Show HN: An open-source media hosting site that's anonymous and fast
blog.mediacru.sh
blog.mediacru.sh
I am seriously impressed. I loaded up your README on github and had your app running within 10 minutes locally---including `gif` uploads. That's just really nice craftsmanship that is usually missing in fresh projects. Giant kudos to you guys.
(There were a couple trivial steps I had to do that weren't documented. I submitted a pull request. [1])
PS: Merged your pull request, thanks!
The IPv4 address namespace is so small that brute-forcing hashes would be trivial, so this isn't an effective approach.
>>> timeit.timeit('bcrypt.generate_password_hash("127.0.0.1")', "from app import bcrypt", number=10)
3.342690944671631And yes, I know that 12 rounds of bcrypt doesn't mean much. It will delay brute force attacks, though.
A better approach would be something quicker to compute but that you can destroy equally easily. Generate a random token that cycles every X minutes/hours. The HMAC the remote IP and this secret. Use the result for bans/rolling rate limiting. If you keep the token only in memory then you don't have to worry about the IP lists being leaked as they won't be recoverable.
Its not a 100% guarantee - but it's a start.
Well, GA is quite convenient - we get pretty graphs, realtime analytics and so on. It's not something we have considered moving away from, since it's trivial to disable it entirely. And it's not significantly worse than any other tracking tool.
That said, those all entail a lot of work and/or additional cost. You're also absolutely right that allowing users to disable it (and ads) is an amazing feature.
Piwik is really ancillary to the discussion at hand, but I often see the claim that Piwik can't handle busy sites, and it's important to quantify the claim.
I've had success (and others report similar behavior) with 500,000+ hits per day. http://piwik.org/docs/optimize/ reports adequate support to higher levels. It's quite easy to set this up with EC2 + RDS, and using autoscaling gets you a very resilient solution that can easy handle those numbers. Also, in the case of mediacru.sh, many of the optimizations have little impact since they optimize for reporting on the already-gathered analytics. With only two analytics viewers/users - this is not much of an issue.
If you're doing more than 1mil per day, then I think something like snowplow, a commercial solution, or a fully custom solution are appropriate anyway.
There is no excuse for not running your own: http://demo.piwik.org/
Also worth reading: http://manurevah.com/blah/en/blog/Like-this-if-You-are-Again...
We've realised that self-hosting our analytics might be a better choice. I've created an issue[1] to discuss this matter. Ideally what we'd want is something as close to GA as possible - real time analytics being reasonably important.
Note: we were aware of the implications of using GA on the site, but since we offer the ability to disable them very easily we didn't think it was a big deal. That's a mistake on our part, so let's discuss how to fix it.
To be less off-topic: good job on making it, openness and finally shipping it.
[1] https://mediacru.sh/demo
[2] http://en.wikipedia.org/wiki/Love,_Chunibyo_%26_Other_Delusions2011 had Fate/Zero, Madoka, Steins;Gate, Hunter x Hunter, Mawaru Penguindrum
2012 had From the New World, Jojo's Bizarre Adventure, Humanity has Declined, Mirai Nikki, Hyouka
2013 has.. uh.. Attack on Titan, I guess?
Any plans to have an API that other products/services can use? Is it against the TOS to post to /upload from a different domain?
I'll be working on a site soon that might allow some type of media upload. Would it be okay to use mediacru.sh for something like that?
I could see "free hosting" getting really expensive for you guys though, especially if you allowed hotlinking, etc.
Anyways, best of luck to you. Hopefully this becomes profitable for you.
Got an idea for a good way to compress mp3 files?
Our only source of income is donations and the advertisements that we show exclusively on the home page. You can check all of our accountability at https://mediacru.sh/transparency, by the way.
https://github.com/MediaCrush/MediaCrush/blob/master/config/... (BTW, how to hightlight two separate lines?)
are considered taxing
http://wiki.nginx.org/Pitfalls#Taxing_Rewrites
and you could replace them with just a "return."
I love the idea, the fact that you provide all the configs, that it's written in python... it's a really great project.
Thanks for the heads up!
I tried to upload 3 different files. 2x PNG file (no more than 1MB in total) and a gif file (~5MB). I was only able to upload one of them (one of the PNG files). I tried the upload the same files on 2 different browsers (Chrome 29.0.1547.49 & Firefox 23) in both normal and private mode but the result was the same. Maybe you're dealing with heavy traffic right now or maybe the problem was on my side. I hope I don't sound like I'm criticizing you (not that there's anything wrong with that), but I'm merely pointing out my experience in the first 5 minutes. I'll keep using the service to see if everything works out, though. Because I'm currently looking for a service like yours.
Another point I want to make is the similar to the one I've already made. You need to provide more information about the service. Clearly since this is an anonymous service, users won't be able to sign up for an account to manage their files, but what happens when I upload my files? Are they going to be indexed by the search engines? How long are you going to keep my files online?
As for information, I'll make sure it's more clear on the site, but I'll answer you directly as a temporary measure: When you upload your files, they disappear into our servers and can only be accessed by that URL. If you lost it, just upload it again, we'll hash it on the client before you actually do the upload. As for indexing, view pages are not shown in search engines. Your files stay there forever.