跳转到内容

kepano

0:00 · Hey everyone, it’s Zsolt here.

0:03 · Today I want to talk about a topic that is highly personal, somewhat sensitive, maybe even controversial, but I think we need to have an honest conversation.

Steph Ango’s announcement & the new plugin review site

Section titled “Steph Ango’s announcement & the new plugin review site”

0:20 · For me, it all started with Steph Ango-Posted on X last week.

0:26 · And those of you who don’t know who Steph is, he’s the CEO of Obsidian MD and Obsidian MD is a privacy-first markdown note-taking tool that has been gaining increasing popularity over the last couple of years.

0:43 · Steph announced the new community site for Obsidian.

0:48 · The new community site essentially gives users access to plug-in reviews, both quality and in terms of is it maintained, is the owner active, and security and code quality reviews in terms of are there any suspicious behaviors, are there heightened privileges, what is under the hood.

1:12 · So why is this important?

1:14 · Because Obsidian has close to 4000 plug-ins and over the lifetime of the Obsidian ecosystem, the number of plug-in downloads has now reached 120 million, which is a huge number.

1:30 · Now mind you, Obsidian was obliged to take a step.

1:35 · They were not acting on their own timeline because third-party plug-in review sites started to mushroom and these sites conveyed a picture about the plug-ins that was not very good.

1:51 · They highlighted lots of security issues and I think overall the concern was that here’s a markdown editor that’s local-first privacy-centric and it has tons of plug-ins with glaring holes and essentially plug-ins make Obsidian really useful so there is no two ways about it.

2:16 · Something had to be done.

My perspective as the Excalidraw plugin developer (6.1M downloads)

Section titled “My perspective as the Excalidraw plugin developer (6.1M downloads)”

2:19 · Now where do I come to the picture?

2:22 · I’m the developer of the Obsidian Excalidraw plug-in, which is or has been for the last two to three years the most downloaded plug-in in the Obsidian plug-in store or community plug-ins.

2:39 · I recently crossed the six million download mark and now I’m at 6.1 million so I take up roughly 5% of the total downloads.

2:51 · Now in the last two months my focus was elsewhere.

2:56 · I was starting up the Sketch Your Mind community.

3:00 · I was building the site.

3:02 · I was planning the content.

3:03 · I was focused on creating a community around visual thinking, Excolidro and all of these stuff the visual PKM stuff.

3:14 · So I was completely blind-sighted.

3:17 · I didn’t know about the third-party review sites.

3:20 · There was some discussion on the Alpha Tester channel.

3:25 · So this is the internal channel between the key plug-in developers and the Obsidian devs.

3:32 · There was already some conversation about the community site but I missed those conversations because my attention was elsewhere.

Getting blind-sided by Excalidraw’s initial security score

Section titled “Getting blind-sided by Excalidraw’s initial security score”

3:42 · And when I looked at the community site and I looked at the score for Excolidro I thought I’m going to blow up.

3:51 · I was so upset, so angry.

3:55 · How come Obsidian does not let me know that they are launching this site that paints Excolidro in a completely dirty and I think incorrect light?

4:14 · Because over the past four to five years I poured my heart into this tool.

4:20 · I built the capability that I dreamt of my entire life.

4:26 · A visual thinking power tool that does everything I ever wanted.

4:33 · And I was heavily working on creating trust, transparency to be authentic with my user community.

4:43 · That’s why I started the YouTube channel.

4:45 · That’s why I was working actually on the community site.

4:49 · And here comes Obsidian.

4:51 · They publish this crappy report that undermines user trust and I was already starting to receive questions from the user community that oh they understand but they are scared.

5:04 · What am I going to do?

5:05 · What’s going to happen?

5:07 · I felt that Obsidian put me on the spot.

5:12 · Now later on I learned that it was actually already the third party sites putting me on the spot but I was extremely upset.

5:24 · I wanted to create a video then but I thought better of that.

5:29 · Maybe you would have enjoyed that more because I would have been raging in that video.

5:34 · Now I’m more calm and probably more boring.

5:39 · But yeah, I want to tell you the developer side of the story.

5:44 · Because I think there is a perception gap.

5:50 · I think there are the scanner scores versus the reality.

5:55 · There’s of course the issue of the damage to trust which I care a lot about because I have only the best intent with the tool that I created.

6:08 · And if it shows, if the report shows that the tool is high risk because of all sorts of scanning results, I think that does not show a proper picture.

6:23 · Now don’t get me wrong.

6:25 · I understand and agree with the intent because especially since the AI code generators are available, anyone with zero technical skills can start to build plug-ins and unfortunately the world is full of people who have malicious intent.

6:50 · So essentially that opens a great risk of how well the plug-ins are reviewed and what risk it creates.

