frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Security breaks during partial failures – design notes from distributed systems

3•sandhyavinjam•1h ago
TL;DR: Many security mechanisms fail not during attacks, but during partial outages. This post documents early design notes for a failure-aware security framework for distributed systems.

The problem

In production distributed systems, security often breaks when things are half working:

auth services degrade → retries explode

fallback paths widen access

recovery logic becomes the attack surface

Nothing is “exploited”, yet the system becomes unsafe.

Most security models assume stable components and clean failures. Real systems don’t behave that way.

Design assumptions

We assume:

correlated failures

retries are adversarial

timeouts are unsafe defaults

recovery paths matter as much as steady-state logic

We don’t assume:

global consistency

perfect identity

reliable clocks

centralized enforcement

Framework ideas (high level)

This work explores four ideas:

1. Failure-aware trust

Trust degrades under failure, not just compromise

Access narrows automatically during partial outages

2. Security invariants at runtime

Invariants are continuously enforced

Violations trigger containment, not alerts

3. Retry-safe security primitives

Idempotent, monotonic, side-effect bounded

Retries can’t escalate privilege

4. Security as observable state

Trust level, degradation, and containment are visible

If you can’t observe it, you can’t secure it

What this is not

Not zero trust marketing

Not compliance

Not a finished system

It’s an attempt to treat failure as the normal case, not an exception.

Why publish this early?

Because many real failures:

don’t fit clean research papers

happen during incidents, not attacks

are invisible outside production systems

We’re sharing design notes to get feedback before formalizing or evaluating further.

Feedback welcome

If you’ve seen security regressions during outages or retries causing unsafe behavior, I’d like to hear about it.

This is ongoing work. No claims of novelty or completeness.

Comments

1970-01-01•36m ago
Check out https://news.ycombinator.com/item?id=31627925

The Useless Web

https://theuselessweb.com/
1•nateb2022•7m ago•0 comments

What Is Plus Times Plus? (Lambda Calculus Visually) [video]

https://www.youtube.com/watch?v=RcVA8Nj6HEo
2•rramadass•10m ago•0 comments

The US's 2k-year-old mystery mounds

https://www.bbc.com/travel/article/20221204-the-us-2000-year-old-mystery-mounds
1•1659447091•11m ago•0 comments

The Monty Hall Problem, a side-by-side simulation

https://www.pcloadletter.dev/blog/monty/
3•ronbenton•18m ago•1 comments

The State of Agentic iOS Engineering in 2026

https://dimillian.medium.com/the-state-of-agentic-ios-engineering-in-2026-c5f0cbaa7b34
2•Anon84•20m ago•1 comments

On biological & artificial consciousness: A case for biological computationalism

https://www.sciencedirect.com/science/article/pii/S0149763425005251
2•bookofjoe•22m ago•0 comments

Show HN: Sentinel Shield – Pure C DMZ for AI Security (23K LOC, <1ms latency)

2•Chgdz•23m ago•0 comments

Ask HN: Favorite Articles in the ACM Digital Library

2•lioeters•25m ago•2 comments

Interpreter – Offline screen translator for Japanese retro games

https://github.com/bquenin/interpreter
3•bane•29m ago•0 comments

Making beautiful PDF documents from HTML and CSS

https://css4.pub/
2•jez•29m ago•0 comments

Ask HN: Which AI productivity tools are you using in 2026?

3•Vishal19111999•34m ago•0 comments

Ukraine enters EU's single mobile roaming zone

https://www.yahoo.com/news/articles/ukraine-enters-eus-single-mobile-164712435.html
4•gok•35m ago•0 comments

Steam On Linux Ends 2025 With 3.19% Marketshare

https://www.phoronix.com/news/Steam-December-2025-Survey
7•doener•37m ago•0 comments

Engineering Is Becoming Beekeeping

https://bits.logic.inc/p/engineering-is-becoming-beekeeping
5•highfrequency•37m ago•0 comments

Balsa M2-F3 Lifting Body

https://www.engineersneedart.com/blog/m2f32025/m2f32025.html
3•chmaynard•37m ago•0 comments

Outrage as X's Grok morphs photos of women, children into explicit content

https://www.cnbctv18.com/technology/global-outrage-as-xs-grok-morphs-photos-of-women-children-int...
11•anonymousab•38m ago•1 comments

China's BYD set to overtake Tesla as top EV seller

https://www.bbc.com/news/articles/cj9rjwpvmpzo
11•decimalenough•39m ago•1 comments

Show HN: VideoCalling.app – Free Video Calling Service

https://videocalling.app
2•Airyisland•41m ago•0 comments

Webmention is an open web standard (W3C Recommendation) for conversations

https://indieweb.org/Webmention
4•doener•42m ago•0 comments

Show HN: Turning 100-plus comments HN threads into readable discussions

4•freakynit•45m ago•1 comments

DENT: A network operating system (NOS) for everyone else

https://dent.dev/
4•teleforce•45m ago•0 comments

Ask HN: Best videos for learning Java concurrency?

2•michalgad•46m ago•1 comments

Delete Request and Opt-Out Platform (Drop)

https://consumer.drop.privacy.ca.gov/
3•doener•47m ago•1 comments

Simulating a negative tax city on Cities Skylines 2 [video]

https://www.youtube.com/watch?v=MK_0mQ7TLY0
2•MinimalAction•49m ago•0 comments

ReactOS Starts 2026 with a Major Step Toward Windows NT6 Compatibility

https://www.phoronix.com/news/ReactOS-Starts-2026
7•hackthemack•51m ago•0 comments

Ask HN: Building a tool to ensure things get done on time

3•Vishal19111999•52m ago•0 comments

I bootstrapped an AI OSINT search engine to 35k users. Trying $5 Day Pass Model

https://ai.cylect.io/
2•nuzzl•53m ago•1 comments

Cerelog ESP-EEG is a new 8-channel biosensing board at a hobbyist-friendly price

https://www.autodidacts.io/cerelog-esp-eeg-affordable-openbci-like-board/
3•Curiositry•1h ago•0 comments

Designing Predictable and Maintainable Forms in React

https://jsdev.space/react-form-primitives/
3•javatuts•1h ago•0 comments

Construction to begin on Florida expressway that will charge EVs while driving

https://www.nbcmiami.com/news/construction-to-begin-on-florida-expressway-that-will-charge-evs-wh...
5•geox•1h ago•3 comments