frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Salt Lake Tribune is gambling one third of revenue by ditching paywall

https://pressgazette.co.uk/paywalls/why-salt-lake-tribune-is-gambling-one-third-of-revenue-by-dit...
1•jawns•29s ago•0 comments

Google is paying Play Store developers for code to train its AI

https://www.neowin.net/reports/google-wants-to-pay-play-store-developers-for-code-to-train-its-ai/
1•bundie•41s ago•0 comments

Guide to Codex Goals

https://www.augmentedswe.com/p/codex-goals
1•wordsaboutcode•1m ago•0 comments

Harvard Law: Anthropic is about to sell a safety mission Wall Street can veto

https://fortune.com/2026/06/01/openais-guardian-ben-jerrys-ice-cream-anthropic/
1•1vuio0pswjnm7•6m ago•0 comments

Patterns of Structure and Argument: a guide to mathematical thinking(2017) [pdf]

https://www.ux1.eiu.edu/~cidelman/Research/foundationsbook.pdf
1•nill0•12m ago•0 comments

Ask HN: Does using non-English languages affect LLM output quality?

1•boundless88•15m ago•0 comments

Show HN: A crowdsourced map of surveillance camera's based on OSM

https://mapcomplete.org/surveillance?z=0.5&lon=12.732776
2•pietervdvn•18m ago•0 comments

AI Dark Output: The Visible Cost of Invisible Output

https://newsletter.semianalysis.com/p/ai-dark-output-the-visible-cost-of
1•paulpauper•21m ago•0 comments

The Risk-Free Rate and the Risk-Adjusted Growth Rate

https://www.nber.org/papers/w35260
1•paulpauper•22m ago•0 comments

The Ordinary Miracle of Existing

https://www.theatlantic.com/philosophy/2026/06/the-ordinary-miracle-of-existing/687351/
2•littlexsparkee•24m ago•1 comments

Best Clearbit Alternatives for Company Data Enrichment

https://fastbusinessapi.com/article/best-clearbit-alternatives-for-company-data-enrichment/
1•ApiFB-Dev•26m ago•0 comments

Roku LT Operating System open source distribution

https://blog.roku.com/developer/roku-lt-os
2•dpmdpm•26m ago•0 comments

Meta scales back plan for internal mouse-tracking tech, citing staff concerns

https://www.reuters.com/world/meta-scales-back-ai-mouse-clicks-tool-citing-employee-concerns-2026...
5•cebert•26m ago•2 comments

The Many Ways to Build a Black Hole

https://nautil.us/the-many-ways-to-build-a-black-hole-1281480
1•boarsofcanada•29m ago•0 comments

Florida lawsuit accuses OpenAI and CEO Sam Altman of endangering children

https://www.washingtonpost.com/technology/2026/06/01/florida-lawsuit-accuses-openai-ceo-sam-altma...
2•1vuio0pswjnm7•29m ago•0 comments

Blind Agent Trusting Sheeple [video]

https://www.youtube.com/watch?v=3mLYNxgw9wE
1•kshri24•38m ago•0 comments

Experimental Randomness Amplification

https://www.nature.com/articles/s41586-026-10521-8
2•thunderbong•40m ago•0 comments

I Found a Bug in Apple's Fsck_hfs

https://medium.com/@kivancgunalp/i-found-a-bug-in-apples-fsck-hfs-here-s-how-i-tracked-it-down-ed...
2•zdw•40m ago•0 comments

Structured Procrastination

https://www.structuredprocrastination.com/
1•gurjeet•42m ago•0 comments

Brazil's beloved instant payment system faces scrutiny from Trump administration

https://apnews.com/article/brazil-payment-system-pix-investigation-credit-card-fd04428f309a2b3299...
7•CXSHNGCB•43m ago•0 comments

A cryptographically verifiable state-transition engine for AI systems

https://github.com/Ghoti6098/AgenticOS
1•GregariousApe•44m ago•0 comments

OpenTelemetry "Blueprints"

https://www.infoq.com/news/2026/06/opentelemetry-blueprints-launch/
1•mattdecker100•44m ago•0 comments

