Show HN: Use Slack Emoji on GitHub
single-emoji.vercel.app
single-emoji.vercel.app
GH also seems to use the data-canonical-src attribute to reference the original URI.
First time I used it it ran so quickly I thought it wasn't working properly.
Thanks for your hard work.
It’ll be like BetterTTV but for HN :catjam: :meow_party:
all you need is to connect random javascript to a major channel for social engineering and then run it inside major channel for software supply chain risk
Are the other responses in here non-ironic?
But I understand that the shadiest people say they are legit, so I’ll prioritize open sourcing the extension so others can review it :) sounds good?
I get that you just wanted to make something cool, and it is very cool, but people are also right to be paranoid here. Compare the value between having a certain tiny image in your PRs versus being able to check code into any organization's Git repo as a trusted engineer at that organization, and how much someone would pay you on the black market for either of those things.
- people who use both a Web Extensions-supporting browser and Slack
- people who install extensions with permissions to run arbitrary JS on every page
- people who install or use Slack bots/etc with excessive access to Slack data
… is likely very nearly a circle. The emoji use case isn’t one for which I’d personally take that combination of risks. But I can imagine a wide variety of more appealing/risk worthy and likely even higher risk “use [CLOUD_SERVICE_FOO_RESOURCES] seamlessly in GitHub” use cases where I’d pause to at least consider it.
This is just basically everyone using Slack, as Firefox, Chrome, and Safari support web extensions API
> - people who install extensions with permissions to run arbitrary JS on every page
I would bet that most people who use Chrome or Firefox install extensions that can run arbitrary JS on every page, like ad blockers, full page screenshot, or “nifty” discount-coupon-code extensions.
would be great if something like ublock is only able to disable dom elements, not insert them, for example, and has strong guarantees about not doing IO
users are much more able to audit permissions than to audit changing code
but permissions need to be 'shaped like' APIs or else they are too broad to provide power + safety together
~Basically my point. I made allowances for people who use neither, but they’re a vanishingly small user share.
> I would bet that most people who use Chrome or Firefox install extensions that can run arbitrary JS on every page, like ad blockers, full page screenshot, or “nifty” discount-coupon-code extensions.
Pretty much my point. Along with the former point, the Venn diagram is roughly all Slack users.