frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

AWS announces EC2 instance attestation

https://aws.amazon.com/about-aws/whats-new/2025/09/aws-announces-ec2-instance-attestation/
14•patch_cable•2h ago

Comments

patch_cable•1h ago
Excited to say I worked on this feature! (Standard disclaimer: thoughts and opinions are my own and may or may not be shared by my employer.)

To give an idea of the kinds of things you can do now:

  - Keys or other secrets can only be decrypted (via KMS) by an EC2 instance if it is running an approved AMI. 
  - You could build a certificate authority (CA) which only issues a certificate to an instance running an approved AMI. 
This is similar to the functionality that was available in Nitro Enclaves. However, enclaves came with restrictions (such as only being able to communicate through a vsock) that made them not a great fit for all use cases.
sxzygz•48m ago
On AWS, if I run my software (some VM image), what guarantee is there that you are indeed running the image I provided to you? And, if is an approved image, what guarantee is there that image being run is the one publicly disclosed?
QuinnyPig•29m ago
At some point it does come down to "we have to trust the provider isn't outright lying to us about what they're doing."

That was a hard bridge for me to cross for a long time; I got there via sustained in-depth conversations with folks there who simply wouldn't stand for something that breathtakingly opposed to everything AWS has strived to achieve from a trust perspective, that they'd sooner tear it all down than implement such a thing.

Some folks can't get there, and that's okay; if you don't have that level of trust, perhaps the cloud is not a fit for all of your workloads.

sxzygz•9m ago
The point I am concerned about is that I am forced to trust a single party. AWS is not ever explicit in admitting this, at which point does it matter that your workload is on Nitro-this or attested-that? No university researcher, afaik, has physical access to audit these systems. I think the other major player(s) have a better story for this by harnessing features of certain cpu vendors.

To every cloud/server vendor: This is a big deal. I need a system I can audit, from silicon and firmware up, but I don’t want to water it, give it sunlight, or whisper sweet nothings to it, just to rent it out as needed.

everfrustrated•5m ago
It's less about being able to prove to yourself and more about being able to prove to _other_ people.
jiggawatts•16m ago
Who is this for? I don’t know of any customers that are this paranoid but also trust the public cloud.
privatelypublic•2m ago
This doesn't appear to he exclusively anti-evil maid. It takes "build an AMI that doesn't have enough userland to extract the keys" and extends it to "only approved AMI's can access the keys."

Lateral movement of attackers. Shadow IT. People modifying things between test and Prod.

All easy examples that don't require you to trust AWS hasn't backdoored it to still get better security.

Ask HN: How important is peer programming?

1•Awesomedonut•1m ago•0 comments

Ron DiMenna, Founder of the Ron Jon Surf Shop Chain, Dies at 88

https://www.nytimes.com/2025/09/22/business/ron-dimenna-dead.html
1•bookofjoe•1m ago•1 comments

Green Lights More Often: The Secret 2018 Study of Sydney's Traffic Signals

https://jakecoppinger.com/2025/09/green-lights-more-often-the-secret-2018-study-of-sydneys-traffi...
1•CharlesW•2m ago•0 comments

Layoffs and H-1Bs: Texas Instruments' Billion-Dollar Balancing Act

https://dallasexpress.com/business-markets/layoffs-and-h-1bs-texas-instruments-billion-dollar-bal...
1•strict9•2m ago•0 comments

ReDisclosure: New technique for exploiting FTS in MySQL (myBB case study)

https://exploit.az/posts/wor/
1•mekhatai•3m ago•0 comments

Multi-Kernel Architecture Proposed for the Linux Kernel

https://www.phoronix.com/news/Linux-Multi-Kernel-Patches
1•mooreds•5m ago•0 comments

We got Claude Code to stop gaslighting our tests

https://www.nuanced.dev/blog/using-nuanced-with-claude-code
1•rewinfrey•5m ago•0 comments

