Live data from Hacker News

The Future of Obsidian Plugins

obsidian.md

171–180 of 186 posts

Re: The Future of Obsidian Plugins

#171
post #30

Obsidian CEO here. We've been working for nearly a year to launch this new Community site and review system. I'm very excited about this first version but there are many more improvements to come. I've tried to be exhaustive with the blog post, FAQs, and next steps on our roadmap, but I am sure I forgot some things, so feel free to ask! This has been an incredibly challenging project for a number of reasons. We're on…

A bit of UI/UX sand: Store the scroll position when navigating the list.

User clicks on a project, views the details and returns to the same position in the list (including all the expansions via “Show more”)

Re: The Future of Obsidian Plugins

#172
post #125

Earlier quoted context omitted.

> the enshittification A strong reason to stick to using Obsidian as just a Markdown editor and not get sucked into the plugin ecosystem at all. If your Obsidian vault is just a folder of Markdown files, you're ready to leave at a moment's notice. If I ever go in on some plugin ecosystem, it'll be FOSS, non-commercial, and have been around long enough to drink. (Emacs?) Haven't felt the need; a Markdown vault for ref…

If I just use obsidian as a markdown editor without plugins, I have no need for obsidian.

It has a nice and fully-featured editor, it syncs reliably between devices and it has a mobile app for notes on the go. I don't see why I wouldn't use it.

(What a weird false dichotomy? As if the only two choices were either to extract every possible pound of flesh from something, or not use it at all?)

Re: The Future of Obsidian Plugins

#173
post #137
post #133

Earlier quoted context omitted.

I have indeed read the blog post. Can you point out which part of my post is inaccurate? It is certainly possible I misunderstood something. Surely you're not about to claim that asking plugins to "disclose" what resources they use is in any way comparable to sandboxing and permissions.

As I wrote, yes, a permission system is planned. But 1. we cannot oversimplify the problem of getting from here to there, 2. permissions are not a panacea. If you look at the scorecards for a few plugins you'll immediately see issues that a permission system wouldn't catch. Millions of people depend on thousands of Obsidian plugins. We cannot just flip a switch and break everyone's workflows overnight. It will be a g…

No, I don't agree. Asking plugins to pinky-promise which resources they will and will not use is absolutely meaningless from a security perspective. If anything, it engenders a false sense of security in end users, and continues a pattern whereby Obsidian tacitly endorses things that are inherently risky.

The fundamental issue here is that the current plugin model is intrinsically broken, and tinkering around the edges is just a diversion of efforts from clearing that tech debt. It doesn't need to happen overnight, but it does need to happen.

The meaningful improvement here is the promise of sandboxed plugins in the future, assuming I understood correctly, and that's just a fairly vague promise at this stage. I absolutely and in full earnestness wish you guys the best with that one. It will meaningfully improve Obsidian and make it easier to recommend to others.

Re: The Future of Obsidian Plugins

#174
post #173
post #137

Earlier quoted context omitted.

As I wrote, yes, a permission system is planned. But 1. we cannot oversimplify the problem of getting from here to there, 2. permissions are not a panacea. If you look at the scorecards for a few plugins you'll immediately see issues that a permission system wouldn't catch. Millions of people depend on thousands of Obsidian plugins. We cannot just flip a switch and break everyone's workflows overnight. It will be a g…

No, I don't agree. Asking plugins to pinky-promise which resources they will and will not use is absolutely meaningless from a security perspective. If anything, it engenders a false sense of security in end users, and continues a pattern whereby Obsidian tacitly endorses things that are inherently risky. The fundamental issue here is that the current plugin model is intrinsically broken, and tinkering around the edg…

It's not tacit, it's explicit. People should have the freedom to do dangerous things as long they understand and accept the risks. I'm not interested in making software that imposes limits on what a person can do with their own computer.

I completely understand if you disagree, in which case Obsidian is not for you. It's perfectly fine to not recommend it! Obsidian is not trying to be for everyone.

See also: https://stephango.com/saw

Re: The Future of Obsidian Plugins

#175
post #139

Earlier quoted context omitted.

This is fantastic news. Just a few days ago I mentioned [1] the Obsidian Community Plugins model was broken and needed an overhaul. This is a step in the right direction. If I may, two suggestions: 1) Allow the user to filter for plugins based on the desired level of strictness (manually reviewed, safety rating, etc). 2) The Disclosures seems a bit too lenient. For example, the popular Templater plugin [2] gets a 92…

1) Yes. Working on it. (You can already partially do this e.g. ?score=90) 2) Yes. You will see these radically improve over the next few weeks. As stated on the scorecard itself they are a work in progress. You have to consider that overnight we intentionally exposed tens of thousands of warning messages across thousands of plugins, so there will be false positive, false negatives, and severity tweaks as we gather fe…

This is awesome news. Thank you for the great work, and being so open to suggestions from the community. That's what makes Obsidian a world apart from all its competitors and predecessors.

