frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Snare – catch hijacked AI agents before they make their first AWS call

https://github.com/peg/snare
1•trevxr•1h ago

Comments

trevxr•1h ago
I built this because Canarytokens.org has a published static bypass — TruffleHog identifies their AWS keys without triggering them by pattern-matching the key format. It's in TruffleHog's own README.

The other issue is CloudTrail latency. Median ~2-3 minutes. For a compromised AI agent that can enumerate credentials and pivot in under 10 seconds, that's too slow.

Snare plants fake credentials that fire at resolution time — before any API call, before CloudTrail sees anything. The awsproc canary uses AWS's credential_process feature: a shell command that runs when the SDK resolves credentials. The callback fires before the first packet leaves the machine.

Three precision canaries by default: awsproc (AWS), ProxyCommand (SSH), fake server URL (k8s). All fire on active use only, near-zero false positives from your own tooling.

Happy to dig into the implementation or threat model in the comments.

A factual warning for other media buyers

https://blog.karljtaylor.com/blog/2026-03-18-free-speech-on-x-10-dollar-promoted-post-experiment/
1•karljtaylor•43s ago•0 comments

Show HN: Ossature – Spec-driven code generation with LLMs

https://ossature.dev
1•beshrkayali•3m ago•0 comments

30 Days Left

https://krollsec.github.io/thirty-days/
1•Ksecurity•3m ago•0 comments

Clipboard Is Now a Memory

https://github.com/memorypasta/memorypasta
1•starboyy•4m ago•1 comments

Some thoughts on security after ten years of qmail 1.0 [pdf]

https://cr.yp.to/qmail/qmailsec-20071101.pdf
1•b-man•4m ago•0 comments

An Important Update to the Sencha ExtJS Licensing Model

https://www.sencha.com/blog/sencha-ext-js-is-moving-to-subscription-only-licensing-what-you-need-...
1•gjvc•7m ago•0 comments

I replaced FastAPI's HTTP core with Zig

https://twitter.com/rachpradhan/status/2034191434182738096
1•tosh•8m ago•0 comments

Moscow residents turn to pagers and maps as Russia enforces internet whitelist

https://kyivindependent.com/moscow-citizens-turn-to-pagers-printed-maps/
1•embedding-shape•9m ago•0 comments

A Wheel That Hijacks Waymos [video]

https://www.youtube.com/watch?v=YmPTfPh3T-Y
2•nkalupahana•9m ago•0 comments

In search of falsehood – using Opus 4.6 to prove False

https://tristan.st/blog/in_search_of_falsehood
1•shiftingleft•11m ago•0 comments

Zebra – A simple, fast, all-in-one config loader for Zig

https://github.com/omkar-foss/zebra
1•omkar-foss•11m ago•1 comments

Matrixes

https://code.kx.com/phrases/matrix/
1•tosh•12m ago•1 comments

The Landscape Architecture of Auroras on Demand

https://bldgblog.com/2026/03/the-landscape-architecture-of-auroras-on-demand/
1•arbesman•12m ago•0 comments

Open Source Gave Me Everything Until I Had Nothing Left to Give

https://kennethreitz.org/essays/2026-03-18-open_source_gave_me_everything_until_i_had_nothing_lef...
1•speckx•13m ago•2 comments

Show HN: Playing LongTurn FreeCiv with Friends

https://github.com/ndroo/freeciv.andrewmcgrath.info
1•verelo•13m ago•0 comments

How to Not Get Hacked Through File Uploads

https://www.eliranturgeman.com/2026/03/14/uploads-attack-surface/
2•birdculture•16m ago•0 comments

Months to minutes: AI feature-gap harness

https://dheer.co/feature-gap-harness/
1•bushido•17m ago•0 comments

Robinhood is making a social network

https://www.theverge.com/tech/896989/robinhood-social-network-beta
2•cdrnsf•17m ago•0 comments

How to Make Sense of AI

https://commoncog.com/how-to-make-sense-of-ai/
2•jger15•18m ago•0 comments

Silicon Valley Musters Behind-the-Scenes Support for Anthropic

https://www.nytimes.com/2026/03/18/technology/silicon-valley-anthropic-pentagon.html
2•goplayoutside•18m ago•0 comments

Argus-AI – G-ARVIS scoring for LLM observability in 3 lines of Python

https://github.com/anilatambharii/argus-ai
1•anilsprasad7•19m ago•0 comments

Show HN: CameraClaw – record and review what OpenClaw did in its sandbox

https://github.com/SharpAI/CameraClaw
3•aegis_camera•21m ago•0 comments

I built a Shopify bundling app that runs natively through checkout

https://www.getappfox.com/
1•rishabh0530•22m ago•0 comments

Getopt: Go package for POSIX/GNU-style command line parsing

https://pkg.go.dev/gitlab.com/natano/getopt
1•PaulHoule•22m ago•0 comments

VPN interest spikes in Brazil as mandatory age verification law takes effect

https://www.techradar.com/vpn/vpn-privacy-security/vpn-interest-spikes-in-brazil-as-mandatory-age...
1•mmaia•22m ago•0 comments

Meta is becoming too efficient, the Bull Case

https://josephblumenfeld.substack.com/p/the-case-for-meta
1•InvestingEasy•23m ago•0 comments

A speed reading UX to train focus

https://cyrusradfar.com/speed-read/https://paulgraham.com/words.html
1•cyrusradfar•24m ago•1 comments

Show HN: Clippy – screen-aware voice AI in the browser

https://RememberClippy.com
2•krschacht•25m ago•0 comments

Show HN: Nora – AI that finds you the right health plan

https://norahelps.com
2•nliang86•25m ago•1 comments

Show HN: Knowza.ai – Free 10-question trial now live (AI-powered AWS exam prep)

https://www.knowza.ai/
2•johnnyChiv•25m ago•0 comments