frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: I built a Bitcoin signing device where the private key is physical

https://frozensecurity.com/
1•frozensecurity•1h ago
The core problem I kept running into with hardware wallets: the private key exists as a persistent digital object inside a chip. It’s protected — but it exists. That’s the vulnerability. Protection fails; existence is structural. I built a different model. The private key is encoded as a geometric hole pattern in a titanium plate. A signing terminal reads the plate optically, derives the key transiently in volatile memory, signs the transaction, and discards everything. The plate doesn’t change. Nothing is stored. A few implementation details that might interest people here: The signing terminal uses two physically isolated MCUs — one handles communications, one handles signing. They are not software-separated. The communications MCU is physically disconnected during key derivation. This isn’t air-gapped in the usual sense; the isolation is enforced at the hardware layer, not the software layer. The key derivation follows BIP-39/BIP-32. The plate encodes the seed phrase as a geometric representation. The terminal reads the geometry, derives the entropy, derives the key, signs, clears volatile memory. The plate never changes state and has no electronic components. The threat model this addresses: persistent digital key at rest. Hardware wallet attacks — glitching, side-channel, physical decapping — all require the key to exist somewhere in the device. If it doesn’t exist, those attack surfaces don’t exist. The attack window is constrained to a single observable physical interaction, not an indefinite future. Patent application published: US 2026/0039478. Pre-orders open at frozensecurity.com. Happy to go deep on the architecture, the encoding scheme, or the threat model.

Ask HN: After three years of open source software, I can't stand it

https://github.com/drl990114/MarkFlowy
2•drl5•3m ago•0 comments

Adding custom webhooks to my Samsung smart ring

https://github.com/TheVellichor/SamsungOpenRing
1•_vellichor•11m ago•1 comments

Proposal for adding a useful pipe operator to JavaScript

https://github.com/tc39/proposal-pipeline-operator
1•jcbhmr•12m ago•0 comments

Review: The Wireless Cookbook

https://www.helpnetsecurity.com/2025/10/28/review-the-wireless-cookbook/
1•teleforce•13m ago•0 comments

Managing API keys and launching coding agents across providers

https://getaivo.dev
1•spirit23•14m ago•0 comments

What Happens When AI Stops Being Artificially Cheap

https://danielmiessler.com/blog/ai-stops-being-artificially-cheap
2•davikr•16m ago•0 comments

Using AI to inflate your ego

https://blog.avas.space/ai-ego/
1•davikr•16m ago•0 comments

Book Review: Building a Debugger

https://blogs.newardassociates.com/blog/2025/book-review-building-a-debugger.html
1•teleforce•17m ago•0 comments

Ask HN: What TLD would AI companies be using if .ai wasn't an option?

1•Cider9986•21m ago•0 comments

Coatue Projected $1.995T Valuation for Anthropic in 2030

https://www.newcomer.co/p/coatue-projected-1995-trillion-valuation
1•aanet•24m ago•0 comments

The Terrarium

https://www.lesswrong.com/posts/znbfRXHq285nS7NAh/the-terrarium
1•johnfn•25m ago•0 comments

Naga siren – song of the siren [video]

https://www.youtube.com/watch?v=Rs0vhQFIKx4&list=RDRs0vhQFIKx4
1•marysminefnuf•25m ago•0 comments

Cheese ingredients included in certain Hello Fresh brand meal kits recalled

https://recalls-rappels.canada.ca/en/alert-recall/cheese-ingredients-included-certain-hello-fresh...
1•gnabgib•27m ago•0 comments

Emerging Litigation Risks in Financing AI Data Centers Boom

https://www.quinnemanuel.com/the-firm/publications/client-alert-emerging-litigation-risks-in-fina...
2•pier25•27m ago•0 comments

National Design Studio

https://ndstudio.gov/
1•Cider9986•30m ago•0 comments

Show HN: Gravity doesn't track mass, it tracks waveform complexity

2•ordinarily•38m ago•0 comments

Easel is now an expression language (March 2026 update)

https://easel.games/blog/2026-mar-update
1•BSTRhino•38m ago•0 comments

Icons inside underlined links without text <span>ning

https://blades.ninja/css/link-icon/
1•anydigital•38m ago•1 comments

Gavin Newsom signs executive order to strengthen AI protections, responsible use

https://www.gov.ca.gov/2026/03/30/as-trump-rolls-back-protections-governor-newsom-signs-first-of-...
3•hentrep•38m ago•0 comments

Rec Room announces upcoming shutdown

https://blog.recroom.com/posts/schools-out-for-rec-room
2•someperson•39m ago•1 comments

Move fast and break things doesn't work in banking and finance

https://www.synctera.com/post/six-years-of-synctera-built-to-win
1•thatdrew•40m ago•0 comments

Geomys – a Gopher client for Macintosh 68K (2026)

https://github.com/ecliptik/geomys
1•rickcarlino•41m ago•0 comments

Mad Bugs: Vim vs. Emacs vs. Claude

https://blog.calif.io/p/mad-bugs-vim-vs-emacs-vs-claude
3•unacorner•43m ago•0 comments

Eleven Days

https://www.thewirechina.com/2026/03/29/eleven-days-part-i/
1•ilamont•43m ago•0 comments

Secretary Hegseth broker looked to buy defense fund before Iran attack

https://www.reuters.com/business/finance/us-defense-secretary-hegseths-broker-looked-buy-defense-...
6•inaros•45m ago•0 comments

VoE

https://github.com/dbuchacher/VoE
1•maxi_j309•47m ago•0 comments

Everyone is Lying to You for Money (trailer)

https://www.everyoneislying.com/trailer
2•ynac•48m ago•0 comments

Bullet used to kill Charlie Kirk did NOT match rifle allegedly used by suspect

https://www.dailymail.co.uk/news/article-15692625/Tyler-Robinson-bullet-rifle-match-Charlie-Kirk....
6•Bender•48m ago•1 comments

Show HN: Live map of SF fires and 911 calls – P25 radio decoded with AI

https://sf.monitorsthesituation.com
1•teocalin37•48m ago•0 comments

Private Credit Is Reeling, but New Rule May Allow It into 401(k)s

https://www.wsj.com/personal-finance/retirement/private-credit-is-reeling-but-new-rule-may-allow-...
1•petethomas•49m ago•2 comments