frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Spine – Verifiable audit logs with BLAKE3 and Ed25519

https://github.com/EulBite/spine-oss
2•mattiaaleo•1h ago
I've been working on a question that kept coming up in audits: How do you actually prove that logs haven’t been modified after the fact?

Most logging stacks (Splunk, Datadog, ELK) are great for analytics, but when auditors ask “how do you prove integrity?”, the answer is usually vague or procedural.

Spine answers this using cryptographic audit logs that can be verified offline, without trusting the logging system itself.

The SDK and CLI are now open source. GitHub: https://github.com/EulBite/spine-oss

The problem Recent EU regulations (DORA, NIS2) explicitly require tamper-evident audit trails, but the problem exists independently of regulation:

- Auditors increasingly ask how logs can be proven immutable

- Most companies I talked to had no concrete technical answer

Quick example:

from spine_client import WAL, WALConfig, SigningKey

key = SigningKey.generate() wal = WAL(key, WALConfig(data_dir="./audit_log"))

await wal.initialize() await wal.append({"event_type": "user.login", "user_id": "alice"})

Then verify offline:

$ spine-cli verify --wal ./audit_log

Status: VALID Events verified: 2,341 Signatures verified: 2,341 Chain integrity: INTACT

No server required. An auditor can verify integrity without access to the system that generated the logs.

What’s open source

- spine-sdk-python – create signed audit logs locally

- spine-cli (Rust) – independently verify integrity

Apache 2.0 licensed

The server-side components (batch ledger coordination, timestamping, HA) remain proprietary.

Technical approach:

Each event → BLAKE3 hash → Ed25519 signature → append-only chain.

Instead of a single linear chain (where one corrupted entry invalidates everything after), Spine uses a batch ledger model: events are grouped into signed batches. A compromised batch doesn’t invalidate unrelated history.

Performance notes:

Benchmarks (Criterion, NVMe), included mainly to sanity-check overhead:

Signed + fsync: ~3,900 events/sec

Chain verification: ~537k events/sec

BLAKE3 @ 1KB: ~1.24 GiB/s

Benchmarks are included to validate design tradeoffs, not to claim absolute performance leadership.

Why open source the client? Audit systems require trust. By releasing the SDK + CLI:

Anyone can verify the integrity claims

Audit data remains readable without our infrastructure

Independent security review of verification logic is possible

Looking for discussion

Happy to get feedback or be challenged on architecture choices, crypto primitives, or verification logic.

Repo: https://github.com/EulBite/spine-oss

Project page: https://eulbite.com/open-source

Hypergrowth Isn't Always Easy

https://tailscale.com/blog/hypergrowth-isnt-always-easy
1•usrme•1m ago•0 comments

Mugabo Rongin

https://github.com/Ronny12345-art/MRcutter
1•Networkchuck•2m ago•0 comments

Why We've Tried to Replace Data Analytics Developers Every Decade Since 1974

https://blog.rittmananalytics.com/why-weve-tried-to-replace-data-analytics-developers-every-decad...
1•sebg•5m ago•0 comments

AI SlopStop by Kagi

https://help.kagi.com/kagi/features/slopstop.html
1•janandonly•5m ago•0 comments

Oracle ERP for Port Operations: What It Takes to Get It Right

1•INTECHCreative•6m ago•0 comments

Debating CBR/CBZ Inefficiency on Discord Inspired Me to Create a New File Format

https://old.reddit.com/r/selfhosted/comments/1qi64pr/i_got_into_an_argument_on_discord_about_how/
1•birdculture•6m ago•0 comments

Coding Agents and the Future of Design

https://veen.com/jeff/archives/coding-agents-design.html
1•kaizenb•8m ago•0 comments

Users don't care about your app's complexity

2•Fh_•13m ago•1 comments

Show HN: Environment variable scanner for JavaScript/TS projects

https://dotenv-diff-docs.vercel.app/
1•chrilleweb•16m ago•0 comments

China's Renewable Energy Revolution Is a Mess That Might Save the World

https://www.wired.com/story/china-renewable-energy-revolution/
2•kalli•16m ago•0 comments

From Scripts to Buy-In: Small Clojure Wins Create Big Opportunities – Choomnuan [video]

https://www.youtube.com/watch?v=jWkEKdp0gqk
1•adityaathalye•17m ago•0 comments

AI Regulation: Fact or Fiction?

https://www.aivojournal.org/ai-regulation-fact-and-fiction/
2•businessmate•20m ago•1 comments

AgentiCorp: AI Agents Orchestrator from Jordan Hubbard

https://github.com/jordanhubbard/AgentiCorp
1•pointedulac•22m ago•0 comments

In Praise of APL (1977)

https://www.jsoftware.com/papers/perlis77.htm
2•tosh•22m ago•0 comments

FBI's Washington Post Investigation Shows How Your Printer Can Snitch on You

https://theintercept.com/2026/01/21/fbi-washington-post-perez-lugones-natansan-classified/
3•breve•22m ago•0 comments

Performance Is Not a Technical Problem

https://shud.in/thoughts/performance-is-not-a-technical-problem
1•MaxLeiter•24m ago•0 comments

Show HN: An accurate AI password guesser based on personal information

https://github.com/Tzohar/PassLLM
1•Plarsy•27m ago•0 comments

yOU pRoBABly dON't nEEd a dOCkeR cOntAiNer!!!

1•tobimadehin•29m ago•0 comments

Show HN: I built a Chrome extension to add emoji autocomplete to X

https://xmoji.xyz/
1•ugo_builds•30m ago•1 comments

What Is DreamAct? Turning Reference Motion into Expressive AI Avatars

https://www.dreamfaceapp.com/
1•harperzhang•32m ago•1 comments

Why do users happily use my AI tool but refuse to pay for it?

https://www.zolly.dev/
1•Parameswar•37m ago•1 comments

NodeAudio: A multi-effect pedal designed as a general-purpose audio plugin host

https://node97.com
2•watchful_moose•43m ago•0 comments

Show HN: Best PG Management Software in India (HarGharPG))

https://www.hargharpg.com/
1•ishqdehlvi•45m ago•2 comments

SpaceX lowering orbits of 4,400 Starlink satellites for safety's sake

https://www.space.com/space-exploration/satellites/spacex-lowering-orbits-of-4-400-starlink-satel...
8•thread_id•46m ago•1 comments

Crash Clock Measures Dangerous Overcrowding in Low Earth Orbit

https://spectrum.ieee.org/kessler-syndrome-crash-clock
1•thread_id•47m ago•0 comments

Convolutional-neural-operator-based transfer learning for solving PDEs

https://arxiv.org/abs/2512.17969
2•PaulHoule•48m ago•1 comments

Discovered: An outline of a hand that's at least 67,800 years old

https://www.cnn.com/2026/01/21/science/hand-stencil-oldest-rock-art
3•breve•48m ago•0 comments

CleanshotX and Screen Studio in One App

https://capty.app
1•543310•49m ago•0 comments

Show HN: A Free Online Podcast Transcription Tool

https://audioconvert.ai/podcast-transcription
1•Katherine603•52m ago•0 comments

Bamum Syllabary

https://www.omniglot.com/writing/bamumsyllabary.htm
1•prmph•53m ago•0 comments