Cross-Agent Privilege Escalation: When Agents Free Each Other

https://embracethered.com/blog/posts/2025/cross-agent-privilege-escalation-agents-that-free-each-...
1•simonw•7m ago•0 comments

Musical mel transform in Torch for Music AI

https://github.com/worldveil/musical_mel_transform_torch
1•muzakthings•8m ago•1 comments

Crystallabs.io

https://www.crystallabs.io/
1•casey2•8m ago•0 comments

Qualcomm's New Snapdragon X2 Elite Extreme and Elite Chips for PC

https://www.tomshardware.com/pc-components/cpus/qualcomms-new-snapdragon-x2-elite-extreme-and-eli...
2•pier25•13m ago•0 comments

Show HN: Aegis – A Self-Hosted Code Hosting Server Written in Golang

https://github.com/AegisCodeForge/aegis
1•kasumispencer2•14m ago•0 comments

Textile Encoding via Elastically Graded Embroidered Tessellations

https://advanced.onlinelibrary.wiley.com/doi/10.1002/adma.202500959
1•PaulHoule•15m ago•0 comments

Expat 2.7.3 released, includes security fixes

https://blog.hartwork.org/posts/expat-2-7-3-released/
1•spyc•15m ago•0 comments

SonyShell – an effort to "SSH into my Sony DSLR"

https://github.com/goudvuur/sonyshell
1•beligum•19m ago•1 comments

Isometric Asset Builder

https://iab.thomasburgess.dev/
1•Ninjinka•20m ago•0 comments

Best React Native UI resources for creating beautiful apps

https://wojtek.im/journal/best-react-native-ui-resources
1•gregwolanski•20m ago•0 comments

iPhone Air Review: Beauty Is Pain [video]

https://www.youtube.com/watch?v=tDARtYjUiHs
1•ZeljkoS•21m ago•0 comments

The whole bull run is because of an influx of money

https://www.ft.com/content/6f549890-c2a6-4823-a095-c8ea73f7e6bb
2•sharadov•22m ago•0 comments

Understanding AddressSanitizer: Better memory safety for your code (2024)

https://blog.trailofbits.com/2024/05/16/understanding-addresssanitizer-better-memory-safety-for-y...
1•ashvardanian•22m ago•0 comments

How I was secretly logged as a criminal by police

https://thecritic.co.uk/how-i-was-secretly-logged-as-a-criminal-by-police/
1•binning•23m ago•0 comments

Power Retention – Drop-In Replacement for Flash_attention

https://manifestai.com/articles/release-power-retention/
2•Roritharr•27m ago•0 comments

Disobey

https://untested.sonnet.io/notes/disobey
1•gregsadetsky•30m ago•0 comments

Project Rain:L1TF

https://bughunters.google.com/blog/4684191115575296/project-rain-l1tf
3•darkamaul•32m ago•0 comments

Weak Memory Model Formalisms: Introduction and Survey

https://arxiv.org/abs/2508.04115
2•matt_d•34m ago•0 comments

Intel Is Seeking an Investment from Apple as Part of Its Comeback Bid

https://www.bloomberg.com/news/articles/2025-09-24/intel-is-seeking-an-investment-from-apple-as-p...
4•mfiguiere•35m ago•0 comments

How to Raise a Reader in an Age of Digital Distraction

https://lithub.com/how-to-raise-a-reader-in-an-age-of-digital-distraction/
2•gmays•35m ago•0 comments

Amiga40 Germany – 40 years of Amiga, a celebration for everyone

https://amigaevent.de/
2•doener•36m ago•0 comments

Judge finds Amazon acted in bad faith during discovery in FTC litigation

https://www.courtlistener.com/docket/67515622/404/federal-trade-commission-v-amazoncom-inc/#text
7•1vuio0pswjnm7•36m ago•1 comments

Information, Experience, Knowledge, and Wisdom

https://zakelfassi.com/john-reeled-me-in-information-wisdom-ai-consciousness
1•zakelfassi•37m ago•0 comments