Show HN: Turtl – A secure, encrypted Evernote alternative
turtl.it
turtl.it
- No iOS client (Although the site does say coming soon)
- No Firefox webclipper
- No Web interface
- Large / heavy application
- No Drawing / Diagram support
- The app is not native, it's seems it's a web frame
It's interface doesn't feel very snappy, it feels like it's built with in a Javascript framework perhaps?
Evernote has been around for a long time and has grown to 110MB uncompressed / installed, this app is 100MB and it's only in its early stages and has hardly any features implemented yet - that's worrying to me.
Looking at OSX's power utilisation Turtle appears to often utilise one CPU core heavily under load where Evernote seems to thread processes more efficient and ends up using around 60% less power on my 2015 Macbook in the use I put it through which was common activities such as adding and removing notes, copy / pasting text, launching and closing the app etc...
What I do really like is that it uses Markdown, that's something sorely missed in Evernote.
I'm really sorry to be quite harsh, I really do love when people try to improve software by creating their own alternative and that's something that's sorely needed in the land of Evernote like apps, however I don't think this comes close to a possible alternative.
Edit: Also, I should note that I have many hundreds of notes in Evernote, where I created 15-20 in this app, I would have expected Evernote to need more resources to search such a large number of notes.
~/Library/Application Support/com.evernote.Evernote % du -sh .
608M .We do utilize multiple core when encrypting/decrypting, but things like indexing and searching all take place on the same thread the app runs on.
This is something that could be improved in the future.
Neither of these is unfixable over time, as the product develops, and some may be a function of the increased security implementation. None of these criticisms stops the app being usable, as far as I can see.
JS on desktop is never going to perform well.
*Edit: clarification
So let's be practical here. If I am doing a startup or a side projects I am definitely going with JavaScript on the client - I have more freedom on the server and will probably pick either elixir/Phoenix, rails or .net
Stuff gets rewritten all the time when it makes sense to do so. That's rarely a big enough issue that you decide you'll never do it.
Just like the new macbook pro's, which are thermalthrottling as soon as you look at pictures of cats. You could say they never going to perform well, but then you could always throw it in a cold bath.
I will say this: Turtl will queue encryption/decryption in background threads so it does utilize cores while doing heavy processing. As far as how it utilizes cores in the main UI, that's really up to the underlying javascript engine, which most likely will be single-threaded unless instructed otherwise.
> I'm really sorry to be quite harsh
Not harsh at all. Turtl is a start, a goal. Evernote has so many features and so many use-cases for so many people. I agree saying it's a viable alternative right now isn't entirely true, but for those who value privacy over features, Turtl is worth a look.
Regardless of my technical opinions congratulations on launching your app publicly and I'm sure you learnt a lot along the way.
*Edit: Typos
And my personal motto as a system tester: "It's my job to show that stuff is still broken and tell in it such a way that my head won't be chopped off and people stilltalk to me."
That said, please post updates -- I'm on the lookout for Evernote alternatives, now that its demise seems imminent.
I don't use any of the fancy evernote features, so if you're interested, this is what I'd require at a minimum:
- Save and sync text between OS X and Android
- Button to take a picture and insert it into a note
That's really all I use.
I currently find myself stuck syncing text files using SyncThing or ownCloud or making notes in my KeePass database just to get the level of privacy I want in this.
I saw Turtl before and this makes Turtl highly appealing to me, I'll definitely be trying it out more thoroughly as it looks like mobile support has matured since last I tried it.
One thing I seem to remember having an issue with was DPI scaling support, I use 4k screens at home and at work, but everything was blurry as the apps didn't support DPI scaling - any chance this has been addressed?
Another issue I seem to remember was self-hosting, I'd most likely self-host it (though I'll definitely chip you a donation if it's all working), but I didn't see any way to configure the server used - did I miss something or has this been added now or would I need to recompile to do this?
Thanks for all your hard work.
EDIT: Just tried it again - DPI scaling on Windows is now working and there appears to be a button to change the server. Sweet. I'll be moving in to this tonight if all goes well. Thank you again. This looks like an excellent product.
I noticed your page doesn't have a donation link though and since I intend to self-host I can't send you anything, any chance you can put one up?
