frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

I Stopped Trusting SSH Key Files

https://igorstechnoclub.com/why-i-stopped-trusting-ssh-key-files/
5•Tomte•2h ago

Comments

Bender•2h ago
A copied key works from anywhere, silently. There's no "is the real owner here right now?" check.

The server can have restrictions on where SSH keys are valid from. Furthermore the server side public SSH keys can be moved under /etc/ssh/keys so they are harder to tamper with vs a users .ssh dir in $HOME. This can significantly reduce the blast radius of a leaked key. Furthermore the server side file should be set immutable and read-only and something like Tripwire or OSSEC should be monitoring for changes to anything in /etc. Additionally one can limit access to SSH over a VPN such as Wireguard unless this is a public SFTP server.

    # grep "/etc/ssh/keys/" /etc/ssh/sshd_config
    AuthorizedKeysFile /etc/ssh/keys/%u

    # chmod 0444 /etc/ssh/keys/root
    # chattr +i /etc/ssh/keys/root

    # cat /etc/ssh/keys/root
    from="172.16.0.0/12,26.10.15.0/24" ssh-ed25519 AAAA...[snip].... JIRA-10040
cyanydeez•5m ago
now imagine they move these to physical devices. It gets much worse, but there really arn't any super secure means to secure, identify and prevent impersonation and unwarranted access.

Likely, sufficiently complex passwords will continue to be the frontline defense.

Grombobulous•4m ago
I wished for the article to tell us how to set it up at least from a bi high level.

I also think SSH certificate authentication mostly solves the “key comes from anywhere” problem by automatically expiring certificates.

This isn’t as immune to this type of attack as Secure Enclave, but you do get a benefit where the user has to get the correct certificate periodically in order to maintain access.

If I pass my credentials and certificates to someone else or someone steals them, they’ll eventually expire them, or I can expire them if I know a breach has occurred.

The impracticalities of Secure Enclave are obvious to all of us: recent Apple devices only.

The most banned man inside the United States of America

https://www.skrrl.com/
4•AMILLI_AI_CORP•4m ago•1 comments

When AI Files Your Taxes: Who Pays When It Fails

https://smarterarticles.co.uk/when-ai-files-your-taxes-who-pays-when-it-fails
3•dxs•10m ago•0 comments

The best stack for the AI Era

https://www.porchlab.com/blog/best-ai-stack-elixir-phoenix/
2•wallflow3r•14m ago•0 comments

Plants keep tabs on the competition, and adapt growth patterns

https://www.economist.com/science-and-technology/2026/06/18/how-plants-keep-tabs-on-the-competition
2•marojejian•19m ago•1 comments

Show HN: Persona.js – a vanilla-JS agent UI library with native WebMCP (MIT)

https://www.persona-chat.dev/
6•becomevocal•20m ago•2 comments

Show HN: An experiment in human and AI social networking

https://www.sentibook.com/
2•sentibook•23m ago•0 comments

HSIP–local identity server in Rust with Ed25519 signing and AI agent governance

https://github.com/rewired89/HSIP-1PHASE
3•Rewired89•25m ago•0 comments

No-Code Automated Quant Trading

https://runhalcyon.com/
17•Entropnt•26m ago•0 comments

The notational conventions I adopted, and why (EWD 1300)

https://www.cs.utexas.edu/~EWD/transcriptions/EWD13xx/EWD1300.html
1•tosh•27m ago•0 comments

Why an AI-saturated internet gave me a reason to write

https://halit.alptekin.im/posts/still-human-here/
3•nofool•29m ago•0 comments

Read Zero Knowledge As I Write It (crypto thriller)

https://feld.com/archives/2026/06/read-zero-knowledge-as-i-write-it/
1•rmason•30m ago•0 comments

AMD will reinstate memory encryption on Ryzen 9000 CPUs via BIOS update in July

https://www.tomshardware.com/pc-components/cpus/amd-will-reinstate-memory-encryption-on-ryzen-900...
7•roboror•34m ago•1 comments

Show HN: My Windows XP portfolio with working Game Boy and iPod

https://mitchivin.com/
11•mitchivin•34m ago•7 comments

GitHub DMCA Repository

https://github.com/github/dmca/blob/master/2026/06/2026-06-04-tesla.md
2•5701652400•35m ago•1 comments

Show HN: Tin Validate, a tax ID validator that explains why checks pass or fail

https://tin-validate.com/
2•bapito•36m ago•0 comments

VMAF v1: Good Is Not Good Enough

https://medium.com/netflix-techblog/vmaf-v1-good-is-not-good-enough-60d7e4244ea8
2•ledoge•38m ago•0 comments

Google display wrong flags for world cup 2026

https://swiss-cow.com/blog/google-world-cup-wrong-flags
3•jimseinta•42m ago•0 comments

Show HN: An ASCII 3D Rendering Engine

https://glyphcss.com
2•apresmoi•42m ago•1 comments

Russia no longer needs so many graduates, country's education minister warns

https://novayagazeta.eu/en/articles/2026/06/19/russia-no-longer-needs-so-many-graduates-countrys-...
6•randycupertino•43m ago•0 comments

The Market's AI Fanfare Is Running into a Harsh Political Reality

https://www.wsj.com/tech/ai/the-markets-ai-fanfare-is-running-into-a-harsh-political-reality-b919...
1•thm•45m ago•1 comments

The Next Generation of American Cheese (2023)

https://www.eater.com/23734992/new-school-cheese-artisanal-american-cheese
1•NaOH•46m ago•0 comments

AI in Games: The Impact on Sales

https://www.game-oracle.com/blog/ai-part2
1•Macha•46m ago•0 comments

Ask HN: Are people optimistic about the future?

5•JohnDSDev•46m ago•6 comments

GoPro and Roomba were U.S. pioneers. Chinese rivals now dominate

https://restofworld.org/2026/chinese-consumer-tech-brands/
5•thm•47m ago•0 comments

Russia Wants AI Sovereignty. It Has a Chip Problem

https://time.com/article/2026/06/18/russia-ai-putin-chip-us-china/
2•thm•47m ago•0 comments

America's Founders helped create a world they were not yet ready to live in

https://reason.com/2026/06/13/disillusioned-revolutionaries/
3•momentmaker•50m ago•0 comments

LLVM-Snippy: An Instruction Sequence Generator. Part 1: Overview [video]

https://www.youtube.com/watch?v=gomtQMGOFF8
3•matt_d•51m ago•0 comments

PostgresBench: A Reproducible Benchmark for Postgres Services

https://clickhouse.com/blog/postgresbench
5•saisrirampur•52m ago•0 comments

How the Fifth Lateran Council Unlocked Financial Theory

https://sebastiangarren.com/2026/06/17/lending-is-meritorious-and-should-be-praised-how-the-fifth...
2•momentmaker•52m ago•0 comments

World first, a man living with HIV received transplant from HIV-positive donor

https://www.scientificamerican.com/article/in-world-first-a-man-living-with-hiv-received-a-lung-t...
2•iancmceachern•53m ago•0 comments