Show HN: A Chrome extension to see notifications for comments on your HN threads
chrome.google.com
chrome.google.com
We made a chrome extension to notify you of new comments on your stories and comments.
Once installed, it adds a bell to HN's header and shows new notifications in real-time. Clicking on the bell loads a notification inbox with easy access to all your notifications with a clear distinction between the read/unread ones.
Unlike some other options like HN replies, here are the key differences
We don't ask for your email address - we use the HN cookie to identify you. There is no setup beyond adding the extension. Apart from on-page notifications, you can also subscribe to web-push notifications.
We are using HN Firebase API to get a real-time feed of notifications, and our startup, [MagicBell (YC W21)](https://magicbell.io), to power the notification inbox. We built this extension because we found it hard to keep track of our [Launch HN thread](https://news.ycombinator.com/item?id=26037645) comments.
We want to build a version for Firefox & Safari, and if you'd like to know when they go live, please follow us on [Twitter](https://twitter.com/magicbell_io). Dozens of early users have tested the extension, but if you run into any issues, please tweet at us, and we'd be more than happy to help you with it. We'd also love to hear your ideas on additional functionality you'd like to see.
does this extension contact any servers apart from hn itself?
user=gruez&[redacted]
Are you sending the entire session cookie, or just the part with the username?This is a security hazard, period.
While the feature is nice, and I like the design of the notification dropdown, this is a risk I (and probably many) won't take.
But why is that a problem? If somebody wants to get notified of replies to my comments, let them.
I understand why you need a unique token so that collisions don't happen, but that token doesn't need to be one-to-one unique with Hackernews usernames. It's OK to have two unique tokens that are separate from my session cookie that point to me as a user, and to have the "read" status be per-token, not per-user.
More to the point, why does this read status and everything need to be stored serverside for a browser extension? Where are you putting this information where you're worried about collisions with random internet users, why have it leave the browser at all?
You don't need a unique token if you're not storing everything in a centralized location off-device, the browser profile that's using the extension is itself the unique token. Why does anything need to be transmitted anywhere? Let the extension store the read statuses locally on my device, then there's zero chance of them colliding with anybody else's installation. Even if someone turns on push notifications, the push API already sends you a unique, randomized device ID/key. What's the reason why you can't push an RSS-style feed out to the device using that ID?
But to answer the question:
> Why does anything need to be transmitted anywhere?
It's because the extension is written by, and "powered by", MagicBell. They are writing it to bring attention to their product concept, where notifications like this are all handled by them.
So that's also a unique identifier that they could use to prevent collisions. They could have a randomized ID generated locally for this "promotional" extension, and if a user creates an account on MagicBell at that point they could migrate them over to an official user ID.
If this is being tied to a real backend service, I'm almost more confused why it's important to transmit my session cookies around.
Also, your chrome web store page says "The publisher has disclosed that it will not collect or use your data". But you do collect and use users session cookie.
And your linked privacy page has no content (it is literally an empty page at the current time): https://magicbell.io/privacy-policy.
Sometimes I come to a particularly interesting article in its early stages before there are many comments or I read through all the comments of a mature discussion that continues later. I'd like to be able to see what is new without rereading many comments.
My ideal would probably be an interface similar to mutt that shows all the threaded comments of an article. Keyboard driven, of course. Almost a bit like HN as newsgroups!
Impressive use of MagicBell too!
I honestly believe the underlying concept here is slightly immoral, moreso because it's an attempt to SAASify something that cleary doesn't need a server, and steal your info while they're at it. Hmmm, now that I've written it out like that I guess I'll bump it up to clearly immoral.
It fits with trying to optimize for (intellectual) curiosity: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&sor.... If something is interesting enough, you'll be motivated to look at it. If you're not motivated, probably you're more interested in something else and should look at that instead.
You are addressing the need gap - 'On-demand Hacker News notification'[1] posted on my problem validation platform. You're welcomed to explain how you're solving that problem with the link to your extension.
[1] https://needgap.com/problems/144-on-demand-hacker-news-notif...
Do you have a blogpost of how you built it?