frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

RFCs vs. READMEs: The Evolution of Protocols

https://h3manth.com/scribe/rfcs-vs-readmes/
1•init0•5m ago•1 comments

Kanchipuram Saris and Thinking Machines

https://altermag.com/articles/kanchipuram-saris-and-thinking-machines
1•trojanalert•5m ago•0 comments

Chinese chemical supplier causes global baby formula recall

https://www.reuters.com/business/healthcare-pharmaceuticals/nestle-widens-french-infant-formula-r...
1•fkdk•8m ago•0 comments

I've used AI to write 100% of my code for a year as an engineer

https://old.reddit.com/r/ClaudeCode/comments/1qxvobt/ive_used_ai_to_write_100_of_my_code_for_1_ye...
1•ukuina•11m ago•1 comments

Looking for 4 Autistic Co-Founders for AI Startup (Equity-Based)

1•au-ai-aisl•21m ago•1 comments

AI-native capabilities, a new API Catalog, and updated plans and pricing

https://blog.postman.com/new-capabilities-march-2026/
1•thunderbong•21m ago•0 comments

What changed in tech from 2010 to 2020?

https://www.tedsanders.com/what-changed-in-tech-from-2010-to-2020/
2•endorphine•26m ago•0 comments

From Human Ergonomics to Agent Ergonomics

https://wesmckinney.com/blog/agent-ergonomics/
1•Anon84•30m ago•0 comments

Advanced Inertial Reference Sphere

https://en.wikipedia.org/wiki/Advanced_Inertial_Reference_Sphere
1•cyanf•31m ago•0 comments

Toyota Developing a Console-Grade, Open-Source Game Engine with Flutter and Dart

https://www.phoronix.com/news/Fluorite-Toyota-Game-Engine
1•computer23•34m ago•0 comments

Typing for Love or Money: The Hidden Labor Behind Modern Literary Masterpieces

https://publicdomainreview.org/essay/typing-for-love-or-money/
1•prismatic•34m ago•0 comments

Show HN: A longitudinal health record built from fragmented medical data

https://myaether.live
1•takmak007•37m ago•0 comments

CoreWeave's $30B Bet on GPU Market Infrastructure

https://davefriedman.substack.com/p/coreweaves-30-billion-bet-on-gpu
1•gmays•48m ago•0 comments

Creating and Hosting a Static Website on Cloudflare for Free

https://benjaminsmallwood.com/blog/creating-and-hosting-a-static-website-on-cloudflare-for-free/
1•bensmallwood•54m ago•1 comments

"The Stanford scam proves America is becoming a nation of grifters"

https://www.thetimes.com/us/news-today/article/students-stanford-grifters-ivy-league-w2g5z768z
2•cwwc•58m ago•0 comments

Elon Musk on Space GPUs, AI, Optimus, and His Manufacturing Method

https://cheekypint.substack.com/p/elon-musk-on-space-gpus-ai-optimus
2•simonebrunozzi•1h ago•0 comments

X (Twitter) is back with a new X API Pay-Per-Use model

https://developer.x.com/
3•eeko_systems•1h ago•0 comments

Zlob.h 100% POSIX and glibc compatible globbing lib that is faste and better

https://github.com/dmtrKovalenko/zlob
3•neogoose•1h ago•1 comments

Show HN: Deterministic signal triangulation using a fixed .72% variance constant

https://github.com/mabrucker85-prog/Project_Lance_Core
2•mav5431•1h ago•1 comments

Scientists Discover Levitating Time Crystals You Can Hold, Defy Newton’s 3rd Law

https://phys.org/news/2026-02-scientists-levitating-crystals.html
3•sizzle•1h ago•0 comments

When Michelangelo Met Titian

https://www.wsj.com/arts-culture/books/michelangelo-titian-review-the-renaissances-odd-couple-e34...
1•keiferski•1h ago•0 comments

Solving NYT Pips with DLX

https://github.com/DonoG/NYTPips4Processing
1•impossiblecode•1h ago•1 comments

Baldur's Gate to be turned into TV series – without the game's developers

https://www.bbc.com/news/articles/c24g457y534o
3•vunderba•1h ago•0 comments

Interview with 'Just use a VPS' bro (OpenClaw version) [video]

https://www.youtube.com/watch?v=40SnEd1RWUU
2•dangtony98•1h ago•0 comments

EchoJEPA: Latent Predictive Foundation Model for Echocardiography

https://github.com/bowang-lab/EchoJEPA
1•euvin•1h ago•0 comments

Disablling Go Telemetry

https://go.dev/doc/telemetry
1•1vuio0pswjnm7•1h ago•0 comments

Effective Nihilism

https://www.effectivenihilism.org/
1•abetusk•1h ago•1 comments

The UK government didn't want you to see this report on ecosystem collapse

https://www.theguardian.com/commentisfree/2026/jan/27/uk-government-report-ecosystem-collapse-foi...
5•pabs3•1h ago•0 comments

No 10 blocks report on impact of rainforest collapse on food prices

https://www.thetimes.com/uk/environment/article/no-10-blocks-report-on-impact-of-rainforest-colla...
3•pabs3•1h ago•0 comments

Seedance 2.0 Is Coming

https://seedance-2.app/
1•Jenny249•1h ago•0 comments
Open in hackernews

Show HN: Offline Deterministic Security Gate

2•EldorZ•4w ago
Hi HN,

I’m working on a security tool born out of frustration with how most security controls work today.

In many environments, security happens after the fact: scan later, alert louder, hope someone reacts in time. Most tools also assume network access, dynamic updates, and trust in external services — which breaks down in regulated, air-gapped, or high-assurance environments.

I decided to explore a different approach.

Sentinel Gate

Sentinel Gate is a deterministic security gate that runs before code leaves the developer machine or CI boundary.

Key design choices:

Offline by design No call-home, no cloud dependency, no remote APIs. Can run fully air-gapped.

Deterministic outcomes The gate does not score or recommend. Artifacts either pass or are blocked.

Immutable ruleset No dynamic rule updates, no remote plugins. The ruleset is versioned and explicitly managed to avoid supply-chain surprises.

Pre-commit and CI enforcement Focused on preventing secrets leakage, CI/CD injection risks, and certain classes of logic/configuration flaws before they propagate.

The goal is simple: answer with certainty whether an artifact is allowed to exist outside a defined boundary.

This is intentionally a hard control, not a flexible scanner.

Auditor Core (related but separate)

Alongside the gate, I’m building Auditor Core, which serves a different purpose.

Auditor Core focuses on understanding and explaining systems, not blocking them:

Repository and infrastructure topology mapping

Baseline drift detection

Analysis across IaC, CI/CD pipelines, containers, Kubernetes, and cloud configs

Evidence-driven reports aimed at engineers and auditors

I keep these as two separate engines on purpose:

Gates prevent mistakes

Audits explain reality

Trying to merge both usually compromises one of them.

Trade-offs & limitations

This approach is not for everyone:

Deterministic rules mean less flexibility

Offline mode means no shared intelligence feeds

It will block things — sometimes inconveniently — by design

It’s not a replacement for dynamic testing or runtime protection

The target audience is environments where predictability and control matter more than coverage breadth.

Code note: The implementation is private at the moment. I’m intentionally validating the architecture, threat model, and assumptions before deciding what to open. Happy to discuss internals and trade-offs in the comments.

This is still evolving, and I’m actively validating assumptions.

I’d especially appreciate feedback from people working in:

regulated or air-gapped environments

CI/CD security

supply-chain security

or anyone who has strong opinions about deterministic vs adaptive controls

Happy to answer technical questions and criticism.