.algolia.com, a HN search API provided by the company Algolia.
- chmod775 9y agoJust.... don't. There's so much that can go wrong with that, especially if this stuff eventually shows up in some data leak. Here's some examples: 1. URLs can contain sensitive data, which will tie your session to your person (facebook URLs etc) 2. This could create vulnerabilities in (for example) checkout flows that pass data via URLs 3. I'd rather not make the job of intelligence services easier than it already is 4. Sometimes I clear my browser history for a reason
- jdormit 9y agoAlthough I trust Algolia not to abuse their service, I understand why you do not. Maybe the "number of comments" display could be opt-in as well? Unfortunately, I don't think there's a way to get that particular UI feature without sending all URLs to some external server.
- nerdponx 9y agoYou can at least start by stripping all query parameters and anchors off of the URL. And instead of automatically piping everything to Algolia, just give the user a damn button.
- sunaurus 9y agoAlgolia doesn't even have to (intentionally) abuse their service. Request logs can be leaked through software bugs, malicious actors can gain access to their servers, etc. Trying to find matches for URL hashes would be a much nicer approach, but you would need a database of hashed URLs for that, so it's not a trivial fix.
- zeveb 9y ago> Unfortunately, I don't think there's a way to get that particular UI feature without sending all URLs to some external server. Look up the protocol that Google's SafeBrowsing[0] project uses. The short version is that your extension should check visited URLs against a locally-downloaded database of HN-posted URLs. For SafeBrowsing there's a bit more optimisation (e.g. hashing URLs & storing only hash prefixes to reduce the size of the database), but that's the short version. This secures the end user's privacy. [0] https://safebrowsing.google.com/ https://safebrowsing.google.com/
- jdormit 9y agoCool, thanks for the link! Sounds like there a bunch of security and privacy improvements I can make.
- jacquesm 9y agoAt least change it so it sends a hash of the URL to a server that knows the hashes of all the HN submitted posts. That way if there is no match you'd have to have hashes of all legal URLs to leak anything.
- tzs 9y agoDoesn't that still leak a fair amount? Suppose I'm an evil overlord and someone in my organization has been tipping off the FBI about my upcoming operations. I'm pretty sure it is one of my work-at-home minions. If I can obtain the hashes of the URLs that my minions have visited, I can look for a minion that has in their history the hash of https://tips.fbi.gov/ https://tips.fbi.gov/ and now I've got a good suspect.
- jacquesm 9y agoHow will you tie the relevant minion to the hash? You'd have to have a lot more than just that hash, the log would at least have to include a static IP or something that you can isolate by window-of-opportunity, for instance all the other minions were at a ballgame and the timestamp indicates that that one minion that wasn't at the ballgame visited tips.fbi.gov right then from an IP not associated with a stadium hotspot. Regardless, if you're going to leak stuff on 'evil overlord's organization you'd better make sure you don't do it from anything that can be associated with you, so not your laptop, not your IP, not your browser and certainly not with all kinds of weird plugins installed. Burner device and a location and time chosen so it could be anybody in 'the organization' leaking.
- yorwba 9y agoThe first submission on the "New Links" page that is at least 1 day old is number 1140 currently. The first item is 4137 days old. That yields an estimate of less than ≈4.7 million submissions so far, many of which are likely to be duplicates, flagged or devoid of comments. The hashes of all relevant posts likely fit in less than a megabyte, no need to contact a server, except to add fresh posts to the list.
- 9y ago