frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

PEP 761 – Deprecating PGP signatures for CPython artifacts (2024)

https://peps.python.org/pep-0761/
2•marksomnian•2h ago

Comments

westurner•2h ago
Dislike. Don't put all your eggs in one basket.

I am aware of gpg.fail; https://news.ycombinator.com/item?id=46403200

Have they yet eliminated the single points of failure from Sigstore (i.e. the centralized database)?

westurner•2h ago
From the PEP: https://peps.python.org/pep-0761/#support-for-offline-verifi... :

> During the pre-PEP discussion, there was a question of whether offline verification was supported by Sigstore. Using a Sigstore bundle (.sigstore) file, Sigstore clients support verifying the artifact completely offline.

> Using offline verification with Sigstore requires disabling root of trust updates and “pinning” a root of trust in a file to use during verification.

> [...]

> Offline verification also makes revocation checks impossible, but this is similar to PGP’s model where revocation of keys requires an online lookup.

How does this compare to CRL and OCSP for key revocation?

Fairly certain this just reinvents the wheel with less years of review

Synchronizing CT Certificate Transparency logs to browsers is apparently considered infeasible. Merkle Certificates may help with this too?

Life is wasting my time (2013)

https://blog.daemonl.com/2013/03/life-is-wasting-my-time.html
1•chistev•1m ago•0 comments

PySDR: A Guide to SDR and DSP Using Python

https://pysdr.org/content/intro.html
1•kklisura•2m ago•0 comments

Simple Small Markdown Reader

https://github.com/thomasfuhringer/ecce
1•ThomasFuhringer•10m ago•1 comments

any-sync-bundle - Self-host Notion alternative

https://github.com/grishy/any-sync-bundle
1•grishy•13m ago•1 comments

Netshell – A 90s Unix hacking simulator with AI-powered NPCs

https://beyondlogiclabs.com/netshell/
1•livespx•14m ago•2 comments

Intellectual AI Bubble

https://xendo.bearblog.dev/intellectual-ai-bubble/
1•xendo•14m ago•0 comments

Show HN: I built Ctrl+F for YouTube videos using Gemini's multimodal AI

https://momentclip.com
1•jmcdev•15m ago•0 comments

Show HN: Hokage – Unified Orchestration for Semgrep, Trivy, and Zap

https://github.com/hokage-sec/hokage-platform
1•kirumachi•17m ago•1 comments

Nvidia Groq Update: Everyone Gets Rich, Patent Warfare Begins

https://ossa-ma.github.io/blog/groq-update
2•ossa-ma•18m ago•0 comments

'Better C' Playgrounds

https://antonz.org/better-c/
3•ingve•19m ago•0 comments

Ice Ring: Free Printable Board Game

https://printed.games/icering/
1•psarna•21m ago•0 comments

No it's not a Battleship

https://www.navalgazing.net/No-its-not
3•hermitcrab•23m ago•1 comments

AOL (Sign On – Dial Up) [video]

https://www.youtube.com/watch?v=D1UY7eDRXrs
1•avonmach•24m ago•1 comments

Show HN: Warlocks – a real-time browser multiplayer game running at 60fps

https://warlocks.icegaming.org/
1•iCeGaming•25m ago•0 comments

Here's Why Your Turn Signals Make That Clicking Noise

https://www.jalopnik.com/heres-why-your-turn-signals-make-that-clicking-noise-1793380845/
1•thunderbong•26m ago•0 comments

There's No Happy Ending for Movie Theaters, No Matter Who Wins Warner

https://www.wsj.com/business/media/theres-no-happy-ending-for-movie-theaters-no-matter-who-wins-w...
1•bookofjoe•28m ago•1 comments

K2pdfopt

https://www.willus.com/k2pdfopt/
2•piinbinary•31m ago•0 comments

The $20 Domain Trap: Why Buying a Domain Feels Like Progress but Isn't

https://www.validatemy.app/blog/why-a-20-dollar-domain-is-a-trap
2•alexcloudstar•32m ago•2 comments

Biological and artificial consciousness: A case for biological computationalism

https://www.sciencedirect.com/science/article/pii/S0149763425005251
1•XzetaU8•35m ago•0 comments

Why programmatic tool calling is awesome

https://www.guillemus.com/on-programmatic-tool-calling/
1•crowdyriver•37m ago•0 comments

Book recommendations based on reading history

2•easywood•38m ago•3 comments

Benefits of Fullstack Rust

https://github.com/ibaryshnikov/fullstack-rust-iced
1•rekireki•39m ago•1 comments

AI Has Made It Easy to Own Your Tools

https://jimmyhmiller.com/ai-own-your-tools
1•ingve•40m ago•0 comments

Show HN: Tinytunes DJ – A DJ deck in the browser

3•dworks•43m ago•1 comments

How to Deconstruct Almost Anything(1993)

https://www.fudco.com/chip/deconstr.html
1•kelseyfrog•46m ago•0 comments

Why Are Cars Getting Rid of Android Auto?

https://www.bgr.com/2049834/why-cars-getting-rid-android-auto-explained/
2•dataflow•48m ago•1 comments

rLLM: Reinforcement Learning for Language Agents

https://rllm-project.readthedocs.io/en/latest/
1•jonbaer•48m ago•0 comments

Elephant habituation to drones as a behavioural observation tool

https://www.nature.com/articles/s41598-025-25762-2
1•PaulHoule•48m ago•0 comments

BM25 search and Claude = efficient precision

https://github.com/rhobimd-oss/shebe/blob/main/WHY_SHEBE.md
2•marwamc•49m ago•2 comments

BTRS – Babylon Tower Reasoning System

https://www.docdroid.com/Crjz2cp/btrs-babylon-tower-reasoning-system-pdf
1•pulsepro•51m ago•1 comments