frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Cifer, zero-key custody using threshold cryptography

https://cifer-security.com
1•mikflex•1h ago
I built CIFER, a distributed encryption + access-control system designed so that no component ever holds a complete decryption key at rest.

Core idea: each “secret” (per user or per dataset) has its own independent post-quantum keypair. There is no master key.

Architecture summary:

Control plane: verifiable ownership, delegation, revocation, and append-only audit records (tamper-evident authorization history)

Custody plane: 5 custody nodes running in TEEs, each storing 1 key fragment

Orchestration: validates authorization then collects fragments to reconstruct keys only when needed

Key custody model:

Private key is generated in a TEE then immediately split via Shamir secret sharing into 5 fragments

Fragments are distributed to independent custody nodes

Original private key is destroyed

Threshold is 3-of-5 for reconstruction

Each custody node independently verifies authorization against the control plane before releasing its fragment

Clusters are disabled if membership changes (node exits disable the cluster)

Encryption scheme (hybrid PQ + symmetric):

Fetch ML-KEM-768 public key from content-addressed storage, verify integrity

ML-KEM-768 encapsulation per message/file/chunk to derive a fresh shared secret

Derive one-time AES key + IV via HKDF-SHA256

Encrypt payload with AES-256-GCM

Output includes a fixed-size envelope: ML-KEM ciphertext (1088 bytes) + GCM tag (16 bytes)

Decryption flow:

Requester signs a decryption request

Orchestrator checks owner/delegate status + freshness window (replay defense)

Orchestrator requests fragments in parallel, accepts the first 3 valid fragments

Reconstructs the private key and decrypts

Audit logs record the operation

Reconstructed keys may be cached in memory for 36 hours (availability vs exposure tradeoff)

Design goal: reduce blast radius from insider threats and single-node compromise, and address long-term confidentiality via post-quantum KEM.

I would love feedback on:

TEE trust assumptions and practical hardening for custody nodes

Whether 36h key caching is acceptable, and safer alternatives

Control plane failure modes (partition, reorg) and best practices for “deny by default” behavior

Metadata strategy for large-file workflows (I currently keep filename/size in plaintext metadata)

Better approaches for custody node independence and anti-collusion guarantees

Show HN: Deadhand – trustless Bitcoin inheritance in 2 minutes

https://github.com/pyoneerC/deadhand
1•maxcomperatore•33s ago•0 comments

Show HN: Deff – side-by-side Git diff review in your terminal

https://github.com/flamestro/deff
1•flamestro•40s ago•0 comments

Show HN: The best agent orchestrator is a 500-line Markdown file

https://github.com/bassimeledath/dispatch
1•bombastic311•1m ago•0 comments

California Public Technology Principles

https://argo-marketplace.github.io/future_of_california/
1•patwater10•4m ago•1 comments

Show HN: Conjure – 3D printed objects from text description only

https://conjure.tech
2•suchanekj•5m ago•1 comments

AI could help make society less selfish

https://techxplore.com/news/2026-02-ai-society-selfish.html
2•bikenaga•5m ago•0 comments

Travel North Tahoe Nevada ensures winter access

https://www.tahoedailytribune.com/news/travel-north-tahoe-nevada-ensures-winter-access-at-east-sh...
1•qualudeheart•5m ago•0 comments

Is It All over for Filmmakers?

https://www.shokunin.studio/blog/2026/2/18/is-it-all-over-for-filmmakers
1•SLHamlet•5m ago•1 comments

Show HN: Browser-based WebGL terrain editor with authoring mode and camera

https://playzafiro.com/isle-lab/
1•bartoszu_•6m ago•0 comments

The mechanics of autonomous software translation

https://alperenkeles.com/posts/autonomous-translations/
1•alpaylan•8m ago•0 comments

Pentagon officials send Anthropic best and final offer for military use of AI

https://www.cbsnews.com/news/pentagon-anthropic-offer-ai-unrestricted-military-use-sources/
3•rob•10m ago•0 comments

Durov Drama

https://substack.com/home/post/p-189273634
1•KyleVlaros•13m ago•0 comments

Show HN: I built a managed Claude AI and hosting service

https://codedoc.us
1•novatrope•14m ago•0 comments

Open Source in the Age of AI

https://john.onolan.org/open-source-in-the-age-of-ai/
1•Tomte•14m ago•0 comments

What I learned from the book 'Software Engineering at Google'

https://newsletter.techworld-with-milan.com/p/what-i-learned-at-swe-at-google-book
1•samspenc•16m ago•0 comments

Google Street View in 2026

https://tech.marksblogg.com/google-street-view-coverage.html
9•marklit•16m ago•0 comments

Show HN: I made a directory for Claude skills

https://skillsplayground.com/skills/
1•jackculpan•16m ago•0 comments

Kawasaki Corleo Electric Horse

https://global.kawasaki.com/en/corp/newsroom/news/detail/?f=20251211_7502
2•dabinat•17m ago•1 comments

Houston, we have a problem: Study points to clotting glitch in space

https://medicalxpress.com/news/2026-02-houston-problem-clotting-glitch-space.html
2•bikenaga•18m ago•1 comments

Show HN: Duck Talk – Real-time voice interface to talk to your Claude Code

https://github.com/dhuynh95/duck_talk
5•DanyWin•19m ago•0 comments

Thinking out loud: evolution and pretraining

https://hiranmay.com/blog/evolution-pretraining
1•hdarshane•19m ago•0 comments

OpenAI Has Poached Instagram's Celebrity Whisperer

https://www.vanityfair.com/news/story/openai-hires-charles-porch-instagram
1•herbertl•19m ago•0 comments

America Chose Not to Hold the Powerful to Account

https://www.theatlantic.com/ideas/2026/02/elite-accountability-powerful-impunity/686134/
18•JumpCrisscross•21m ago•0 comments

Self-Hosted LLMs Tier List

https://www.onyx.app/self-hosted-llm-leaderboard
1•RohoSwagger•21m ago•0 comments

Show HN: Depwire – Dependency graph and MCP tools so AI stops refactoring blind

https://github.com/depwire/depwire
2•atefataya•22m ago•2 comments

Show HN: Claude/Gemini/Codex 10-100x faster with pandō (CAD for code)

https://getpando.ai/
3•george_ciobanu•23m ago•2 comments

SynthID

https://deepmind.google/models/synthid/
3•tosh•26m ago•1 comments

Show HN: EK-1 – A local-first, sovereign AI agent built in Go and Rust

https://egokernel.com
1•felixche•26m ago•0 comments

Pacific Fusion finds a cheaper way to make its fusion reactor work

https://techcrunch.com/2026/02/05/pacific-fusion-finds-a-cheaper-way-to-make-its-fusion-reactor-w...
2•PaulHoule•28m ago•0 comments

Hanging with news-free friends preserves my sanity in a chaotic world

https://theishything.bearblog.dev/i-have-been-hanging-out-with-people-who-dont-watch-the-news/
1•speckx•28m ago•0 comments