frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

OpenClaw Is Changing My Life

https://reorx.com/blog/openclaw-is-changing-my-life/
1•novoreorx•4m ago•0 comments

Everything you need to know about lasers in one photo

https://commons.wikimedia.org/wiki/File:Commercial_laser_lines.svg
1•mahirsaid•6m ago•0 comments

SCOTUS to decide if 1988 video tape privacy law applies to internet uses

https://www.jurist.org/news/2026/01/us-supreme-court-to-decide-if-1988-video-tape-privacy-law-app...
1•voxadam•7m ago•0 comments

Epstein files reveal deeper ties to scientists than previously known

https://www.nature.com/articles/d41586-026-00388-0
1•XzetaU8•15m ago•0 comments

Red teamers arrested conducting a penetration test

https://www.infosecinstitute.com/podcast/red-teamers-arrested-conducting-a-penetration-test/
1•begueradj•22m ago•0 comments

Show HN: Open-source AI powered Kubernetes IDE

https://github.com/agentkube/agentkube
1•saiyampathak•25m ago•0 comments

Show HN: Lucid – Use LLM hallucination to generate verified software specs

https://github.com/gtsbahamas/hallucination-reversing-system
1•tywells•28m ago•0 comments

AI Doesn't Write Every Framework Equally Well

https://x.com/SevenviewSteve/article/2019601506429730976
1•Osiris30•31m ago•0 comments

Aisbf – an intelligent routing proxy for OpenAI compatible clients

https://pypi.org/project/aisbf/
1•nextime•32m ago•1 comments

Let's handle 1M requests per second

https://www.youtube.com/watch?v=W4EwfEU8CGA
1•4pkjai•32m ago•0 comments

OpenClaw Partners with VirusTotal for Skill Security

https://openclaw.ai/blog/virustotal-partnership
1•zhizhenchi•33m ago•0 comments

Goal: Ship 1M Lines of Code Daily

2•feastingonslop•43m ago•0 comments

Show HN: Codex-mem, 90% fewer tokens for Codex

https://github.com/StartripAI/codex-mem
1•alfredray•46m ago•0 comments

FastLangML: FastLangML:Context‑aware lang detector for short conversational text

https://github.com/pnrajan/fastlangml
1•sachuin23•49m ago•1 comments

LineageOS 23.2

https://lineageos.org/Changelog-31/
1•pentagrama•52m ago•0 comments

Crypto Deposit Frauds

2•wwdesouza•53m ago•0 comments

Substack makes money from hosting Nazi newsletters

https://www.theguardian.com/media/2026/feb/07/revealed-how-substack-makes-money-from-hosting-nazi...
3•lostlogin•54m ago•0 comments

Framing an LLM as a safety researcher changes its language, not its judgement

https://lab.fukami.eu/LLMAAJ
1•dogacel•56m ago•0 comments

Are there anyone interested about a creator economy startup

1•Nejana•57m ago•0 comments

Show HN: Skill Lab – CLI tool for testing and quality scoring agent skills

https://github.com/8ddieHu0314/Skill-Lab
1•qu4rk5314•58m ago•0 comments

2003: What is Google's Ultimate Goal? [video]

https://www.youtube.com/watch?v=xqdi1xjtys4
1•1659447091•58m ago•0 comments

Roger Ebert Reviews "The Shawshank Redemption"

https://www.rogerebert.com/reviews/great-movie-the-shawshank-redemption-1994
1•monero-xmr•1h ago•0 comments

Busy Months in KDE Linux

https://pointieststick.com/2026/02/06/busy-months-in-kde-linux/
1•todsacerdoti•1h ago•0 comments

Zram as Swap

https://wiki.archlinux.org/title/Zram#Usage_as_swap
1•seansh•1h ago•1 comments

Green’s Dictionary of Slang - Five hundred years of the vulgar tongue

https://greensdictofslang.com/
1•mxfh•1h ago•0 comments

Nvidia CEO Says AI Capital Spending Is Appropriate, Sustainable

https://www.bloomberg.com/news/articles/2026-02-06/nvidia-ceo-says-ai-capital-spending-is-appropr...
1•virgildotcodes•1h ago•3 comments

Show HN: StyloShare – privacy-first anonymous file sharing with zero sign-up

https://www.styloshare.com
1•stylofront•1h ago•0 comments

Part 1 the Persistent Vault Issue: Your Encryption Strategy Has a Shelf Life

1•PhantomKey•1h ago•0 comments

Show HN: Teleop_xr – Modular WebXR solution for bimanual robot teleoperation

https://github.com/qrafty-ai/teleop_xr
1•playercc7•1h ago•1 comments

The Highest Exam: How the Gaokao Shapes China

https://www.lrb.co.uk/the-paper/v48/n02/iza-ding/studying-is-harmful
2•mitchbob•1h ago•1 comments
Open in hackernews

Encrypt Your .env in a Meme

https://github.com/thoughtlesslabs/memevault
3•thoughtlesslabs•3w ago

Comments

thoughtlesslabs•3w ago
Was thinking about how to make leaking keys less of an issue, especially as ai loves to just commit stuff. And why not store them in memes.

Memevault is a zero-dependency, single-binary secret manager that lets you keep encrypted project secrets anywhere by storing them inside a meme image. Instead of sharing `.env` files or relying on ad hoc workflows, teams can grant and revoke access per user, and the vault is re-encrypted accordingly. It works consistently across Windows, Linux, and macOS, injects secrets only into the environment of the command you run (`memevault run -- ...`), and includes key rotation plus a `scan` command to catch secrets referenced in code but missing from the vault.

0o_MrPatrick_o0•3w ago
Man- I am noticing so many people are writing and ruminating on the defense of the .env file right now!

I can't tell if the project name ("memevault") implies that this is a real tool or a jab at us ruminating weirdos X'D

thoughtlesslabs•3w ago
Haha! In this case a real tool, but I wanted to have a little fun be embedding the secrets into memes.

You can actually use any image though

theamk•3w ago
> Revoke Access

> To remove a team member:

> memevault access remove bob

> This immediately re-encrypts the vault with the remaining keys, locking Bob out.

Unless you rewrite the git history, force-push every branch, then do the same on every developers' computer (and ask Github support to garbage-collect your repo too), this actually does not "lock the Bob out", it just removes it from latest commit, but the Bob can still access every older commit.

thoughtlesslabs•3w ago
The idea is about sharing secrets and keys not locking people out of the codebase.

Let's say you are using an OpenAI api key. The only people who can use your key are the ones you added their public key to the vault.

If you decide they can no longer have access, you change the secret and pull their public key from the repo.

This is no different then if you were sharing secrets in a .env except that they are not stored in plain text which is why you can upload it to github.

If you never give anyone access to the vault they can never use your secrets even if they have the code. They can create their own vaults and keys but they can't use yours.