frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

I built a "Carfax for Chrome Extensions" using AI to audit 250k+ extensions

https://chromeboard.com/extension/metamask-nkbihfbeogaeaoehlefnkodbefgpgknn
1•jozefjarosciak•2h ago

Comments

jozefjarosciak•2h ago
Folks, we’ve all been there... you find a cool Chrome extension, go to install it, and then you see the warning: "This extension can read and change all your data on all websites."

Is it a technical necessity? Or is it a keylogger sending your bank logins to a server in a basement somewhere? Unless you're a developer willing to manually download and decompile the .crx file, you’re just guessing.

I got tired of that "blind trust" model and built an AI-powered security scanner that goes through the actual code of every extension on the store: ChromeBoard.com.

What ChromeBoard Does: - Full Source Code Analysis: We don’t just read the description; we scan the entire codebase. - Plain English Reports: We explain permissions in simple terms. No "trust scores"—just the facts so you can decide. - Network Mapping: We identify every external server your data is sent to. - Flagging Dangerous Patterns: Our AI detects eval(), obfuscation, crypto-mining, and potential keyloggers. - Version Comparisons: See exactly what changed (or what was added) between updates. - Auto-Rescans: We trigger a new scan whenever an extension updates.

The Vision: Why this matters Right now, each scan takes about 2 minutes. Why? Because I’m running this entire operation on a single RTX 4090 using a local Qwen3-Coder-30B model. I’m doing this locally because: - Privacy: I refuse to send extension code to some cheap no-privacy third-party AI APIs. - Cost: I can’t afford $50k/month in inference fees for 250k+ extensions.

The site has only been live for two days, but the goal is to make this the "Carfax" of the Chrome Ecosystem. - For Users: A "check before you install" report that actually makes sense. - For Developers: A way to get "Verified Trust" signals to drive adoption. - For Enterprises: A third-party vetting tool for IT admins to secure their org.

The "Ask": Help me scale this I’ve reached the limit of what a single local GPU can do. I am looking for Cloud AI/Inference sponsors to help me move this from "side project speed" to "ecosystem speed."

With the right compute partners, I could scan 1,000x faster, provide real-time alerts when a behavior changes, and open up an API for other security tools. If you represent a cloud provider or AI platform, here is why you want to be the engine behind ChromeBoard:

- Massive Visibility: Your brand on every security report ("Powered by..."). - High Volume: A sustained, high-integrity API flow through your stack. - The "Good Guy" Factor: You’re helping secure the browsers of millions of people.

I’m just one dev who got tired of clicking "Install" and praying. If you’re a dev, an admin, or just hate malware, check out the site and let me know: Which extension should I scan next?

Check it out: ChromeBoard.com

1Password announces big price increases coming next month

https://9to5mac.com/2026/02/24/1password-announces-big-price-increases-coming-next-month/
1•m0nhawk•2m ago•1 comments

Show HN: Hedit – Modern Hosts File Editor

https://github.com/valtlfelipe/hedit
1•valtlfelipe•3m ago•1 comments

The Mainframe Renaissance: Why AI Needs a 1970s Adult to Supervise Its Homework

https://the-mind-of-ai.com/posts/mainframe-reborn/
1•agentic-wiki•4m ago•1 comments

Hyperagent

https://www.hyperagent.com
1•ptrhvns•5m ago•1 comments

My lobster lost $450k this weekend

https://pashpashpash.substack.com/p/my-lobster-lost-450000-this-weekend
1•__cayenne__•6m ago•0 comments

The Longest Line of Sight

https://tombh.co.uk/longest-line-of-sight
1•giraffe_lady•7m ago•0 comments

Ductape – One SDK for any backend integration

https://www.ductape.app/?hnlaunch=1
1•snifideezy•7m ago•1 comments

You Can't Optimize What You Can't See. AI Cost Observability

https://www.edgee.ai/blog/posts/2026-02-23-ai-cost-observability-missing-layer
1•Gillesray•7m ago•1 comments

