It's shocking to me how often this is glossed over when discussing E2EE services: you still must trust the platform.
The implementation of E2EE must be robust and there must be somebody who is actually checking the source code (plus verifiable builds)
One thing you might want to consider is having one domain for a website about collectednotes (collectednotes.com) and another for hosting user's blogs (collectednotes.blog for example) because it is currently not clear what urls are official and made by you and which are just blogs made by anyone.
For example, https://collectednotes.com/accounts/ is genuine and made by you whilst https://collectednotes.com/account/ is a blog I just created. To me there seems a very real risk of users being mislead.
“I want to be able to take notes on my phone, share some of them online, and publish a few on my personal blog — oh, an I also want an API!”
I built this is because no tool out there satisfied my needs: - Notion had no native app so it's very slow to use on mobile. Plus is too general. - Medium is a disaster for readers, they shouldn't be the ones paying to read. Native app is slow AF. - Most note-taking apps were too complex and feature creep. I wanted speed + power with simplicity first. Just give me markdown. - Apps are either online or offline, none tried to mix those two models seamlessly. - Blogs are either static (I need to be on my laptop and code) or use CMS which are too general and complex.
I sense there’s a demand for an easy to use native note-taking app that can also serve as an online publishing platform. A place where you can use your domain and update your notes right from your phone.
Of course, this is just a theory, so I would love to see if you all find it useful. You can try it https://collectednotes.com
Features:
- Simplicity. - Markdown with live preview. - Custom Domains. - No ads, no tracking, no modals, no vanity, no nonsense. - No data lock-in. Export your notes from day one. - Restful API, Your Notes in different formats. - Native experience iPhone & iPad: Share extension, Quick actions, FaceID, Quick Actions, Keychain, Keyboard shortcuts, Slide Over & Split View, Dark Mode.
Sample note: https://collectednotes.com/blog/api, Would love to hear what you all think
One thing you might want to consider is having one domain for a website about collectednotes (collectednotes.com) and another for hosting user's blogs (collectednotes.blog for example) because it is currently not clear what urls are official and made by you and which are just blogs made by anyone.
For example, https://collectednotes.com/accounts/ is genuine and made by you whilst https://collectednotes.com/account/ is a blog I just created. To me there seems a very real risk of users being mislead.
This is definitely inaccurate. Many elements of CDL are clearly still in effect, such as the use of DRM to enforce the "check out" provision. It's a real lending system. The only thing that's new is the "unlimited" claim wrt. the number of copies that can be checked out at any given time - and we still don't know how far that "unlimited" actually goes. We should wait for IA's legal response on this.
Just look at SARS for an example of where trusting the official information from China made for a terrible idea.
If you're the person having their reputation smeared by anonymous cowards it maybe doesn't seem so "petty" as you dismiss.
This seems like a perfectly reasonable thing to do; have the person slandering somebody anonymously brought into the light where there is a level playing field in which they can present their case.