frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Ask HN: Why doesn't Netflix add a theater mode that recreates the worst parts?

1•amichail•22s ago•0 comments

Show HN: Engineering Perception with Combinatorial Memetics

1•alan_sass•6m ago•1 comments

Show HN: Steam Daily – A Wordle-like daily puzzle game for Steam fans

https://steamdaily.xyz
1•itshellboy•8m ago•0 comments

The Anthropic Hive Mind

https://steve-yegge.medium.com/the-anthropic-hive-mind-d01f768f3d7b
1•spenvo•8m ago•0 comments

Just Started Using AmpCode

https://intelligenttools.co/blog/ampcode-multi-agent-production
1•BojanTomic•9m ago•0 comments

LLM as an Engineer vs. a Founder?

1•dm03514•10m ago•0 comments

Crosstalk inside cells helps pathogens evade drugs, study finds

https://phys.org/news/2026-01-crosstalk-cells-pathogens-evade-drugs.html
2•PaulHoule•11m ago•0 comments

Show HN: Design system generator (mood to CSS in <1 second)

https://huesly.app
1•egeuysall•11m ago•1 comments

Show HN: 26/02/26 – 5 songs in a day

https://playingwith.variousbits.net/saturday
1•dmje•12m ago•0 comments

Toroidal Logit Bias – Reduce LLM hallucinations 40% with no fine-tuning

https://github.com/Paraxiom/topological-coherence
1•slye514•14m ago•1 comments

Top AI models fail at >96% of tasks

https://www.zdnet.com/article/ai-failed-test-on-remote-freelance-jobs/
4•codexon•15m ago•2 comments

The Science of the Perfect Second (2023)

https://harpers.org/archive/2023/04/the-science-of-the-perfect-second/
1•NaOH•16m ago•0 comments

Bob Beck (OpenBSD) on why vi should stay vi (2006)

https://marc.info/?l=openbsd-misc&m=115820462402673&w=2
2•birdculture•19m ago•0 comments

Show HN: a glimpse into the future of eye tracking for multi-agent use

https://github.com/dchrty/glimpsh
1•dochrty•20m ago•0 comments

The Optima-l Situation: A deep dive into the classic humanist sans-serif

https://micahblachman.beehiiv.com/p/the-optima-l-situation
2•subdomain•20m ago•1 comments

Barn Owls Know When to Wait

https://blog.typeobject.com/posts/2026-barn-owls-know-when-to-wait/
1•fintler•21m ago•0 comments

Implementing TCP Echo Server in Rust [video]

https://www.youtube.com/watch?v=qjOBZ_Xzuio
1•sheerluck•21m ago•0 comments

LicGen – Offline License Generator (CLI and Web UI)

1•tejavvo•24m ago•0 comments

Service Degradation in West US Region

https://azure.status.microsoft/en-gb/status?gsid=5616bb85-f380-4a04-85ed-95674eec3d87&utm_source=...
2•_____k•24m ago•0 comments

The Janitor on Mars

https://www.newyorker.com/magazine/1998/10/26/the-janitor-on-mars
1•evo_9•26m ago•0 comments

Bringing Polars to .NET

https://github.com/ErrorLSC/Polars.NET
3•CurtHagenlocher•28m ago•0 comments

Adventures in Guix Packaging

https://nemin.hu/guix-packaging.html
1•todsacerdoti•29m ago•0 comments

Show HN: We had 20 Claude terminals open, so we built Orcha

1•buildingwdavid•29m ago•0 comments

Your Best Thinking Is Wasted on the Wrong Decisions

https://www.iankduncan.com/engineering/2026-02-07-your-best-thinking-is-wasted-on-the-wrong-decis...
1•iand675•29m ago•0 comments

Warcraftcn/UI – UI component library inspired by classic Warcraft III aesthetics

https://www.warcraftcn.com/
1•vyrotek•31m ago•0 comments

Trump Vodka Becomes Available for Pre-Orders

https://www.forbes.com/sites/kirkogunrinde/2025/12/01/trump-vodka-becomes-available-for-pre-order...
1•stopbulying•32m ago•0 comments

Velocity of Money

https://en.wikipedia.org/wiki/Velocity_of_money
1•gurjeet•34m ago•0 comments

Stop building automations. Start running your business

https://www.fluxtopus.com/automate-your-business
1•valboa•39m ago•1 comments

You can't QA your way to the frontier

https://www.scorecard.io/blog/you-cant-qa-your-way-to-the-frontier
1•gk1•40m ago•0 comments

Show HN: PalettePoint – AI color palette generator from text or images

https://palettepoint.com
2•latentio•40m ago•0 comments
Open in hackernews

Ask HN: Decentralized Auth for Information Exchange?