Show HN: Fastdedup – Rust dataset deduplication (2:55 vs. 7:55 688MB vs. 22GB)

https://wapplewhite4.github.io/fastdedup/
1•wapplewhite4•7m ago•0 comments

Hegseth gives Anthropic until Friday to back down on AI safeguards

https://www.axios.com/2026/02/24/anthropic-pentagon-claude-hegseth-dario
4•rurp•9m ago•0 comments

Training my dog to vibe code B2B SaaS apps

https://dogomation.darefail.com/
2•jimhi•12m ago•1 comments

Can agentic coding raise the quality bar?

https://lpalmieri.com/posts/agentic-coding-raises-quality/
1•SatvikBeri•12m ago•0 comments

Show HN: MakLock – Free macOS App Locker with Touch ID and Apple Watch

https://github.com/dutkiewiczmaciej/MakLock
1•makmakapps•12m ago•0 comments

"SaaS is Dead" – they say

https://kudmitry.com/articles/saas-is-dead-they-say/
1•skwee357•12m ago•0 comments

Show HN: YouAM – An address, contact card, and encrypted inbox for AI agents

1•midlifedad•12m ago•0 comments

Show HN: Shelfctl – PDF/ePub library manager backed by GitHub Release

https://github.com/blackwell-systems/shelfctl
1•daynablackwell•14m ago•0 comments

Intel Formally Ends Four of Their Go Language Open-Source Projects

https://www.phoronix.com/news/Intel-Stops-Go-Projects
1•LorenDB•14m ago•0 comments

Spacydo: State machine example with own calldata for state transition rules

1•tracyspacy•15m ago•0 comments

Data vs. Hype: How Orgs Win with AI – The Pragmatic Summit [video]

https://www.youtube.com/watch?v=LOHgRw43fFk
1•cyndunlop•15m ago•0 comments

Implementing a Clear Room Z80 / ZX Spectrum Emulator with Claude Code

https://antirez.com/news/160
1•cyndunlop•16m ago•0 comments

Coding Agent, Good?

https://teetracker.medium.com/coding-agent-its-a-good-idea-1d34966c44ab
1•hasszhao•16m ago•1 comments

Steel Bank Common Lisp

https://www.sbcl.org/
2•tosh•16m ago•0 comments

Forests don't just store carbon. They keep people alive, scientists say

https://news.mongabay.com/2026/02/forests-dont-just-store-carbon-they-keep-people-alive-scientist...
1•PaulHoule•16m ago•0 comments

The Deceptively Simple Act of Writing to Disk

https://www.scylladb.com/2026/02/18/the-deceptively-simple-act-of-writing-to-disk/
1•cyndunlop•16m ago•0 comments

Inception Launches Mercury 2, the Fastest Reasoning LLM

https://www.businesswire.com/news/home/20260224034496/en/Inception-Launches-Mercury-2-the-Fastest...
1•tinco•17m ago•0 comments

OpenAI, the US government and Persona built an identity surveillance machine

https://vmfunc.re/blog/persona/
6•rzk•17m ago•2 comments

OpenAI resets spending expectations, from $1.4T to $600B

https://www.cnbc.com/2026/02/20/openai-resets-spend-expectations-targets-around-600-billion-by-20...
3•randycupertino•18m ago•0 comments

I think WebRTC is better than SSH-ing for connecting to Mac terminal from iPhone

https://macky.dev
2•Sayuj01•19m ago•1 comments

China May Grab a Lead in the Race for Military Fusion

https://www.wsj.com/opinion/china-may-grab-a-lead-in-the-race-for-military-fusion-c5ab6d2b
1•JumpCrisscross•19m ago•0 comments

An AI agent bought from our WooCommerce store. Here's what we learned

https://zologic.nl/the-next-evolution-of-conversion-why-your-store-needs-to-be-agent-ready/
1•Zologic•19m ago•1 comments