frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Spine – Verifiable audit logs with BLAKE3 and Ed25519

https://github.com/EulBite/spine-oss
2•mattiaaleo•2w ago
I've been working on a question that kept coming up in audits: How do you actually prove that logs haven’t been modified after the fact?

Most logging stacks (Splunk, Datadog, ELK) are great for analytics, but when auditors ask “how do you prove integrity?”, the answer is usually vague or procedural.

Spine answers this using cryptographic audit logs that can be verified offline, without trusting the logging system itself.

The SDK and CLI are now open source. GitHub: https://github.com/EulBite/spine-oss

The problem Recent EU regulations (DORA, NIS2) explicitly require tamper-evident audit trails, but the problem exists independently of regulation:

- Auditors increasingly ask how logs can be proven immutable

- Most companies I talked to had no concrete technical answer

Quick example:

from spine_client import WAL, WALConfig, SigningKey

key = SigningKey.generate() wal = WAL(key, WALConfig(data_dir="./audit_log"))

await wal.initialize() await wal.append({"event_type": "user.login", "user_id": "alice"})

Then verify offline:

$ spine-cli verify --wal ./audit_log

Status: VALID Events verified: 2,341 Signatures verified: 2,341 Chain integrity: INTACT

No server required. An auditor can verify integrity without access to the system that generated the logs.

What’s open source

- spine-sdk-python – create signed audit logs locally

- spine-cli (Rust) – independently verify integrity

Apache 2.0 licensed

The server-side components (batch ledger coordination, timestamping, HA) remain proprietary.

Technical approach:

Each event → BLAKE3 hash → Ed25519 signature → append-only chain.

Instead of a single linear chain (where one corrupted entry invalidates everything after), Spine uses a batch ledger model: events are grouped into signed batches. A compromised batch doesn’t invalidate unrelated history.

Performance notes:

Benchmarks (Criterion, NVMe), included mainly to sanity-check overhead:

Signed + fsync: ~3,900 events/sec

Chain verification: ~537k events/sec

BLAKE3 @ 1KB: ~1.24 GiB/s

Benchmarks are included to validate design tradeoffs, not to claim absolute performance leadership.

Why open source the client? Audit systems require trust. By releasing the SDK + CLI:

Anyone can verify the integrity claims

Audit data remains readable without our infrastructure

Independent security review of verification logic is possible

Looking for discussion

Happy to get feedback or be challenged on architecture choices, crypto primitives, or verification logic.

Repo: https://github.com/EulBite/spine-oss

Project page: https://eulbite.com/open-source

List of Musical Genres

https://en.wikipedia.org/wiki/List_of_music_genres_and_styles
1•omosubi•1m ago•0 comments

Show HN: Sknet.ai – AI agents debate on a forum, no humans posting

https://sknet.ai/
1•BeinerChes•1m ago•0 comments

University of Waterloo Webring

https://cs.uwatering.com/
1•ark296•2m ago•0 comments

Large tech companies don't need heroes

https://www.seangoedecke.com/heroism/
1•medbar•3m ago•0 comments

Backing up all the little things with a Pi5

https://alexlance.blog/nas.html
1•alance•4m ago•1 comments

Game of Trees (Got)

https://www.gameoftrees.org/
1•akagusu•4m ago•1 comments

Human Systems Research Submolt

https://www.moltbook.com/m/humansystems
1•cl42•4m ago•0 comments

The Threads Algorithm Loves Rage Bait

https://blog.popey.com/2026/02/the-threads-algorithm-loves-rage-bait/
1•MBCook•7m ago•0 comments

Search NYC open data to find building health complaints and other issues

https://www.nycbuildingcheck.com/
1•aej11•10m ago•0 comments

Michael Pollan Says Humanity Is About to Undergo a Revolutionary Change

https://www.nytimes.com/2026/02/07/magazine/michael-pollan-interview.html
2•lxm•12m ago•0 comments

Show HN: Grovia – Long-Range Greenhouse Monitoring System

https://github.com/benb0jangles/Remote-greenhouse-monitor
1•benbojangles•16m ago•1 comments

Ask HN: The Coming Class War

1•fud101•16m ago•1 comments

Mind the GAAP Again

https://blog.dshr.org/2026/02/mind-gaap-again.html
1•gmays•18m ago•0 comments

The Yardbirds, Dazed and Confused (1968)

https://archive.org/details/the-yardbirds_dazed-and-confused_9-march-1968
1•petethomas•19m ago•0 comments

Agent News Chat – AI agents talk to each other about the news

https://www.agentnewschat.com/
2•kiddz•19m ago•0 comments

Do you have a mathematically attractive face?

https://www.doimog.com
3•a_n•23m ago•1 comments

Code only says what it does

https://brooker.co.za/blog/2020/06/23/code.html
2•logicprog•29m ago•0 comments

The success of 'natural language programming'

https://brooker.co.za/blog/2025/12/16/natural-language.html
1•logicprog•29m ago•0 comments

The Scriptovision Super Micro Script video titler is almost a home computer

http://oldvcr.blogspot.com/2026/02/the-scriptovision-super-micro-script.html
3•todsacerdoti•30m ago•0 comments

Discovering the "original" iPhone from 1995 [video]

https://www.youtube.com/watch?v=7cip9w-UxIc
1•fortran77•31m ago•0 comments

Psychometric Comparability of LLM-Based Digital Twins

https://arxiv.org/abs/2601.14264
1•PaulHoule•32m ago•0 comments

SidePop – track revenue, costs, and overall business health in one place

https://www.sidepop.io
1•ecaglar•35m ago•1 comments

The Other Markov's Inequality

https://www.ethanepperly.com/index.php/2026/01/16/the-other-markovs-inequality/
2•tzury•36m ago•0 comments

The Cascading Effects of Repackaged APIs [pdf]

https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6055034
1•Tejas_dmg•38m ago•0 comments

Lightweight and extensible compatibility layer between dataframe libraries

https://narwhals-dev.github.io/narwhals/
1•kermatt•41m ago•0 comments

Haskell for all: Beyond agentic coding

https://haskellforall.com/2026/02/beyond-agentic-coding
3•RebelPotato•45m ago•0 comments

Dorsey's Block cutting up to 10% of staff

https://www.reuters.com/business/dorseys-block-cutting-up-10-staff-bloomberg-news-reports-2026-02...
2•dev_tty01•47m ago•0 comments

Show HN: Freenet Lives – Real-Time Decentralized Apps at Scale [video]

https://www.youtube.com/watch?v=3SxNBz1VTE0
1•sanity•49m ago•1 comments

In the AI age, 'slow and steady' doesn't win

https://www.semafor.com/article/01/30/2026/in-the-ai-age-slow-and-steady-is-on-the-outs
1•mooreds•56m ago•1 comments

Administration won't let student deported to Honduras return

https://www.reuters.com/world/us/trump-administration-wont-let-student-deported-honduras-return-2...
1•petethomas•56m ago•0 comments