frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: unTamper – cryptographically verifiable audit logs for app events

2•unTamper•1h ago
https://untamper.com

Built this after hitting the same gap on multiple projects: teams log critical events (admin actions, permission changes, PII access) but have no structural way to prove those records weren't altered after the fact.

Immutable storage (S3 Object Lock, WORM) are common, but it only covers tampering after the write lands. It doesn't protect against someone with DB write access, and it doesn't give a third party, e.g. an auditor, a way to verify integrity without touching your infrastructure.

My approach: hash chaining. Each event is SHA-256 hashed against its canonical payload + the hash of the previous event. Any insertion, deletion, or modification breaks all subsequent hashes. Anyone with the public API can re-verify the chain independently.

A few decisions I'm happy to discuss:

- Canonicalization before hashing: JSON isn't canonical by default. Ended up writing a strict sorted-key schema rather than fighting recursive serialization. - Per-actor chains vs. one global chain: Global is simpler to verify but creates write contention and makes auditor exports painful. Per-actor trades some global integrity for operational sanity.

- Trusted server-side timestamps anchored into the hash: If the client controls the timestamp, you can reorder events without breaking hashes.

- Periodic anchoring to a public chain: On the roadmap for the "full infra access + rewrite the whole chain" attack vector.

SDK is available (nodejs, others are coming). Integration is trivial. Free tier available without CC.

Happy to go deep on the crypto model, the canonicalization approach, or the trust assumptions.

Comments

saidnooneever•1h ago
this is a really cool idea, it excites me, and thats rare. work in cyber, did a lot of IR. this is a real issue.

i see now it requires npm and is JSey. In my personal oppinion this would be super valuable if it could be applied to any kind of logging. so maybe a lib in a different language or some wrappers, so i could make a rust, c or whatever application log in such a way, and chuck the logs in a log verifier that does the verification magic.

(ofc did not read all the docs so of this is actually already possible, maybe highlight it more, and ignore my comment :p)

unTamper•1h ago
Really appreciate that. IR folks are exactly who this is built for.

The JS SDK is just the first one out the door. The verification model is language-agnostic: it's HTTP(S) + JSON at the core, so wrapping it in Rust, Python, Go etc. is straightforward. A language-agnostic spec + more SDKs is on the roadmap, but honestly feedback like this moves it up.

If you're interested in a Rust wrapper specifically, I'd love to build that with someone who'd actually use it. BTW the verification protocol is built in the SDK so it's client side, you don't have to rely on server-side verification.

gnapapp•12m ago
I've actually been considering Splunk few years back just for a similar capability. nice

Whatever Happened to NFTs?

https://www.rnz.co.nz/news/business/590008/whatever-happened-to-nfts
1•billybuckwheat•41s ago•0 comments

NBomber Studio 0.6.2

https://nbomber.com/blog/2026/03/18/nbomber-studio-v0.6.2/
1•antyadev•1m ago•0 comments

Jax Metal vs. MLX

https://ndalton12.github.io/blog/jax-vs-mlx/
1•tosh•1m ago•0 comments

The Download: The Pentagon's new AI plans, and next-gen nuclear reactors

https://www.technologyreview.com/2026/03/18/1134371/the-download-the-pentagons-new-ai-plans-and-n...
1•joozio•1m ago•0 comments

Home Assistant AI Task – Turn Any Camera into an AI Vision Sensor [video]

https://www.youtube.com/watch?v=-bLVTHzfHyk
1•whynotmaybe•3m ago•0 comments

System Kills Itself Trying to Recover

https://aalpar.github.io/2026/03/18/your-system-kills-itself-trying-to-recover.html
1•aalpar•4m ago•0 comments

Quantum pioneers win Turing Award for encryption breakthrough

https://www.bbc.co.uk/news/articles/c7474004g01o
1•zeristor•4m ago•0 comments

Free tool: Competitive intelligenece report generator

https://www.foresightiq.co/competitive-intelligence-report
1•nandorsky•4m ago•0 comments

I built a reader mode Chrome extension that works on any site

https://chromewebstore.google.com/detail/readr-–-clean-page-one-cl/acpeognnfhdbfdmdpkfbjgppjpgp...
1•Ogbon•4m ago•0 comments

California Weighs Crackdown on Social Media for Kids Under 16

https://www.bloomberg.com/news/articles/2026-03-18/california-weighs-crackdown-on-social-media-fo...
1•1vuio0pswjnm7•9m ago•1 comments

Gaming publisher's CEO used ChatGPT in failed bid to avoid paying $250M bonus

https://www.theguardian.com/technology/2026/mar/18/subnautica-2-publisher-krafton-ceo-reinstated-...
2•prmph•10m ago•1 comments

Stop spending money on Claude, Chipotle's chat bot is free

https://www.reddit.com/r/ClaudeCode/s/rhT0uFqxYa
1•m4tthumphrey•11m ago•0 comments

Is Web3 hype dead now?

1•jensec•13m ago•1 comments

Oil nears $110 a barrel after gas field strike

https://www.bbc.com/news/articles/c78x83lpgngo
2•tartoran•13m ago•0 comments

Bayesian statistics for confused data scientists

https://nchagnet.pages.dev/blog/bayesian-statistics-for-confused-data-scientists/
2•speckx•13m ago•0 comments

WFP projects food insecurity could reach record levels

https://www.wfp.org/news/wfp-projects-food-insecurity-could-reach-record-levels-result-middle-eas...
2•saikatsg•15m ago•0 comments

What 81,000 people want from AI

https://www.anthropic.com/features/81k-interviews
2•jbegley•16m ago•0 comments

Qman: A more modern man page viewer for our terminals

https://github.com/plp13/qman
2•PaulHoule•16m ago•0 comments

Fair Source Software in the AI Age

https://blog.sentry.io/fair-source-software-in-the-ai-age/
1•jshchnz•17m ago•0 comments

Show HN: Open-source Typeform

https://forms.md/
4•darkhorse13•18m ago•0 comments

An American physicist and Canadian scientist devised a way to keep secrets safe

https://www.cnn.com/2026/03/18/science/quantum-key-cryptography-turing-award-winners
2•rawgabbit•19m ago•1 comments

Show HN: Tmux-IDE, OSS agent-first terminal IDE

https://tmux.thijsverreck.com
3•thijsverreck•19m ago•0 comments

Hacker News London Meetup #7

https://www.meetup.com/hackernewslondon/events/313625563/
1•Wdorf•21m ago•1 comments

Congestion Pricing for WDC?

https://www.washingtonpost.com/opinions/2026/03/15/congestion-pricing-dc-tax-bowser-mayor/
3•paulpauper•21m ago•0 comments

EU Inc.: A new harmonised corporate legal regime

https://commission.europa.eu/topics/business-and-industry/doing-business-eu/company-law-and-corpo...
2•guidoiaquinti•23m ago•0 comments

Mass AI opinions engine for research, product and strategy

https://github.com/thingsthat/mass
2•jprosser•24m ago•0 comments

TaskyBear: AI Agent for To-Do Planning and Habit Tracking

https://openinapp.link/taskybear-app
1•kravixstudio•26m ago•0 comments

Show HN: Snare – catch hijacked AI agents before they make their first AWS call

https://github.com/peg/snare
1•trevxr•27m ago•1 comments

We're building a better rich text editing toolkit

https://handlewithcare.dev/pitter-patter/
3•smoores•27m ago•1 comments

I haven't used a mouse for 14 years

https://axelk.ee/i-havent-used-a-mouse-for-14-years-and-how-to-enable-three-fingers-drag-on-macos/
2•speckx•29m ago•1 comments