frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Remote LUKS disk decryption over mTLS

https://github.com/luishfonseca/network-unlock
3•luishfonseca•1h ago
I have two VPSs with full disk encryption. Sadly, neither provides a TPM so I've always had to connect by SSH to type my password. I've spent the last weekend thinking of a way to automate the process without weakening the threat model and came up with this protocol. You can find the sequence diagram in the README, consider that the spec.

This is the threat model:

- Internal network is trusted, nodes are not. However, a compromised network unlock server won't collude with a network attacker.

- Attacker has full access to the public network.

- Attacker has eventual access to the disk and can recover any deleted file.

Any full disk encryption unlocking scheme of a remote machine without a TPM, e.g. SSH-ing into a dropbear initramfs, is vulnerable to the same attacker: someone who can read your unencrypted /boot partition and sit on your network. Against dropbear, they extract the SSH host key from the initramfs, impersonate your server, and capture the passphrase you type.

This protocol doesn't strive to be stronger than that, it accepts the same threat model. An attacker with disk access + network access within the TTL window can steal the ephemeral TLS cert + key from /boot, connect to the server, and retrieve Na. The protocol just removes the human from the loop while being no worse than typing a password over SSH.

I'm running this on my pair of VPSs, so if anyone finds a hole inside the threat model please let me know! I don't run anything critical but would rather not get hacked by playing with homebrew protocols. This wasn't vibe coded, so you'd be arguing with my ideas and not an LLM.

Proof and Progress in Mathematics (1994)

https://marqr.codes/b8_cj
1•ajax33•48s ago•0 comments

Body Is Betraying Your Right to Privacy

https://www.wired.com/story/book-excerpt-your-data-will-be-used-against-you-andrew-guthrie-ferguson/
1•Brajeshwar•1m ago•0 comments

NanoClaw Adopts OneCLI Agent Vault

https://nanoclaw.dev/blog/nanoclaw-agent-vault/
2•turntable_pride•2m ago•0 comments

Show HN: An agent-first Kanban board for harness engineering

https://github.com/saltbo/agent-kanban
1•saltbo•2m ago•0 comments

Anthropic: Enable Claude to Use Your Computer from Mobile

https://claude.com/blog/dispatch-and-computer-use
1•pookieinc•3m ago•0 comments

Train the smallest LM you can that fits in 16MB. Best model wins

https://github.com/openai/parameter-golf
1•bilsbie•4m ago•0 comments

Super-rich are turning their backs on the 'Giving Pledge'. That's good news

https://www.thefp.com/p/giving-up-on-the-giving-pledge
1•mhb•6m ago•0 comments

Show HN: Named failure modes that stop AI agents from cutting corners

https://github.com/travisdrake/context-engineering
1•travisdrake•6m ago•0 comments

Nobody Wants to Create a New Repo

https://infrahouse.com/blog/2026-03-23-nobody-wants-to-create-a-new-repo/
1•aleks2•7m ago•0 comments

Show HN: a Rust Redis GUI that doesn't freeze on 100k keys

https://github.com/vicanso/zedis
1•vicanso•7m ago•0 comments

From error-handling to structured concurrency

https://blog.nelhage.com/post/concurrent-error-handling/
1•fanf2•8m ago•0 comments

LocalRouter: MCP via LLM

https://localrouter.ai/
1•matusfaro•8m ago•0 comments

Now Available: Depot CI

https://depot.dev/blog/now-available-depot-ci
3•dan_manges•11m ago•0 comments

Workslop

https://build.ms/2026/3/23/workslop/
1•mergesort•12m ago•0 comments

The FCC Just Banned the Sale of New Wi-Fi Router Models Made Outside US

https://www.pcmag.com/news/fcc-just-banned-the-sale-of-new-wi-router-models-made-outside-us
1•InfamousRece•12m ago•0 comments

Show HN: I built a local open-source tracker to bypass Jira UI friction

1•chadders13•13m ago•0 comments

LiteLLM Python package compromised by supply-chain attack

https://github.com/BerriAI/litellm/issues/24512
4•theanonymousone•14m ago•0 comments

What Does Claude Need to Be My Social Media Manager?

https://cate.blog/2026/03/24/what-does-claude-need-to-be-my-social-media-manager/
1•xngbuilds•14m ago•0 comments

Show HN: AI agent got 237 rules from another agent, still made the same mistakes

https://github.com/getcalx/oss
3•spenceships•15m ago•0 comments

I think Anthropic's approach to data poisoning is solving from the wrong end

https://coloradochris.substack.com/p/why-i-think-anthropics-approach-to
2•czbond•16m ago•0 comments

We scanned 900 MCP configs on GitHub. 75% had security problems

https://orchesis.ai/blog/mcp-scan
1•driftnode•16m ago•0 comments

Show HN: Crawdad – Runtime security layer for autonomous AI agents

https://getcrawdad.dev
1•AndrewGS•18m ago•0 comments

Ask HN: $50 monthly budget, which coding models would you recommend now?

2•klueinc•18m ago•0 comments

'Work from home,' encourages the energy watchdog

https://www.theverge.com/science/897874/iea-fuel-gas-shortage-recommendations-work-from-home
1•abdelhousni•19m ago•0 comments

Is social media addictive? The science reveals what's at stake

https://www.scientificamerican.com/article/is-social-media-addictive-the-science-reveals-whats-at...
1•Brajeshwar•19m ago•0 comments

Vibe Coding: Programming for the rest of us?

https://numericcitizen.me/vibe-coding-programming-for-the-rest-of-us/
1•numericcitizen•20m ago•0 comments

Machine Learning: A First Course for Engineers and Scientists

http://smlbook.org/
2•teleforce•22m ago•0 comments

Show HN: Drop – Linux sandboxing for LLM agents and untrusted code

https://github.com/wrr/drop
1•mixedbit•22m ago•0 comments

OpenAI models answer an older prompt instead of the current one

https://www.vincentschmalbach.com/openai-models-answer-an-older-prompt-instead-of-the-current-one/
1•vincent_s•23m ago•0 comments

Welfare on Wheels: The Truth About the Supposed Truck Driver Shortage

https://reason.com/2026/03/24/welfare-on-wheels/
1•mhb•23m ago•0 comments