8 ms·
My number one requirement for a tool like this is that the JSON content never leaves the machine it's on. I can only imagine the kind of personal information o
by einichi 4y ago
My number one requirement for a tool like this is that the JSON content never leaves the machine it's on.
I can only imagine the kind of personal information or proprietary internal data that has been unwittingly transmitted due to tools like this.
If my objective was to gain the secrets of various worldwide entities, one of the first things I would do is set up seemingly innocent Pastebins, JSON checkers, online file format convertors and permanently retain all submitted data.
- deleted 4y ago[deleted]
- Mogzol 4y agoCompletely agree. I could actually get a lot of use out of a tool like this, but the fact that even the VSCode extension sends the JSON to their servers and opens it at a publicly accessible URL makes this a no-go for me. I wouldn't recommend anyone use this for any remotely sensitive data.
- chii 4y agothe extension apparently can be configured to use a locally running instance of the server. But yes, by default it uses the remote version, and thus you post publicly the json, which may or may not be ideal depending on what you're doing.
- Mogzol 4y agoThe fact that it needs a server at all seems unnecessary. It's all written in JavaScript, and isn't doing anything that couldn't be done in a browser, I see no reason why this can't be an entirely client-side application.
- mholt 4y agoProcessing multi-GB files in the browser is... fun. Doing that kind of thing on a server is easier. *I'm not justifying doing it on the server, especially for an application like this where yes: it can be done in the client.* But I do sympathize because I know from experience why it's easier to do it server-side, without any conspiracies. I wrote Papa Parse[0] about 10 years ago, and back then at least, it was extremely difficult to stream large files in an efficient, reliable way. Web Workers make things slightly better, but there's so many issues with large-scale local compute in a browser tab. A few examples: - https://stackoverflow.com/questions/24708649/why-does-web-worker-performance-sharply-decline-after-30-seconds https://stackoverflow.com/questions/24708649/why-does-web-wo... (the answer actually came from Google+ which is still linked to, but no longer available; fortunately I summarized it in my post) - https://stackoverflow.com/questions/27081858/how-can-i-make-a-really-long-string-using-indexeddb-without-crashing-the-browser https://stackoverflow.com/questions/27081858/how-can-i-make-... You get deep enough into the weeds and eventually you realize you can make it work cross-browser if you know which browser you're using (YES, User-Agent does matter for things like this) and call you crazy for trying to find out: - https://stackoverflow.com/questions/27084036/how-can-i-reliably-detect-the-browser-without-using-window-navigator https://stackoverflow.com/questions/27084036/how-can-i-relia... Despite all this, I *100%* agree and local-only processing is also a hard-rule for me as well. (That's why JSON-to-Go[1] does it all client-side. `go fmt` event compiles to WASM and runs in the browser!) [0]: https://www.papaparse.com/ https://www.papaparse.com/ [1]: https://mholt.github.io/json-to-go/ https://mholt.github.io/json-to-go/
- rob74 4y agoOk, I think I get what you're saying - this is a VS Code extension, but because VS Code is an Electron application, it's still "running in a browser"?
- simplotek 4y ago> Processing multi-GB files in the browser is... fun. Doing that kind of thing on a server is easier. This sounds like a strawman. Not everyone wrangles multi-GB files, let alone JSON documents. Those who do are already readily aware of the implications. I mean,some popular text editors even struggle with multi-GB of plain text files. You don't need a server to handle JSON. There is no excuse.
- hutzlibu 4y ago"You don't need a server to handle JSON. There is no excuse." No technical excuse, but lots of buisness reasons I guess.
- rob74 4y ago"the extension apparently can be configured to use a locally running instance of the server" - well that sounds needlessly complicated, I mean, the code could be implemented directly in the extension (I know, that's probably easier than it sounds if you are trying to maintain both the extension and the online version with the same code base). "you post publicly the json, which may or may not be ideal depending on what you're doing" - that's never ideal, it's just a smaller problem (if the JSON is publicly available anyway) or a much bigger problem (if it's sensitive personal data).
- TeMPOraL 4y ago> or a much bigger problem (if it's sensitive personal data). Personal data is a red herring. It's not the only thing that matters. For starters, using this at work with anything not explicitly public is likely a violation of your contract. In some contexts, it may even be gross misconduct or illegal and potentially exposing your employer to large fines. And, in general, I'd say a tool like this that comes without explicit, bold warning that it's shipping data off your machine, is just being rude.
- pletnes 4y agoI agree, mostly. But since when isn’t it obvious that posting data with a browser will send that data somewhere? And the users here are (from what I can tell) developers. I think this is a cool tool for public data and obviously I can’t paste private data sets on any public website, ever.
- TeMPOraL 4y agoIt's not obvious ever since some of those tools started to blur the line; there are plenty of such little utilities that do everything client-side, or at least claim so. I don't use them with anything but public data, as it takes one mistake or one silent update for the data to get shipped off my machine, but there's a whole generation of devs now who were growing up with webapps and online-first software, so I can easily see some developers making this mistake. Plus, they offer a VS Code extension. It's not so obvious that it's just the same public website underneath. Additionally, developers who understand those concerns kind of expect that other developers also understand them, and thus would not create an on-line tool like this in the first place.
- kQq9oHeAz6wLLS 4y agoJust set up an online HL7 or better yet CCDA parser and let the PHI roll in.
- eallam 4y agoEric here (one of the creators of JSON Hero) and this is a really good point. We built JSON Hero earlier this year and partly wanted to use it to try out Cloudflare Workers and Remix, hence the decision to store in KV and use that kind of architecture. We're keen to update JSON Hero with better local-only support for this reason, and to make it easier to self-host or run locally.