Re: The Future of Obsidian Plugins

#176
post #30

Obsidian CEO here. We've been working for nearly a year to launch this new Community site and review system. I'm very excited about this first version but there are many more improvements to come. I've tried to be exhaustive with the blog post, FAQs, and next steps on our roadmap, but I am sure I forgot some things, so feel free to ask! This has been an incredibly challenging project for a number of reasons. We're on…

Nice! It was pretty easy to take my extension[1] from a middling Health and Review score to in the green. The obsidian eslint extension is helpful. [1] https://github.com/joeriddles/extended-task-lists

Same, very cool DX. A Markdown report of issues would be nice to have though to save a few tokens ^^

Re: The Future of Obsidian Plugins

#177
post #59

Earlier quoted context omitted.

Got any cool plugins you recommend? I'm finally getting comfortable after switching from OneNote and getting sync set up.

IMO Obsidian is currently the king of "personal software frameworks". You can look at YT channels for inspiration of what other people are doing, but I'd avoid trying to copy someone else's setup (for the vague promise of productivity), and instead just start to tinker and tailor your environment to yourself. The base experience is really good. What matters most is that you spend time actually writing useful things d…

Fully agree with you

Context Management for teams deserves more attention. I'm focused on this at work. Some of that will be covered in my upcoming videos

Re: The Future of Obsidian Plugins

#178
post #13

For those not aware, it has basically been impossible to submit new plugins due to the manual review (and how easy/fun it is to write a plugin with AI). The developer community was becoming increasingly frustrated, and the team was burning out under the load. So congrats to the team! This relieves a huge scaling bottleneck. It has been really cool to see how y'all build and scale.

Got any cool plugins you recommend? I'm finally getting comfortable after switching from OneNote and getting sync set up.

Check out my article: https://www.dsebastien.net/the-must-have-obsidian-plugins-fo...

Re: The Future of Obsidian Plugins

#179
post #126

No permissions system, nothing resolved. Plugins still have access to everything - full disk, network, etc. How does one even speak of security vulnerabilities when the security model of Obsidian plugins is just straight up "click here for RCE". All I see is a spanking new interface that will accelerate the pace of plugin turnover, bringing forward the next inevitable security incident.

This is a HUGE improvement to the status quo. Give it some time. They do care

Re: The Future of Obsidian Plugins

#180
post #174
post #173

Earlier quoted context omitted.

No, I don't agree. Asking plugins to pinky-promise which resources they will and will not use is absolutely meaningless from a security perspective. If anything, it engenders a false sense of security in end users, and continues a pattern whereby Obsidian tacitly endorses things that are inherently risky. The fundamental issue here is that the current plugin model is intrinsically broken, and tinkering around the edg…

It's not tacit, it's explicit. People should have the freedom to do dangerous things as long they understand and accept the risks. I'm not interested in making software that imposes limits on what a person can do with their own computer. I completely understand if you disagree, in which case Obsidian is not for you. It's perfectly fine to not recommend it! Obsidian is not trying to be for everyone. See also: https://…

I'm a programmer, I have zero fear of programmable tools, and it's a clumsy attempt to divert from my point to suggest I do.

You're creating a false dichotomy. A well designed sandbox with accurate permissions is HOW a person "understands and accepts risks". A system whereby a plugin pinky-promises one thing, and then does another, precludes informed consent.

Obsidian tacitly endorses this ecosystem because it is profitable for Obsidian to point to plugins for missing base functionality, and then throw up its hands and pretend like it's not their problem when something inevitably goes pear-shaped. That's how we end up with "warning screens" that in fact encourage the user to press "Yes". (And, as in the recent security incident, Obsidian then disclaims any responsibility when the user does click Yes, despite the heavy encouragement by Obsidian.)

Not hard to see why a business would act this way - all profits are ours and all risks are someone else's - but spare me the faux moralising about software freedom.

It is surreal to claim that a well defined sandbox with accurately described permissions is somehow against freedom. It would be a far more robust, trustworthy and empowering plugin ecosystem than the one Obsidian has now.

> Obsidian is not for you

Ooft.

And a lot of other HN commenters and other tech-savvy users with my exact concerns, apparently.

Somehow, most other software doesn't have this recurrent problem of mainlining third party malware to their users. See you at the next Obsidian "security incident", I guess?

Post reply on HN