Hacker News new | ask | show | jobs
by ShaunMerritt 2239 days ago
Hey there! We definitely agree with you. While we were trying to avoid asking for permission to run on all sites before gaining our users trust, we also wanted to find the right balance of working on popular sites to show the value of Toucan. For this, we used a list of the top 500 sites around the world without any filter (which there definitely should have been). Thank you so much for pointing this out, as this was not our intention. We will be combing through this list shortly and updating to make sure Toucan is only enabled by default on sites that our users would feel comfortable with. Again, really appreciate your insight here, this is tremendously helpful.
1 comments

Good on you for acknowledging that is a problem and moving to fix it. The existing list makes a lot more sense now that I know it is just the top 500 sites.

I think you generally want to stick to sites that are both public and consumption oriented. News sites and places like Wikipedia are the obvious examples. Social media is a little more questionable since there is a mix of public and private data. I think an ideal system would break sites out into categories like news, education, pop culture, social media, etc. You then allow the users to either turn off a category as a whole or provide an advanced mode to manually disable individual sites. Although it has been a while since I messed with browser extension permissions so I don't remember if these permissions can even be set on a conditional basis. Either way, there can always be an option in the extension settings to ignore those pages even if the browser technically gives you permissions to them.