Show HN: Plus – Self-updating screenshots
21–30 of 126 posts
Re: Show HN: Plus – Self-updating screenshots
#22This seems like a spectacular way to break permissions restrictions and escape data to non-authorized entities. If it's successful, it's the sort of thing that will be brutally blocked by IT all over the place. Very slick, though.
Is it all that much more a risk than taking a screenshot, putting it on cloud storage like OneDrive/GDrive, and sharing with a "anyone who has the link" permission? B/c I feel like that is super common and kind of impossible to stop with a permissions approach.
The example video shows him taking a screenshot of an Amplitude dashboard using a browser plug-in. Thinking about how that’s possible, it must be skimming the session cookie off the browser, and using it to request the same page on Plus’s side to generate an image. You can imagine how that might be compromising.
Edit: you log in within the plus web app itself, which feels a little better. Still no totally secure way to do this but seems really useful.
Re: Show HN: Plus – Self-updating screenshots
#23Free to use for now.
Re: Show HN: Plus – Self-updating screenshots
#24Anyone do something similar?
Re: Show HN: Plus – Self-updating screenshots
#25This seems like a spectacular way to break permissions restrictions and escape data to non-authorized entities. If it's successful, it's the sort of thing that will be brutally blocked by IT all over the place. Very slick, though.
Is it all that much more a risk than taking a screenshot, putting it on cloud storage like OneDrive/GDrive, and sharing with a "anyone who has the link" permission? B/c I feel like that is super common and kind of impossible to stop with a permissions approach.
In other words, if Plus becomes popular, its database will become a prime target for hackers and three letter agencies.
Re: Show HN: Plus – Self-updating screenshots
#26Earlier quoted context omitted.
The nice thing about this approach, to my mind, is that it can turn interactive interfaces and make them "read-only". It also seems like a pretty safe way to send data from behind your firewall.
Stick an `opacity: 0` div in front of it to "disable" interactivity
Re: Show HN: Plus – Self-updating screenshots
#27Really interesting tool and not even quite sure how the technology works. It's opening it's own browser window (hidden) and capturing the same x/y pixels? Pretty clever. Also, does anyone know what this new design trend is called? The bordered / minimal-but-not look?
It feels like a call back to 90s print, like the magazines I remember as a kid. 3-2-1 contact and the like.
Re: Show HN: Plus – Self-updating screenshots
#28Hey, I helped build this! Thanks for submitting this. I'm an engineering manager at Plus — would be happy to answer anyone's questions about our product. You can also shoot me an email at zach(at)plusdocs.com if you'd like to hear more about what we're up to.
Re: Show HN: Plus – Self-updating screenshots
#29This seems like a spectacular way to break permissions restrictions and escape data to non-authorized entities. If it's successful, it's the sort of thing that will be brutally blocked by IT all over the place. Very slick, though.
Is it all that much more a risk than taking a screenshot, putting it on cloud storage like OneDrive/GDrive, and sharing with a "anyone who has the link" permission? B/c I feel like that is super common and kind of impossible to stop with a permissions approach.
Re: Show HN: Plus – Self-updating screenshots
#30It also circumvents 2fa, because sessions are leaked to Plus after you've used your TOTP code or Yubi key. How can any business be OK with this??