7:00 · But I think without the technical context, without the broader context of plug-ins, the results can be super misleading.

The hidden reality of plugin economics (Hobby vs. Commercial expectations)

Section titled “The hidden reality of plugin economics (Hobby vs. Commercial expectations)”

7:12 · Now I think there’s also, and this is the more important discussion, I think there is a hidden question about plugin economics because Excalidraw and I think pretty much all of the other plugins in the community plugin store are hobby projects.

7:33 · These are typically one person maintenance projects and right now these hobby projects are suddenly receiving commercial expectations.

7:45 · They are put on the spot and there’s an expectation that they meet certain quality guidelines.

7:52 · And again, I have no issue with the code reviews with all of the material, but the reality is a single person hobby developer is in an extremely hard situation because the single person might still sound like a lot, but think of this.

8:15 · So you do this next to your day job, you come home, you might do it in the evening, you might do it over the weekend.

8:23 · So this is really 0.1 person who works on a plugin if the person works on it frequently like I did.

8:32 · I think many other people don’t sacrifice this much time and pushing this commercial set of expectations on these hobby projects I think is unfair or at least it raises some important questions that we need to talk about.

Fixing the gaps: Moving Excalidraw’s score to 78

Section titled “Fixing the gaps: Moving Excalidraw’s score to 78”

8:51 · I spent the last four days of working on the gaps and by now I’ve managed to move the needle from I think 40% or 38% was the first value I saw to now 78% quality.

9:09 · And I think in both sectors, the plugin is right now considered good by these tools.

9:18 · And yes, I have found a few hidden bugs, albeit they were very low risk bugs, but okay, by doing some of these actions, I found bugs.

9:30 · I did implement a GitHub release workflow, which is going to help me going forward as well.

9:37 · So I’m happy about it.

9:39 · And I did update the plugin readme to be much more transparent.

9:44 · So I think that’s a win as well, because transparency and honesty are super important for me.

Architectural constraints & missing Obsidian APIs

Section titled “Architectural constraints & missing Obsidian APIs”

9:53 · But I think we also need to understand the architectural constraints.

9:59 · Because many of the solutions and mind you, Excalidraw I think is probably without exaggeration the most complex plugin in the plugin store.

10:12 · But I struggle with lots of things that Obsidian didn’t provide.

10:17 · So you know, now I suddenly receive this set of requirements without the financial framework, without the supporting API’s and capabilities.

10:29 · So what am I talking about?

10:31 · For example, Obsidian does not provide a means for plugins to deploy multiple assets.

10:39 · I’m talking about fonts.

10:41 · I’m talking about different packages.

10:43 · In my case, for example, for LaTeX, I need to deploy the MathJax library because the one in Obsidian does not support SVG export and for Excalidraw, that’s what I need.

10:58 · I’m forced into all sorts of workarounds.

11:01 · For example, I wanted to implement proper PDF printing of drawings, which was a heavy user requirement.

11:09 · But there is no API for that.

11:12 · So I’m using Electron, that’s the browser under Obsidian, Electron API calls.

11:21 · And now that’s highlighted as a high risk item.

11:24 · I was pushed by the community to create features.

11:29 · Indeed, just today I received another feature request to expand this set of features set in Excalidraw to allow external files, so files that are on your file system, but not in your Obsidian vault, to be featured on Excalidraw drawings.

11:47 · And for a long time I pushed back, but finally I gave in.

11:52 · And of course, that is a security finding that Excalidraw has file system access.

11:58 · But I could go on about the API missing for Obsidian publish, and so on with Mermaid, with pretty much everything I do, I run into blockers or run into missing capability in Obsidian and I solve it, but now those solutions suddenly get in the spotlight and they are shown as weaknesses, they are shown as security risks.

12:30 · I don’t think that that is okay.

Building a bridge between two moving continents

Section titled “Building a bridge between two moving continents”

12:33 · And on top of this, you need to understand that Excalidraw is like building a bridge between two moving continents, because Obsidian has been constantly developing.

12:51 · of what’s going to happen in half year time.

12:54 · So it’s always reacting to whatever Obsidian did.

12:58 · And I’m in the same situation with Excalidraw.

13:01 · Excalidraw is also a rapidly growing tool component.

13:06 · And my integration, the Excalidraw plugin tries to bridge this gap, tries to be the rubber that connects these two such that everything moves, but it still works.

13:18 · I think it’s an amazing product.

13:21 · But now with the code reviews, I’m getting punished for this flexibility, for this capability.

13:31 · And I think there is a fundamental imbalance.

Will this incentivize closed-source plugins?

Section titled “Will this incentivize closed-source plugins?”

13:36 · You know, Obsidian is closed source.

13:39 · They have public security reviews, and that’s great.

