frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: A password system with no database, no sync, and nothing to breach

https://bastion-enclave.vercel.app
2•KevinChasse•1h ago
Hi HN, Bastion Enclave is an experiment in removing centralized trust from password management by eliminating server-side state entirely. Instead of storing an encrypted vault or syncing secrets through a backend, Bastion computes credentials deterministically on-the-fly using explicit cryptographic inputs. Given the same master entropy, service name, username, and version counter, the same password is reproduced across platforms. There is no account system, no database, and no persistent server storage — the server serves static code only. Password generation uses domain-separated salts and PBKDF2-HMAC-SHA512 (210k iterations) to produce a byte stream, followed by unbiased rejection sampling to avoid modulo bias when mapping to character sets. Nothing is stored; passwords are derived when needed and discarded immediately after use. When users choose to persist data locally (vault state, notes, file keys), encryption is handled separately using Argon2id (64 MB memory, 3 iterations) to derive a master key, followed by AES-256-GCM for authenticated encryption. All plaintext exists only in volatile memory; closing the tab tears down the runtime. Recovery and key escrow are handled via Shamir Secret Sharing over a large prime field (secp256k1 order) using a hybrid scheme: the secret is encrypted with a random session key, and only that key is split into shards. Invalid or mismatched shards fail cryptographically via AEAD tag verification. The security claim here is architectural, not policy-based: no stored vaults, no encrypted blobs on servers, no sync endpoints, and no recovery infrastructure to subpoena or breach. Attacking Bastion means attacking individual devices, not a centralized honeypot. This design intentionally trades convenience (sync, automated recovery) for reduced attack surface and deterministic guarantees. It assumes a trusted local execution environment and a strong master secret; it does not attempt to defend against a compromised OS or browser runtime. Live demo: https://bastion-enclave.vercel.app Spec / source / threat model: https://github.com/imkevinchasse/Bastion-Enclave-repo-V2 I’d appreciate critique of the threat model and whether this class of design meaningfully removes attack vectors inherent to cloud-based managers.

Comments

KevinChasse•1h ago
FYI: Bastion assumes a trusted local execution environment and a strong master secret. It does not defend against a compromised OS or browser runtime. The system trades convenience (sync, cloud recovery) for deterministic, stateless, and cryptographically verifiable password generation.

She's upending Japanese politics with two words: "I'm pregnant"

https://www.nytimes.com/2026/02/06/world/asia/japan-election-pregnant-candidate.html
1•binning•22s ago•0 comments

The Loneliest Rung

https://twitter.com/austinbv/status/2019825314365632530
1•austinbv•1m ago•0 comments

Flickr discloses potential data breach exposing users' names, emails

https://www.bleepingcomputer.com/news/security/flickr-discloses-potential-data-breach-exposing-us...
1•gslin•1m ago•0 comments

Christopher Nolan: Director, AI agent builder

https://darshdeep.substack.com/p/christopher-nolan-director-ai-agent
1•darshdeep351•1m ago•0 comments

Males are the Secondary Sex

https://designmom.substack.com/p/males-are-the-secondary-sex
1•binning•2m ago•0 comments

Google's Cyber Disruption Unit Kicks Its First Goal

https://www.lawfaremedia.org/article/google%27s-cyber-disruption-unit-kicks-its-first-goal
1•hn_acker•2m ago•0 comments

NASA astronauts will soon fly with the latest smartphones

https://twitter.com/NASAAdmin/status/2019259382962307393
1•tosh•3m ago•0 comments

Why all the bootstrapped AI consulting firms are hitting a –$4M ceiling

https://www.aienablementinsider.com/p/why-bootstrapped-ai-consulting-firms-get-stuck-at-4m-revenue
1•dylancollins•3m ago•0 comments

A portable ultrasound sensor may enable earlier detection of breast cancer

https://news.mit.edu/2026/portable-ultrasound-sensor-may-enable-earlier-detection-breast-cancer-0202
1•binning•3m ago•0 comments

I Put My Cat on a T-Shirt That References the Movie 'Hackers', You Can't Stop Me

https://defector.com/i-put-my-cat-on-a-t-shirt-that-references-the-movie-hackers-and-you-cant-sto...
1•dmschulman•4m ago•0 comments

Samsara SDKs Generated by Fern

https://github.com/samsarahq/samsara-dotnet/pulls
1•shoinker•4m ago•0 comments

Incident: SAS A20N at Brussels on Feb 5th 2026, attempted takeoff from taxiway

https://avherald.com/h?article=5345bfac&opt=0
1•hggh•6m ago•0 comments

We Didn't Ask for This Internet

https://www.nytimes.com/2026/02/06/opinion/ezra-klein-podcast-doctorow-wu.html
1•7402•6m ago•1 comments

Spider monkeys found to share 'insider knowledge' to help locate best food

https://www.theguardian.com/science/2026/jan/25/spider-monkeys-found-to-share-insider-knowledge-t...
1•PaulHoule•10m ago•0 comments

The Panic That Built WeChat's $700B Super-App

https://howardyu.substack.com/p/the-panic-that-built-wechats-700
1•pieterr•13m ago•0 comments

Fear and Loathing in America by Hunter S. Thompson

https://www.espn.com/espn/page2/story?id=1250751
1•yesbabyyes•13m ago•0 comments

What Is Good?

https://www.howtomakesenseofanymess.com/chapter2/33/what-is-good/
1•righthand•13m ago•0 comments

Ai.com bought by Crypto.com founder for $70M in biggest-ever website name deal

https://www.ft.com/content/83488628-8dfd-4060-a7b0-71b1bb012785
1•jmsflknr•15m ago•0 comments

How Much Would Continued Low Fertility Affect the US Standard of Living?

https://pubs.aeaweb.org/doi/pdfplus/10.1257/jep.20251462
1•jeffreyrogers•16m ago•0 comments

Mob Together: When AI Joins the Team

https://blog.flurdy.com/2026/02/mob-together-when-ai-joins-the-team
1•flurdy•17m ago•0 comments

BitBills Zero-Day (non-destructive private key sweeping)

https://bitcointalk.org/index.php?topic=5573683.0
1•tcatm•17m ago•1 comments

AI is becoming a go-to reason for layoffs. But is it replacing workers?

https://sherwood.news/markets/ai-is-becoming-a-go-to-reason-for-layoffs-but-is-it-actually-replac...
2•speckx•18m ago•1 comments

Waterloo Style

http://theprogrammersparadox.blogspot.com/2023/04/waterloo-style.html
1•brodouevencode•18m ago•0 comments

Burn Selection: How Fire Injury Shaped Human Evolution

https://onlinelibrary.wiley.com/doi/10.1002/bies.70109
1•bookofjoe•18m ago•0 comments

Spies arrested in France trying to intercept Starlink communication

https://www.france24.com/en/france/20260205-france-places-two-chinese-nationals-under-investigati...
1•RyanShook•19m ago•0 comments

I Take Spam Personally (And how Shopify enables it)

https://blog.mxroute.com/why-i-take-spam-personally/
1•hippich•19m ago•0 comments

Show HN: A customer billing portal built to reduce "can you resend the invoice?

https://flexprice.io/
2•ShreyaChaurasia•21m ago•1 comments

Ask HN: What book are you reading?

1•diggyhole•22m ago•1 comments

Once Operations: Why Idempotency Belongs in the Business Layer

https://equatorops.com/resources/blog/idempotency-business-layer
1•bobjordan•23m ago•0 comments

Show HN: Cbx – Local TTS CLI Wrapping Chatterbox ONNX (Single Rust Binary)

https://github.com/srv1n/cbx
1•Tsarp•23m ago•0 comments