frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Monitor Cron Jobs Without Migration – DeadManPing

https://www.deadmanping.com/blog/monitor-cron-jobs
1•BlackPearl02•1m ago•0 comments

Doing a variety of exercise makes you 19% less likely to die than doing one

https://bmjmedicine.bmj.com/content/5/1/e001513
1•kareemm•2m ago•0 comments

Starting a Startup at 25, 35, or 45 Is Not the Same Decision

2•alx_sukhanov•10m ago•0 comments

We spent 5 YEARS building New York City in Minecraft [video]

https://www.youtube.com/watch?v=ZouSJWXFBPk
1•KolmogorovComp•10m ago•0 comments

Rent-Only Copyright Culture Makes Us All Worse Off

https://www.eff.org/deeplinks/2026/01/rent-only-copyright-culture-makes-us-all-worse
1•hn_acker•11m ago•0 comments

Show HN: Memcachex, a high-performance Memcached client for Go

https://github.com/atsegelnyk/memcachex
1•atsegelnyk•12m ago•1 comments

Utah Continues to Ban More Books, Even as It Racks Up More Lawsuits

https://www.techdirt.com/2026/01/22/utah-continues-to-ban-more-books-even-as-it-racks-up-more-law...
1•hn_acker•12m ago•0 comments

Kona: Energy-Based Models (EBMs) for AI Reasoning

https://logicalintelligence.com/kona-ebms-energy-based-models
2•gfortaine•14m ago•0 comments

Revealjs-skill: a better way for Claude to make presentations

https://github.com/ryanbbrown/revealjs-skill
1•ryanbbrown•15m ago•0 comments

Stunnel

https://www.stunnel.org/
2•firesteelrain•17m ago•0 comments

Vibe a Guitar Pedal

https://polyend.com/endless/
2•mulhoon•18m ago•0 comments

Four Ingredients for Successful Retrofitting

https://bmin.ai/retrofitting/
1•nl•19m ago•0 comments

TikTok Strikes Deal for New U.S. Entity, Ending Long Legal Saga

https://www.nytimes.com/2026/01/22/technology/tiktok-deal-oracle-bytedance-china-us.html
4•jbegley•24m ago•0 comments

Why medieval city-builder video games are historically inaccurate (2020)

https://www.leidenmedievalistsblog.nl/articles/why-medieval-city-builder-video-games-are-historic...
14•benbreen•24m ago•1 comments

WAForth: Forth Interpreter+Compiler for WebAssembly

https://github.com/remko/waforth
1•publicdebates•27m ago•0 comments

Clean Web UI for Steve Yegge's Beads

https://github.com/nmelo/bdui
1•nmelo•27m ago•0 comments

Apple's John Ternus Takes over Design in Latest CEO Succession Move – MacRumors

https://www.macrumors.com/2026/01/22/john-ternus-apple-design-lead/
1•latexr•27m ago•0 comments

Guiding the Future of Chainguard OS: Announcing the FUD Committee

https://www.chainguard.dev/unchained/guiding-the-future-of-chainguard-os-announcing-the-fud-commi...
1•milkglass•28m ago•0 comments

Back to Bellevue

https://theamericanscholar.org/back-to-bellevue/
1•prismatic•29m ago•0 comments

Arkansas inmates restricted from receiving physical books, other media directly

https://arkansasadvocate.com/2025/12/19/arkansas-inmates-restricted-from-receiving-physical-books...
2•hn_acker•29m ago•2 comments

The Physicians of Decay

https://tantaman.substack.com/p/the-physicians-of-decay
1•tantaman•30m ago•0 comments

Yabai: A tiling window manager for macOS based on binary space partitioning

https://github.com/asmvik/yabai
2•behnamoh•30m ago•0 comments

Metastable Failures and Interactions Between Systems

https://charap.co/on-metastable-failures-and-interactions-between-systems/
2•PaulHoule•31m ago•0 comments

Node.js: New HackerOne Signal Requirement for Vulnerability Reports

https://nodejs.org/en/blog/announcements/hackerone-signal-requirement
2•latexr•32m ago•0 comments

Ispc: Origins (Part 1)

https://pharr.org/matt/blog/2018/04/18/ispc-origins
1•luu•33m ago•0 comments

Penis Size, height, and body shape influence assessment of male attractiveness

https://journals.plos.org/plosbiology/article?id=10.1371/journal.pbio.3003595
4•doener•33m ago•1 comments

Lessons of Design

https://lessons.design/
2•SouravInsights•34m ago•0 comments

Malignant Narcissism

https://en.wikipedia.org/wiki/Malignant_narcissism
2•u1hcw9nx•36m ago•0 comments

Samsung hits ₩1,000T market cap (~$740B)

https://biz.chosun.com/en/en-finance/2026/01/22/CEEEPNBOIFFCDKMGIT2ISDAENM/
2•xthe•38m ago•0 comments

Is that allowed? Authentication and authorization in Model Context Protocol

https://stackoverflow.blog/2026/01/21/is-that-allowed-authentication-and-authorization-in-model-c...
1•mooreds•38m ago•0 comments
Open in hackernews

FIPS dependencies and prebuilt binaries

https://www.docker.com/blog/fips-dependencies-and-prebuilt-binaries/
15•LaurentGoderre•1h ago
Author here. This came out of debugging a real Rails app running in a FIPS enabled container.

Everything looked correct. OpenSSL 3 with the FIPS provider enabled. Ruby built against it. A simple pg connection worked.

The app failed once ActiveRecord was involved. The error came from libpq. It turned out the pg gem had pulled in a prebuilt native dependency that was linked against different crypto. That path was always there. It just was not exercised until ActiveRecord hit it.

Forcing a source build fixed the issue because the extension then linked against the OpenSSL in the image.

The takeaway is that a FIPS base image does not mean your dependency graph respects the same boundary once native code is involved.

Curious how others have seen this play out in Ruby, Python wheels, Go with CGO, or Node native addons.

Comments

JasonADrury•1h ago
> FIPS compliance is a great idea that makes the entire software supply chain safer

Yes, gotta implement that Dual_EC_DRBG compatibility.

FIPS compliance is not a great idea, the benefits are questionable and possibly nonexistent. It's also significantly worse advice than simple "implement decent modern crypto", you can do all kinds of really bizarre stuff and still be FIPS compliant.

direwolf20•1h ago
FIPS compliance should be used when the customer demands FIPS compliance, and at no other time. It does not make your software more secure. The federal government has many reasons for its Information Processing Standards, and actual security isn't high up the list.
voidfunc•44s ago
FIPS is what happens when idiots get promoted and start reading too much LinkedIn CISO slop.

If a customer demands FIPS compliance charge them out the ass for it. Its not inherently secure, it requires in some cases massive re-engineering of product and toolchains, and mostly seems to be an ask from clueless deep pocketed Fortune 500 companies looking to minimize liability claims after a breach by being able to point at their FIPS compliance.