frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

The P in PGP isn't for pain: encrypting emails in the browser

https://ckardaris.github.io/blog/2026/02/07/encrypted-email.html
1•ckardaris•2m ago•0 comments

Show HN: Mirror Parliament where users vote on top of politicians and draft laws

https://github.com/fokdelafons/lustra
1•fokdelafons•2m ago•1 comments

Ask HN: Opus 4.6 ignoring instructions, how to use 4.5 in Claude Code instead?

1•Chance-Device•4m ago•0 comments

We Mourn Our Craft

https://nolanlawson.com/2026/02/07/we-mourn-our-craft/
1•ColinWright•6m ago•0 comments

Jim Fan calls pixels the ultimate motor controller

https://robotsandstartups.substack.com/p/humanoids-platform-urdf-kitchen-nvidias
1•robotlaunch•10m ago•0 comments

Exploring a Modern SMTPE 2110 Broadcast Truck with My Dad

https://www.jeffgeerling.com/blog/2026/exploring-a-modern-smpte-2110-broadcast-truck-with-my-dad/
1•HotGarbage•10m ago•0 comments

AI UX Playground: Real-world examples of AI interaction design

https://www.aiuxplayground.com/
1•javiercr•11m ago•0 comments

The Field Guide to Design Futures

https://designfutures.guide/
1•andyjohnson0•11m ago•0 comments

The Other Leverage in Software and AI

https://tomtunguz.com/the-other-leverage-in-software-and-ai/
1•gmays•13m ago•0 comments

AUR malware scanner written in Rust

https://github.com/Sohimaster/traur
3•sohimaster•15m ago•1 comments

Free FFmpeg API [video]

https://www.youtube.com/watch?v=6RAuSVa4MLI
3•harshalone•15m ago•1 comments

Are AI agents ready for the workplace? A new benchmark raises doubts

https://techcrunch.com/2026/01/22/are-ai-agents-ready-for-the-workplace-a-new-benchmark-raises-do...
2•PaulHoule•20m ago•0 comments

Show HN: AI Watermark and Stego Scanner

https://ulrischa.github.io/AIWatermarkDetector/
1•ulrischa•21m ago•0 comments

Clarity vs. complexity: the invisible work of subtraction

https://www.alexscamp.com/p/clarity-vs-complexity-the-invisible
1•dovhyi•22m ago•0 comments

Solid-State Freezer Needs No Refrigerants

https://spectrum.ieee.org/subzero-elastocaloric-cooling
2•Brajeshwar•22m ago•0 comments

Ask HN: Will LLMs/AI Decrease Human Intelligence and Make Expertise a Commodity?

1•mc-0•24m ago•1 comments

From Zero to Hero: A Brief Introduction to Spring Boot

https://jcob-sikorski.github.io/me/writing/from-zero-to-hello-world-spring-boot
1•jcob_sikorski•24m ago•1 comments

NSA detected phone call between foreign intelligence and person close to Trump

https://www.theguardian.com/us-news/2026/feb/07/nsa-foreign-intelligence-trump-whistleblower
9•c420•24m ago•1 comments

How to Fake a Robotics Result

https://itcanthink.substack.com/p/how-to-fake-a-robotics-result
1•ai_critic•25m ago•0 comments

It's time for the world to boycott the US

https://www.aljazeera.com/opinions/2026/2/5/its-time-for-the-world-to-boycott-the-us
3•HotGarbage•25m ago•0 comments

Show HN: Semantic Search for terminal commands in the Browser (No Back end)

https://jslambda.github.io/tldr-vsearch/
1•jslambda•25m ago•1 comments

The AI CEO Experiment

https://yukicapital.com/blog/the-ai-ceo-experiment/
2•romainsimon•27m ago•0 comments

Speed up responses with fast mode

https://code.claude.com/docs/en/fast-mode
5•surprisetalk•30m ago•0 comments

MS-DOS game copy protection and cracks

https://www.dosdays.co.uk/topics/game_cracks.php
4•TheCraiggers•31m ago•0 comments

Updates on GNU/Hurd progress [video]

https://fosdem.org/2026/schedule/event/7FZXHF-updates_on_gnuhurd_progress_rump_drivers_64bit_smp_...
2•birdculture•32m ago•0 comments

Epstein took a photo of his 2015 dinner with Zuckerberg and Musk

https://xcancel.com/search?f=tweets&q=davenewworld_2%2Fstatus%2F2020128223850316274
14•doener•33m ago•2 comments

MyFlames: View MySQL execution plans as interactive FlameGraphs and BarCharts

https://github.com/vgrippa/myflames
1•tanelpoder•34m ago•0 comments

Show HN: LLM of Babel

https://clairefro.github.io/llm-of-babel/
1•marjipan200•34m ago•0 comments

A modern iperf3 alternative with a live TUI, multi-client server, QUIC support

https://github.com/lance0/xfr
3•tanelpoder•35m ago•0 comments

Famfamfam Silk icons – also with CSS spritesheet

https://github.com/legacy-icons/famfamfam-silk
1•thunderbong•36m ago•0 comments
Open in hackernews

Looking for Feedback for Hardware Server Security

6•b112•9mo ago
Last time I bought a large number of servers new, it was 2012. Everyone knew IPMI(iLo, idrac, supermicro's variant) was unsecure, rarely updated, and rife with vulnerabilities. People lamented the fact, and then shrugged and bought.

