frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Show HN: Env-shelf – Open-source desktop app to manage .env files

https://env-shelf.vercel.app/
1•ivanglpz•52s ago•0 comments

Show HN: Almostnode – Run Node.js, Next.js, and Express in the Browser

https://almostnode.dev/
1•PetrBrzyBrzek•1m ago•0 comments

Dell support (and hardware) is so bad, I almost sued them

https://blog.joshattic.us/posts/2026-02-07-dell-support-lawsuit
1•radeeyate•1m ago•0 comments

Project Pterodactyl: Incremental Architecture

https://www.jonmsterling.com/01K7/
1•matt_d•2m ago•0 comments

Styling: Search-Text and Other Highlight-Y Pseudo-Elements

https://css-tricks.com/how-to-style-the-new-search-text-and-other-highlight-pseudo-elements/
1•blenderob•3m ago•0 comments

Crypto firm accidentally sends $40B in Bitcoin to users

https://finance.yahoo.com/news/crypto-firm-accidentally-sends-40-055054321.html
1•CommonGuy•4m ago•0 comments

Magnetic fields can change carbon diffusion in steel

https://www.sciencedaily.com/releases/2026/01/260125083427.htm
1•fanf2•5m ago•0 comments

Fantasy football that celebrates great games

https://www.silvestar.codes/articles/ultigamemate/
1•blenderob•5m ago•0 comments

Show HN: Animalese

https://animalese.barcoloudly.com/
1•noreplica•5m ago•0 comments

StrongDM's AI team build serious software without even looking at the code

https://simonwillison.net/2026/Feb/7/software-factory/
1•simonw•6m ago•0 comments

John Haugeland on the failure of micro-worlds

https://blog.plover.com/tech/gpt/micro-worlds.html
1•blenderob•6m ago•0 comments

Show HN: Velocity - Free/Cheaper Linear Clone but with MCP for agents

https://velocity.quest
2•kevinelliott•7m ago•1 comments

Corning Invented a New Fiber-Optic Cable for AI and Landed a $6B Meta Deal [video]

https://www.youtube.com/watch?v=Y3KLbc5DlRs
1•ksec•8m ago•0 comments

Show HN: XAPIs.dev – Twitter API Alternative at 90% Lower Cost

https://xapis.dev
1•nmfccodes•9m ago•0 comments

Near-Instantly Aborting the Worst Pain Imaginable with Psychedelics

https://psychotechnology.substack.com/p/near-instantly-aborting-the-worst
2•eatitraw•15m ago•0 comments

Show HN: Nginx-defender – realtime abuse blocking for Nginx

https://github.com/Anipaleja/nginx-defender
2•anipaleja•15m ago•0 comments

The Super Sharp Blade

https://netzhansa.com/the-super-sharp-blade/
1•robin_reala•16m ago•0 comments

Smart Homes Are Terrible

https://www.theatlantic.com/ideas/2026/02/smart-homes-technology/685867/
1•tusslewake•18m ago•0 comments

What I haven't figured out

https://macwright.com/2026/01/29/what-i-havent-figured-out
1•stevekrouse•19m ago•0 comments

KPMG pressed its auditor to pass on AI cost savings

https://www.irishtimes.com/business/2026/02/06/kpmg-pressed-its-auditor-to-pass-on-ai-cost-savings/
1•cainxinth•19m ago•0 comments

Open-source Claude skill that optimizes Hinge profiles. Pretty well.

https://twitter.com/b1rdmania/status/2020155122181869666
3•birdmania•19m ago•1 comments

First Proof

https://arxiv.org/abs/2602.05192
4•samasblack•21m ago•1 comments

I squeezed a BERT sentiment analyzer into 1GB RAM on a $5 VPS

https://mohammedeabdelaziz.github.io/articles/trendscope-market-scanner
1•mohammede•22m ago•0 comments

Kagi Translate

https://translate.kagi.com
2•microflash•23m ago•0 comments

Building Interactive C/C++ workflows in Jupyter through Clang-REPL [video]

https://fosdem.org/2026/schedule/event/QX3RPH-building_interactive_cc_workflows_in_jupyter_throug...
1•stabbles•24m ago•0 comments

Tactical tornado is the new default

https://olano.dev/blog/tactical-tornado/
2•facundo_olano•26m ago•0 comments

Full-Circle Test-Driven Firmware Development with OpenClaw

https://blog.adafruit.com/2026/02/07/full-circle-test-driven-firmware-development-with-openclaw/
1•ptorrone•26m ago•0 comments

Automating Myself Out of My Job – Part 2

https://blog.dsa.club/automation-series/automating-myself-out-of-my-job-part-2/
1•funnyfoobar•26m ago•1 comments

Dependency Resolution Methods

https://nesbitt.io/2026/02/06/dependency-resolution-methods.html
1•zdw•27m ago•0 comments

Crypto firm apologises for sending Bitcoin users $40B by mistake

https://www.msn.com/en-ie/money/other/crypto-firm-apologises-for-sending-bitcoin-users-40-billion...
1•Someone•28m ago•0 comments
Open in hackernews

Passing the Torch – My Last Root DNSSEC KSK Ceremony as Crypto Officer 4

https://technotes.seastrom.com/2025/11/23/passing-the-torch.html
72•greyface-•2mo ago

Comments

shruubi•2mo ago
Not sure how geographically diverse it is to have two "highly secure sites" on the same continent.
ggm•2mo ago
Several people either in this circuit or close by made submissions to this effect to ICANN recently.

