Live data from Hacker News

Less is safer: Reducing the risk of supply chain attacks

obsidian.md

261–270 of 274 posts

Re: Less is safer: Reducing the risk of supply chain attacks

#261

Earlier quoted context omitted.

I have my own Discord.profile! This is my ~/.config/firejail/Discord.profile[1]: include disable-common.inc include disable-devel.inc include disable-interpreters.inc include disable-shell.inc noblacklist /sys/fs noblacklist /sys/module keep-config-pulse keep-dev-shm name discord apparmor caps.drop all caps.keep sys_admin,sys_chroot netfilter nodvd #nogroups #noinput nonewprivs noroot notv #nou2f #novideo protocol un…

This is great. Thanks for the detailed reply!

It was not THAT detailed and it makes me feel a bit guilty, so if you have any questions let me know.

Re: Less is safer: Reducing the risk of supply chain attacks

#262

Earlier quoted context omitted.

You can't. But that wasn't the point, was it? Point is, you don't need Obsidian (or all of its plugin). People have been making do with Dropbox and plain text (.txt) files perfectly fine for years.

Wow I never knew I "can already build such a system yourself quite trivially by getting an FTP account, mounting it locally with curlftpfs, and then using SVN or CVS on the mounted filesystem". This is why people use Obsidian.

Plain-text folder on a cloud sharing service. Edit with notepad.exe or whatever editor you prefer. Others have been doing it with .doc files forever, or .rtf.

Re: Less is safer: Reducing the risk of supply chain attacks

#263
post #57

'It may sound obvious but the primary way we reduce the risk of supply chain attacks is to avoid depending on third-party code." What a horribly disingenuous statement, for a product that isn't remotely usable without 3rd-party plugins. The "Obsidian" product would be more aptly named "Mass Data Exfiltration Facilitator Pro".

That's just...what? It's highly usable without plugins. Yes, I use plugins...but that's by choice. Obsidian is still a superior Markdown editor with backlink support, plugins or not.

I think you and your fellow commenters are missing the point. The degree to which Obsidian is "a superior Markdown editor with backlink support" can be debated. What I'm saying is that actual usability, in this context, is not a matter of opinion -- see ISO 9241-210, ISO/IEC 25010, etc.. Having said that, I'm glad you're happy.

Re: Less is safer: Reducing the risk of supply chain attacks

#264
post #86

Earlier quoted context omitted.

Yeah, this is always the response. Usability can be assessed objectively, so you just have low standards.

A more charitable interpretation would be that that have different needs . My keyboard costs more than my computer, but most people probably spend $15-$50 on a keyboard. Even my mouse is well outside that range. Do I have high standards or do I have tendonitis?

Software usability, in this context, is measured objectively, there is no interpretation. This is separate from a specific user's preferences, the ergonomics of their hardware, etc.. As for your high standards vs tendonitis distinction, I'd say these things are not mutually exclusive, and the comparison is not related to what we're talking about.

Re: Less is safer: Reducing the risk of supply chain attacks

#265
post #264

Earlier quoted context omitted.

A more charitable interpretation would be that that have different needs . My keyboard costs more than my computer, but most people probably spend $15-$50 on a keyboard. Even my mouse is well outside that range. Do I have high standards or do I have tendonitis?

Software usability, in this context, is measured objectively, there is no interpretation. This is separate from a specific user's preferences, the ergonomics of their hardware, etc.. As for your high standards vs tendonitis distinction, I'd say these things are not mutually exclusive, and the comparison is not related to what we're talking about.

> Software usability, in this context, is measured objectively, there is no interpretation.

What is the objective measure of usability to which you are referring? I'm not aware of any such metric.

> As for your high standards vs tendonitis distinction, I'd say these things are not mutually exclusive, and the comparison is not related to what we're talking about.

The connection is that I have different needs in HIDs, just like some people have different needs in Obsidian. There are great ergonomic keyboards available for $50. I just can't use them.

Generally I buy the cheapest peripherals available. My standards are not all that high. Several of them have bugs I've learned to work around.

Re: Less is safer: Reducing the risk of supply chain attacks

#266
post #51

I love Obsidian dearly, but if you build an app that's only really useful with plugins, and that has a horrifyingly bad security model for plugins and little to no assurance of integrity of the plugins... Maybe, just maybe, don't give fullmouthed advice on reducing risk in the supply chain.

But what about VScode?

Do you hear the VSCode team talk about supply chain security?

