frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Jon Stewart – One of My Favorite People – What Now? With Trevor Noah Podcast [video]

https://www.youtube.com/watch?v=44uC12g9ZVk
1•consumer451•2m ago•0 comments

P2P crypto exchange development company

1•sonniya•15m ago•0 comments

Vocal Guide – belt sing without killing yourself

https://jesperordrup.github.io/vocal-guide/
1•jesperordrup•20m ago•0 comments

Write for Your Readers Even If They Are Agents

https://commonsware.com/blog/2026/02/06/write-for-your-readers-even-if-they-are-agents.html
1•ingve•21m ago•0 comments

Knowledge-Creating LLMs

https://tecunningham.github.io/posts/2026-01-29-knowledge-creating-llms.html
1•salkahfi•21m ago•0 comments

Maple Mono: Smooth your coding flow

https://font.subf.dev/en/
1•signa11•28m ago•0 comments

Sid Meier's System for Real-Time Music Composition and Synthesis

https://patents.google.com/patent/US5496962A/en
1•GaryBluto•36m ago•1 comments

Show HN: Slop News – HN front page now, but it's all slop

https://dosaygo-studio.github.io/hn-front-page-2035/slop-news
4•keepamovin•37m ago•1 comments

Show HN: Empusa – Visual debugger to catch and resume AI agent retry loops

https://github.com/justin55afdfdsf5ds45f4ds5f45ds4/EmpusaAI
1•justinlord•39m ago•0 comments

Show HN: Bitcoin wallet on NXP SE050 secure element, Tor-only open source

https://github.com/0xdeadbeefnetwork/sigil-web
2•sickthecat•41m ago•1 comments

White House Explores Opening Antitrust Probe on Homebuilders

https://www.bloomberg.com/news/articles/2026-02-06/white-house-explores-opening-antitrust-probe-i...
1•petethomas•42m ago•0 comments

Show HN: MindDraft – AI task app with smart actions and auto expense tracking

https://minddraft.ai
2•imthepk•47m ago•0 comments

How do you estimate AI app development costs accurately?

1•insights123•48m ago•0 comments

Going Through Snowden Documents, Part 5

https://libroot.org/posts/going-through-snowden-documents-part-5/
1•goto1•48m ago•0 comments

Show HN: MCP Server for TradeStation

https://github.com/theelderwand/tradestation-mcp
1•theelderwand•51m ago•0 comments

Canada unveils auto industry plan in latest pivot away from US

https://www.bbc.com/news/articles/cvgd2j80klmo
3•breve•52m ago•1 comments

The essential Reinhold Niebuhr: selected essays and addresses

https://archive.org/details/essentialreinhol0000nieb
1•baxtr•55m ago•0 comments

Rentahuman.ai Turns Humans into On-Demand Labor for AI Agents

https://www.forbes.com/sites/ronschmelzer/2026/02/05/when-ai-agents-start-hiring-humans-rentahuma...
1•tempodox•56m ago•0 comments

StovexGlobal – Compliance Gaps to Note

1•ReviewShield•59m ago•1 comments

Show HN: Afelyon – Turns Jira tickets into production-ready PRs (multi-repo)

https://afelyon.com/
1•AbduNebu•1h ago•0 comments

Trump says America should move on from Epstein – it may not be that easy

https://www.bbc.com/news/articles/cy4gj71z0m0o
7•tempodox•1h ago•4 comments

Tiny Clippy – A native Office Assistant built in Rust and egui

https://github.com/salva-imm/tiny-clippy
1•salvadorda656•1h ago•0 comments

LegalArgumentException: From Courtrooms to Clojure – Sen [video]

https://www.youtube.com/watch?v=cmMQbsOTX-o
1•adityaathalye•1h ago•0 comments

US moves to deport 5-year-old detained in Minnesota

https://www.reuters.com/legal/government/us-moves-deport-5-year-old-detained-minnesota-2026-02-06/
9•petethomas•1h ago•3 comments

If you lose your passport in Austria, head for McDonald's Golden Arches

https://www.cbsnews.com/news/us-embassy-mcdonalds-restaurants-austria-hotline-americans-consular-...
1•thunderbong•1h ago•0 comments

