frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: TrueLock – secure messages as encrypted files with unlock rules

https://truelock.pro/
3•dkatsura•1h ago
I built TrueLock for “secure messaging without a messenger”.

Instead of sending plaintext in chat, you wrap a message (and attachments) into a single encrypted capsule file (.cfcaps) and share it via any channel (Telegram/email/drive/USB). The recipient opens the file in the app.

What’s different vs “just encrypt a file” is that the unlock policy travels with the ciphertext:

time window

geo radius

password (Argon2id)

visual key (optional)

AND/OR logic across rules

Current clients: Android + Windows. Crypto: AEAD (AES-GCM / ChaCha20-Poly1305).

Threat-model boundary: policy checks are local; a fully compromised endpoint can bypass checks or exfiltrate plaintext after legitimate open.

I’d value technical feedback on:

threat-model clarity

strongest real use case

what trust artifact you’d want next (format spec, test vectors, reproducible builds)

https://truelock.pro

Comments

dkatsura•1h ago
Maker here. Quick challenge for the skeptics:

Assume the capsule file leaks (someone forwards/copies it). In your view, does embedding the access policy (time/geo/password/visual key) into the same artifact as the ciphertext add any value, or is it pure security theater?

If you think it’s theater, what’s the smallest, most realistic bypass you’d try first — and what constraint would you add to make this primitive actually useful?

dkatsura•1h ago
Maker here — adding a concrete detail to make critique easier.

Capsule = one file: header (version, KDF/AEAD ids) + encrypted payload chunks + policy tree (AND/OR over time/geo/password/visual). Password path uses Argon2id; payload encryption is AEAD (AES-GCM or ChaCha20-Poly1305).

If you were reviewing this: what would you want first — (a) public capsule format spec, (b) test vectors for decrypt/verify, or (c) a short threat-model page with explicit non-goals?

dkatsura•59m ago
Maker here. If you think this is security theater, please don’t be polite — pick one and attack it:

1. “policy travels with ciphertext” — why is that a bad idea vs external workflow? 2. geo/time gating — useless gimmick or actually valuable friction? 3. visual key — dumb novelty or practical multi-party secret?

I’m genuinely trying to find the sharpest criticism, not compliments.

Lise Meitner's Nuclear Vision

https://www.historytoday.com/archive/great-debates/lise-meitners-nuclear-vision
1•samizdis•1m ago•0 comments

Where things stand with the Department of War

https://www.anthropic.com/news/where-stand-department-war
1•surprisetalk•2m ago•0 comments

Third Kairos (Space One) launch fails

https://spacenews.com/third-kairos-launch-fails/
1•HardwareLust•2m ago•0 comments

The FCC Wants Your Next Customer Service Agent to Be in the U.S.

https://www.wsj.com/business/telecom/the-fcc-wants-your-next-customer-service-agent-to-be-in-the-...
1•petethomas•3m ago•1 comments

Show HN: Multicorn Shield – Open-source permissions and approvals for AI agents

https://github.com/multicorn-ai/multicorn-shield
1•rachelle-r•6m ago•1 comments

Vet

https://github.com/imbue-ai/vet
1•handfuloflight•6m ago•0 comments

Self-Learning Customer Engagement

1•davismartens•6m ago•0 comments

Show HN: Ghoten – OpenTofu fork with ORAS back end for state in OCI registries

https://github.com/vmvarela/ghoten
1•vmvarela•10m ago•1 comments

Obfuscated C – Wordle hard mode solver

https://www.ioccc.org/2024/burton/index.html
1•coldsunrays•11m ago•1 comments

Remembering Mayhem

https://blog.metabrainz.org/2026/03/05/remembering-mayhem/
2•brw•12m ago•0 comments

Au Revoir, Eleventy

https://hamatti.org/posts/au-revoir-eleventy/
1•birdculture•13m ago•0 comments

Show HN: Claw Messenger, Text OpenClaw over iMessage Without a Mac Mini

https://www.clawmessenger.com/
2•demegire•14m ago•0 comments

Stackoverflow (Beta)

https://beta.stackoverflow.com/
2•AznHisoka•16m ago•0 comments

Investor Sam Lessin likens Iran war to Purim, the murder of 75,000 Persians

https://twitter.com/lessin/status/2029663841181979097
2•gravisultra•19m ago•1 comments

Gog – Google in Your Terminal

https://gogcli.sh/
1•atkrad•20m ago•1 comments

The nightmare war scenario is becoming reality in energy markets

https://www.economist.com/finance-and-economics/2026/03/03/the-nightmare-war-scenario-is-becoming...
5•petethomas•20m ago•1 comments

Context Engineering

https://github.com/m727ichael/context-engineering
1•m727ichael•21m ago•0 comments

Tracking Apple's Environmental Claims Across Product Generations

https://tostracker.app/entity/apple-inc/environment
1•tldrthelaw•23m ago•0 comments

GZOO Cortex – local-first knowledge graph that watches your project files

https://github.com/gzoonet/cortex
1•gzoo•23m ago•0 comments

LinguaKin is an offline-first, non-addictive language encyclopedia for polyglots

https://play.google.com/store/apps/details?id=com.linguakin.app&hl=en_US
1•mwveliz•25m ago•0 comments

FARS: Automated Research System

https://analemma.ai/fars
1•xiaoyu2006•25m ago•0 comments

Xiaomi Vision Gran Turismo Makes Global Debut at MWC Barcelona 2026

https://www.mi.com/global/discover/article/
1•gnabgib•26m ago•0 comments

The Editor Who Helped Build a Golden Age of American Letters

https://newrepublic.com/article/205583/editor-helped-build-golden-age-american-letters
1•samclemens•27m ago•0 comments

Can the Most Abstract Math Make the World a Better Place?

https://www.quantamagazine.org/can-the-most-abstract-math-make-the-world-a-better-place-20260304/
1•pseudolus•30m ago•0 comments

Minivum (mini-Vim)

https://ojhaugen15.github.io/minivum/
1•programmexxx•31m ago•0 comments

Temporal drives demand for Durable Execution – Temporal

https://temporal.io/blog/temporal-raises-usd300m-series-d-at-a-usd5b-valuation
1•atkrad•33m ago•0 comments

Show HN: Sick Clock" by Obeo – Predict your next sick day

https://apps.apple.com/us/app/obeo-forecast-your-health/id6754228624
2•jasnoor111•33m ago•2 comments

World Monitor – Real-Time Global Intelligence Dashboard

https://www.worldmonitor.app/
1•colinprince•34m ago•0 comments

Oracle plans job cuts as data center costs rise, Bloomberg News reports

https://www.reuters.com/business/oracle-plans-thousands-job-cuts-data-center-costs-rise-bloomberg...
5•nis0s•34m ago•1 comments

The growth of command line options, 1979-Present

https://danluu.com/cli-complexity/
2•teddyh•35m ago•0 comments