2•vxsz•1mo ago
I have a media server project that I want to work on. But I'm stuck on one thing, convenience vs privacy.

As the project is about spinning your own server (media server), I want to have a smoother way to have a simple account system where the user just enters an email and a password, and get the server/ip list (everything from there is done on the actual server). For example, a user could be invited to 2 servers, and would see them in the same page, which makes things more straight-forward and a lot easier.

Now, I thought a lot about it, and mostly came down to the conclusion that centralizing it is the most sane option. The data itself comes down to: email, encrypted password, encrypted IP(s) list (via key exchanges).Is there any-way to do it decentralized? I searched, even asked LLMs, but nothing felt solid (best was a Nostr suggestion) but such method would make emails, password resets painful or almost impossible. I don't know a lot regarding this topic so its quite the challenge.

What's the point/why not just use URL? convenience. I know, but it SUCKS having to give a parent a URL, even with some techy friends it takes a bit communicating it. I want to eliminate as much friction as possible. Also, if centralized, this has the ability that users don't need to buy a domain, setup lets encrypt and all that which costs money and time (especially for simple/new selfhosters); its a lot nicer and smoother and in a way provide better privacy out-of-the-box.

Note, This project doesn't even exist yet. But I'm pursuing quite soon. I also only took 1 encryption course back in college days, while I understood and was good at it, I still need to audit/verify my method. It basically is: 1. hash the password+salt in a different algorithm, save the private key from it and send the public key to the central server 2. (media server owner wants to invite) the media server checks for a public key, encrypts the message containing all the details (IP, status, ports etc), and sends the encrypted message to the central server. 3. The client later checks, if there's a new message, it decrypts the ip/info from the server and connect.

Every device can login in this way and grab server list info securely. There's gonna be some sort of way to "quick connect" on TVs and such, and change passwords, but I don't want to get ahead of myself for now. I don't think the IP/server-info encryption suffers from any major things, but that's the general core principle. I maybe (probably?) have missed something.

The only issues I can maybe think of, is a "centralized" URL/domain would be showing up all the time instead of the owner. Note, it would be designed in a way that would allow you to instead send them to your own URL/domain and such.

Anyways, let me know what would be best. btw I'm not rich but such simple "auth" server would probably cost like $5/m + 2x5/m for redundancies, shouldn't be too bad.

Comments

ZuoCen_Liu•1mo ago
As an entrepreneur, this feels like a classic case of over-engineering for a problem you haven't earned yet.

Decentralized auth is a fascinating technical rabbit hole, but it introduces a massive friction point for your first 1,000 users. For a new, unproven project, credibility is your biggest bottleneck, not decentralized storage.

By building your own complex auth/privacy stack, you are asking users to trust you to get the crypto right—which is a huge leap of faith.

A more pragmatic approach: Outsource the trust. > Use 'Sign in with Google/Apple/GitHub.' You leverage their multi-billion dollar security infrastructure and their existing trust relationship with the user. It provides immediate convenience (one-click onboarding) and shifts the perceived privacy liability to a known entity.

Don't spend your innovation tokens on auth. Spend them on the core value of your information exchange. You can always 'decentralize' the back-end later once you have enough users to actually make it matter.

vxsz•1mo ago
Yeah I think decentralization will be a stretch, especially at the beginning.

About the login, SSO is nice and it will probably be an option, but I heavily prefer good old email+password. It might be trickier, haven't explored SSO before.

The auth/central server will be open source of course, and I'm hoping I could get feedback/auditing that way if anything's wrong (even tho I feel like the process is simple with encryption libs and knowledge). At first it will be heavily experimental and will hold just dummy data and then gradually go from there if it works out.

ZuoCen_Liu•1mo ago
Single Sign-On (SSO) is not complicated, and platforms that provide services all have detailed tutorials.

I don't think obtaining authentication data is useful; it's better to use it for collecting data on functional experiences.