Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
comntr
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
comntr
7y ago
(1) The author of this extension shouldn't have any powers to moderate comments. At the moment I can, but this will be fixed. I believe in a fragmented network with different rules about how to moderate content, or don't moderate
32.
▲
by
comntr
7y ago
In fact, I seriously considered ipfs. Then I tried to patch its severe connectivity problems with webtorrent dht. I even considered dat. But internet consists of symmetric NATs, that make any such DHTs hardly possible. An extension based on
33.
▲
by
comntr
7y ago
Yup. That's why I don't post my SSN everywhere. A single data server with all the comments without any moderation won't survive. But a group of data servers with different rules and many entry points via extensions or website
34.
▲
by
comntr
7y ago
Yep, it's possible in theory. Comments are signed with ed25519 and the author can sign a request to delete the comment.
35.
▲
by
comntr
7y ago
I guess my extension doesn't none of these. Will be fixed in v2.
36.
▲
by
comntr
7y ago
The extension does two things: - It sends sha1 of the url to the data server to check the numebr of comments, but doesn't pull the comments. - It renders an <iframe src="comntr.github.io#foobar.com"> to show the comment
37.
▲
by
comntr
7y ago
There is one in the extension page, but sure, I can add one to github.
38.
▲
by
comntr
7y ago
Why is this a problem? I even considered MD5, to be honest. Afaik, the only reason MD5 or SHA1 are considered "insecure" now is that it's possible to use sophisticated techniques called differential analysis to carefully craf
39.
▲
by
comntr
7y ago
The idea is very similar, but I can't agree with a few implementation details: - The extension shouldn't need to have access to the page. Inserting an iframe into the page seems wrong. - The extension shouldn't own the comm
40.
▲
by
comntr
7y ago
The extension can pull comments from multiple urls. But I think this situation is unique and most of the commentable content is hosted on static urls.
41.
▲
by
comntr
7y ago
No, I agree that this problem has to be solved before this idea can hope to get wide adoption. Mr A posts something really evil on Mr B's facebook page. What happens next? Mr B files a complaint to facebook. Since this is a legal matte
42.
▲
by
comntr
7y ago
So it effectively runs arbitrary javascript in the current page? I mean, if I run it on my online banking page, it'll have access to everything. The extension isn't ideal either - access to the current URL is too much - but at lea
43.
▲
by
comntr
7y ago
I think there should be many data servers with different rules. Some will blindly accept and serve any comments. Some will have mods and a buffer of comments waiting for review. Some will review only those comments that are flagged by their
44.
▲
by
comntr
7y ago
Data is the payment.
45.
▲
by
comntr
7y ago
There should be at least basic formatting filter that would block 1 MB comments or clearly non human written comments. This won't stop the spammers, of course. It should be time consuming to create a user id. It should be anonymous, bu
46.
▲
by
comntr
7y ago
[2] is very similar to what I want to do. They chose to insert an iframe into the current page and I don't agree with this decision: the extension should have as little access as possible to the page, ideally it only gets a hash of the
47.
▲
by
comntr
7y ago
Currently nothing. But I've only mentioned this extension to a small technical audience, so I wouldn't expect a flood of spam. In practice, this needs some sort of "local captcha" that doesn't involve 3rd parties, i
48.
▲
by
comntr
7y ago
All the data here is actually stored in indexedDb and localStorage. I guess I'll implement import/export next time.
49.
▲
by
comntr
7y ago
Yep, I didn't have to do much other then doing if(chrome.contextMenus){...} to make this extension run on Firefox and Firefox Android. But I intentionally chose the <iframe> approach to minimise the browser-dependent surface, so
50.
▲
by
comntr
7y ago
Thanks for the links! I'll do some research before rolling out v2 of my extension.
51.
▲
by
comntr
7y ago
Wow, it's surprising how much difference a proper post title makes. The v1 of this post had a long, but technically correct title without a link, but with a long, boring description about technical details with links. The post got like
52.
▲
by
comntr
7y ago
Apart from encrypting the comments so the server wouldn't be able to read them, I've been thinking that it's actually possible to leave private messages: it would be a comment on SHA1(user.publicKey), and the message would be
53.
▲
by
comntr
7y ago
I've deleted the previous "Show HN" post because it was messy and hard to read and replaced it with this one.
54.
▲
Show HN: A Firefox extension to leave comments on any URL
(github.com)
227 points
by
comntr
7y ago
|
235 comments
55.
▲
Show HN: Comntr, a browser extension to leave comments on any website
6 points
by
comntr
7y ago
|
1 comments