8 ms·
Show HN: Protect your links with a password
Keep your links safe and accessible only to authorized users
- solardev 2y agoIf it's just a redirect, isn't it going to be bypassed as soon as the first user shares the real URL?
- hosteur 2y agoThat was my thought as well. Not sure what the actual value is here.
- sigmoid10 2y agoEspecially since links can already be pretty private by default if they are random enough and not shared on any site where a crawler can access them. If you want actual security, you need to protect content on your end. If you don't really care and just don't want it publicly indexed, share it privately and keep it off the surface web.
- n_ary 2y agoI suppose it is the same concept as gumroad vendors. Most of them simply put an s3 url behind the gumroad paywall. Once you are done buying, the s3 url can be shared with anyone.
- solardev 2y agoI think the S3 URLs typically expire after a bit, at which point a new one would have to be generated the next time you need to re-download.
- n_ary 2y agoTrue, but most stuff I bought from gumroad, url never expires. Guess, we tech folks are conditioned to think too much into basics that non-tech folks don’t think about.
- jszymborski 2y agoI ran a similar service when In was in high school. People were using it to distribute links in public settings that were meant for small circle of folks. Lots of club newsletters were distributed this way. People also used it for selling files and things but as you've said it was trivial to defeat and only filtered out the least technical folks. It was surprisingly popular.
- mmanfrin 2y agoI, too, ran a similar service in high school. It also got weirdly popular, and then spammers started using it and the FBI sent a shutdown notice to my server provider while I was working at a summer camp (with no internet access) and all my sites got taken down for a week :(
- jszymborski 2y agoI shut down for similar concerns (phishing/spam), albeit before law enforcement required me to. I would certainly be running URLs through block lists, with a Report Abuse system if I were doing this today.
- graypegg 2y agoI guess since you’re going to have to give a password to someone, you can tell them not to do that. Though I’m a bit confused why this is even needed. The sort of thing most people want accessible via a link, but only for certain people, tend to already have unpredictable URLs. I’m not sure how https://gaggledocs.com/documents/aboevdowugwhoaofh https://gaggledocs.com/documents/aboevdowugwhoaofh Is different from https://protectmylink.xyz/owndoavwyagdo https://protectmylink.xyz/owndoavwyagdo + a password Especially when the original url is still publicly accessible on the internet. Additionally, you normally have much better authorization options in the app you’re linking to. I guess you get the benefit of a changeable link, unlike the canonical one? But then a link shortener is almost enough already.
- 8organicbits 2y agoDon't combine link shorteners with unguessable URLs, the result is a guessable URL.
- deleted 2y ago[deleted]
- oron 2y agoWhat's the biz model ?
- frankwiles 2y agoI hear what you're saying, but people DO just put stuff out there for it to exist and aren't necessarily looking to monetize it. Crazy I know :)
- BoorishBears 2y agoI hear what you're virtue signaling, but people DO have a right to wonder what will happen if a link redirect service runs out of money and kills their links
- solardev 2y agoThen it becomes even more secure! Passwordless, serverless, you name it.
- derefr 2y agoYou don't hear what they're saying. On HN, and especially regarding "infrastructure" services that you might depend on indefinitely for something, "what's the business model" isn't a question about how the service will be enshittified. Rather, it's a question of what incentive there is to keep a free service like this running. If there isn't one, then nobody should use the service, because it'll very likely get shut down as soon as it gets popular enough for its hosting costs to become nontrivial.
- ranger_danger 2y agoWhat's your alternative? Nobody wants a corporate solution, but they do want free services that fly under the radar. Of course not all of them last forever, but what better choice is there?
- bongodongobob 2y agoIt is crazy for someone to expect someone to use a service that has a 99% chance of getting shut down in a year when the domain name needs to be renewed. If there's no plan, there's no reason to use this for anything, ever.
- niqmk 2y ago[flagged]
- deleted 2y ago[deleted]
- bongodongobob 2y ago[flagged]
- n_ary 2y agoA hobby project does not necessarily have to be needed or valuable to everyone. The learning experience of the author is much more valuable.
