frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: I built a tamper-evident audit logging service to prevent DB rewrites

https://github.com/Ashish-Barmaiya/attest
1•ashish-barmaiya•1h ago

Comments

ashish-barmaiya•1h ago
Hi HN,

I’m currently building a zero-knowledge digital inheritance platform called SecureVault. While designing the threat model, I kept running into a fundamental flaw with standard audit logs: they only prove internal consistency.

If a sophisticated attacker (or a rogue admin) gets full access to my Postgres database, they could easily delete the last 10 events, forge 10 new ones, recompute the hashes, and present a perfectly "valid" log.

I needed cryptographic proof of log integrity for SecureVault, so I stepped back and built Attest to solve it. It’s an open-source, multi-tenant audit logging service that makes history rewrites mathematically detectable.

It works by combining strict cryptographic hash chaining (every event hashes the previous one) with a background worker that periodically anchors the "Chain Head" to an external, append-only system (like Git). To rewrite history without detection, an attacker would have to compromise both the database and the external Git repository simultaneously.

The core trade-off: To guarantee strict serializability and a linear hash chain, writes are serialized per project. This means it maxes out around 25-30 writes/sec per project due to optimistic locking contention. It is intentionally built for high-assurance security events where integrity matters more than raw throughput.

I would love to hear your brutal, honest feedback on the architecture, the threat model, or better ways to handle the optimistic locking approach without sacrificing strict ordering.

Happy to answer any questions!

CHERIoT Rust: Status update #0

https://rust.cheriot.org/2026/02/15/status-update.html
1•remexre•52s ago•0 comments

The CHIPS Act Spends $52.7B on Fabs but $0 on Defending Them from Ransomware

https://thehgtech.com/articles/semiconductor-ransomware-chips-act-2026.html
1•thehgtech•1m ago•0 comments

Show HN: Dance of Tal V2 – Dependency injection and lockfiles for AI agents

https://github.com/dance-of-tal/dance-of-tal
1•monarchjuno•2m ago•0 comments

Trump made tax day more complicated. ChatGPT and Claude can make it easier

https://www.vox.com/life/480317/trump-taxes-chatgpt-claude-turbotax
1•speckx•2m ago•0 comments

Turning a 2 ton robot into a 3D printer [video]

https://www.youtube.com/watch?v=peY_KK_nGc8
1•rmast•2m ago•0 comments

Show HN: Nosh – Fast native shell with built-in AI (natural language commands)

https://github.com/TryNosh/nosh
1•pouya-eghbali•2m ago•0 comments

"A file is an app" – Selfware, a unified file format for the Agent eramory)

https://github.com/floatboatai/selfware.md
2•floatboat•3m ago•1 comments

Show HN: Read the Room, a FOSS human bioindicator

1•soudk•4m ago•0 comments

Who will regulate Elon Musk and China's data centers in space?

https://restofworld.org/2026/orbital-data-centers-ai-sovereignty/
1•vinhnx•4m ago•0 comments

AncestorTree – Open-source genealogy for Vietnamese families

1•dttai•4m ago•0 comments

Retool silently removes self-hosted plans

https://community.retool.com/t/self-hosted-docs-now-state-enterprise-only/64586
2•assumptions•4m ago•0 comments

Was software a scarce commodity all along?

https://harmonique.one/posts/was-software-a-scarce-commodity-all-along
1•futurecat•4m ago•0 comments

Online Accusations in Guthrie Abduction Leave One Family 'Scared Numb'

https://www.nytimes.com/2026/02/25/us/nancy-guthrie-true-crime-accusations.html
1•duxup•6m ago•0 comments

AI Dev Tool Stack for 2026

https://qa.tech/blog/ai-dev-tool-stack-for-2026
2•Liriel•7m ago•1 comments

Show HN: Memograph CLI- A tool to diagnose 'memory failures' in AI agents

1•memograph•7m ago•1 comments

Show HN: Dola Seed 2.0 – AI video generator with multi-shot narrative control

https://dolaseed.site
1•yuni_aigc•7m ago•1 comments

Show HN: SeeVideo – Access Seedance 2.0 and Kling 3.0 without a subscription

https://seevideo.dance/
1•naxtsass•8m ago•0 comments

Jesse Jackson Paved the Way for a New US Left

https://jacobin.com/2026/02/jesse-jackson-death-left-sanders/
2•PaulHoule•8m ago•0 comments

We run 20M models in parallel on Ray

https://mixpeek.com/blog/ray-distributed-ml-pipeline-architecture
1•Beefin•8m ago•1 comments

HTP

1•MiachelC•8m ago•0 comments

Ask HN: What if your LLM violates a patent?

1•VikingCoder•8m ago•0 comments

When access to knowledge is no longer the limitation

https://idiallo.com/blog/access-to-knowledge-is-no-longer-a-limitation
1•Brajeshwar•9m ago•0 comments

The Absolute Insider Mess of Prediction Markets

https://philippdubach.com/posts/the-absolute-insider-mess-of-prediction-markets/
1•Brajeshwar•9m ago•1 comments

Show HN: Tracking my bin (trash can)

https://timang.us/2026-02-16-bin-tracker/
1•tim_angus•9m ago•0 comments

Where We Should Discuss Only Computing Research

https://cacm.acm.org/opinion/where-we-should-discuss-only-computing-research/
1•bikenaga•9m ago•0 comments

Ask HN: Who Is Using XMPP?

2•nunobrito•9m ago•0 comments

People 18-60 are not concerned "education vs. AI" But it affects them personally

1•kokhanserhii•10m ago•0 comments

Style and Politics: On "The National Security Strategy of the United States "

https://www.publicbooks.org/style-and-politics-on-the-national-security-strategy-of-the-united-st...
1•treetalker•11m ago•0 comments

Jefferson Lab Tapped to Lead Development for Exploring Nuclear Waste Treatment

https://www.jlab.org/news/releases/jefferson-lab-tapped-lead-technology-development-exploring-nuc...
1•rbanffy•11m ago•0 comments

Will Americans Get over Their Fear of Eating Animal Blood?

https://www.nytimes.com/2026/02/24/t-magazine/animal-blood-food-restaurants.html
2•carride•11m ago•0 comments