Notesnook – open-source and zero knowledge private note taking app
notesnook.com
notesnook.com
Oh and to clear a few confusions:
1. Notesnook is 100% open source. That includes the server, client apps, and everything else. It's not partially open source.
2. Zero knowledge does not mean Zero Knowledge Proof but Zero Knowledge as in we, the company and people behind Notesnook, have no knowledge regarding what you have in your notes. I see that this might be more accurately called "no knowledge".
What about self-hosting?
https://news.ycombinator.com/item?id=38708878
EDIT: maybe it takes a long time to do that, i don't know. it made me a bit suspicious, but I shouldn't assume malice.
I'm working to get a webrtc type light server
Do you see this server as a way make it easier to build ‘P2P first apps’?
Have some signaling and make Data Channel so can be a peer also.
no technical server, so really the only infrastructure is the signalling, and it's straight forward to scale that.
might still be a niche but it serves my day job needs. field work and reporting asynchronous is a pain.
After v3, our primary focus will be on self hosting and getting an audit done.
I don't know...does self-host equal slow changes? For me that's part of being a self-hoster, I have to keep the softwares up-to-date, and I actually appreciate if updates are frequent.
> After v3, our primary focus will be on self hosting
Sounds good, good luck on further development, if I ever see a self-hosting guide I'll check y'all out ;)
that's pretty much the gold standard I'm headed for.
Yes this is nitpicking but I think when it comes to cryptography you have to be precise.
Then again, even popular services like CloudFlare use that term wrong, e.g. their setting where traffic is encrypted client-to-cloudflare and then separately cloudflare-to-server is called "end-to-end" in their dashboard.
Once technical terms become marketing points, you can expect them to be used for a whole new variety of meanings.
I have seen services market E2EE while not being truly zero knowledge, so it's important to watch out for that sneaky marketing lingo.
“Woopsie, we marketed that wrong hehe”. It’s “wrong” on purpose.
Their GitHub has slightly more info regarding this, but I agree that stuff like this should have at least a page dedicated for it that explains how they've implemented their security.
> Notesnook is a free (as in speech) & open-source note-taking app focused on user privacy & ease of use. To ensure zero knowledge principles, Notesnook encrypts everything on your device using XChaCha20-Poly1305 & Argon2.
https://www.freebsd.org/security/advisories/FreeBSD-SA-23:19...
"The attack exploits weaknesses in the specification of SSH paired with widespread algorithms, namely ChaCha20-Poly1305 and CBC-EtM, to remove an arbitrary number of protected messages at the beginning of the secure channel, thus breaking integrity."
[0] https://arstechnica.com/security/2023/12/hackers-can-break-s...
People are using "zero knowledge" in different contexts:
(1) ZKP terminology in cryptography : https://en.wikipedia.org/wiki/Zero-knowledge_proof
(2) zero knowledge cloud service: https://en.wikipedia.org/wiki/Zero-knowledge_service
This Notesnook is using meaning #(2).
>, or where the OP got this for the title.
View source of webpage has this:
<title>Notesnook | Open source & zero knowledge private note taking app</title>> The term "zero-knowledge" was popularized by backup service SpiderOak, which later switched to using the term "no knowledge" to avoid confusion with the computer science concept of zero-knowledge proof.
Regarding title, missed that as it was truncated on my phone, appologies to OP.
Obsidian works on top of your existing or new notes and knows how to deal with them without chewing them up in an App -- even if they are encrypted. If you are playing on that theme, you are trying to be another Evernote “but better.”
Many other Note-Taking apps succeed by focusing on other areas of Note-Taking, such as better team collaboration, 10x better UX than the competitors, database-ish capabilities, etc.
One has to be far better than Obsidian (and their counterparts) or focus elsewhere to compete. Also, it is tough to beat FREE, but it is excellent that you want to pay.
This is more from a personal angle. For work, I still want to use something the team is happy using, but I will still look for something that I can export out and answer YES to my question, “Can I walk out when I need to?”
I don't think that's a requirement to use Obsidian? I've had, let's say "less computer savvy" friends who've gotten use out of Obsidian.
AFAIK, you need to create a vault in the beginning, so you need to select somewhere on your computer where stuff gets stored. All the other things are automatic and within Obsidian, although some things are paid addons (like Obsidian Sync).
Markdown, images, tags, plugins ... etc.
Obsidian all the way.
I'm going for a different approach. All my docs are stored as Markdown in iCloud, and I use iA Writer to edit them. It's a proprietary app, but one with an exception track record of "buy once, use forever". It's a native app, too, unlike a lot of the alternatives. And if iA Writer ever explodes, all my files are right there in glorious plaintext. I could do, and have done, the same with Obsidian, but I just like using Writer more.
The only database-backed app I've ever completely trusted is Drafts. Yes, my data is stored in its proprietary system. However, it exports the data regularly to a JSON backup file that's trivially easy to parse. It's also never, not once, ever, lost a single byte I've put in it. That little app's bulletproof.
Working Copy (paid, free for students): https://github.com/CharlesChiuGit/Logseq-Git-Sync-101/wiki/F...
ish (free): https://forum.obsidian.md/t/mobile-sync-with-git-on-ios-for-...
It understands Markdown formatting cues, with some more flair (color, tables, etc.), however it needs a different way of thinking.
I used them for a brief period of time while I got weary of bugs in Evernote's publicly shared notes' formatting. However, I love Evernote for what it is.