It's very hard to get traction on this story because there is a lot of "don't prod the bear" regarding things ICANN can and should ask Department of State about, and things which really have moved into "self managed, independent international body" space. The reason there are two HSM east and west coast was because of this kind of national-strategic sensitivity. It would be a low bar (only money) decision to duplicate the investment in Singapore and Geneva, two locations which ICANN has existing investment in, with good secure facilities and accepted by the wider public as "neutral" points.

When the KSK ceremonies started up, several people also pointed out that this "diverse locations" thing was a bit hokey. The response above is my re-write of the kinds of things said to me, at the time. If somebody wants to deny State or any other US federal agency influenced the decision I have no formal proof.

I should add as a declaration of interest I was at Rob's goodbye KSK event, I am a TCR, and I made such a submission this year. I have not received any indication it was understood or read, despite asking for some acknowledgement, but the process wheels in an agency like ICANN run to their own time.

tptacek•2mo ago
What would "poking the bear" do here? What's the risk?
ggm•2mo ago
The risk is being told no, and inviting dissent into the independence of ICANN. Not asking, means no risk of being told "no, you do as you're told" which would endanger the whole 3 legged stool. the GAC would immediately question the assumption the US government had that level of signoff, the money flows and lawyers would fire up, it would be come a shitstorm in a teacup.

The least likely outcome of asking the department of state if ICANN is "permitted" to add an HSM outside the USA, is a positive answer.

The most likely path to doing it, is not to assume you have to ask.

tptacek•2mo ago
Interesting. Thanks!
ggm•2mo ago
It's my personal opinion from beer convos with people in the circuit. As I said I have no firm proofs and you should hedge belief in this by the lack of verifyable facts.
jacquesm•2mo ago
Don't we have the '98 DNS ROOT incident as a nice example of what could happen when the bear gets poked?
ggm•2mo ago
Yes, but we're a long way down "our hands are off it's ICANN now". The exception might be DNSSEC and the verisign contract continuance. I have no complaint against verisign, far from it: their staff are excellent and they are amazingly diligent and risk averse.

But at a contractual level you could ask is there another company which could tender to operate the root publication function, and meet all stakeholder requirements? And, could that company be legally constituted outside the USA?

jacquesm•2mo ago
CERN?

Given that they contributed one of the key components that made the internet into the success that it is as well as being internationally respected.

ggm•2mo ago
Possibly. Ex CERN staff have indicated they were dismayed when the address management function went elsewhere in Europe. I know people both sides of this divide, it's ancient history in some ways.

I worked in another RIR. I still contract there.

dc396•2mo ago
Asking the US Dept. of State would almost certainly result in "huh?" from the folks there. The part of the USG that plays in the ICANN kiddie pool is US Dept. of Commerce (NTIA) and they no longer have a veto on what ICANN does.

One of the issues is section 4.2 of the IANA Naming Functions contract:

"[...] Contractor must be able to demonstrate that all primary operations and systems will remain within the United States (including the District of Columbia). [...]"

The Key Management Facilities are considered a part of the "primary operations and systems". IIRC, this clause was included in order to move the transition of the IANA functions forward in the face of some resistance within the US government.

Until that bit of legalese is revised, there will be no movement on creating a non-US key management facility. I believe changing the IANA Functions contract requires the Customer Standing Committee. As far as I am aware, no one within the CSC thought it worth the effort, i.e., "if it ain't broke, don't fix it".

Perhaps under the current US administration, that feeling as changed, but I haven't heard of any significant efforts in that regard.

charcircuit•2mo ago
There are security concerns having sites outside of America. I prefer keeping them only within my home country.
shmel•2mo ago
Equally there are security concerns having sites inside the US.
blibble•2mo ago
I'd rather have it somewhere stable like Switzerland

I suspect the only reason this hasn't been used as part of "deal leverage" is because the US regime doesn't know of its existence

monkey_monkey•2mo ago
The USA has shown, over the last 12 months, what a security-conscious country it is. The Defense Secretary's almost fanantical regard for messaging security should be held up as an object lesson for all future generations.
0x50000000•2mo ago
KMF-East is the Gegenvorschlag, or counterproposed key-management for the resolution of TCP/IP ICANN domain certifications.

DNSSEC requires cycling existing TCR for AES-256 symmetric encryptions or leveraging localised key share cycles.

teddyh•2mo ago
He should probably update his “About” page on his blog to remove ”I sign the DNSSEC root”, then.
tptacek•2mo ago
If you're looking to correct people about random parts of their website, perhaps it'd be a better idea to mail them than to comment here, where they're never going to see it. What was the point of this comment, other than mean-spiritedness?
teddyh•2mo ago
So you think I should e-mail somebody out of the blue, bothering them personally, to complain about their personal web site? Do you think that most people would react well if they recieved such a message?

HN is a quote well-known community. It is very common that people read the discussion on HN when their project or themselves are featured. And if they are that interested in what others think, they would then likely see comments such as mine. And if they are not the type to want to read comments, they won’t see my comment and therefore not be bothered by it.

I am baffled when trying to imagine why you think this is “mean-spirited”. On the contrary, this is the most respectful way to offer a minor suggestion that I can think of.

tptacek•2mo ago
Or just kept it to yourself.
teddyh•2mo ago
Why? This is a discussion forum, meant for comments.
gorgoiler•2mo ago
I enjoyed reading the ceremony log itself, a lot! It’s linked at the bottom of the article.

https://technotes.seastrom.com/assets/2025-11-23-passing-the...

Hypothetically, is there a way to know that those present were not under duress? I am guessing that duress is the only viable attack against the ceremony protocol — everyone present appears to play their part but, offscreen and visible only to the participants, are the villains and some hostages.