Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
tony_codes
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
tony_codes
4y ago
it's ok, it's hacker news so I expected honesty which I appreciate. But What would you call an authentication mechanism which never passes the decryption key off the browser? It's an improvement over systems that handle the k
32.
▲
by
tony_codes
4y ago
the decryption key never leaves the browser. Maybe it's not perfect, but I'm not using the keywords because it's trendy, this project started out of an interest in more secure authentication and data security.
33.
▲
by
tony_codes
4y ago
writing is a tool to help us think. Since we have limited active memory to think with, the words act like storage which helps organise thoughts and cover more ground
34.
▲
by
tony_codes
4y ago
whoops, I can delete your account if you want to create a new one with the same login, just let me know.
35.
▲
by
tony_codes
4y ago
Thanks for the feedback! The hash is actually used to derive an actual key using PBKDF2 -- the library used is https://cryptojs.gitbook.io/docs/ Also, I'm interested if you see an attack vector on the authenticati
36.
▲
by
tony_codes
4y ago
I just deployed a fix for this; if you see this and happen to check let me know if it's better :)
37.
▲
by
tony_codes
4y ago
Sorry for that; I'm a backend engineer; still learning some of the frontend best practices. I just deployed a fix for this; if you see this and happen to check let me know if it's better :)
38.
▲
by
tony_codes
4y ago
just deployed a fix for this; if you see this and happen to check let me know if it's better :)
39.
▲
by
tony_codes
4y ago
just deployed a fix for this; if you see this and happen to check let me know if it's better :)
40.
▲
by
tony_codes
4y ago
one benefit of online is privacy. I've talked to many people that really don't like having a physical journal laying around with personal information that a partner might read. But yeah, I get there are workaround to that problem
41.
▲
by
tony_codes
4y ago
It would go the SAAS route if enough people find it useful; if there are consistent users I can't afford to make it free forever unfortunately
42.
▲
by
tony_codes
4y ago
Thanks a lot, this is really useful feedback. I completely agree the landing page branding needs some work. I've recently done some workshops to get some clarity on target audience and will try to tighten this up. Currently the app is
43.
▲
by
tony_codes
4y ago
Just bitcoin for us :)
44.
▲
by
tony_codes
4y ago
1/ For me it's similar to meditation in terms of the appeal. It's a way to slow down and think, not necessarily for measurable gain but to be a bit more present in the flow of things. I've learned a lot about myself as I
45.
▲
by
tony_codes
4y ago
thank you! It's an SPA build with React
46.
▲
by
tony_codes
4y ago
probably not in the near term, I want to make the webapp work well on mobile and encourage users to employ a keyboard when journaling
47.
▲
by
tony_codes
4y ago
Interesting, haven't heard this approach before.
48.
▲
by
tony_codes
4y ago
Thanks for the advice, yeah I'd like to add guided journaling modules and some optional prompts. Just knowing where to get started helps a lot with journaling
49.
▲
by
tony_codes
4y ago
some users hesitate to journal due to privacy concerns
50.
▲
by
tony_codes
4y ago
ah yes, thanks for posting that
51.
▲
by
tony_codes
4y ago
Built with serverless tools on the backend. AWS Lambda, dynamo, S3. ReactJs SPA for frontend.
52.
▲
by
tony_codes
4y ago
The main thing is that the encryption keys never leave the browser. So even an engineer in control of the backend cannot see the information being saved. With E2E encryption the owner of the data usually also handles the decryption keys.
53.
▲
by
tony_codes
4y ago
interesting; I benefited from the opposite, which was having a goal of filling one page. This acted as a sort of reward and feeling of accomplishment. But also found any expectations on quality tend to deter me.
54.
▲
by
tony_codes
4y ago
yes agree, thanks! The white paper is here https://docs.google.com/document/d/1T0SEj5WrymfyzNDD8rNGKQ2O... need to add to landing page
55.
▲
by
tony_codes
4y ago
I agree with the pain points you've highlighted -- but I think certain applications do benefit from zero-knowledge. Password managers for example. In the case of journaling, I think one reason people resist is fear of exposure. I agree
56.
▲
Show HN: Working on a Zero-Knowledge Daily Journaling App
(jumblejournal.org)
98 points
by
tony_codes
4y ago
|
106 comments
57.
▲
by
tony_codes
4y ago
Is Azure truly locked out from access to the decryption keys and access the unencrypted data (whilst being run against a model)? I followed the link but didn't find these details regarding their security model
58.
▲
by
tony_codes
4y ago
I did not have in mind a way to keep data on the customer premise, it's more about a verifiable zero-knowledge architecture so the data never leaves unencrypted, and the decryption keys never leave the secure enclave which decrypts the
59.
▲
by
tony_codes
4y ago
thanks a lot!
60.
▲
by
tony_codes
4y ago
that sounds difficult. Is it possible? Once the customer has access to the data, how can you guarantee they don't copy it?
More ›