Am I the only one who thinks Obsidian is perfect without plugins? Half the reason I switched to it from Anytype was that it was rather spartan in its offerings. If they announced tomorrow they would ban plugins, I would not care.
I wouldn't say "perfect", but to me it's clear that adding plugins could only make it worse, even without considering the security issues. What I want from Obsidian is something that "just works". Adding third-party plugin would break this immediately since the plugins can either be straight up buggy, create conflicts with each other or simply become incompatible with new Obsidian releases. And what I've seen from th…
Obsidian plugin was abused to deploy a remote access trojan
161–170 of 241 posts
Re: Obsidian plugin was abused to deploy a remote access trojan
#162Earlier quoted context omitted.
This is pearl clutching. This feels like a massive overreaction. If you don't want to use it because it's not open source, that's fine, but you're spreading a lot of snarky FUD about the creators. They are not making excuses, they stated clearly why open sourcing it is tangential to this problem at best, and they're not the only user to call out the hijacking of the thread. They have been quite clear about why they k…
That's your opinion. I respect your choices and your opinions. I speak for myself. This is the first time I've seen this company's CEO post somewhere. I really couldn't trust this software less. To be fair, when someone comes up with excuses for not making something open source, it comes off as dishonest. Be honest. Say that you want to keep it closed to keep control and make money. There's no need to say otherwise.…
If you look at my GitHub profile[1] you'll see that the majority of my time is spent on open source. But my priority is open sourcing the tools and libraries I would want if I were building an alternative to Obsidian (Defuddle, JSON Canvas, Web Clipper, Importer, Flexoki, etc) because I believe all software is ephemeral and that files matter more than apps[2].
Obsidian is a free app made by seven people. If we were purely financially-motivated there are many levers we could have pulled, e.g. adding feature gates, not allowing alternatives to our paid services into the official directory, etc. But as I wrote in the tweet linked above, I have spent decades making open source projects and those have never paid the bills. So yes, there is some financial motivation behind that decision.
Re: Obsidian plugin was abused to deploy a remote access trojan
#163Earlier quoted context omitted.
This is pearl clutching. This feels like a massive overreaction. If you don't want to use it because it's not open source, that's fine, but you're spreading a lot of snarky FUD about the creators. They are not making excuses, they stated clearly why open sourcing it is tangential to this problem at best, and they're not the only user to call out the hijacking of the thread. They have been quite clear about why they k…
That's your opinion. I respect your choices and your opinions. I speak for myself. This is the first time I've seen this company's CEO post somewhere. I really couldn't trust this software less. To be fair, when someone comes up with excuses for not making something open source, it comes off as dishonest. Be honest. Say that you want to keep it closed to keep control and make money. There's no need to say otherwise.…
This is a wild take even coming from HN. Nobody needs an excuse to not make something open source.
This sort of entitlement does, and has done, far more damage to the OSS movement than anyone's "excuses" for not open sourcing their code. Full stop.
You can absolutely prefer open source software and choose not to trust closed-source apps. That’s all fair. But treating closed source itself as evidence of deception or impending betrayal is exactly the kind of ideological purity test that makes these conversations exhausting.
Re: Obsidian plugin was abused to deploy a remote access trojan
#164Re: Obsidian plugin was abused to deploy a remote access trojan
#165Love Obsidian but I've previously commented about the security model for plugins here: https://news.ycombinator.com/item?id=45308131 . TLDR: your entire vault (and possibly filesystem) is exposed to every single plugin you install. I really do think Obsidian needs 2 things to have any reasonable security: 1. It needs to be a lot more batteries-included. A user shouldn't need a plugin for basic functionality. 2. It ne…
Can I ask, what basic functionality is Obsidian missing in 2026? (I work on the app)
Re: Obsidian plugin was abused to deploy a remote access trojan
#166This is a misleading headline. It makes it seem like another supply chain attack where some good plug-in was taken over and used to deliver malware. Thats not the case here. Victims are invited to collaborate on a synced vault which comes preloaded with a non official plug-in that delivers the rat. Very very different story
"Novel Campaign Abuses Obsidian Note-Taking App to Target Finance and Crypto Professionals with PHANTOMPULSE RAT”
It’s novel (new), an abuse of Obsidian, specifically targeting a group of people.. and the RAT is embedded in the vault.
