If I open the Gist on https://gist.github.com/ then go to the original gist at 'kobble-git/channel-groups.json' I can navigate to all the forks and see data for other users.
Please read the comments above about the various uses of Kobble. Gists are for public use and sharing. Private repos are coming very soon for other use cases.
A timely reminder that online services _have_ to prioritise security if they want to be taken seriously. I guess day one is a good day to learn that lesson though...
I'm one of the Kobble devs. This is intentional. Please read the comments above about public and private use of Kobble. The intros on the web have been clarified also.
I'm one of the devs on Kobble. Kobble is a versatile tool that can be used in a variety of ways.
One way is as a content sharing platform. Gists are great for this purpose, because as you have noted, the discovery mechanisms are largely built into GitHub. Our use of gists for this purpose was entirely intentional. On top of that, we have built a flexible data model (similar to YouTube) for organizing and sharing the content. We are attempting to build an open content sharing platform where users have control over the data.
For note taking, obviously you want private access. We will have support for private repos very shortly. This was stated in the intros, and we have improved the wording to make it clearer.
I think we assumed that GitHub users would know that gists are not private. We added a clarification to the onboard slideshow. Support for public and private repos is coming, via GitHub Integrations.
I quote from your website: "Don't worry if you don't know what GitHub is, you only need to create an account." You don't appear to make any assumptions that your users understand that their notes will be published and readable by anyone on the internet.
Furthermore, your clarification: "Currently, Kobble stores all user data in secret GitHub Gists, under your account. Secret gists are not private." does not help because it does not explicitly state the fact that notes will be readable by anyone on the internet.
Having read through the information on your site now it's been updated, it's much clearer than it was before. I feel like it should have been closer to this before submitting to HN, but the changes ("Gists are not private, and are suitable for content that you want to share", "control" rather than "own") are definitely a step in the right direction.
We are trying to clarify the multiple ways Kobble can be used. Gists are for public data that you want to share. Private repos (coming soon) are for private data. I think the intros on the web make this clearer now.
If I open the Gist on https://gist.github.com/ then go to the original gist at 'kobble-git/channel-groups.json' I can navigate to all the forks and see data for other users.