frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Could Alzheimer's Disease Begin in the Nerves Rather Than the Brain?

https://neurosciencenews.com/alzheimers-peripheral-nervous-system-30540/
1•bookofjoe•46s ago•0 comments

Show HN: TokenLight – Move Lights in a Photograph in 3D

https://vrroom.github.io/tokenlight/
1•matroid•4m ago•0 comments

Service Level Disagreement

https://insights.euclid.vc/p/service-level-disagreement-ai-services-versus-software
1•warthog•4m ago•0 comments

Migrating from DigitalOcean to Hetzner: From $1,432 to $233 With Zero Downtime

https://isayeter.com/posts/digitalocean-to-hetzner-migration/
1•yusufusta•4m ago•0 comments

Major e-bike company set to launch semi-solid-state battery electric bicycles

https://electrek.co/2026/04/17/major-e-bike-company-set-to-launch-semi-solid-state-battery-electr...
1•Bender•6m ago•0 comments

North America just got its first new kind of lithium refinery

https://electrek.co/2026/04/17/north-america-just-got-its-first-new-kind-of-lithium-refinery/
1•Bender•8m ago•0 comments

Quantum 'Jamming' Explores the Fundamental Principles of Nature

https://www.quantamagazine.org/quantum-jamming-explores-the-truly-fundamental-principles-of-natur...
1•ibobev•8m ago•0 comments

Tourists Try to Ride Elk Which Are Taking over Beaches in Coastal Oregon Town

https://cowboystatedaily.com/2026/04/16/tourists-sometimes-try-to-ride-elk-taking-over-beaches-in...
1•Bender•8m ago•0 comments

The Mystery of Rennes-Le-Château, Part 4: Non-Fiction Meets Fiction

https://www.filfre.net/2026/04/the-mystery-of-rennes-le-chateau-part-4-non-fiction-meets-fiction/
1•ibobev•9m ago•0 comments

The Abstraction Fallacy: Why AI Can Simulate but Not Instantiate Consciousness

https://deepmind.google/research/publications/231971/
1•jonbaer•9m ago•0 comments

An LLM becomes more coherent as we train it

https://www.gilesthomas.com/2026/04/how-an-llm-becomes-more-coherent-over-training
1•ibobev•9m ago•0 comments

Hello old new "Projects" directory

https://blog.tenstral.net/2026/04/hello-projects-directory.html
2•LorenDB•11m ago•1 comments

Working hurts less than procrastinating, we fear the twinge of starting (2011)

https://www.lesswrong.com/posts/9o3QBg2xJXcRCxGjS/working-hurts-less-than-procrastinating-we-fear...
1•davikr•14m ago•0 comments

The Abstraction Fallacy: Why AI Can Simulate but Not Instantiate Consciousness [pdf]

https://philpapers.org/archive/LERTAF.pdf
1•danielmorozoff•16m ago•0 comments

The Impact of New Housing Supply on the Distribution of Rents

https://www.journals.uchicago.edu/doi/10.1086/733977
1•littlexsparkee•18m ago•0 comments

Silicon Valley Is Turning into Its Own Worst Fear (2017)

https://www.buzzfeednews.com/article/tedchiang/the-real-danger-to-civilization-isnt-ai-its-runaway
1•nz•19m ago•0 comments

Adventure Travel in Costa Rica Done Right

https://johnquam.substack.com/p/adventure-travel-in-costa-rica-done
1•headmonkey•19m ago•0 comments

How to Fine-Tune a Reasoning Model?

https://huggingface.co/papers/2604.14164
1•Anon84•21m ago•0 comments

Show HN: Readox – Turn web pages and PDFs into a playable reading queue

https://readox.ai/
2•siegers•23m ago•0 comments

When Students Believe That Personal Characteristics Can Be Developed (PDF, 2012)

https://thrive.arizona.edu/sites/default/files/Mindsets%20That%20Promote%20Resilience%20When%20St...
1•lucidplot•25m ago•0 comments

Science Home

https://sah.borca.ai/
1•parksb•25m ago•0 comments

Trump's reversal on day care upends a bipartisan push to lower costs

https://www.washingtonpost.com/politics/2026/04/15/trump-childcare-abandoned-pledge/
1•doctaj•26m ago•0 comments

Failed Companies Are Selling Old Slack Chats and Email Archives to Train AI

https://gizmodo.com/failed-companies-are-selling-old-slack-chats-and-email-archives-to-train-ai-2...
2•01-_-•26m ago•1 comments

Babies Born from Dead Parents Will Increase with New Tech

https://www.404media.co/babies-born-from-dead-parents-will-increase-with-new-tech-are-we-ready/
1•salkahfi•31m ago•0 comments

Euro-Office: License compliance and what open source means

https://nextcloud.com/blog/euro-office-license-compliance-and-what-open-source-means/
1•maxloh•35m ago•0 comments

LingBot-Map: Geometric Context Transformer for Streaming 3D Reconstruction

https://github.com/Robbyant/lingbot-map
2•flux_w42•36m ago•0 comments

Modern Spectacle

https://px.philosopheasy.com/architecture-illusion-soral-media-control/
1•obscureline•36m ago•0 comments

Isaac Asimov: The Last Answer (1980)

https://www.highexistence.com/the-last-answer-short-story/
1•genphy1976•37m ago•0 comments

Client-Led Game/Simulation Projects' Effects on Motivation and Career Readiness

https://dl.acm.org/doi/book/10.1145/3786353?af=R
1•salkahfi•38m ago•0 comments

Generative Drinker: An Idea for Improving Wine Compatibility

https://hajo.me/blog/2026/04/18/generative-drinker-an-idea-for-improving-wine-compatibility/
1•fxtentacle•39m ago•0 comments
Open in hackernews

Tell HN: GitHub Apps – Private key is not private

https://github.com/login
1•time4tea•1h ago

Comments

time4tea•1h ago
When you create an app in GitHub - you are required to create a private key so that you can sign requests on behalf of your app.

Sounds reasonable.

However... to create the private key, they require you to download the private key from them. Which means they have it. So ANY APP on GitHub can be impersonated by GitHub as they have the key material for every app... so what is the point?

Am I losing my mind?

edit: i can't edit the link - it should be https://github.com/settings/apps

codingdave•1h ago
Well, first of all, them giving you the key doesn't prove they kept it. From all I know, it is discarded, not stored.

But even if they do keep it, github owns their own platform. If they wanted to do shit with your app, they wouldn't need the key for that, they could just skip any security that required the key. At some point, you either trust github to securely host your stuff, or you don't.

In any case, keys are for protection from 3rd parties and an audit trail of who did what, neither of which are invalidated by github having access to their own platform.

time4tea•11m ago
Hmm, not sure - the entire point of this sort of thing is that nobody should ever have your private key material. Whether they say they discard it is immaterial, they have had it, so they could use it, and then as far as everyone is concerned, they are you.

Because the key is sent via the web, anyone in the way can see it. In lots of companies, trusts are manipulated so that the content is visible to intermediate proxies.

With a private key that has been given to you by somebody else, it is possible to repudiate any transaction that was made with the key. Its not so much as they could skip any security - its that if they have the key, they don't have to.

keys are protection from anyone, and an audit trail isn't useful when its possible to forge/repudiate literally anything.

imagine if your card pin was also written down in the card factory - you'd be suspicious that anyone can withdraw money from your account - and the bank would say 'ah but only you know it'. In fact this did happen - the bank was only issuing 3 different pin numbers.