frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Show HN: HypothesisHub – An open API where AI agents collaborate on medical res

https://medresearch-ai.org/hypotheses-hub/
1•panossk•2m ago•0 comments

Big Tech vs. OpenClaw

https://www.jakequist.com/thoughts/big-tech-vs-openclaw/
1•headalgorithm•4m ago•0 comments

Anofox Forecast

https://anofox.com/docs/forecast/
1•marklit•4m ago•0 comments

Ask HN: How do you figure out where data lives across 100 microservices?

1•doodledood•5m ago•0 comments

Motus: A Unified Latent Action World Model

https://arxiv.org/abs/2512.13030
1•mnming•5m ago•0 comments

Rotten Tomatoes Desperately Claims 'Impossible' Rating for 'Melania' Is Real

https://www.thedailybeast.com/obsessed/rotten-tomatoes-desperately-claims-impossible-rating-for-m...
1•juujian•7m ago•0 comments

The protein denitrosylase SCoR2 regulates lipogenesis and fat storage [pdf]

https://www.science.org/doi/10.1126/scisignal.adv0660
1•thunderbong•8m ago•0 comments

Los Alamos Primer

https://blog.szczepan.org/blog/los-alamos-primer/
1•alkyon•11m ago•0 comments

NewASM Virtual Machine

https://github.com/bracesoftware/newasm
1•DEntisT_•13m ago•0 comments

Terminal-Bench 2.0 Leaderboard

https://www.tbench.ai/leaderboard/terminal-bench/2.0
2•tosh•13m ago•0 comments

I vibe coded a BBS bank with a real working ledger

https://mini-ledger.exe.xyz/
1•simonvc•14m ago•1 comments

The Path to Mojo 1.0

https://www.modular.com/blog/the-path-to-mojo-1-0
1•tosh•16m ago•0 comments

Show HN: I'm 75, building an OSS Virtual Protest Protocol for digital activism

https://github.com/voice-of-japan/Virtual-Protest-Protocol/blob/main/README.md
4•sakanakana00•20m ago•0 comments

Show HN: I built Divvy to split restaurant bills from a photo

https://divvyai.app/
3•pieterdy•22m ago•0 comments

Hot Reloading in Rust? Subsecond and Dioxus to the Rescue

https://codethoughts.io/posts/2026-02-07-rust-hot-reloading/
3•Tehnix•22m ago•1 comments

Skim – vibe review your PRs

https://github.com/Haizzz/skim
2•haizzz•24m ago•1 comments

Show HN: Open-source AI assistant for interview reasoning

https://github.com/evinjohnn/natively-cluely-ai-assistant
4•Nive11•24m ago•6 comments

Tech Edge: A Living Playbook for America's Technology Long Game

https://csis-website-prod.s3.amazonaws.com/s3fs-public/2026-01/260120_EST_Tech_Edge_0.pdf?Version...
2•hunglee2•28m ago•0 comments

Golden Cross vs. Death Cross: Crypto Trading Guide

https://chartscout.io/golden-cross-vs-death-cross-crypto-trading-guide
2•chartscout•30m ago•0 comments

Hoot: Scheme on WebAssembly

https://www.spritely.institute/hoot/
3•AlexeyBrin•33m ago•0 comments

What the longevity experts don't tell you

https://machielreyneke.com/blog/longevity-lessons/
2•machielrey•35m ago•1 comments

Monzo wrongly denied refunds to fraud and scam victims

https://www.theguardian.com/money/2026/feb/07/monzo-natwest-hsbc-refunds-fraud-scam-fos-ombudsman
3•tablets•39m ago•1 comments

They were drawn to Korea with dreams of K-pop stardom – but then let down

https://www.bbc.com/news/articles/cvgnq9rwyqno
2•breve•42m ago•0 comments

Show HN: AI-Powered Merchant Intelligence

https://nodee.co
1•jjkirsch•44m ago•0 comments

Bash parallel tasks and error handling

https://github.com/themattrix/bash-concurrent
2•pastage•44m ago•0 comments

Let's compile Quake like it's 1997

https://fabiensanglard.net/compile_like_1997/index.html
2•billiob•45m ago•0 comments

