frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

1•darkmatternews•10s ago

Show HN: Live AI Design Benchmark

https://shuffle.dev/ai-design
1•kemyd•22s ago•0 comments

PayPal Attracts Takeover Interest After Stock Slump

https://www.bloomberg.com/news/articles/2026-02-23/paypal-attracts-takeover-interest-after-stock-...
1•mikece•47s ago•1 comments

ClawSecurity: CrowdStrike for OpenClaw Agents

https://twitter.com/yq_acc/status/2025977732048511379
1•jiayaoqijia•1m ago•1 comments

Stressful People in Your Life Could Be Adding Months to Your Biological Age

https://www.pnas.org/doi/10.1073/pnas.2515331123
1•m463•1m ago•0 comments

Code isn't what's slowing projects down

https://shiftmag.dev/code-isnt-slowing-your-project-down-communication-is-7889/
2•birdculture•2m ago•0 comments

Strix Is an Open-Source Claude Code Security

https://www.strix.ai/
1•bearsyankees•3m ago•0 comments

Show HN: Plyra-guard – intercepts AI agent tool calls before execution

https://github.com/plyraAI/plyra-guard
1•plyra•4m ago•0 comments

Learn Visual Studio Code (E-Book)

https://lazarpress.gumroad.com/l/learnvscode
1•LouisLazaris•4m ago•1 comments

Global Intelligence Crisis – Summary

https://toolong.co/s/dl2dyojl
1•a_void_sky•5m ago•0 comments

Let's Discuss Sandbox Isolation

https://www.shayon.dev/post/2026/52/lets-discuss-sandbox-isolation/
1•shayonj•5m ago•0 comments

Claude Code for MBAs (Part 1)

https://essilfie.substack.com/p/claude-code-for-mbas-part-1
1•lordleft•6m ago•0 comments

Meta found 19% of young teen Instagram users saw unwanted nude or sexual images

https://www.reuters.com/legal/litigation/meta-survey-found-19-young-teen-instagram-users-saw-unwa...
1•giuliomagnifico•7m ago•0 comments

Cripix Technology?

1•kellkell•7m ago•0 comments

Open-AutoGLM: Zhipu AI's Open-Source Framework for Phone Agents (23k Stars)

https://theagenttimes.com/articles/open-autoglm-23k-stars-the-phone-agent-framework-from-chinas-a...
1•Ross00781•7m ago•0 comments

Decided to fly to the US to buy some hard drives

https://old.reddit.com/r/DataHoarder/comments/1rb9ot4/decided_to_fly_to_the_us_to_buy_some_hard_d...
2•HelloUsername•7m ago•0 comments

Some silly Z3 scripts I wrote

https://www.hillelwayne.com/post/z3-examples/
1•azhenley•8m ago•0 comments

Cryptographic Reciprocity for Shared Reality in the Deepfake Era

https://aquariuos.com
1•AquariuOS•8m ago•1 comments

Show HN: Yet Another Firebase Alternative

https://linkedrecords.com/
1•WolfOliver•8m ago•0 comments

AI is destroying open source, and it's not even good yet [video]

https://www.youtube.com/watch?v=bZJ7A1QoUEI
1•delduca•9m ago•0 comments

Simon Wardley – From here to there and back again

https://www.youtube.com/watch?v=hEjjCI3kTM4
1•RebootStr•9m ago•0 comments

The first general computer action model

https://si.inc/posts/fdm1/
5•nee1r•9m ago•3 comments

Rozenite Zustand Devtools

https://github.com/IronTony/rozenite-zustand-devtools
1•IronTony•10m ago•1 comments

Museum of Plugs and Sockets

https://plugsocketmuseum.nl/index.html
2•ohjeez•10m ago•0 comments

What the Wealthy Want in Their Private Jets

https://www.wsj.com/style/design/what-the-wealthy-want-in-their-private-jets-46b94ea0
1•bookofjoe•10m ago•1 comments

Sell Everything for This 1997 McLaren F1 GTR That's Going to Auction

https://www.thedrive.com/news/sell-everything-and-then-some-for-this-1997-mclaren-f1-gtr-thats-go...
1•PaulHoule•11m ago•0 comments

Federal Gov Trafficking Pregnant Children to Texas So They Can't Get Abortions

https://www.throughline.news/p/the-trump-administration-is-trafficking
2•hn_acker•12m ago•1 comments

Show HN: What I've learned from shipping 25 mobile apps

https://newsletter.masilotti.com/p/what-ive-learned-from-shipping-25
1•joemasilotti•12m ago•0 comments

Why doesn't Anthropic use Claude to make a good Claude desktop app?

https://manualdousuario.net/en/claude-desktop-app-ai-electron/
1•rpgbr•13m ago•0 comments

Infosec Exchange Mastodon server downsizing due to Hetzner price increase

https://infosec.exchange/@jerry/116120025252406744
1•speckx•13m ago•0 comments
Open in hackernews

Show HN: A2SPA – Cryptographic payload signing and verification for AI agents

https://aimodularity.com/A2SPA
1•caprioladevin•1h ago

Comments

caprioladevin•1h ago
Hey HN, I'm Devin, one of the co-founders of A2SPA along with my dad Jonathan and my brother Gavin.

The problem we're solving: every AI agent framework today — LangChain, AutoGen, CrewAI, MCP, AWS Bedrock — treats incoming payloads as legitimate by default. There's no cryptographic verification that a payload was actually sent by the agent who claims to have sent it, that it hasn't been modified in transit, or that it hasn't been replayed from a previous session.

This creates what we call the Payload Trust Gap. All the upstream security layers — orchestration, tool schemas, sandboxing, permissions, guardrails, logging — operate on the assumption that the payload is fine. If it isn't, those controls are all working on a bad premise.

A2SPA sits at the execution boundary (Layer 5 of the agent stack) and enforces:

- SHA-256 payload signing with the sending agent's private key

- Nonce + 24hr TTL replay protection

- Per-agent permission mapping with instant on/off toggle

- Tamper-proof audit logging of every agent interaction

It's framework-agnostic and priced at $0.01 per verification — pay as you go, no minimums.

A few things I'd genuinely love feedback on:

1. Is the "Payload Trust Gap" framing accurate to how you think about agent security, or is there a better mental model?

2. Are there attack scenarios we haven't accounted for?

3. For those running agents in production — is this a problem you've already solved internally, and if so how?

Happy to get into the technical details of the implementation. Thanks for taking a look.