frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

JumpServer: Open-Source Privileged Access Management

https://github.com/jumpserver/jumpserver
13•neitsab•1h ago

Comments

denysvitali•52m ago
I will never understand why SSH in such tools isn't native but always via some weird web UI...

I used to work for a company who allowed SSH only after jumping through Citrix => RDP => Putty => Jumphost => Target server.

Incredibly painful, also considering that each layer had a different keymap

jasongill•7m ago
I've been in the industry for a long, long time, and I would say that use of bastion hosts ranks #2 on my list of things that tell me your environment is not secure (right behind "we use fail2ban to protect us" as the #1 clue).

I've bought a bunch of companies and seriously evaluated hundreds of them, and the ones where people had a bastion host set up commonly seemed to act as if it protected them from everything, to the point where they just stopped worrying about security otherwise.

It gives a false sense of security and makes people put their guard down - like "OK, we have everything secured behind the firewall and only people who can log in to the bastion host, so there's no need for firewall rules or policies on the servers inside our firewall perimeter". Which inevitably breaks down over time as things get opened up to the internet, employees come and go, etc.

I can't tell you the number of companies where I look at their setup and their bastion host itself is root owned - since those hosts are always being used (and are tied to everything so you can't easily reboot or replace them), and are considered nothing more than a "tool" that you rarely actually have to look at, they don't get updated nearly enough and are neglected.

Not saying that bastion hosts are a bad idea - but just like any easy to use, easy to forget, high risk part of the stack, they are often a sign of inexperience and neglect elsewhere in the architecture.

(Yes, I know that there are plenty of big companies that use jump boxes without issue, and this jumpserver product is different, but I'm specifically talking about the idea of having one little machine that is open to SSH and then you bounce off of that to get into the "secured" machines, and all of this just based on my own experience and may not reflect yours)

Show HN: Clockclear – 12 ephemeral tools that auto-delete

https://us.clockclear.com/
1•annrap1d•1m ago•0 comments

Disposable Chat System

https://nonconfirmed.com/app/chatza/
1•colenikol2•2m ago•0 comments

Solar outproduced coal in April but not on the grid

https://arstechnica.com/science/2026/06/solar-outproduced-coal-in-april-but-not-on-the-grid/
1•Bender•4m ago•0 comments

Perform DFU Restores on Apple Silicon Macs with Macvdmtool (2021)

https://www.bkurtz.io/posts/macvdmtool/
1•gregsadetsky•4m ago•0 comments

Suffocating mega heat dome to engulf 35 states as forecasters issue urgent alert

https://www.dailymail.com/sciencetech/article-15938463/mega-heat-dome-weather-alert.html
1•Bender•5m ago•0 comments

Supreme Court expands Trump's power over the federal bureaucracy

https://www.washingtonpost.com/politics/2026/06/29/supreme-court-expands-trumps-power-over-federa...
1•throw0101a•9m ago•2 comments

Comparison Between ATProto and Tim Berners-Lee's Solid Protocol

https://forum.solidproject.org/t/comparing-solid-to-atproto-pds/9461
1•xeonmc•10m ago•0 comments

Small Penetrator Instrument Concept for the Advancement of Lunar Surface Science

https://iopscience.iop.org/article/10.3847/PSJ/abda4f
1•rbanffy•10m ago•0 comments

Learn X in Y Minutes

https://learnxinyminutes.com/
1•skogstokig•13m ago•0 comments

Show HN: Turn documents into lip-synced video readers

https://shashekhar.github.io/screencastgen/demo-reader/
1•ShaShekhar•13m ago•0 comments

LinkedIn without lunatics is deeply weird

https://designcapitalpower.substack.com/p/linkedin-without-lunatics-is-deeply
3•domstatecraft•16m ago•1 comments

About the security content of iOS 26.5.2 and iPadOS 26.5.2

https://support.apple.com/en-us/127594
1•akyuu•16m ago•0 comments

Open-sourcing Revolut's talent system: How we built Europe's top tech company

https://twitter.com/Revolut/status/2071623149955805247
2•rzk•19m ago•0 comments

Title: Show HN: 10 Killer Game Apps – O(1) hash-table lookup for game logic

https://big.lain.technology/gameapps/
1•glyph_os•21m ago•1 comments

California Leaders Agree to $351B Budget, Software Tax

https://www.bloomberg.com/news/articles/2026-06-27/california-leaders-agree-to-351-billion-budget...
3•rndsignals•23m ago•0 comments

The (real) dead economy theory

https://pluralistic.net/2026/06/17/its-the-stupid-economy-stupid/#trillionairitis
1•momentmaker•23m ago•0 comments

Show HN: Entity Event Matrix on any topic

https://reloadium.com/reloadium-investigations/
1•julienreszka•25m ago•0 comments

Show Up in Person 8:30 Am Tuesday in Sacramento to Save 3D Printing [video]

https://www.youtube.com/watch?v=vSU6QZO_rHM
1•jshprentz•26m ago•0 comments

Evals: The strategic IP that will define the next era of AI

https://twitter.com/GarrettLord/status/2068754262440767500
2•gmays•26m ago•1 comments

Segmenting Robot Video into Actionable Subtasks

https://macrodata.co/blog/annotating-robot-video-subtasks
1•tomaspduarte•30m ago•0 comments

A.I. 'Employees' Might Disrupt Work in Unexpected Ways

https://www.nytimes.com/2026/06/29/business/artificial-intelligence-workplace-consequences.html
4•speckx•32m ago•0 comments

Announcing .self: A New Top-Level Domain Designed to Support Self-Hosting

https://hccf.onmy.cloud/2026/06/21/reclaiming-our-digital-selves-hccfs-vision-for-a-human-centere...
5•HumanCCF•33m ago•2 comments

How the first solo-founder unicorn gets built

https://www.thisandthat.chat/blog/how-the-first-solo-founder-unicorn-gets-built/
1•jreynar•34m ago•1 comments

The Richest Country Is Pretty Mid Now [video]

https://www.youtube.com/watch?v=4FZy1lBNykA
6•onemoresoop•36m ago•0 comments

Video compression takes advantage of your eyes

http://stefano.petrilli.xyz/how-video-compression-takes-advantage-of-your-eyes/
2•stefanopetrilli•39m ago•0 comments

Zero Mostel's Testimony Before the Committee on Un-American Activities

https://www.nypl.org/events/exhibitions/galleries/literature-and-film/item/17519
1•kayo_20211030•40m ago•1 comments

Asymmetric Quantization: Near-Lossless Retrieval with 97% Storage Reduction

https://www.mixedbread.com/blog/asymmetric-quant
1•breadislove•41m ago•0 comments

Microsoft worker emails colleagues about company's support for genocidal Israel

https://www.thecanary.co/global/world-analysis/2026/06/26/microsoft-worker-emails/
12•DeusExMachina•41m ago•0 comments

AI has lots of people digging out their iPods

https://news.harvard.edu/gazette/story/2026/06/ai-has-lots-of-people-digging-out-their-ipods/
2•gnabgib•43m ago•0 comments

The Billionaires' Vagina Club

https://www.newyorker.com/magazine/2026/07/06/the-billionaires-vagina-club
4•mitchbob•46m ago•1 comments