Reverse Engineering Medium.com's Editor: How Copy, Paste, and Images Work

https://app.writtte.com/read/gP0H6W5
2•birdculture•50m ago•0 comments

Go 1.22, SQLite, and Next.js: The "Boring" Back End

https://mohammedeabdelaziz.github.io/articles/go-next-pt-2
1•mohammede•56m ago•0 comments

Laibach the Whistleblowers [video]

https://www.youtube.com/watch?v=c6Mx2mxpaCY
1•KnuthIsGod•57m ago•1 comments

Slop News - The Front Page right now but it's only Slop

https://slop-news.pages.dev/slop-news
1•keepamovin•1h ago•1 comments
Open in hackernews

Show HN: Free and Anonymous Age Verification Demo

https://www.youtube.com/watch?v=MmcUJ5u65Q0
1•jwally•4mo ago
========================

What is this?

========================

A short demo showing how a merchant can outsource age verification to a trusted institution (bank/KYC provider) with minimal cost and minimal data leakage. The user never hands the merchant their identity — only signed attestations like over_18: true. It’s a pragmatic build: WebAuthn proves token ownership; ECDSA signatures from the bank prove attestation integrity.

========================

Why Does It Matter?

========================

Age verification is usually either privacy-destroying (share DOB/SSN) or expensive. Banks already do KYC for many customers. If they can safely issue attestations that protect privacy and are cryptographically verifiable, merchants get compliance without storing PII and users keep their data. Age Verification becomes less useful in de facto outlawing free speech.

========================

How does it work (user-flow)?

========================

1) Go to https://app.hornpub.click

2) Click Generate PassKey

3) Copy the PassKey (there's a button for you)

4) Click on The Iron Bank link

5) Click on "Age Verification"

6) Make up some credentials to log in with - (un: xxx, pw: xxx, 2fa: 111111)

7) Paste your token into the TextArea

8) Copy the bank's token

9) Go back to HornPub (click button or whatever)

10) Paste the token into the "Complete Verification" text-area

11) Click the "Complete Verification" button

12) Complete the PassKey flow, and access the site

========================

How does it work (merchant-flow)?

========================

1) The user creates a PassKey, and you extract the key's ID and PublicKey

2) Base64 encode the {id, PublicKey} and let the user copy it

3) The user goes to their Bank or KYC provider.

4) The user provides the Bank's token

5) Have the user perform a WebAuthn Authentication by extracting the credential's Id and Public key from the bank's data. Use the entire bank's payload as your WebAuthn Challenge

6) Send the Authentication payload to the server

7) Verify the WebAuthn Authentication - this proves the user didn't create a token and sell it

8) Verify the bank's signature. You control what banks you accept. This proves it wasn't tampered with

9) Verify a salted-hash of the user's IP address.

========================

How does it work (bank-flow)?

========================

1) Publish your ECDSA signing key at /.well-known/keys

2) Accept a string payload from your user that you will sign. You do not have to verify or look at it.

3) Look the user up and add age attestations of `over_18:boolean` and `over_21:boolean`

4) Create a nonce, and provide it and sha256(nonce:ip) in your signature target

5) Sign base64Encode({over_18, over_21, nonce, ipHash, userPayload })

6) Provide the signature and signature-target to the user for them to copy back to the merchant site:

========================

Security Notes & Trade Offs

========================

WebAuthn proves the holder of the PassKey created the credential — prevents a user from inventing a credential and selling it.

ECDSA signatures from the bank prove the attestation came from an accepted bank and wasn’t tampered with. Merchant picks which banks to trust.

Nonce + IP hash minimize replay/copy-paste attacks. They do not make the system 100% subpoena-proof — logs and warrants can still correlate events.

Privacy: merchant receives boolean attestations only, not DOB or identity. Banks don't know where the user will use the token.