15 ms·
Show HN: Comntr – a widget that adds comments to your page
- comntr 7y agoMy first post about the web extension idea got some interest (and almost 150 stars on github!), so I've made the next logical step: an <iframe> that renders the comntr.github.io page and effectively adds comments to your page. The spam problem is partially addressed by the filters: the iframe.src can have a special ?filter=[...] param that can hide some of the comments you don't like. Although it's unlikely one can bypass the security model around those filters (but you are welcome to try!), advanced spammers can still post a lot of garbage to those comments as they can easily generate new ed25519 keys.
- comntr 7y agoAlso, it's already possible to have your own comntr server: you just need to git clone the comntr/http-server repo, npm install & npm start it, and tell the iframe to use your server with ?srv=https://foobar.com:42751 https://foobar.com:42751. This would be an "on-prem" solution.
- jeremyjh 7y agoThe hard problem in this space is spam prevention. Its not immediately clear me to if this even addresses it? Other than giving ban/filter controls to a human.
- eeeeeeeeeeeee 7y agoCurious about this too. I don’t like using Disqus (it’s so bloated) but the spam issue is pretty much non-existent even on several high-traffic sites.
- unmole 7y agoHave you checked out Commento? It's open source and pretty lightweight: https://commento.io/ https://commento.io/
- cmroanirgo 7y agoInteresting. Thanks for sharing. > Commento is a proud recipient of the Mozilla Open Source Support award. The $19,200 grant was given in recognition of Commento's contributions to make the internet more privacy-friendly. That said, it uses akismet for spam control, which I'm not sure how trustworthy it is... But definitely better than nothing!
- strokirk 7y agoFWIW, we've been using Akismet for the last 10 years on at my company, and are very happy with it.
- cmroanirgo 7y agoHappy or not, I'm not sure that too many people seem to appreciate the data leakage that happens through WordPress and their affiliated products (such as Akismet). Considering how much people comment negatively about Gooogle Analytics, I'm always surprised that WordPress & co manages to slip under the radar, constantly. From https://automattic.com/privacy-notice/ https://automattic.com/privacy-notice/ (the owners of Akismet): > Site Comments: When a visitor leaves a comment on a Site, we collect that comment, and other information that the visitor provides along with the comment, such as the visitor’s name and email address. > Technical Data from a Visitor’s Computer and Etcetera: We collect the information that web browsers, mobile devices, and servers typically make available about visitors to a Site, such as the IP address, browser type, unique device identifiers, language preference, referring site, the date and time of access, operating system, and mobile network information. > We may determine the approximate location of a visitor’s device from the IP address. We collect and use this information to, for example, tally for our Users how many people visit their Sites from certain geographic regions. If you’d like, you can read more about our Site Stats feature for WordPress.com sites and Jetpack sites. > Akismet Commenter Information: We collect information about visitors who comment on Sites that use our Akismet anti-spam service. The information we collect depends on how the User sets up Akismet for the Site, but typically includes the commenter’s IP address, user agent, referrer, and Site URL (along with other information directly provided by the commenter such as their name, username, email address…oh, and the comment itself, of course). > A cookie is a string of information that a Site stores on a visitor’s computer, and that the visitor’s browser provides to the Site each time the visitor returns. Pixel tags (also called web beacons) are small blocks of code placed on Sites. Automattic uses cookies and other technologies like pixel tags to help identify and track visitors and Site usage, and to deliver targeted ads > We also collect any other information that our Users provide to us about visitors to their Sites. For example, a User may upload a directory or other information about Site visitors and customers to the “backend” administrative platform for managing the Site. How We Use Visitor Information > We use information about Site visitors in order to provide our Services to our Users and their Sites. Our users may use our Services to, for example, create and manage their Site, sell products and services on their Site, flag and fight comments from spammers, and collect information through polls, quizzes and other surveys. > We may also use and share information that has been aggregated or reasonably de-identified, so that the information could not reasonably be used to identify any individual. For instance, we may publish aggregate statistics about the use of our services. Then there's Gravatar, which is another method of user tracking and I'm sure there's a slew of other ways.