EDIT2: Hmm, noticing something strange here - I thought the DPI scaling was working when I saw the notes in the main screen looked very sharp, http://i.imgur.com/BfSDcca.png but when I view notes expanded it seems to lose its sharpness. See http://i.imgur.com/gpJ7zsC.png
I'm not sure what the reason for this is but I've noticed similar problems with Atom and other browser based solutions so perhaps this is unavoidable for now, in any case it's much better than it was before.
Markdown support in the notes would be quite nice. The UI could be improved for that usecase as well.
I really like having only app for those use cases.
I really like that I can use my Yubikey for 2f authentication over NFC.
So I haven't looked at the code yet but there are many ways to make a web / JavaScript app feel snappier. There is the basic "do everything async" so you, more frequently, release the thread back to drawing / changing the DOM. Some others including:
- Making sure you got rid of the 300ms delay on mobile devices (http://stackoverflow.com/questions/12238587/eliminate-300ms-...)
- Making use everything is minified, combined and loaded up front to ensure initial loading is quick
- If you're using a front end framework look into whether there exists optimizations for speedup otherwise if you profile and find a lot of time is being spent in the framework you may want to work directly with the native DOM APIs
I won't keep going but I've seen a very small, handful of html / javascript mobile apps that have felt practically native in speed so it's possible. But I certainly agree that when first starting up it's a great way to go. React Native may be another good stepping stone.
But I agree that speed is critical. The most important features of a note taking program for me are speed and durability (in the database sense - no worries about data-loss). If it's long to navigate to the last viewed spot in my shopping list or my workout log, I'm annoyed.
Everyone has to start somewhere. Being a new company, calling yourself an Evernote alternative says to me that you're either available everywhere or you will _eventually_ be available everywhere. Maybe not being available everywhere right now is too much of a down point for you but it may be fine for others.
This strikes me as an MVP and it looks like a good start. Saying Evernote took forever to hit 100MB and this app just starting out at 100MB doesn't mean anything but you're implying it'll only balloon further. When they get a revenue stream and / or funding and go full native I would suspect that size would go down considerably.
I think your points are fair but I think you're looking at this company as something far, far more than what it really is.
Nothing says secure like PBKDF2-SHA1 with 50 rounds.
https://github.com/turtl/js/blob/2ca59900d71284795e278e75585...
...or timing attacks on MAC validation. (Yeah, you switched to GCM, but a downgrade attack could potentially be used to find a valid MAC for a chosen ciphertext without the attacker knowing the key...)
source: https://en.wikipedia.org/wiki/PBKDF2
*Edit: Oh.. it's PBKDF1....
But if it's not exponential, then adding thousands of iterations doesn't do much. Maybe instead of 1 day to break it, now it takes 1000 days, or instead of spending $4,000 on CPU time now you need to spend $4M to crack it. Big deal - it's just as broken.
So can anyone explain the math here? How can they seriously suggest linearly increasing the number of iterations over time?
PBKDF2 doesn't have this property, so if you're forced to use it, the standard recommended iteration count is 86000.
50 is a joke.
If you're building software in 2016, you want to use one of the following for turning a password into a crypto key:
- Argon2
- scrypt
- bcrypt
PBKDF2 should be your last resort. Don't fall back to a simple hash function.Why do you think recommended password length and complexity has increased?
Why do you think the default for RSA key length is 2048-bit now instead of 1024?
This code is deriving an encryption key and an HMAC key from a master key. The master key is already a random value, so even if you managed to "crack" either one of the derived keys, you wouldn't know it.
> or timing attacks on MAC validation
Good point, I'll fix that!
If SJCL doesn't offer HKDF, I'll be surprised. It's not hard to implement, however.
Your feedback on the crypto side of things is really important and well received. I appreciate you taking the time to look through the code.
Heh, humility goes a long way towards becoming an expert. ;)
Thanks for taking this feedback well. :)
Also, a friend in IRC point out that:
https://github.com/turtl/js/blob/master/library/tcrypt.js#L6...
Your default iterations here is only 400.
Then I noticed the link to sources on GitHub and the ability to build the APK oneself.[0] I will certainly try this. Thank you for the option.
Looks good anyway, I am going give it a try.
