Tells me everything I need to know about this industry. No regard or seriousness to security at all.
Notion leaks email addresses of all editors of any public page
91–100 of 162 posts
Re: Notion leaks email addresses of all editors of any public page
#92Notion’s macOS app is some of the worst software I’ve ever used. If there is a platform design idiom, they likely break it without a second thought.
Re: Notion leaks email addresses of all editors of any public page
#93Hi, this is Max from Notion. First: This is documented and we also warn users when they publish a page. But, that’s not good enough! Second: We don’t like this and are looking at ways to fix this either by removing the PII from the public endpoints or by replacing it with an email proxy similar to GitHub’s equivalent functionality for public commits. P.S: Some folks here have speculated that this should be a 1 minute…
4 years.
Re: Notion leaks email addresses of all editors of any public page
#94Earlier quoted context omitted.
Can you share the warning? I made a public page and would say it was not clear to me this was a consequence of doing that. The warning as I remember it (a month ago) makes it sound like the information on this page is going to be public -- not - oh yeah the email addresses of everyone who edited this page will also be leaked.
When you start contributing to a page you see this: https://cleanshot.com/share/trYdqYFZ This is pretty meh. We will deploy more explicit messaging while we mitigate this properly.
Re: Notion leaks email addresses of all editors of any public page
#95Earlier quoted context omitted.
For a personal knowledge base? I would stay far away from anything proprietary for personal notes. I love logseq though I'm increasingly worried it's abandonware
Logseq was captured by VC a long time ago. They switched from open files to a database, their synching product is closed source (not selfhostable), and they have built-in telemetry.
Re: Notion leaks email addresses of all editors of any public page
#96Very timely. I literally ran a Claude prompt "compare and contrast Notion vs Obsidian" and flipped over to HN while it was thinking, and this comes up. Thanks HN!
For a personal knowledge base? I would stay far away from anything proprietary for personal notes. I love logseq though I'm increasingly worried it's abandonware
Re: Notion leaks email addresses of all editors of any public page
#97Earlier quoted context omitted.
For a personal knowledge base? I would stay far away from anything proprietary for personal notes. I love logseq though I'm increasingly worried it's abandonware
https://anytype.io/ is the open-source CC of Notion AFAIK.
Re: Notion leaks email addresses of all editors of any public page
#98Hi, this is Max from Notion. First: This is documented and we also warn users when they publish a page. But, that’s not good enough! Second: We don’t like this and are looking at ways to fix this either by removing the PII from the public endpoints or by replacing it with an email proxy similar to GitHub’s equivalent functionality for public commits. P.S: Some folks here have speculated that this should be a 1 minute…
Re: Notion leaks email addresses of all editors of any public page
#99Earlier quoted context omitted.
A terrorist works with terror (fear). Also at least in democracies you can reject the government without physical violence.
> in democracies you can reject the government No, you cannot. You can reject the current party, but the government is much more than that. In the US, for example, the government is a set of institutions that were put in power in the American revolution. If you try to reject this your own life is at risk.
The U.S. government is confident enough in their appearance of legitimacy that they allow pretty broad liberty to criticize it. This is in contrast to other governments like China or Russia or even Singapore which are much less secure about their legitimacy.
Re: Notion leaks email addresses of all editors of any public page
#100Earlier quoted context omitted.
Good luck with that. Companies simply don't want to invest in security. It's simply cheaper to write a post-mortem and apology blog post after the fact. The sad thing is that people are used by now that anything they enter on a website is sooner or later going to be leaked, if not sold as if often happens with email addresses.
Sue them out of existence then.