- jessikat 4y agoIf the vscode extension did it all locally, I'd 100% install in an instant!
- donkeyd 4y agoTo add to this, I'd probably pay for this too, if it wasn't too expensive.
- T3RMINATED 4y agoIf the vscode extension did it all locally, I'd 100% install in an instant! DITTO
- epaulson 4y agoThere are instructions in the readme to 'run locally' - are you saying that even that version (running on localhost:8787) is sending something back to y'all, either from the client in the browser or sending something back via the locally-running server? I was totally about to clone this repo and run it locally so I can play with some internal json.
- cryptonector 4y agoTry WASM.
- alias_neo 4y agoPersonal requirements aside (I have the same requirements); just using this would constitute misconduct at the very least at my place of work. Yes it's a cool looking tool, but there are certslain requirements that ignorance doesn't exempt us from. My pet gripe is all of the seemingly local (open source) tools that phone home with opt-out metrics, not mentioned in the "getting started" and take some obscure flag to disable and it's just that little bit more complex to do when running the defacto (containerised) build.
- Jenk 4y ago> My pet gripe is all of the seemingly local (open source) tools that phone home with opt-out metrics, not mentioned in the "getting started" and take some obscure flag to disable and it's just that little bit more complex to do when running the defacto (containerised) build. Exhibit A: DotNet! https://learn.microsoft.com/en-us/dotnet/core/tools/telemetry#how-to-opt-out https://learn.microsoft.com/en-us/dotnet/core/tools/telemetr...
- alias_neo 4y agoOuch, this is particularly egregious: "...To opt out, set the DOTNET_CLI_TELEMETRY_OPTOUT environment variable before you install the .NET SDK"
- pseudonymcoward 4y agoThat's only for the telemetry that happens during the install process (if I've read the link correctly). Seems quite reasonable as long as we accept them sending telemetry during install. ("A single telemetry entry is also sent by the .NET SDK installer when a successful installation happens") For telemetry during actual use, you can set that flag any time, and a message is shown on first use to inform you about it. So seems relatively reasonable to me.
- simplotek 4y ago> That's only for the telemetry that happens during the install process (if I've read the link correctly). Wrong. That's for the dotnet cli tool to phone home each and every time you run a command. https://learn.microsoft.com/en-us/dotnet/core/tools/telemetry https://learn.microsoft.com/en-us/dotnet/core/tools/telemetr... Microsoft even provides a page which showcases summaries of some of the metrics they collect from you if you don't disable this feature. These metrics even include MAC addresses. https://dotnet.microsoft.com/en-us/platform/telemetry https://dotnet.microsoft.com/en-us/platform/telemetry > Seems quite reasonable as long as we accept them sending telemetry during install. There is nothing reasonable about this. You should not be required to have tribal knowledge on how to use arcane tricks prior to running an application just to avoid being spied upon. It's a dark pattern, and one that conveys a motivation to spy upon unsuspecting users whether they approve it or not.
- veltas 4y agoNo Dave, you can't upload this export-controlled document to this web tool. I don't care how convenient it is.
- wohfab 4y agoThis reminds me of an "Online HTML Minifier" website that analyzed the text and included affiliate links for random words within the text. And they operated for years, when someone noticed links on their own website, they haven't added themselves and tried to figure out, how it happened, because nobody else had access to the website. (Will update with a link, if I find it.)
- naan_bread 4y agoI agree. My tool flatterer: https://lite.flatterer.dev/ https://lite.flatterer.dev/ converts deeply nested JSON to csv/xlsx, is done in web assembly in the browser. It hard to prove that it is not sending data to a server, so it can be trusted. I know people could check dev tools but that is error prone and some users may not be able to do it. I wish there was an easy way to prove this to users as it would make online tools like this much more attractive.
- alpaca128 4y agoWould be nice to have the option to switch tabs into offline mode, just like we can mute them.
- informalo 4y agoYou can do that with Chrome dev tools: Network -> No throttling -> Offline Don't know how reliable this is though or whether a web developer could work around this.
- jspash 4y agoTurn off wifi? Unplug the ethernet cable? Try it from my garden shed where there never seems to be connectivity no matter what I try.
- ljw1004 4y agoI think there is an easy way to prove this to users. Make your thing be a single page self contained html file which they save into the hard disk. Then they can trust the restricted permissions with which chrome runs such local files. If you have a tech savvy audience they can also view your thing in an iframe with only sandbox="allow-scripts" to prove that it's not making network requests. I wrote an html/js log viewer with those security models https://GitHub.com/ljw1004/seaoflogs https://GitHub.com/ljw1004/seaoflogs - it handles up to 10kline log files decently, all locally.
- throw903290 4y agoEven more, it has to work completely offline! And if it makes ANY network calls, it is a huge red flag for some!
- ottoflux 4y ago100% literally came here to make sure someone said this.
- kwertyoowiyop 4y agoAll those free online .PSD utilities make my spidey-sense tingle.
- 2devnull 4y agoBetter yet, build an operating system and link it to the cloud.
- plusminusplus 4y agoThere's an issue on the github requesting a local version https://github.com/apihero-run/jsonhero-web/issues/134 https://github.com/apihero-run/jsonhero-web/issues/134
- syngrog66 4y agoyep if I were a Bad Guy and had nation state resources I'd be salivating over trying to get "in" at JetBrains, GitHub and the like