Re: Obsidian plugin was abused to deploy a remote access trojan
#167Love Obsidian but I've previously commented about the security model for plugins here: https://news.ycombinator.com/item?id=45308131 . TLDR: your entire vault (and possibly filesystem) is exposed to every single plugin you install. I really do think Obsidian needs 2 things to have any reasonable security: 1. It needs to be a lot more batteries-included. A user shouldn't need a plugin for basic functionality. 2. It ne…
> More batteries-included Can I ask, what basic functionality is Obsidian missing in 2026? (I work on the app)
Here are some feature I wish existed in Obsidian without any plugins:
* Dataview [1] (this is now solved with Bases, so I really appreciate that)
* Folder Note [2] (I, and I assume many others come from Notion, and I wish this were a thing)
* Recent files [3]
* A built in calendar [4]
* Link embeds [5] (or something to store previews for pasted links)
* Waypoint [6], or something to create a table of contents
These are just things I wish existed, but whether or not these are 'basic' can be debated. Ultimately I do wish there were a robust permission system for plugins so that personal functionality gaps can be plugged, but without compromising safety.
References: [1] https://blacksmithgu.github.io/obsidian-dataview/ [2] https://github.com/xpgo/obsidian-folder-note-plugin [3] https://github.com/tgrosinger/recent-files-obsidian [4] https://github.com/liamcain/obsidian-calendar-plugin [5] https://github.com/Seraphli/obsidian-link-embed [6] https://github.com/IdreesInc/Waypoint
Re: Obsidian plugin was abused to deploy a remote access trojan
#168Earlier quoted context omitted.
That's your opinion. I respect your choices and your opinions. I speak for myself. This is the first time I've seen this company's CEO post somewhere. I really couldn't trust this software less. To be fair, when someone comes up with excuses for not making something open source, it comes off as dishonest. Be honest. Say that you want to keep it closed to keep control and make money. There's no need to say otherwise.…
> when someone comes up with excuses for not making something open source This is a wild take even coming from HN. Nobody needs an excuse to not make something open source. This sort of entitlement does, and has done, far more damage to the OSS movement than anyone's "excuses" for not open sourcing their code. Full stop. You can absolutely prefer open source software and choose not to trust closed-source apps. That’s…
The business model is obvious. Sell the sync service.
Either way, that's your opinion.
Re: Obsidian plugin was abused to deploy a remote access trojan
#169This is a misleading headline. It makes it seem like another supply chain attack where some good plug-in was taken over and used to deliver malware. Thats not the case here. Victims are invited to collaborate on a synced vault which comes preloaded with a non official plug-in that delivers the rat. Very very different story
What’s misleading? "Novel Campaign Abuses Obsidian Note-Taking App to Target Finance and Crypto Professionals with PHANTOMPULSE RAT” It’s novel (new), an abuse of Obsidian, specifically targeting a group of people.. and the RAT is embedded in the vault.
Re: Obsidian plugin was abused to deploy a remote access trojan
#170Earlier quoted context omitted.
That's your opinion. I respect your choices and your opinions. I speak for myself. This is the first time I've seen this company's CEO post somewhere. I really couldn't trust this software less. To be fair, when someone comes up with excuses for not making something open source, it comes off as dishonest. Be honest. Say that you want to keep it closed to keep control and make money. There's no need to say otherwise.…
Consider a quick search. I have answered this question many times over the years, e.g. https://x.com/kepano/status/1701359669791670416 If you look at my GitHub profile[1] you'll see that the majority of my time is spent on open source. But my priority is open sourcing the tools and libraries I would want if I were building an alternative to Obsidian (Defuddle, JSON Canvas, Web Clipper, Importer, Flexoki, etc) because…
Some are OK with the use of a closed source note taking app. Perhaps an enterprise version with a different feature set might be useful to companies.
For notes written on my own computer, I use open source software to write and handle the sync myself.