4 ms·
I might enjoy using this. But, PRIVACY! Sending back every visited URL has never been ok for any reason, first time I saw this idea shot down was in '93. But t
by atotic 11y ago
I might enjoy using this. But, PRIVACY! Sending back every visited URL has never been ok for any reason, first time I saw this idea shot down was in '93.
But there might be a way out:
I'd be willing to give up privacy of URL hashes. This is how I'd do it:
- you already track a set of URLs that have discussions (I assume). If not, you need to figure out how to seed these. Volunteers, APIs....
- hash these URLs on server, and use a not-too-unique hash function. You want to end up with a high collision rate, but not too high.
- now, the client can query for conversations without revealing the URL it has visited:
- ask server whether there are any conversations for a particular hash.
- if server finds any, it returns { pageUrl: '', conversationsUrls[]}
- now client can decide whether the url really matches, or it was just a random hash collision.
- I know this is not perfect. A privacy-busting determined enemy could generate hashes of large number of public sites and use statistics to infer what sites you've visited just from your hashes. But it'd be good enough for me.
Bonus money-making idea:
- offer your plugin as a paid service to different web communities. Increases their "community engagement".
I seriously contemplated starting an "annotations" startup in the 90s. Someone else did, and they folded after a few years.
- fowl2 11y agoThis is kinda how Google's Safe Browsing[1] works, although with a few extra layers, such as (IIRC) always requesting some random hashes when confirming matches. I read a better explanation on a mozilla mailing list once, but the key point is that it tries /really/ hard not to disclose private data. [1] https://developers.google.com/safe-browsing/developers_guide_v3#Overview https://developers.google.com/safe-browsing/developers_guide...