13:43 · Kudos.

13:44 · I am really happy to see the Obsidian security reviews published, but they did it on their own clock.

13:52 · I don’t know how many attempts they did until they got the right audit.

13:57 · They had the time to fix the issues behind the curtains.

14:01 · But plugins, they are expected to be open source.

14:05 · And now if they’re open source, then suddenly everyone can scan it.

14:11 · And without technical expertise, without understanding of the context, you get reviews.

14:18 · And I think one of the real risks here is this is going to incentivize towards closed plugins, because that’s the easiest to avoid this.

14:31 · Now of course you cannot hide everything.

14:34 · So in the end, the code that you publish is going to be visible.

14:40 · But you can hide lots of things that this or these reviews highlight.

14:46 · So if you want to avoid the spotlight, I’m afraid the incentive is going to be towards closed plugins.

14:53 · Now I don’t plan to do that.

14:55 · I believe in open sharing.

14:58 · I believe in collaboration.

15:01 · And I believe in giving everyone an opportunity to learn and to develop.

15:07 · But I see this risk as a real huge risk.

15:12 · And I think there is this issue about freedom versus control.

15:20 · Because there are some trade-offs.

15:22 · And be careful what you ask for, because you might actually get it.

15:28 · I love Obsidian, because it’s open, it’s powerful, and because there are no limitations.

15:37 · It’s not like I’m not going to name other tools.

15:41 · I have my turf with lots of other tools that are closed and cannot be really extended.

15:46 · But maybe one example, for a long time, for roughly 20 years, I was using an application called the brain.

15:57 · The only reason I left the brain was because it does not provide custom development.

16:04 · Yes, you could do it, and I found ways to do it.

16:07 · But it was really a closed system, and it always frustrated me.

16:14 · Obsidian is flexible.

16:16 · It’s innovative.

16:17 · It’s powerful because it’s open and flexible.

16:23 · And I think putting the code scanners, putting security in the forefront, of course you cannot not do that, but it has the risk of closing down an open ecosystem and that way damaging the value that Obsidian creates.

User responsibility & the true measure of a plugin’s trust

Section titled “User responsibility & the true measure of a plugin’s trust”

16:43 · And I think it also puts the user responsibility in the wrong place.

16:51 · Because if you’re using Obsidian, if you’re opening a plugin, you need to understand what you’re doing.

16:59 · Plugins and Obsidian has an opt-in to turn on plugins, and of course, I guess most people never read that opt-in, but it is your responsibility to understand what you’re doing.

17:14 · And I think beyond security reviews, I think what’s maybe more relevant in terms of trusting plugins is their lifetime, their level of support, and the connection you might have with the developer.

17:30 · I think in that regard, Excolitro stands out.

17:34 · I have over 300 videos about Excolitro.

17:38 · I’m available.

17:39 · I respond to issues.

17:42 · I don’t solve every issue, but pretty much every issue I respond to, at least with a comment.

17:48 · If someone contacts me, I support the person.

17:52 · I think that should count, and not the security reviews.

17:57 · And I think also the security reviews miss an important point, that Obsidian is a local first application.

18:08 · What does it mean?

18:10 · It provides a fully transparent local environment, and focusing on the security issues highlighted in the different reviews, to a large extent feels like that you’re super concerned about locking the windows on your house, I mean, while your garage, your back door, your front door, everything is wide open.

18:36 · Obsidian is powerful.

18:39 · It’s a free environment, but you need to use it with the right level of caution and the right level of skill.

18:50 · If you don’t have that, then I think it’s better not to have plugins installed, or at least not many plugins installed.

18:59 · And also, I think the issue is the number of plugins you install.

Why installing 100 plugins is a terrible idea

Section titled “Why installing 100 plugins is a terrible idea”

19:05 · I actually install only a few plugins, roughly 10 plugins, and I sometimes get reports by users that they find a compatibility issue with Excalator, etc.

19:19 · I ask them to send me their list of plugins, and I’ve seen lists of close to 100 plugins.

19:27 · That’s not going to work.

19:29 · A, I don’t believe that you can effectively use 100 plugins in your workflow.

19:34 · And B, that is super high risk, not because someone wants to fraud you.

19:39 · But let’s be honest, these plugins are hobby projects.

19:44 · They are not tested for compatibility with each other.

19:49 · And I have even a list of all the plugins that are not really compatible with Excalator.

19:56 · If you have this plugin and Excalator, then Obsidian slows down.

20:00 · Not because Excalator is poorly written, or the other plugin is poorly written, but they are not designed, they are not tested together.

20:12 · And I think there’s also an issue about sustainability.