Re: Less is safer: Reducing the risk of supply chain attacks

#267
post #264

Earlier quoted context omitted.

Software usability, in this context, is measured objectively, there is no interpretation. This is separate from a specific user's preferences, the ergonomics of their hardware, etc.. As for your high standards vs tendonitis distinction, I'd say these things are not mutually exclusive, and the comparison is not related to what we're talking about.

> Software usability, in this context, is measured objectively, there is no interpretation. What is the objective measure of usability to which you are referring? I'm not aware of any such metric. > As for your high standards vs tendonitis distinction, I'd say these things are not mutually exclusive, and the comparison is not related to what we're talking about. The connection is that I have different needs in HIDs,…

> What is the objective measure of usability to which you are referring? I'm not aware of any such metric.

Evaluators normally use scoring systems for this purpose, in which heuristic violations are rated on a severity scale (commonly 0-4). So when apps like Obsidian rack up many 3s and 4s, you have an objective basis on which to characterize it as unusable. Besides this, there are accessibility and security metrics consisting of pass/fail tests, which are countable.

I guess the best analogy would be a street vendor passing dog meat off as beef. You may think the dog is delicious, but that doesn't make it beef.

Re: Less is safer: Reducing the risk of supply chain attacks

#268
post #267

Earlier quoted context omitted.

> Software usability, in this context, is measured objectively, there is no interpretation. What is the objective measure of usability to which you are referring? I'm not aware of any such metric. > As for your high standards vs tendonitis distinction, I'd say these things are not mutually exclusive, and the comparison is not related to what we're talking about. The connection is that I have different needs in HIDs,…

> What is the objective measure of usability to which you are referring? I'm not aware of any such metric. Evaluators normally use scoring systems for this purpose, in which heuristic violations are rated on a severity scale (commonly 0-4). So when apps like Obsidian rack up many 3s and 4s, you have an objective basis on which to characterize it as unusable. Besides this, there are accessibility and security metrics…

That's interesting and thank you for sharing, but that does still seem like a judgment call and I would guess different companies would have different rubrics. Quantifying things is helpful but doesn't really mean that there isn't interpretation involved. Just that it's communicated more clearly and consistently.

I don't think the beef analogy is appropriate. For one it involves deception, and I don't think that's fair to Obsidian. For another Obsidian presents itself as a personal knowledge base, and is a personal knowledge base. Maybe it's a bad one. But that would make it inferior beef, not dog meat. If you think it lacks necessary features, a.) that would seem to me to be beef that needs some steak sauce and b.) the existence of people who do not use plug-ins would seem to empirically prove those features are not always necessary. Because different people have different needs.

Re: Less is safer: Reducing the risk of supply chain attacks

#269
post #244

Earlier quoted context omitted.

The game simulation will get more detailed/granular as aesthetics dial down in perceived value. You can always go bigger/wider/more procedural/more multiplayer. This is also why every hard problem eventually shows up — games are just simulation + interaction, and eventually everything that can be simulated will have some attempted implementation out there, struggling along. (For some reason, this does not appear to s…

The simulations have yet to release photo-realism in lieu of event-perception, where simulation parallels reality, but that's not really playable as a game, only as a view.

[deleted]

Re: Less is safer: Reducing the risk of supply chain attacks

#270

Earlier quoted context omitted.

Until there is a better alternative you’re left with electron. Nothing come close to obsidian.

There are better alternatives. It's just that people have convinced themselves they need the features Obsidian offers - because it makes them feel smart and important. At the end of the day, you're just taking notes. If you write a journal, don't put it in something like Obsidian. Even Apple Notes is better (in security, privacy, etc) in this regards.

Well I’m pretty convinced I need obsidian because it’s just the best way to manage stuffs and I hate overcomplicated stuffs.

I use it to remember stuffs and classify important informations, for instance I had issue fo years with my government to end my enterprise. I made a note in obsidian « enterprise closure » and every time there was a mail, I would save it as pdf and import it into the note. Same for every letter, scan -> import. I could put out my thoughts, next step, … on the note.

Because it doesn’t crypt notes or attachments, spotlight can index my notes and I can still search for the attachments.

And the back links are just a bonus because you always end up having multiple side note linked to a main note.

I have yet to see another software that allows me to do these kind of things. Apple notes absolutely sucks on attachments.

Putting attachments in folder with notes at the top is hard to search, things always get lost or duplicated.

I believe there are companies tools for that kind of things like « SERM » but then obsidian just works and it’s free.

Post reply on HN