- deleted 2y ago[deleted]
- derefr 2y agoI would point out that this will likely be used 99% of the time by people who want to charge for access to content... that they don't themselves own. If you've ever wandered the skeevier parts of the internet (the parts that a teenager not yet experienced at writing search queries might find themselves on if they were trying to e.g. download a software crack/keygen), then you'll frequently find that the pages you land are run by middle-men trying to grab some margin for themselves. You'll see sites that pretend to be e.g. a torrent tracker or direct-download website, but where all the links actually are indirected by a service like Adfly — a service that interstitials those links with pages full of ads, which pay out to the person who created the links. And these links often don't even go anywhere after the interstitial; the sites make money off of people hoping the site will work and therefore trying the links at least a few times before giving up. (This "dark pattern" of an Adfly link pointing at nothing, or at another Adfly link ad-infinitum, is so prevalent that most adblockers just block adf.ly altogether, since an adf.ly link almost never takes the user anywhere useful but is just stealing their attention to no end.) That's not exactly the parallel here — but I think that's a dark pattern that everyone here has experienced at least once. The pattern that is applicable here, is another one used by these same skeevy sites: the "unlock the Download button below by clicking the link above and filling out a survey" pattern. In theory, some of those might even work. (I've been curious and tried a few times, and I've never seen one that actually ever unlocks the Download button. Maybe because I'm not willing to disable my ad-blocker for the "survey"...) But this service seems perfectly positioned to be used by people building that exact scummy flow. "Go through stupid revenue-for-me-generating process A, and I'll give you the password required to follow link B." (Where link B likely isn't even to something the person themselves owns / has any right to be making money on, but just something they found hosted somewhere else and SEO MITMed themselves in front of.) --- I would note that anyone that actually wants to charge for their own original content these days... would likely use a platform that both hosts the content and protects it behind a paywall. Gumroad, for example, or Patreon. (Or OnlyFans, even.) Unlike a link-redirection service, these platforms protect the content to ensure that only the people who pay for it will be able to access it — people can't just bypass it by sharing the redirected-to link. (They can re-upload a download somewhere, but that's a much higher barrier to most people, e.g. on mobile.)
- 2y ago
- LVB 2y agoAlong the lines of some other comments here, this would benefit from some documentation about privacy, terms, are they trying to make a business from this, what they’re doing with the data, etc.
- jcabrera 2y agoThanks! I forget about it. I just added :)
- LoganSnow 2y agoAlternative that is open source and fully client side: https://jstrieb.github.io/link-lock/create/ https://jstrieb.github.io/link-lock/create/
- deleted 2y ago[deleted]
- deleted 2y ago[deleted]
- djaouen 2y ago[flagged]
- deleted 2y ago[deleted]
- pvg 2y agoOmit internet tropes. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- bluish29 2y agoThe choice of.xyz tld is not the best choice for a security service. It is one of the worst tlds when it comes to scam. https://news.ycombinator.com/item?id=28554400 https://news.ycombinator.com/item?id=28554400
- import 2y agoThe website was inaccessible for me then I remember I’ve blocked xyz domains in my AdGuard
- NayamAmarshe 2y agoGreat project! I too have an open source link shortener that supports password protected websites: https://maglit.me https://maglit.me
- deleted 2y ago[deleted]
- deleted 2y ago[deleted]
- zoidb 2y agoSo many link shortners eventually shut down due to people trying to obfuscate illegal stuff. Have you had any issue yet with that?
- NayamAmarshe 2y agoOh yes, of course! I had to remove links several times. Even around 2AM at night. I received so many phishing reports from Vercel and Cloudflare and even the Italian government directly. It was really tough so I had to add Google's Safe Browsing API check to check for any phishing links. I wish I didn't have to but no phishing reports since then.
- lambdaone 2y ago[flagged]
- deleted 2y ago[deleted]
- shahzaibmushtaq 2y agoTake this as a fun project to improve your coding skills.
- laurent123456 2y agoWould be more interesting if the link was encrypted client-side using the provided key. That wouldn't change the UX much and it means you can guarantee that the shared URL will remain private. But anyway I'd expect if someone is naive enough to use this website they would also share the URL and password using a single channel, which would be the same as not "hiding" the URL at all.
- thefilmore 2y agoEnd-to-end encrypted, open-source, ~250 lines of code, password optional, and not just for links - https://plic.cc https://plic.cc
- Algemarin 2y ago> Keep your links safe and accessible only to authorized users Is the operator of this service also able to access the links? If yes, then right away this claim is not true and merits caution: the random unknown owner of this service can now harvest links which were deemed sensitive enough to merit a password to access.
- jcabrera 2y agoHey! In the DB all links and password are encrypted. I only have access to the password if I access to the private url and then unlock the url
- dec0dedab0de 2y agoThis has got to be a scam. if your data need to be secure then use authorization and authentication. If you need to keep a link secret then don’t share it with some random website. This isn’t rocket surgery.
- edoardo-schnell 2y agoPlain text password?