False positives, sustainability, and developer burnout

Section titled “False positives, sustainability, and developer burnout”

20:17 · Because if you expect plugins to be open source hobby projects by volunteers, then I think increasing the quality bar on what you expect plugins to do, putting the magnifying glass on the plugin source codes and starting to call out things like, why are you handling your style sheets like that?

20:46 · Or why do you have that web address in your source code or etc.

20:52 · I think that is going to cause burnout.

20:55 · For example, the review identified, I think originally close to 100 web links in my plugin.

21:05 · And it was highlighted as high risk.

21:08 · So what are those?

21:09 · They are all opt-in features for various AI engines that you can use for OCR services.

21:17 · They are support links to videos and websites in the help, in the script store all over the place that help users get information and learn about the plugin.

21:33 · There’s zero link that would lead to any malicious intent.

21:39 · Indeed, Xfolidro doesn’t even initiate calls without the opt-in consent of the users.

21:47 · But how does this show up in the reviews?

21:49 · It shows up as a huge security risk because the plugin is full of links.

21:56 · I don’t think that’s okay, but I think from a sustainability perspective, that’s not okay because this is drastically raising the maintenance burden.

The harsh truth about community funding (Only 100 regular supporters)

Section titled “The harsh truth about community funding (Only 100 regular supporters)”

22:09 · And you know, Obsidian frequently boasts that it’s a community funded ecosystem, that they don’t have venture capital, that everything is built by a small engineering team of four people.

22:25 · And I think that’s great.

22:28 · Because don’t have a financial framework.

22:32 · There is the coffee option.

22:35 · You know what?

22:36 · I have, based on this new report, I can see I have roughly 110,000 regular users.

22:44 · Out of the 110,000 people, roughly 2% of that community ever felt the need to drop a coin into my coffee mug.

22:59 · And I have roughly 100 regular supporters.

23:04 · If you’re one of them, huge thank you.

23:06 · If you’re one of the ones of supporters, huge thank you.

23:11 · But I think there’s a major imbalance here.

23:14 · The amount of work put in by the plugin developers, the lack of recognition, financial support from the community, the lack of capability by Obsidian to support the plugin ecosystem for complex plugins like Xcolidraw.

23:36 · Obsidian misses the entire feature set to build paid plugins or to create a framework where I could create plugin features that are for money.

23:49 · That doesn’t work.

23:50 · Obsidian doesn’t provide that framework.

23:53 · But I think that is not okay.

23:57 · Because now we have such an imbalance, there’s a request, a requirement to increase the plugin quality.

24:06 · There’s the magnifying glass on it.

24:08 · But we miss the entire framework that would make that possible.

24:14 · We need to have a community that really steps up to support plugins.

24:21 · And now mind you, it might turn out that lack of community support means that actually what I feel is important and valuable, in this case, Obsidian Xcolidraw, but of course everyone has their own plugins, it’s really not that important.

24:39 · It doesn’t add value.

24:41 · It doesn’t create anything for the community.

24:44 · And then I think it’s the right step to kill those plugins.

24:50 · But I don’t think that that’s the case.

24:51 · I think in reality, everyone thinks to step forward to take responsibility.

25:02 · I think plugin developers are now in this situation because they lack the support, they lack the financial framework, and they get the challenge to improve and the pressure to improve.

25:19 · So I think this leads me to this bigger ecosystem question of what is the future of plugins?

The ultimate question: What is the future of Obsidian plugins?

Section titled “The ultimate question: What is the future of Obsidian plugins?”

25:30 · How can we make Obsidian plugins sustainable?

25:35 · Who pays the hit and cost?

25:36 · Because there’s no such thing as a free lunch.

25:40 · Someone pays for it.

25:42 · If it’s not you, then it’s probably the developer paying for it and you taking a free ride.

25:50 · And I know I’m unfair, but you know what?

25:54 · Apart from the extreme cases, I really don’t buy the point that I’m financially not able to give $2, $3 to support the plugin that I’m using.

26:09 · Don’t tell me that.

26:11 · I don’t believe you.

26:12 · I have students among the 100 regular supporters and I don’t think students are typically the most financially capable.

26:22 · But I think this just takes the question of who pays the hit and cost and how are we going to change the game such that support matches the expectations?

26:37 · So if you have a perspective on this, I’d love to see your comments in the discussion below.

Join the conversation in the Sketch Your Mind community

Section titled “Join the conversation in the Sketch Your Mind community”

26:47 · And as well as I want to call your attention to the Sketch Your Mind community, I’m going to post this video of course and a discussion in the community as well.

26:58 · So if you’re already a member of the community, I’d love to hear your voice and discussion in this.

27:05 · And if you’re not a member of the Sketch Your Mind community, then check the link in the video description and join the community.

27:15 · I hope you found this discussion interesting, eye-opening, and I think we need to take action.

27:25 · Let me know what you think and see you in the next video.