Show HN: Nvidia-converge – Plan/apply/rollback for Nvidia drivers on Linux

https://github.com/zeroecco/nvidia-converge
2•zeroecco•47m ago•0 comments

He Blew the Whistle on DOGE. Then His Brakes Were Cut

https://www.wired.com/story/he-blew-the-whistle-on-doge-then-his-brakes-were-cut/
26•cocacola1•52m ago•1 comments

The True Cost of the DOM

https://edge.jmaleonard.com/05-the-true-cost-of-the-dom.html
2•jmaleonard•53m ago•0 comments

Recall – Local search across your Cursor/Claude Code/Codex chat history

https://github.com/pratikgajjar/recall
1•pg_law•53m ago•0 comments

Moxie Docs – Automatic codebase documentation and MCP tools

https://moxiedocs.com
1•ghosts_•54m ago•1 comments

Peach – a free zero-knowledge password manager with paper disaster recovery

https://peachpasswords.com/
1•ashasoftware•59m ago•0 comments

New Zealand testing of Elon Musk's Starshield 'significant', US expert says

https://www.rnz.co.nz/news/science-and-technology/597104/new-zealand-testing-of-elon-musk-s-stars...
5•billybuckwheat•1h ago•0 comments

EEVBlog: Texas Instruments has changed specs of Jellybean OP-Amp

https://www.youtube.com/watch?v=22ZmmZ67SMY
2•brudgers•1h ago•0 comments
Open in hackernews

Why Intel Deprecated SGX?

https://hardenedvault.net/blog/2022-01-15-sgx-deprecated/
22•ricecat•1y ago

Comments

walterbell•1y ago
SGX may be a record holder for exploits, https://hn.algolia.com/?query=sgx
sublimefire•1y ago
Most of them require physical access so it is not the same as some log4j vuln.
walterbell•1y ago
Per article, physical access is within SGX threat model.
anonymousDan•1y ago
About 2 of those are actual exploits?
walterbell•1y ago
For some definition of 2?

  Intel SGX Fuse Key0, a.k.a. Root Provisioning Key Extracted by Researchers
  Plundervolt: Software-Based Fault Injection Attacks Against Intel SGX 
  SGX-Bomb: Locking Down the Processor via Rowhammer Attack
  Foreshadow: Extracting the Keys to the Intel SGX Kingdom
  ÆPIC Leak: SGX, Intel’s data fortress, has been breached yet again
  Intel SGX defeated yet again–this time thanks to on-chip power meter
  SGAxe and Crosstalk: Plundering of crypto keys from ultrasecure SGX 
  Spectre Attack on SGX PoC
anonymousDan•1y ago
Thanks - many of those didn't show up on your original link.
anonymousDan•1y ago
Pretty incoherent article. Not sure what point they are trying to make about the threat model of SGX. SGX was/is a groundbreaking attempt to solve a very difficult problem IMO. TEEs are still an active area of research that has benefited massively from the availability of an actual implementation in mainstream processors. And most other CPU manufacturers are also offering their own flavour of TEE, many of which have learned lessons from SGX.
AstralStorm•1y ago
The point about the threat model of SGX is that insulating an enclave with it does nothing to protect the code actually handling the data from the enclave. It really does not even protect against firmware side attacks. For that, TPM attestation is just as good.

At some point, somewhere, data processed by the SGX enclave has to pass through the usual VTd or such. Unless SGX enclave is used to feed data directly into hardware, in which case the weak point is the firmware and bus instead.

If it ensured no side channel attacks, it would be useful for some operations. But it does not therefore it isn't.

iforgotpassword•1y ago
It was touted as making cloud computing secure. How anyone could actually believe this is beyond me. The cloud provider has physical access to the host machine. For all I know it could all be smokes and mirrors, emulated on a C64, while all my data is getting exfiltrated. The only people who ever bought into this is cryptobro crackheads and government contractors doing it for compliance bullshit. Up to 0% of cloud customers went as far as to even try to verify the thing does what it says it does.