Show HN: Mermaid Formatter – CLI and library to auto-format Mermaid diagrams

https://github.com/chenyanchen/mermaid-formatter
1•astm•1h ago•0 comments

RFCs vs. READMEs: The Evolution of Protocols

https://h3manth.com/scribe/rfcs-vs-readmes/
3•init0•1h ago•1 comments

Kanchipuram Saris and Thinking Machines

https://altermag.com/articles/kanchipuram-saris-and-thinking-machines
1•trojanalert•1h ago•0 comments

Chinese chemical supplier causes global baby formula recall

https://www.reuters.com/business/healthcare-pharmaceuticals/nestle-widens-french-infant-formula-r...
2•fkdk•1h ago•0 comments

I've used AI to write 100% of my code for a year as an engineer

https://old.reddit.com/r/ClaudeCode/comments/1qxvobt/ive_used_ai_to_write_100_of_my_code_for_1_ye...
3•ukuina•1h ago•1 comments
Open in hackernews

Pacc: A Better Unix Password Manager

https://jlucas.codeberg.page/posts/20260101-pacc.html
3•jlucas8•1mo ago

Comments

throwawaybutwhy•1mo ago
Why are you rolling out your own crypto? Timing attacks, unvalidated inputs and no bounds checking.

> I am not a cryptographer. ... However I am fairly confident that this is at least safer than pass. Feel free to prove me wrong.

Translation: I have no experience in safe cooking. Please use my garlic oil, and my chicken salad. Feel free to prove me wrong - from the ER ward.

jlucas8•1mo ago
It's not like I'm writing the algorithms from scratch, OpenSSL is doing all of the heavy lifting. I'm aiming for actual simplicity, and so my vault format is harder to get wrong than parsing PGP packets (sure, that's handled by GPG in the case of pass, but it is still needless complexity for a password manager).

As for the "safer than pass" thing, pass does not encrypt entry names, so yes encrypting my way is safer than not encrypting at all in that aspect at least. Plus the whole KDF + symmetric only thing, though if you don't trust the way I handle it I have nothing to add here.

And I wouldn't translate "use it at your own risk" to "please use it". More like "you may use it if you choose so". You are free to back me up or tear it apart, or do nothing and go about your day. The software is not production-ready, though any help to change that is welcome.

Thank you for your attention.

evil-olive•1mo ago
> It stores all password entries (including names) in a single encrypted file (vault).

> a simple custom vault format.

I understand what you're saying about password-store's directory structure exposing website names as plain text filenames...but, the upside of that design is that it tends to be very resilient.

imagine that you're updating an entry in your vault, and right as you save it you lose power, resulting in file corruption.

with password-store's design, the blast radius of the corruption is limited to that one single entry.

with your design, the potential blast radius of corruption could be my entire password vault.

in particular, looking at your file-management code [0, 1] it looks like it does a complete rewrite of the vault file on every save, without doing "rewrite to temp file then atomically rename" or any similar tricks meant to handle partial file writes.

if you haven't seen it before, I'd suggest reading "SQLite As An Application File Format" [2] and consider using SQLite as the storage backend.

0: https://codeberg.org/jlucas/pacc/src/branch/master/src/db.c

1: https://codeberg.org/jlucas/pacc/src/branch/master/src/vault...

2: https://sqlite.org/appfileformat.html

jlucas8•1mo ago
Thanks for the feedback.

That is a valid concern, but I believe it doesn't justify exposing entry names, as the effect would be the same if the file names were encrypted. Also rewriting only modified entries leaks which/how many are changed/unchanged/added/removed. My db looks entirely different on each write as it is encrypted as a whole with a random IV each time, and with compression you can't tell with certainty how many entries it has.

I'll look into fixing it the "rewrite to temp file then atomically rename" way, or perhaps rename the old one first and keep it around as a backup (which would also allow undoing mistakes).

I can't tell if you're suggesting SQLite as a solution to the same corruption problem or something unrelated, but either way, I'd prefer keeping it simple overall instead of depending on a more complex one-size-fits-all. Thanks for suggesting anyway.