- nexuist 7y agoThis is really cool! One step closer to a decentralized Web.
- personjerry 7y agoAll the comments would be hosted on this site; It's actually centralized.
- comntr 7y agoThat's right. My first attempt was to use IPFS or DAT. Figured out it's not quite possible, but we can get very close to that, in theory. Imagine the extension or the iframe could run a ipfs.js or dat.js that would discover all the http servers with comments via DHT: servers that want to participate, publish a unique key to the DHT and the web clients discover this key and then the IP addresses of the servers. In practice, this doesn't quite work because DHTs are based on the assumption that any node can quickly ping (with a UDP packet) any other node and thus perform the DHT discovery using the Kademlia algorithm in log(N) steps. But in the web, the only way to "ping" someone is to set up a p2p connection with WebRTC: this not only needs a signaling relay, but also implies a multi step exchange with SDPs and has other costly overhead. And I haven't even approached the Symmetric NAT problem. This is why ipfs.js hogs CPU, allocates a 1 GB and keeps 4-8 sockets always open (they aren't even p2p now, but rather web sockets to some relay, for perf reasons).
- nexuist 7y agoIt is technically centralized but with the option to self host the comments server. Given that the source code is out there for a minimalist comments server, that saves a ton of work for anyone who just wants to make a blog/social site and doesn't necessarily want to build a full fledged REST service for it.
- keithnz 7y agoso where's the data getting stored? in a database you are hosting?
- buzzerbetrayed 7y agoOr one you're hosting. You can self host the server, as explained in OP's comment on this thread.
- michelle2019x 7y agoInteresting, a new step in the evolution of the Internet Regards, Michelle My site https://outdoorsly.org/ https://outdoorsly.org/
- jteppinette 7y agoI like all the XSS attack tests in the demo.
- jugg1es 7y agoCan it add vowels to registered trademarks?
- report212312421 7y agowas able to inject script via the username https://github.com/comntr/http-server/blob/master/src/handlers/comments.ts#L22 https://github.com/comntr/http-server/blob/master/src/handle...
- comntr 7y agoYea, I missed the obvious one!
- mouzogu 7y agoIt's a nice idea, not a fan of the name if i'm being honest. Although I know that names are hard.
- pedro1976 7y agoCan i simply prefix any url with commentr.io to get to the comments section? Some time ago i did a scroing and visualization of reddit threads, maybe you find it useful, see https://migor.org/reddit/#/discussion/top?url=https:%2F%2Fwww.reddit.com%2Fr%2Fworldnews%2Fcomments%2F3rlu3g%2Ffull_text_of_the_tpp_has_just_been_released https://migor.org/reddit/#/discussion/top?url=https:%2F%2Fww...
- comntr 7y agoYes, this is how it works: comntr.github.io#http://foobar.com/ http://foobar.com/
- darekkay 7y agoThis sounds interesting. I've added Comntr to my extensive blog post about static site comments [1]. [1] https://darekkay.com/blog/static-site-comments/ https://darekkay.com/blog/static-site-comments/
- comntr 7y agoI think, "comntr" is more like "integrated 3rd party" that can be run like a self hosted solution.
- darekkay 7y agoThanks for the clarification, I've updated the description
- gitgud 7y agoThat's a great collection of libraries for a common problem that many people run into. If you're interested, I made a library for [1] hacker news comments on static sites. Let me know what you think. [1] https://ycomments.benwinding.com/ https://ycomments.benwinding.com/
- zimbatm 7y agoIn the same space: https://utteranc.es/ https://utteranc.es/ A lightweight comments widget built on GitHub issues.
- funkythingsss 7y agoHow is this different from gabs dissenter?
- mro_name 7y agoto just get a few comments (not quick, unmoderated discussions or in the thousands), a radical strip-down may suffice – neither server-code nor JavaScript, let alone a 3rd party: Pure atom xml rendered to html client-side via xslt in an iframe. No comment markup. Feel free to express yourself in unicode. See e.g. at https://mro.name/blog/2009/08/nsdateformatter-http-header/ https://mro.name/blog/2009/08/nsdateformatter-http-header/