It's 2025, and I'm wondering if people have a different impression from some vendors. I used to love Supermicro, but:

* I cannot even get a response via email or calls re: sales

* Their website tells you to never upload the bios or bmc unless you "have a problem", and tries to claim no liability. Hello?! I need microcode updates, and other bios updates (yes I know about OS microcode updates, not my point), as well as IPMI updates

* They have no list of EOL support timeranges for any of their products. I need to know how long IPMI and other products are supported for security issues.

* They still seem to have ridiculous LAN sharing of IPMI, which means that even if you set their IPMI to use the dedicated NIC, and setup an isolated network, a loss of defaults means your IPMI is now no longer on that network but sharing the NIC on your main network. And in the past, I've seen this happen regardless of settings (buggy).

Dumbest setup ever, exceptionally unsecure, and they're still doing it?!

* If their sales channel doesn't respond, then their support channel will be 10x more lagged. Every sane company ensures you have enough resources to sell new product.

Are other vendors this bad too?

Has anyone noticed regular security updates for Dell or HP or other competitors?

Thanks

EDIT:

For clarity, I'm looking for hardware servers, 1Us. Not interested in cloud solutions for this usage case.

Comments

toomuchtodo•9mo ago
Is Oxide an option? https://oxide.computer/

(no affiliation, I just like the solution)

b112•9mo ago
I'm not worried about what I'll put on my servers, but keeping the server hardware updated and secure. Mostly looking for answers from people that have had to deal with, and update IPMI on servers in the last few years.

Thanks though.

bcantrill•9mo ago
Belated response here (and certainly not trying to talk you into Oxide!), but just for anyone who happens upon this, we do solve exactly the problem you describe. We have a true root-of-trust[0], a proper service processor in lieu of the larded-up BMC[1], an isolated management network[2] -- and we don't have a BIOS at all[3][4].

[0] https://oxide.computer/blog/exploiting-undocumented-hardware...

[1] https://oxide.computer/blog/hubris-and-humility

[2] https://rfd.shared.oxide.computer/rfd/0250

[3] https://rfd.shared.oxide.computer/rfd/0241

[4] https://www.youtube.com/watch?v=cWDDx74s090

panick21_•9mo ago
Are you gone do a Oxide and Friends on the root-of-trust?
bcantrill•9mo ago
Yes! We want to get a little further down the road on a few things with respect to plumbing the RoT through the stack -- but an episode on this is coming!
b112•9mo ago
You may have all of these things, but you seem to have a holistic platform, not bare metal servers. I just want servers. I want my own OS. I don't want some VM architecture between me and baremetal.

Can I just install Linux directly on baremetal here?

3np•9mo ago
Only speaking for ASRockRACK, the situation is not much better with regards to firmware updates or confidence in IPMI security. Oh, and there's a fishy undocumented preconfigured second Admin account you have to go into user management to spot... Thank for alleviating buyers remorse as the grass seemed greener at SuperMicro ;^^

> They still seem to have ridiculous LAN sharing of IPMI, which means that even if you set their IPMI to use the dedicated NIC, and setup an isolated network, a loss of defaults means your IPMI is now no longer on that network but sharing the NIC on your main network.

This sounds partilularly weird though, if I am reading it right. Are you saying the BMC will bridge IPMI over multiple NICs in default configuration? And that there is no setup that safely and consistently binds the IPMI to a single NIC?

Isolating management to a dedicated network continues to be part of basic security and it's very surprising to hear that this would not be a supported use-case by SuperMicro...

b112•9mo ago
This sounds partilularly weird though, if I am reading it right. Are you saying the BMC will bridge IPMI over multiple NICs in default configuration? And that there is no setup that safely and consistently binds the IPMI to a single NIC?

By default, their servers have a 'failover' mode for the main NIC. This means that when the server gets power, and IPMI boots, if the IPMI NIC doesn't have a link it will then share connectivity with the main NIC.

# To get LAN mode:

ipmitool raw 0x30 0x70 0x0c 0

# 00 = dedicated, 01 = share, 02 = failover

# To set, use 0|1|2:

ipmitool raw 0x30 0x70 0x0c 1 <value>

You can set it to 'dedicated', but sometimes that's buggy and the setting can get lost. I've had it happen. And it defaults to failover on most servers I've bought, so a dead bios battery means the same outcome.

And if you're not aware, and leave it at failover, your dedicated IPMI LAN switch dies, then next boot all your stuff is exposed.

From what I've read, this is still the same in 2025.

I'd really have preferred a jumper for something this insanely unsecure.

Thanks for the FYI on AsRockRACK.

Have you had any firmware updates for IPMI with them, however?

3np•9mo ago
That sucks. If it were me I'd suck it up and consider that I now have two dedicated IPMI NICs with failover and attach new ones if needed for system network...

> Thanks for the FYI on AsRockRACK.

NP. FWIW at least I think the BMC networking doesn't have the kind of failure mode you're describing.

> Have you had any firmware updates for IPMI with them, however?

Yeah, they have unofficial newer "beta" versions that you will get a private download link for over email if you contact support and ask for it. Same if you want fixes for UEFI or AMD firmware vulnerabilities more than a year or so after board release.

Thinking about supply-chain security when flashing those make me a bit nauseous... The industry seems to be stuck with 90s mindset and processes.

transpute•9mo ago
Thanks to OpenCompute and the Open Source Firmware Conference (OSFC), there has been some progress in servers towards open firmware and open silicon RoT (OpenTitan, Caliptra). The primary beneficiaries have been cloud hyperscalers who buy large quantities of customized OCP servers from ODMs like Quanta.

For businesses buying smaller quantities, HPE servers have made a small step towards open firmware, enabling customer-configured OpenBMC as an alternative to iLO, https://www.youtube.com/watch?v=21kiLA1DVSU