Case in point: TeleMessage. Supposedly E2E-Encrypted message archival turns out to be a plain text database on some servers. Surprised Pikachu face.

sublimefire•1y ago
This is some tinfoilhat stuff. An extreme suggestion that a cloud provider would physically open up machines and exfiltrate the keys so that they could then read the memory of a customer workload, for what reason? Remember that hardware is virtualised and makes it difficult to pin point which server is running what. Not using such tech makes it easier for the cloud provider to inspect memory so that is not a better approach.
underdeserver•1y ago
Should be (2022).
everfrustrated•1y ago
Headline is missing important context:

Intel is keeping SGX on servers and no longer offering it on non-server chips like workstations and laptops.

noname120•1y ago
From Wikipedia[1]:

> A pivot by Intel in 2021 resulted in the deprecation of SGX from the 11th and 12th generation Intel Core processors, but development continues on Intel Xeon for cloud and enterprise use.

[1] https://en.wikipedia.org/wiki/Software_Guard_Extensions#cite...

bjackman•1y ago
This never made any sense to me for consumers.

Enclaves and confidential compute are about the owner of the physical device giving up power and handing it to a remote entity.

In the case of SGX on consumer hardware that usually meant consumers giving up power to Netflix or whoever via DRM bullshit.

On the other hand, TDX on server devices is mostly about cloud providers giving up power to their users. This is a fundamentally better use case for TEEs. So overall this makes sense to me.

Kinda annoying that this stuff is so complicated that they have to leave it out of cheaper parts but that also makes sense, this must be incredibly invasive stuff that increases the cost in so many areas.

lostmsu•1y ago
It could have been used for a distributed cloud over consumer hardware.
bjackman•1y ago
That would be a neat usecase but it's not a slam dunk.

TEEs in theory eliminate the need for the user to trust the owner of the hardware. But for a cloud you need to eliminate the other direction too.

Cloud companies achieve this by... Spending a LOT of money on it. And the technical project of doing that is easier, because they control the whole host stack. I'm not sure it's technically feasible to achieve that in an environment where the host also needs to also support stuff like running Steam!

But still, maybe if you constrained the requirements enough it could be possible, it would have been a really cool thing to try!

bananapub•1y ago
because it kept getting owned, then fixed, then owned again
2bluesc•1y ago
> Chipworks offers $50-250k to fully extract the eFUSE of one Intel i5 processor, so the eFUSE content is encrypted by a master key (called “global wrapping logic key” in the patent).

I wonder how readily things like this are known within the HW security community?

rstuart4133•1y ago
Warning: the article is full of acronyms. Despite having section titles like "SGX Basics" unless you are familiar with terms like EPID, e-Fuse, iclsClient and many more, you aren't going to get much from it beyond "Intel dropped SGX for non-server CPU's in 2022".
iforgotpassword•1y ago
If you argue that you can trust the cloud provider not to be malicious, you also just argued that you don't need SGX at all. No tinfoil hat required.

And yes, not using that tech is not a better approach then, but not worse either. But better in the way that Intel doesn't need to build convoluted shit into their cpus that might actually worsen security through exploits.

mike_hearn•1y ago
SGX is very useful. Source: I built a product that made it easier to use and we explored a lot of use cases as part of that.

Firstly yes SGX is designed to block firmware attacks. That's a part of the threat model indeed.

Secondly, you can't feed data from SGX enclaves directly to hardware devices. It's encrypted data in, encrypted data out. Of course, data must pass through the untrusted host OS and hypervisor, but that is no problem, it's how it's designed to work. That's why the clients of the enclave handshake with it using remote attestation.

You can block side channel attacks with SGX if you are careful. The enclave transitions do clear uarch state in the ways needed, the rest is app-level stuff (but it has to be).

I used to see a lot of confusion about stuff like SGX because some people don't realize it's only intended to be used with remote attestation. If you don't have a smart client that's remotely attesting the enclave over a network, it isn't going to get you anything. That requires changes to app architectures.