Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
j-berman
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
j-berman
6y ago
Got it. Not sure if this was clear here, but when you create an account on this site, the docs do sync to a server automatically. The encryption key is derived from users' passwords (Userbase handles that part). This way if users lose
2.
▲
by
j-berman
6y ago
There's also a challenge here where browsers will literally just start deleting data from IndexedDB if a user starts running out of space on their hard drive. I added this statement: "Keep in mind this is a demo app subject to cha
3.
▲
by
j-berman
6y ago
For starters, I think the number 1 most important thing is open sourcing code. Everyone should be able to read the entirety of the software's code themselves, verify the claim, build the app from source, and run it locally if desired.
4.
▲
by
j-berman
6y ago
Fixed. Sorry bout that. There was a circular reference in there when creating a new doc.
5.
▲
by
j-berman
6y ago
Oof, my bad. Not just you. Fixing now!
6.
▲
by
j-berman
6y ago
No worries, good question :) For one, conflict merging sounds like it could be a nightmare with that approach. Like imagine you have 10 people working on a doc at the same time, and they each have different versions. Hush Docs takes care of
7.
▲
by
j-berman
6y ago
Ah yes! Good point. Could work on a fallback for when IndexeDB isn't present :) It's probably still rough around the edges
8.
▲
Show HN: Hush Docs – private Google Docs alternative that works without internet
(demo.hushdocs.com)
42 points
by
j-berman
6y ago
|
15 comments
9.
▲
by
j-berman
6y ago
Hi HN, Hush Docs is an offline-first, private Google Docs alternative. You can turn off your internet and the site works totally fine. Your docs are stored in your browser (using IndexedDB/Dexie.js), so you can create and edit your doc
10.
▲
by
j-berman
6y ago
Should have been clearer, thank you! And thank you for the algorithm!
11.
▲
by
j-berman
6y ago
We use scrypt for password hashing. From the scrypt paper (which keep in mind is assuming hardware from 2002, and isn't assuming an attacker is using ASICs which have been developed since then), the estimated cost of hardware to brute
12.
▲
by
j-berman
6y ago
Adding to this, properly defending against enumeration also sacrifices a level of security in addition to privacy, since the average user would likely need to store some additional identifiable data (such as an email) in our database in pla
13.
▲
by
j-berman
6y ago
>You built a safe with no guard... and you're telling attackers where you put the safe. You are almost guaranteeing someone will compromise it eventually. Userbase is built on the assumption our entire database and server will be co
14.
▲
by
j-berman
6y ago
>Does it download the entire history of all transactions and replays them into the local database? This is what clients do initially, until the database grows in size. Every time the transaction log increases 50 KB, the client takes a sn
15.
▲
by
j-berman
6y ago
Userbase is built on the assumption that in the event an attacker compromises the Userbase server and database, the attacker would not be able to access protected user data. We chose this assumption to build on because we figure that users
16.
▲
by
j-berman
6y ago
Thanks for all the kind words :)
17.
▲
by
j-berman
6y ago
openDatabase loads the database's state into memory from the server, and then keeps it in sync with the server using the Web Socket. When you insert a transaction via one of the database operations, the server assigns the transaction a
18.
▲
Show HN: Userbase – Auth and E2E encrypted storage in a few lines of code
(userbase.com)
80 points
by
j-berman
6y ago
|
25 comments
19.
▲
by
j-berman
6y ago
Hi HN, Userbase is a tool for developers to build secure and private apps. We launched 1 year ago [1], and have worked hard to widen its use cases. Userbase offers built-in user accounts and authentication, an end-to-end encrypted zero-mana
20.
▲
Show HN: End-to-end encrypted SQL
(github.com)
2 points
by
j-berman
6y ago
|
0 comments
21.
▲
Show HN: Prinvoice – End-to-end encrypted invoicing
(github.com)
2 points
by
j-berman
6y ago
|
1 comments
22.
▲
by
j-berman
6y ago
Hey all, Prinvoice is a simple way to create and track invoices. You — and only you — have access to your own invoices. https://prinvoice.com Invoices are encrypted locally using your password, before being sent to the server fo
23.
▲
by
j-berman
6y ago
Thanks for the tip :) Halved the page load time with code splitting. It's still a relatively fat client that needs to get loaded at page load (handling end-to-end encryption + client-side SQL with sql.js), so there isn't too much
24.
▲
Show HN: Prinvoice – Create secure, private, beautiful invoices
(prinvoice.com)
5 points
by
j-berman
6y ago
|
5 comments
25.
▲
by
j-berman
6y ago
Hey all, Prinvoice is a simple way to create and track invoices. You — and only you — have access to your own invoices. Invoices are encrypted locally using your password, before being sent to the server for storage (thanks to Userbase htt
26.
▲
by
j-berman
7y ago
We looked at libsodium and its choices impacted our discussions on our system. We decided not to use it because it's not compatible with many browsers [0] We also discussed using a modern asymmetric key algorithm. We decided on Diffie-
27.
▲
by
j-berman
7y ago
If we were storing passwords in plaintext, I'd understand that comment Appreciate the apology :)
28.
▲
by
j-berman
7y ago
We expect developers using Userbase are looking to take solid steps toward preventing personal data misuse. This option is still a vast improvement over the alternative of sending all data to a server in plaintext. And even still, you have
29.
▲
by
j-berman
7y ago
Adding on to this, Firebase isn't structured to support end-to-end encryption by default. Our client-server architecture is built and optimized for that intention. I don't think you could build a performant end-to-end encrypted ap
30.
▲
by
j-berman
7y ago
This is tricky. If that single passphrase is mishandled, all of your user's data at rest is now vulnerable
More ›