frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Ask HN: How can you trust your hardware?

1•moquilabs•1h ago
There's a widespread idea in the technical community that TPMs don't provide any security:

- https://news.ycombinator.com/item?id=37435450

- https://learn.omacom.io/2/the-omarchy-manual/50/getting-started?search=tpm#getting-started (see advice on tpm)

- NSA encourages we use it https://media.defense.gov/2024/Nov/06/2003579882/-1/-1/0/CSI-TPM-USE-CASES.PDF

But, TPMs have real use cases: - It theoretically prevents kernel level exploits extracting secrets.

- Projects like Qubes suggest using it to prevent evil maid attacks: https://doc.qubes-os.org/en/latest/user/hardware/system-requirements.html#recommended

BUT...

- It provides a weak level of device attestation from the manufacturer: https://blog.cloudflare.com/anchoring-trust-a-hardware-secure-boot-story/#uefi-attacks

- That cloudflare article suggests using AMD PSP which is equivalent to Intel ME that the NSA is know to request the disabling of https://stateofsurveillance.org/articles/technical/intel-management-engine-deep-dive/

So it seems like to really trust your hardware, you must depend on the vendor. For the vendor to send you the hardware, the hardware could be tampered with, so making it tamper resistant and using a burned in read-only cryptographic signature from the manufacturer. The fips 140 level 4 ibm processor is the closest equivalent I can find:

- https://www.ibm.com/docs/en/cryptocards?topic=4770-overview#ibm_4770_overview__title__7

- Then to trust the vendor, using an open source design with minimal attack surface is really the only option. Something like https://lowrisc.github.io/sonata-system/ based on https://opentitan.org/ and https://github.com/lowRISC/ibex seems to be the closest I can find.

Any thoughts on how to trust your hardware? I'm out of ideas...

Show HN: Ray Hosting – Topology-aware game server orchestrator made from scratch

https://ray-hosting.com/en-US
1•bardhyliis•38s ago•0 comments

Why All the PRs?

https://idiallo.com/blog/why-all-the-prs
1•firefoxd•1m ago•0 comments

Bring Siri AI to EU iPhone Users Safely

https://siri4eu.com
1•peterspath•4m ago•0 comments

The Fertile Void

https://d.glezos.com/the-fertile-void/
1•gtzi•6m ago•0 comments

Companies are scrambling to curtail soaring AI costs

https://www.economist.com/business/2026/06/14/companies-are-scrambling-to-curtail-soaring-ai-costs
1•andsoitis•7m ago•0 comments

UK to announce Australia-style social media ban for teenagers

https://www.ft.com/content/e3b7be6f-99e7-42d2-a3bb-e400690c7bc0
1•mmarian•7m ago•1 comments

The Aeneid by Virgil (19B.C.E)

https://classics.mit.edu/Virgil/aeneid.html
1•andsoitis•9m ago•0 comments

Show HN: Pg-status – lightweight HTTP sidecar for PG master/replica discovery

https://github.com/krylosov-aa/pg-status
2•krylosov-aa•9m ago•0 comments

Claude Code Is Dead

https://claude-code-is-dead.vercel.app/
2•gidellav•10m ago•0 comments

Webxdc – Secure mini apps for chats

https://webxdc.org/
1•birdculture•16m ago•0 comments

Paul Krugman breaks down problems with SpaceX valuation [video]

https://www.youtube.com/watch?v=jqjcOs-N6a8
3•jethronethro•17m ago•0 comments

Is Musk the richest American ever now? No, except as a consumer

1•dfps•18m ago•0 comments

CoreAI_HTCE

https://github.com/miroaleksej/CoreAI_HTCE
1•CoreAi_HTCE•20m ago•0 comments

From AGI to ASI

https://arxiv.org/abs/2606.12683
1•artninja1988•23m ago•0 comments

Pilot and 11 skydiving passengers killed in Missouri plane crash

https://www.theguardian.com/us-news/2026/jun/14/butler-missouri-plane-crash
2•sva_•28m ago•0 comments

How to Build a Phyle

https://lasindias.net/indianopedia/How_to_build_a_phyle
1•rwl•30m ago•0 comments

What does high effort mean when AI has made everything low effort?

2•foxtrot8672•30m ago•2 comments

I built a free tool that tells you if an LLM will run on your GPU

https://www.slopesome.com
1•NexAIGuy•30m ago•0 comments

Leave It to Beaver: Everything is bigger at Buc-ee's

https://thebaffler.com/outbursts/leave-it-to-beaver-wilder
1•NaOH•35m ago•0 comments

Virology Research Is Not a Crime

https://rasmussenretorts.substack.com/p/virology-research-is-not-a-crime
3•hn_acker•39m ago•1 comments

Abandoned and Little-Known Airfields

https://airfields-freeman.com/
2•wizardforhire•39m ago•0 comments

2026 Global Peace Index [pdf]

https://www.visionofhumanity.org/wp-content/uploads/2026/06/Global-Peace-Index-2026-Report.pdf
3•simonebrunozzi•40m ago•0 comments

KPMG report on AI found riddled with AI hallucinations

https://www.cityam.com/kpmg-report-on-ai-found-riddled-with-ai-hallucinations/
4•chrisjj•40m ago•1 comments

Compute 'S Atari ST Reference Books – By Paul Lefebvre

https://www.goto10retro.com/p/computes-atari-st-reference-books
2•rbanffy•41m ago•0 comments

Ask HN: I am a junior CS and math major. I have no hope for SWE or math. Advice?

1•jidhn•43m ago•6 comments

Seer – an Ollama workspace where two models build and review code

https://manticthink.com/c/a57jfwt
1•SEERai•46m ago•0 comments

Show HN: I hate typing continue once my CC quota resets

https://github.com/softcane/cc-session-recover
1•pradeep1177•46m ago•0 comments

Frona v2026.6.0 – self-hosted personal AI assistant

https://github.com/fronalabs/frona/releases/tag/v2026.6.0
1•syncerx•46m ago•0 comments

Itty Bitty Mosquito Committee

https://www.ittybittymosquitocommittee.org
1•mlinksva•46m ago•0 comments

Chaosnet

https://tumbleweed.nu/r/lm-3/uv/amber.html
23•RGBCube•50m ago•1 comments