Within one minute from installing it, the following happened.
I added a note: a text note, fine. So a side bar opens...
Why is it only ever a side bar? I have a 1920px wide monitor - not really unusual - but you're forcing me to edit my notes in a fixed 700px sidebar, the rest of the screen estate just darkened out. Evernote lets me use all my screen.
But I've typed some stuff in. So, I'm clicking on "Add text note", the first most obvious call-to-action that catches my eye. A dialog pops up: "The note has unsaved changes. Really leave?". Well, I just clicked on "Add text note", what do you mean?
Only after a while I realized that I'm not supposed to click on the most prominent (white on black) caption bar at the top, but on the greenish "Add" in bottom right corner. Even though the title does say "Add text note", which is as explicit as it gets.
Okay, time to edit my note. It opens in preview mode by default, I still have to click on a floating button to make it editable - another little mental bump, but okay.
I can click on an eye icon to get a preview of the note. Once I do that, the eye icon vanishes, and I'm left with an uneditable note. That's quite weird, normally the "eye" icon would just be replaced with a symbol indicating return to edit mode, allowing to switch back and forth with no fuss. Makes sense, especially sice it's easy to anticipate that the preview function would often be used just to quickly catch a glimpse of whether our work (markup, etc.) looks fine, and further we go, it's not a Rembrandt painting : )
Not here, though - I click on the eye, but in order to resume editing I have to move mouse cursor to the left now, and tap on the "<-" back button. Or, as it turns out, anywhere outside of the magical 700px wide (36% of my screen) get-things-done area.
I guess I'm sort of a power user (I'm a software dev for starters), so these confusions don't stop me for more than 5 seconds each. It is frustrating nevertheless, because being computer-savvy, I'm not used to that. And when my mum clicks "Add text note" only to be asked if she really wants to cancel all changes, I can tell you she'll look like a deer in headlights rather than mumble "what's this bs" as I did ; )
I understand you're an indie dev, but hallway usability testing doesn't require hiring focus groups etc., all it takes is have a few people sit in front of the monitor and watch them go at it
To be clear, the pricing section only applies if you connect Turtl to our hosted service. If you run your own server, the only pricing that applies is the price you pay for the server you run it on.
Goo on you for trying to do this. Be ambitious and swing for the fences. Evernote's product crashes frequently.
(Please everybody who uses note apps, back them up now to external files!)
cons:
- You need to take certifications for OSX app - it's scare to install un-certificated apps - Uploading file and images should be merged - I don't want to care whether it's image or not, App should detect, isn't it cool? - The note editor, it's too poor to use. and default height of textarea is too thin. expand it to users want to write something.
That’s a rather large font size.
In all seriousness though, it seems the site has linux/chrome issues. I am looking into it.
Thanks for the screenshot =]
There is only one button on the front page but you seem to support multiple platforms so I'm assuming this is a bug?
And of course I am one of those people... I use Evernote because I can take notes anywhere very easily (in my browser, my OS, my phone) and then have access to them always in sync very easily, online and offline. Couple that with nested tags and saved search queries and I unfortunately see no competition, regardless of privacy measures. I don't care if my data is encrypted properly if I don't have easy access to it.
Why? Simply because they are better.
Ugh, this isn't acceptable.
I guess it comes down to weighing the cost of your time / effort into researching / using alternatives vs the risk of trusting random people from the internet - of course there's no one answer or solution so it's probably case by case depending on the data being transferred or stored IMO.
Sometime soon I'm hoping to get enough cash rounded up for a security audit and get a few thumbs up from the security community so at least you won't be taking my word for it. Not only that, I'd love to make the product rock-solid. As much crypto as I've studied in the past few years, nothing beats an expert looking things over.
(You can look at simplenote export/import csv/json format)
You only use their servers if you want to.
The original anonymous maintainers apparently tried to kill it, for reasons that aren't clear, by saying that it's insecure. It seems to have been a red herring, and their suggestions of alternatives were comically bad.
Lots of people are still using the last Truecrypt release, or one of the several forks that have sprung up that have attempted to improve upon it in various ways (sometimes in incompatible ways, though). Hopefully the situation will stabilize with one clear winner in the future.