frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Credential Protection for AI Agents: The Phantom Token Pattern

https://nono.sh/blog/blog-credential-injection
1•decodebytes•2h ago

Comments

decodebytes•2h ago
Hey HN. I'm Luke, security engineer and creator of Sigstore and other open source security projects. I've been building nono, an open source sandbox for AI coding agents that uses kernel-level enforcement (Landlock/Seatbelt) to restrict what agents can do on your machine.

One thing that's been bugging me: we give agents our API keys as environment variables, and a single prompt injection can exfiltrate them via env, /proc/PID/environ, or just an outbound HTTP call. The blast radius is the full scope of that key.

So we built what we're calling the "phantom token pattern" — a credential injection proxy that sits outside the sandbox. The agent never sees real credentials. It gets a per-session token that only works only with the session bound localhost proxy. The proxy validates the token (constant-time), strips it, injects the real credential, and forwards upstream over TLS. If the agent is fully compromised, there's nothing worth stealing.

Real credentials live in the system keystore (macOS Keychain / Linux Secret Service), memory is zeroized on drop, and DNS resolution is pinned to prevent rebinding attacks. It works transparently with OpenAI, Anthropic, and Gemini SDKs — they just follow the *_BASE_URL env vars to the proxy.

Blog post walks through the architecture, the token swap flow, and how to set it up. Would love feedback from anyone thinking about agent credential security.

https://nono.sh/blog/blog-credential-injection

We also have other features we have shipped, such as atomic rollbacks, Sigstore based SKILL attestation.

https://github.com/always-further/nono

Trae Stephens: I want to buy Wired

https://twitter.com/i/status/2028824764656283997
1•mudil•1m ago•0 comments

Show HN: I build a free topical authority map generator for blog

https://kitful.ai/write-tools/topical-map-generator
1•eashish93•3m ago•0 comments

Show HN: Headless Obsidian Sync Client

https://github.com/alexjbarnes/vault-sync
1•recouptreadmill•3m ago•0 comments

Show HN: VibeDiff – Blocks Claude Code from shipping breaking changes

https://github.com/SallahBoussettah/vibe-diff
1•Boussettah•3m ago•0 comments

Buckle Up for Bumpier Skies

https://www.newyorker.com/projects/interactive/2026/20260226-bilger-turbulence-header-prod/202602...
1•rbanffy•5m ago•0 comments

How To Put 30 Languages Into 1.1MB – hypher, a fast hyphenation library for Rust

https://laurmaedje.github.io/posts/hypher/
1•zdw•6m ago•0 comments

Prediction markets on Deutsche Bahn departure delays

https://bahn.bet
2•dancric•6m ago•0 comments

AI causing programmers to work longer hours fixing bugs

https://www.scientificamerican.com/article/why-developers-using-ai-are-working-longer-hours/
3•timoth3y•8m ago•1 comments

Show HN: A Free, interactive API course for product managers

https://api101.org/en
1•matb31240•8m ago•0 comments

Qwen 3.5: best open-weight vision models, now on live video at 200ms

https://blog.overshoot.ai/blog/qwen3.5-on-overshoot
1•YounElh•8m ago•0 comments

Voice Can Make Coding Agents Better (In Some Cases)

https://nimasadri11.github.io/random/voice-input-agents.html
2•nimasadri11•10m ago•0 comments

A Vindication of Bjorn Lomborg

https://humanprogress.org/a-vindication-of-bjorn-lomborg/
1•mpweiher•11m ago•0 comments

Study: LLMs Able to De-Anonymize User Accounts on Reddit, Hacker News

https://wjamesau.substack.com/p/warning-llms-able-to-de-anonymize
1•SLHamlet•12m ago•0 comments

A Soft-Landing Manual for the Second Gilded Age

https://www.joanwestenberg.com/a-soft-landing-manual-for-the-second-gilded-age/
1•spking•14m ago•0 comments

Claude Code skills for modern xOS (iOS, iPadOS, watchOS, tvOS) development

https://github.com/CharlesWiltgen/Axiom
1•rob•17m ago•0 comments

How Teens Use and View AI

https://www.pewresearch.org/internet/2026/02/24/how-teens-use-and-view-ai/
2•bookofjoe•19m ago•0 comments

Three scientists who said no to Epstein

https://www.science.org/content/article/meet-three-scientists-who-said-no-epstein
4•klipt•19m ago•0 comments

TrustLoop – Real-time policy enforcement and audit logging for AI agents

https://www.trustloop.live/
1•soji_mathew•22m ago•0 comments

Cybersecurity Forecast 2026 [pdf]

https://services.google.com/fh/files/misc/cybersecurity-forecast-2026-en.pdf
1•bookofjoe•25m ago•0 comments

Show HN: Interactive WordNet Visualizer-Explore Semantic Relations as a Graph

https://wordnet-vis.onrender.com/
1•ricky_risky•27m ago•0 comments

How to Manage Team Offsites Across Multiple Departments Without Micromanaging

https://daydreamsinruby.com/blog/2026-02-23-aligned-offsite-outcomes/
1•mooreds•28m ago•0 comments

Clud – super light-weight tool to turn natural language to terminal commands

https://github.com/oskob/clud
1•oskob•28m ago•2 comments

Log messages are mostly for the people operating your software

https://utcc.utoronto.ca/~cks/space/blog/programming/LogMessagesAreForOperation
1•todsacerdoti•29m ago•0 comments

A Race Within a Race: Exploiting CVE-2025-38617 in Linux Packet Sockets

https://blog.calif.io/p/a-race-within-a-race-exploiting-cve
3•WalterSobchak•30m ago•0 comments

So long, and thanks for all the logs

https://jerodsanto.net/2026/03/so-long-changelog/
2•mooreds•30m ago•0 comments

Computer Use Protocol – AI agents can perceive and interact with any desktop UI

https://github.com/computeruseprotocol/computeruseprotocol
3•k4cper-g•30m ago•0 comments

Why we love Vim (2021) [audio]

https://changelog.com/podcast/450
1•mooreds•32m ago•0 comments

Show HN: Limabean – a new implementation of Beancount in Clojure/Rust

https://github.com/tesujimath/limabean
1•tesujimath•32m ago•0 comments

Light-responsive porous aromatic frameworks manipulate CO2 uptake

https://www.pnas.org/doi/10.1073/pnas.2520024123
1•PaulHoule•32m ago•0 comments

Tech Legend Stewart Brand on Musk, Bezos and His Extraordinary Life

https://www.theguardian.com/technology/2026/feb/25/tech-legend-stewart-brand-on-musk-bezos-and-hi...
1•rmason•33m ago•0 comments