3,735 karma · joined December 1, 2012
- CEO of Obsidian, https://obsidian.md
Blog:
- https://stephango.com
Elsewhere:
- https://github.com/kepano
- https://twitter.com/kepano
- https://mastodon.social/@kepano
Previously:
- Founded Lumi.com (YC W15)
> Has there been a meaningful increase of understanding and creation thanks to personal knowledge management systems?
My question is: in a world where photography didn't exist, how would your life have been different? How would everyone's lives be different? It's a counterfactual that's impossible to answer meaningfully. Similarly, we can't measure how the world is different as a result of the popularization of [[links]].
A few days ago, someone jokingly asked if Henry Ford had a personal knowledge base in Obsidian... Well, sort of! He had something he called "jot books", where he journaled, kept notes, grocery lists, etc. Not dissimilar to how people use Obsidian. The Henry Ford Museum has fifty of these notebooks: https://www.thehenryford.org/search?Query=%22jot+book%22
How should we quantify the impact of Henry Ford's notebooks? How should we quantify the impact of spreadsheets?
Most people who accomplish anything take notes in some form, because writing is a way of thinking. We love to mythologize the tools and methods of accomplished people because we hope it will let us absorb a bit of their genius. But a good camera doesn't make a good photographer. Taking lots of photos helps.
Should you take notes? Probably. Does it matter what your method is? Probably not. Whatever works for you. Obsidian (or any other form of notetaking) is successful if it disappears and lets you accomplish your work.
The new labels are meant to indicate which plugins have payments, since many plugins connect to paid services. There is no intention for Obsidian to ever become a middleman.
Where the heck are you getting this from? We are explicitly not doing this.
Canvas can be disabled in Core Plugins, like most other features.
In general I mostly see the opposite criticism: that Obsidian out of the box is too barebones and that it requires plugins to be useful.
I tend to be more on your side though. I prefer Obsidian to be as streamlined as possible and hate bloat. Last year I asked the community "what should we remove from the app?" And I mostly got feature requests :(
https://x.com/kepano/status/1890957031017730335
It's a hard thing to balance, but what makes me hopeful that Obsidian won't become bloatware is:
1. We're only seven people, we don't have investors, and we plan to stay a small team so we don't have the same growth pressure that Evernote faced. We simply don't have that much bandwidth.
2. The file-over-app approach makes it easier to build opt-in interoperable tools like you describe. We've explicitly focused on shipping things like Obsidian API, URI, and CLI instead of building everything into the app (most other teams in our space seem busy stuffing a bunch of AI junk in their apps). One example is Obsidian Web Clipper, a separate tool we made that has matured into a great separate product.
3. Plugins (both core and community) mean you can make the app as streamlined as you want.
The team is also working on adding permissions and more controls, see the recent announcement and HN discussion:
https://obsidian.md/blog/future-of-plugins/
https://news.ycombinator.com/item?id=48109970
Since last week hundreds of plugins have been updated to patch vulnerabilities. That said there is a lot more to do and we're actively working on it. It's a very high priority.
If there are any other checks you think we should add to the automated review system I'd be happy to look into those. Since the review system is mostly open source you can also contribute to it directly, though perhaps that would be in conflict with the purpose of your company since our approach doesn't use AI for now?
https://community.obsidian.md/search?type=plugin&categories=...
> No permissions system, nothing resolved.
I could not let that comment stand because it's simply not true, and you probably wouldn't say it that way to me in person. We're not some faceless corporation. We're a team of seven sharing a year's work, which is expressly imperfect and in progress. I'm not looking to be showered with praise, like I said in my comment on the post we're listening to everyones gripes, and working on them. But a bit of nuance and congeniality is appreciated.
I don't think these two points should be particularly controversial:
1. Permissions are planned but they're not a panacea. Apps are sandboxed on iOS/Android, browser extensions have permissions, yet both can easily do dangerous things. Permissions suffer the same issue you described: all a user needs to do is press "Yes" to allow danger. If you care about making powerful software you inevitably must have some way for a user to say they "understand and accept the risks". The other option is to simply not let your software be powerful, which is not what I am interested in working on.
2. Analyzing plugin source code must be part of the overall solution not only for security, but also performance, reliability, ease-of-use, etc. How can you be against that? It makes absolutely no sense to me.
48 hours in, the new review system is already working. Hundreds of updates have been published by developers cleaning up their code and making their plugins safer in ways that a permission system would not catch. You can see that for yourself by looking at recent updates from the community: https://community.obsidian.md/search?type=plugin&sort=update...
As I have stated elsewhere many times, I'd be working on Obsidian even if I were the only user. That's why the app is free, we don't have investors, and we're okay staying small. The way plugins work is not motivated by money, it's a reflection of the kind of software we want to use.
It is fulfilling to see many people find value out of the app. People are creating many useful and interesting plugins I would have never imagined. Selfishly, I want to be able to use and trust those plugins just like anyone else. And that's the only motivation I need to work on the problem of plugin safety.
I understand you wish we had sandboxed plugins first, and built on top of it that way. But we didn't. Now we have been cursed with success and a large ecosystem that needs to be managed and transitioned. We will continue to chip away at the problem bit by bit. I don't think there's any other way to do it.
I completely understand if you disagree, in which case Obsidian is not for you. It's perfectly fine to not recommend it! Obsidian is not trying to be for everyone.
See also: https://stephango.com/saw
The post has instructions to reproduce the review results using our open source eslint plugin:
2) Yes. You will see these radically improve over the next few weeks. As stated on the scorecard itself they are a work in progress. You have to consider that overnight we intentionally exposed tens of thousands of warning messages across thousands of plugins, so there will be false positive, false negatives, and severity tweaks as we gather feedback from the community. But I expect these to get sorted out fairly quickly!
Millions of people depend on thousands of Obsidian plugins. We cannot just flip a switch and break everyone's workflows overnight. It will be a gradual process. We're working on it, and I hope you'll at least concede that this is better than nothing.
AI is not used in the review process. The system is primarily based on our open source eslint plugin, with additional dependency and malware scanning