Weblog.sh – hosted blogging from the command-line
weblog.sh
weblog.sh
https://github.com/hmngwy/weblog.sh/blob/master/lib/ssh/exec...
else if(command[0] === 'password') {
if(args.length===0) {
stream.write('→ You need to specify a password.\n\r');
stream.end();
return;
}
var hash = require('sha256');
var payload = args;
var salt = schemas.randomString(32);
userMeta.user.hash = hash(payload + salt);
userMeta.user.salt = salt;
userMeta.user.token = schemas.randomString(64);
stream.write('… Saving new password'+LB);
userMeta.user.save(function(err, saved){
if(err){
stream.write('→ Password update failed.'+LB);
}
var response = [];
response.push("→ password for "+saved.username+" updated"+LB);
stream.write(response.join(LB));
stream.exit(0);
stream.end();
});
}This is one idea of PHP's that other languages should copy.
When hashing passwords you want a function that is slow and have MANY (but not too many) collisions so that it can not be brute-forced in any direction.
I don't understand this part? Basically if I'm able to find a collision it's like I found the real password, so why is a function with many collisions better for password hashing? Is there a way to differentiate the collisions?
EDIT: typo
What you really want for password hashing is a key derivation function, which will generate a random, unique hash slowly.
First impressions are not good.
• scp very slow; doesn't work
• vim scp:// doesn't work
• emacs tramp[1] definitely doesn't work (scpx says invalid command; ssh, scp and sftp methods say "EDITOR SOON")
I noticed you're using ssh2js[2], but not using its built-in features for getting the public key from the client.
I think this would make a much better experience than asking for a password (that you don't echo, don't confirm, and annoyingly don't reset the terminal state afterwards).
I also think you should look at getting the sftp subsystem working as it is simpler and much more reliable than scp.
I hope you fix these things because I'd like to try it again.
I don't know why they don't like to that from the front page.
I think scp being slow probably has more to do with his/her hosting than implementation. My post went through just fine so I'm tempted to blame your local setup somehow.
I agree completely about resetting the terminal state; I think that may be getting addressed here --- https://github.com/hmngwy/weblog.sh/issues/19.
And yet I'm pessimistic it'll get that funding. I just don't know if it's possible to make money writing software like this.
I'm also rather pessimistic about "making money" like this.
You'd have to sell a service for that to make any kind of sense. Target a minimum of, say, 10$ user/year, or user/month (yes, those are two wildly different prices, and two somewhat different level of "perceived value" you'd need to provide).
Micropayments only make sense at massive scale - and you won't have that starting out. If you cant build up to 10.000 users paying 10/year, you could probably sustain a developer. Just make sure that doesn't generate work for 30 support staff. But "breaking even" (we won't have to stop because we're burning money on hosting) is different from "making money".
It's probably a good idea to one, or the other. Not something in the middle.
Major caveat: I've only thought about pricing models, never found the opportunity to try them out in practice.
https://blog.pushbullet.com/2015/11/17/introducing-pushbulle...
https://www.reddit.com/r/PushBullet/comments/3t5ogz/introduc...
If you want a similar solution, but self-hosted, here's another commandline blogging system contained in a single bash script: https://github.com/cfenollosa/bashblog
Besides that i really like the idea. Reminds me a little of the old-style BBS communities. Even though i understand that people need to make money, a project like this would gain much more from being open source. It would give more people the possibility to run a service like this and everyone would profit from further developments.
But that's up to you, and i'm absolutely fine with people making money from webservices! :)
https://storage.googleapis.com/sunsed.com/images/tutorials/p...
Thanks for trying SunSed my friend!
I'll give it a try in a week or so. Hopefully the problems will be fixed.
IMO the only thing missing is the ability to tag your entries. Maybe the site could parse a markdown tag entry in the file. Something like:
# _tags_ #
programming
c++
network
> Choose your new bolg's template