At the end, my technical notes, and digital garden is moving to Obsidian, but all the private notes are staying in Evernote. Why? 1) I collaborate there. 2) ENEX is a very nice XML format which you can convert to anything. 3) GPS tagged notes are nice when combined with collaboration for me.
So they're different tools, and work differently. They do not fill each-other's places, either. Evernote is more of a note-based mobile and connected office. Obsidian is a documentation and knowledge management powerhouse.
Edit: I have to say that I liked the website overall and few things like planned feature “self hosting sync server” and the ability to download apk for android without the need yo use play store, might give it a try.
Edit2: After signing up, clicking the confirmation email I get “invalid token”, additionally, downloading the iPhone app and after trying to login and providing the 6digits code sent to the email, I get a “failed login attempt” email, can’t login to the app.
I cannot vouch for how well it is implemented but it seems it can work.
I wonder how the interoperability between E2EE (end-to-end encrypted) apps is going to look like. Zero-knowledge sharing is a solved problem, but it is not easy to implement - and many choose not to implement it. They just use key sharing in URLs, making the actual secure sharing the user's problem.
Personally I've moved on to a privately hosted Git repo of plain Markdown files which I currently modify with Obsidian (although I'd prefer an open-source version, and Logseq doesn't quite scratch the itch like Obsidian does) - because I realised what I needed is like a self-hosted Notion-like alternative which I can trust, and Obsidian with all its plugins does exactly what I need.
The only major downside is that taking notes on another device and syncing them without merge conflicts is still a pain.
I do kind of wish more note taking apps would just save to file and forget E2E encryption - the problem is hard, and it's better to let specialist software handle it rather than try and do a mediocre job.
I would love to see more note taking apps to handle git merge conflicts and do git commits though.
At times I've just stopped taking notes because of the high activation energy required, now I just work with my Tablet or Notepad and worry about organising or integrating into my knowledge graph later.
I strongly suggest that you completely ignore methodologies. Write wherever it first seems fit, and keep making backlinks as a way to breadcrumb your way back to your notes. That's how I do it and it has served me extremely well.
By the way, I was pleasantly surprised to find out that Logseq is open source! That's a fantastic bonus. Thanks again for pointing me in this direction – it's making a real difference for me.
These days I've mostly been using vimwiki, Agenda.app or OneNote for notes short/mid/long-term notes, and either of them works for the contexts I use them in.
I feel like the note taking space is completely overcrowded these days, too. Even the iOS notes app does everything I could possibly need (plus syncing), and the cross-platform/private sync space is very well served with SyncThing + whatever Markdown editor you can get your hands on...
That said notes apps never really feel like they're enough of an upgrade to make me switch from text files. It may be different if my notes grew much larger. Tagging and text search is nice but I can also have that in its basic form with grep.
I don't remember why I paid for it, maybe syncing wasn't in the free tier before? I don't know, but I got the yearly sub.
Seems like most of these apps focus on features instead of getting thes basics right.
If I have thought I want to jot it down and continue, not wait a bunch of seconds or more to get going.
Google Keep opens in about a second on my phone, so seems to be the slowest of them all.
But I'm sure there are plenty of notes apps out there that also opens in sub 0.5 seconds, right?
This is not true, many apps (or maybe it's an OS thing) retain an image that is not functional, you should count until you actually type any symbol and see it appear in the app. This also differs between switching to a recently opened app (hot) and an app that's been closed/unloaded from memory, both of which matter for instant note taking.
If I wait ~3 seconds after typing I can see that the change has been persisted to the sync servers and it appears in my Obsidian desktop application.
And for hot start you shouldn't even need to tap in the document if you edited it before, the keyboard will already be opened, so the measurement is "time start, tap the app icon, tap any key, see a character appear, time end". This is a common workflow for app switching and copy&pasting from/to note app/other apps, so here even half-second delays are noticeable, and where Apple Notes shines (and only very few apps match that, but not Obsidian)
Then the cold start is where using other apps forced note app to be unloaded (or after a phone restart or "force swiping up closing" the app (think it has the same effect), here the performance difference between Notes and Obsidian is even more noticeable
But then we were talking about startup times...
You can see a comparison chart here: get-plume.com
Zero knowledge is cool but if you can't even keep the data safe, you're not better than me using gedit and a self-hosted file server.
If I want to install it on my Android phone and my PC and have that sync "zero knowledge", do I have all the pieces in the open source release?
And there is no open source server component, so you can't host this yourself. And say what you will about Evernote, I trust them to stick around way more than another random notes startup thing.
p.s. not to get too political but it seems like the founder is expressing some problematic views on his twitter account (https://twitter.com/thecodrr). Problematic as in, he's this close to being an outspoken supporter of terrorism and radical Islam.
This is subjective, but I didn't find anything beyond reasonably mainstream expressions of support for the people of Palestine and anger at Israel's conduct in Gaza. What did you see that was on the verge of unconscionable?
Across everything I've tried, Standard Notes seems to have the best set of tradeoffs, but they refuse to implement features (like add syntax highliters for modern lagnuages, if I remember correctly, they said that they would only consider it if I prove that thousands of people need it).
Anytype provides good privacy guarantees but they have crappy UX and, ergh, their app needs 5 seconds to start on a modern mac.
The whole notetaking apps market is a shitshow and a total mess. Don't waste your time and money on these half-backed subscription-based electron apps.
There are encrypted backups. Actually, backups are encrypted by default.
Notesnook also works offline by default so there's no need for a special mode. It's also, obviously, local-first since everything gets encrypted on your device. We don't have a lot of options there.
What "might be better" in the editor?