Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think I'm able to view all other gists.

If I open the Gist on https://gist.github.com/ then go to the original gist at 'kobble-git/channel-groups.json' I can navigate to all the forks and see data for other users.



Oh wow. Look at that.

https://gist.github.com/kobble-git/87ea625d421177f9e9307c6ce...

And each fork is a link to a secret gist.


This isn't directly obvious, so I'll clarify. Anyone who has used this app - all of your notes are publicly available by following the link above.

Everyone - revoke access to the app and manually delete all the gists it created in your account.

To view anyone's notes, all you have to do is visit https://gist.github.com/kobble-git/87ea625d421177f9e9307c6ce..., click anyone's "View fork", then follow the trail of gist links in the JSON.


Please read the comments above about the various uses of Kobble. Gists are for public use and sharing. Private repos are coming very soon for other use cases.


A timely reminder that online services _have_ to prioritise security if they want to be taken seriously. I guess day one is a good day to learn that lesson though...


Aaaaaaaand revoked.


Ouch. It does seem as if anyone can view any users' content this way.


I'm one of the Kobble devs. This is intentional. Please read the comments above about public and private use of Kobble. The intros on the web have been clarified also.


I'd just like to announce public and private repo support in Kobble. All data is now stored in a public or private repo, depending on how you log in.


I'm one of the devs on Kobble. Kobble is a versatile tool that can be used in a variety of ways.

One way is as a content sharing platform. Gists are great for this purpose, because as you have noted, the discovery mechanisms are largely built into GitHub. Our use of gists for this purpose was entirely intentional. On top of that, we have built a flexible data model (similar to YouTube) for organizing and sharing the content. We are attempting to build an open content sharing platform where users have control over the data.

For note taking, obviously you want private access. We will have support for private repos very shortly. This was stated in the intros, and we have improved the wording to make it clearer.

Hope this helps.


Not sure why this isn't at the top. This is crazy.


I think we assumed that GitHub users would know that gists are not private. We added a clarification to the onboard slideshow. Support for public and private repos is coming, via GitHub Integrations.


I quote from your website: "Don't worry if you don't know what GitHub is, you only need to create an account." You don't appear to make any assumptions that your users understand that their notes will be published and readable by anyone on the internet.

Furthermore, your clarification: "Currently, Kobble stores all user data in secret GitHub Gists, under your account. Secret gists are not private." does not help because it does not explicitly state the fact that notes will be readable by anyone on the internet.


It really sounds like the creators of the app didn't know that anyone could read the Gists...


Please read the comments above about the multiple ways that Kobble can be used. Our use of gists for openly sharing content was entirely intentional.


Having read through the information on your site now it's been updated, it's much clearer than it was before. I feel like it should have been closer to this before submitting to HN, but the changes ("Gists are not private, and are suitable for content that you want to share", "control" rather than "own") are definitely a step in the right direction.


Cheers! We're grateful for all the comments.


People probably would expect private gists to be reasonably private. They normally are, if you don't publish a global index of them...

This is not users misunderstanding how gists work.


We are trying to clarify the multiple ways Kobble can be used. Gists are for public data that you want to share. Private repos (coming soon) are for private data. I think the intros on the web make this clearer now.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: