frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Microservices Are a Tax Your Startup Probably Can't Afford

https://nexo.sh/posts/microservices-for-startups/
112•nexo-v1•3h ago•63 comments

Google to Back Three New Advanced Nuclear Projects

https://www.esgtoday.com/google-to-back-three-new-advanced-nuclear-projects/
144•aburan28•2h ago•146 comments

Using NASA’s SMAP satellite to detect L-band interference

https://radioandnukes.substack.com/p/how-dare-you-transmit-at-14-ghz
249•c16•7h ago•50 comments

How to Harden GitHub Actions: The Unofficial Guide

https://www.wiz.io/blog/github-actions-security-guide
134•moyer•2d ago•39 comments

Imagineers defend new Walt Disney robot

https://www.yahoo.com/entertainment/articles/keeps-walt-alive-medium-pioneered-170000117.html
26•rmason•2d ago•17 comments

Ask HN: What are good high information density UIs (screenshots, apps, sites)

175•troupo•3h ago•124 comments

Yes, the Apple II MouseCard IRQ Is Synced to the VBL

https://www.colino.net/wordpress/en/archives/2025/05/08/yes-the-apple-ii-mousecard-irq-is-synced-to-the-vbl/
49•mmphosis•4h ago•15 comments

Mycoria is an open and secure overlay network that connects all participants

https://mycoria.org/
273•doener•10h ago•106 comments

How Obama’s BlackBerry got secured (2013)

https://www.electrospaces.net/2013/04/how-obamas-blackberry-got-secured.html
124•lastdong•3d ago•44 comments

How linear regression works intuitively and how it leads to gradient descent

https://briefer.cloud/blog/posts/least-squares/
272•lucasfcosta•3d ago•75 comments

Will protein design tools solve the snake antivenom shortage?

https://www.owlposting.com/p/will-protein-design-tools-solve-the
28•sebg•4h ago•11 comments

20 years to give away virtually all my wealth

https://www.gatesnotes.com/home/home-page-topic/reader/n20-years-to-give-away-virtually-all-my-wealth
259•nrvn•2h ago•284 comments

Ty: A fast Python type checker and language server

https://github.com/astral-sh/ty
829•arathore•22h ago•264 comments

Artifact (YC W25) Is Hiring

https://www.ycombinator.com/companies/artifact-2/jobs/8j2BXI0-forward-deployed-software-engineer
1•antonysamuel•4h ago

Using Coalton to Implement a Quantum Compiler

https://coalton-lang.github.io/20220906-quantum-compiler/
7•andsoitis•3d ago•0 comments

Mass spectrometry method identifies pathogens within minutes instead of days

https://phys.org/news/2025-05-mass-spectrometry-method-pathogens-minutes.html
102•pseudolus•2d ago•31 comments

Inheritance was invented as a performance hack (2021)

https://catern.com/inheritance.html
172•aquastorm•2d ago•179 comments

Huawei unveils laptop running self-developed HarmonyOS as Windows licence expire

https://www.scmp.com/tech/big-tech/article/3309569/huawei-unveils-first-laptop-running-self-developed-harmonyos-windows-licence-expires
41•ksec•2h ago•18 comments

Waiting for Postgres 18: Accelerating Disk Reads with Asynchronous I/O

https://pganalyze.com/blog/postgres-18-async-io
522•lfittl•1d ago•137 comments

QueryHub

https://www.queryhub.ai/blog/introducing-queryhub
10•joeharwood3•2h ago•4 comments

Heat stress mitigation by trees and shelters at bus stops

https://www.sciencedirect.com/science/article/pii/S136192092500063X
105•rntn•2d ago•92 comments

Mistral ships Le Chat – enterprise AI assistant that can run on prem

https://mistral.ai/news/le-chat-enterprise
476•_lateralus_•1d ago•147 comments

June Huh dropped out to become a poet, now he’s won a Fields Medal (2022)

https://www.quantamagazine.org/june-huh-high-school-dropout-wins-the-fields-medal-20220705/
204•bpierre•18h ago•118 comments

Engineered adipocytes implantation suppresses tumor progression in cancer models

https://www.nature.com/articles/s41587-024-02551-2
17•richardboegli•1d ago•0 comments

Bridging the gap between keyword and semantic search with SPLADE (2024)

http://arcturus-labs.com/blog/2024/10/09/bridging-the-gap-between-keyword-and-semantic-search-with-splade/
17•softwaredoug•2d ago•2 comments

Open source Google Analytics replacement

https://github.com/rybbit-io/rybbit
339•samdung•22h ago•152 comments

Trump's NIH Axed Research Grants Even After a Judge Blocked the Cuts

https://www.propublica.org/article/trump-nih-cuts-transgender-research-grants
86•hn_acker•2h ago•47 comments

Samsung is paying $350M for audio brands B&W, Denon, Marantz and Polk

https://www.engadget.com/audio/samsung-is-paying-350-million-for-audio-brands-bowers--wilkins-denon-marantz-and-polk-131514754.html
203•thibautg•23h ago•288 comments

Extending a Language – Writing Powerful Macros in Scheme

https://mnieper.github.io/scheme-macros/README.html
70•textread•3d ago•4 comments

Create and edit images with Gemini 2.0 in preview

https://developers.googleblog.com/en/generate-images-gemini-2-0-flash-preview/
243•meetpateltech•1d ago•99 comments
Open in hackernews

How Obama’s BlackBerry got secured (2013)

https://www.electrospaces.net/2013/04/how-obamas-blackberry-got-secured.html
123•lastdong•3d ago

Comments

gnabgib•3d ago
(2013) Discussion at the time (83 points, 32 comments) https://news.ycombinator.com/item?id=6615066
Jaxkr•5h ago
> This would mean the White House Communications Agency has to carry such a secure base station wherever the president goes.

We used to take security so seriously.

Aloha•2h ago
The reality is that modern (meaning LTE) public networks are more secure today, than they have been, its also trivial to bring an LTE base station with you now - with the hardware at this point being no more complex than a controller driven wifi network.
evanjrowley•3d ago
I remember encountering one of these secure gov blackberry setups approximately one decade ago. The contractor who managed it up had some deep institutional knowledge. He was probably going to do that one job for the rest of his career until retirement.
Jaxkr•5h ago
And now we have our top defense officials using a fork of Signal which sends copies of messages to a third party.

https://www.404media.co/mike-waltz-accidentally-reveals-obsc... http://archive.today/LyWDy

chme•5h ago
Not only that, but the software also contained login information to the AWS backend archive servers:

https://www.techspot.com/news/107792-hacker-breaches-telemes...

janice1999•4h ago
... the third party being run by a foreign 'former' spy whose country was being discussed in those messages.
bigfatkitten•5h ago
These days, NSA's Commercial Solutions for Classified program[1] addresses a lot of these sorts of secure mobility use cases.

The underlying design principle behind CSfC is that the CNSA algorithms[2], when properly implemented are good enough to protect information classified up to TOP SECRET on their own. However, there's still a risk of exposure due to broken implementations, active exploitation or operational error.

To mitigate this, CSfC's "capability packages" (reference architectures) typically use two or more cryptographic layers of different provenance to reduce the risk that a vulnerability in one layer could be used to compromise the whole solution. For a VPN for example, they will use two tunnels; an inner tunnel using a solution from one vendor, and an outer tunnel from another.

There are other considerations apart from cryptography. They also specify the use of "retransmission devices" (mifi routers, basically) in favour of native cellular capability, presumably to mitigate the risk of a cellular baseband exploit being used to compromise a classified handset.

[1] https://www.nsa.gov/Resources/Commercial-Solutions-for-Class...

[2] https://en.wikipedia.org/wiki/Commercial_National_Security_A...

NitpickLawyer•3h ago
> They also specify the use of "retransmission devices" (mifi routers, basically) in favour of native cellular capability

Yeah, this makes the most sense, there's no way they'd let a president's phone be connected to commercial networks. Tracking alone would be a huge issue, not to mention the plethora of ss7 abuses that can be done.

selkin•56m ago
s/they’d let/would have let/

According to a recent interview[0], the president has an uncontrolled phone (maybe in addition to other, approved devices).

[0] https://archive.ph/2025.05.07-050707/https://www.theatlantic...

dymk•24m ago
they’d’ve
mikestew•3m ago
From that linked article: “To this date, she doesn’t even know that I won the Presidency THREE times.”

Holee-shit. Time to start keeping him away from microphones.

miki123211•4h ago
It's so strange to me how little information there is on the internet about how the BlackBerry really worked.

Other phone OSes, both modern ones like iOS and Android, as well as ancient ones like Symbian or even the Nokia 3310 firmware, have their internals well described. All I could find about the BlackBerry was that it used some Java-based OS, but no detailed information about its architecture, conventions, file system layouts, security properties or technical capabilities seems to be available. The communications protocols are just as mysterious, especially on the phone-to-server side. I know it required some kind of carrier integration to work, which makes me think it wasn't just a bog-standard connection over TCP/IP, but I have no idea what it actually was.

There's some information in BlackBerry programming books, which can still be found in the "usual places", some old BlackHat presentations, which seem to mostly focus on the enterprise server component, as well as some company history and brief descriptions of the technical choices made in "Losing the Signal", but that's about it. Even Nintendo's OS is understood much more widely, despite Nintendo being much more secretive and litigious.

amaccuish•3h ago
Quite agree, I find it really sad. The most that is out there was about the BlackBerry Enterprise Server, but the docs were always light on details. And yes that one BlackHat presentation about SRP.

I'd love to know more about the GPRS side of things, how their NOCs were connected to carriers, etc.

gjsman-1000•2h ago
> despite Nintendo being much more secretive and litigious

Eh, kind of? Nintendo has never interfered with solely modding your Switch, or the tools to do so, and will not ban you for loading CFW. Install CFW, overclock your Switch, even cheat in offline games, no interference.

Their lines in the sand for years have been changing your profile image to something arbitrary (and possibly NSFW), installing a pirated game, cheating online, or tampering with system logs. That’s when the ban hammer hits; and the tools for doing those get targeted.

Nullabillity•1h ago
They were never particularly competent about it (from the technical side, anyway), but https://wiibrew.org/wiki/Homebrew_Channel#Changelog is a pretty sad/hilarious read.
Spooky23•2h ago
They shared information with large customers with NDA. They were old school telecom — very tight.

Everything traversed their network. It was a bonkers architecture that would not fly today. The other thing about that obscurity is it enabled all sorts of weird use cases. Because the devices were identified to the BlackBerry network, you could message without user assignment.

It was common for corporate and political people to use them for unaccountable, compartmentalized communications. You could build ad hoc networks of people without there a record of who was who, and periodically reshuffle the devices to add and remove people. It was basically Nextel DirectConnect for texting / “the wire” for corporate people.

dec0dedab0de•27m ago
I think most corporate blackberries were tied to an enterprise server that tracked everything they did.
numpad0•46m ago
? There are more private stuff in the world than what's public on the Internet. Naively believing that private parts must be the minor part and basically everything should be already on the WWW is pure arrogance.

Google paid a lot of effort a while back into putting up obsolete as hell 130nm Skywater PDK on the public 'net. I've seen people on social media describing their anxiety from just seeing some industry specific shapes and forms out in the open, despite knowing those files were thoroughly cleared for release and completely fine for anyone to see.

Reading up stuffs on WWW and thinking it should cover most of everything is like placing yourself in clothes of pre-war physicists who thought physics is all figured out like a sunny backyard except there's a tiny black pinhole in the sky called quantum physics that idiots are obsessed with. There's a whole universe(s) behind it.

schlauerfox•29m ago
We used to install the server-side exchange connector on windows small business server. It was an involved process to get working, but pretty reliable.

Also interesting is some comments from former RIM employee, turned woodworking youtuber https://www.youtube.com/watch?v=GLxjXP-XCJA matthias wandel

blamestross•4h ago
I'm increasingly of the belief that modern governments have lost all advantage in the space of security hardware and software. They only have OpSec and a monopoly on violence to leverage in order to have an improved security situation over the public sector.

They don't seem to be using that OpSec superiority effectively right now.

I work public-sector in supply chain security and I am terrified that the situation we currently have in the corporate world is actually the best there is.

relaxing•4h ago
Okay? What evidence do you base this on?
ceejayoz•4h ago
Photos of them using Signal on iPhones?
throwanem•4h ago
Is that because Signal is as good or because they refuse to listen to anyone telling them to stop using it? Not a serious question, I know it'll be a decade or three before it can be answered from open sources.

But of course I forgot, it wasn't really even Signal they were using...

NickC25•3h ago
> they refuse to listen to anyone telling them to stop using it

That's one of the reasons, yes. Their whole MO is "we have power, we are not accountable to anyone, fuck you"

throwanem•2h ago
Is it? I know that's how they insist on being read.
Spooky23•3h ago
That’s more about officials acting illegally avoiding accountability by shielding their communications from their government. (Of course there’s probably a backlog of foreign governments on those devices.)
blamestross•2h ago
I can only speculate based on publicly available information.

When a was in grad-school, "state level actors" were the boogeyman. You were told to just assume that everything would be compromised to them.

I ended up specializing in p2p systems (distributed hash tables, overlay networks, communication systems) and "State Level Actors" become "in scope" for me. Modern cryptography is focused on the capabilities of hypothetical computers and making radically more computational power required than is reasonable to expect of current human economies. Backdoors in the codebases for encryption is a fun hypothetical, but the level of scrutiny they are under would require a conspiracy beyond any i could imagine to hide.

Eclipse and Sybil attacks were the real threats. Those are Operational attacks, not Signals.

Now that I have spend a decade in the security industry in larger corporations. "State Level Actors" are entirely in the threat model. We don't talk about it explicitly, but these companies stand to loose globally if any one government compromised them. Government funded actors are assumed to be the primary threat. Supply chain attacks like XZ are the ones that scare us, the ones we might have missed. That came from superiority in operations not technical superiority. They actively pay me and a bunch of other people a LOT of money to actively detect and prevent issues like this.

The other side of the argument is a human organizational one. The story of this decade of military spending is outsourcing. Biden's Supply Chain Security EO and the new DoD software procurement requirements are bandaids on gaping wounds.

Even with it's massive defence spending budget, the TLAs couldn't keep up with the industry while also securing all its software. They have 3rd party dependencies too. Assuming that they don't just allways directly outsource.

And why bother? These companies have the entirety of human communications MITMed. Why bother with a complex secret system when a FISA warrant is cheaper and more efficient. PRISM(For attack) and TOR(For defense) stand out as successes of operational attacks. They don't need technological superiority.

I fully expect TLAs maintain an android fork and linux forks, but that is opsec for dependency management, not adding special sauce. The industry simply has more resources and more eyes on the problem than the government could ever afford.

The last part is simple "Brain Drain". The people who are really good at this generally don't want to work for the government and have done too many drugs to ever get clearance. Unless they have a lot of security engineer salaries in classified budgets they also can't afford us. Governments have direct agents that are underpaid and underskilled and they have working relationships with criminal organizations who work deniable offense for them.

Opsec is clearly their leverage-able resource, why not lean into it almost exclusively?

mrweasel•3h ago
> I'm increasingly of the belief that modern governments have lost all advantage in the space of security hardware and software.

What do you mean? Lost the advantage as in "commercial solutions are equally good or better" or as in they just don't use the options they have available because they are more cumbersome?

Quite frankly I'm starting to doubt if leaders of nations should be having electronic devices at their disposal. Take away their phones, laptops, social media access, anything online. Everyone would be better of.

blamestross•2h ago
In terms of technical abilities: - "commercial solutions are equally good or better"

The way governments can have an advantage is in where and how those services are managed. Events like "signalgate" scare me because it means we are not leveraging that effectively due to bad managers.

yapyap•3h ago
Someone listens to the 404media podcast
mschuster91•3h ago
> On March 16, 2016, AP reported that in February 2009, secretary of state Hillary Clinton also wanted a secured BlackBerry like the one used by Obama, but that NSA denied that request. A month later, Clinton began using a private server, located in the basement of her home, to exchange e-mail messages with her top aides through her regular, non-secure BlackBerry. Later it came out that this rather risky solution was also used for sensitive messages.

A good reminder how IT departments need to provide solutions that actually work and are accessible to everyone. If not, "shadow IT" will emerge, rather sooner than later.

And Clinton was Secretary of State, not some low level clerk.

bunabhucan•3h ago
And the lesson every us pol seems to have learned is "use signal, use protonmail."
mschuster91•3h ago
They're using Signal to circumvent the Presidential Records act - the US government nowadays has ample ways to officially and quickly communicate with each other, while being in compliance with recordkeeping and national secrets requirements.
dwood_dev•2h ago
That is what I assumed as well. In both the current and previous admins.

But as more details come out about the current admins use of signal, this appears to not be the case.

They are using a shitty third party patched version of signal specifically designed to archive messages.

Leaving aside the security issues with the version they are using and the lack of public facing policy, the use of a Signal variant that archives chats is a reasonable compromise.

Instead of walling off users, creating a barrier to use and therefore extensive bypassing of the security standards, they have met users where they are and provided them with what the user cannot distinguish from official signal. This allows them to interface internally and externally through signal, preserving records and maintaining a much better level of security than the other options.

This represents a huge breach of trust between external parties and government signal users, but most of the government signal users are probably completely unaware that it's being logged.

My issue is not that they are using Signal. I think it's one of the better options. My issue is that they use a shitty version of it when there should be an in house maintained version for government use.

jandrewrogers•1h ago
Use of Signal has been rife in Washington DC since COVID times.

During COVID they closed many of the secure facilities indefinitely. Building access was on a rotation, so many people couldn’t see or communicate with their counterparts for weeks or months unless their rotation intersected. The government had no plan for how to conduct classified business with their facilities closed for extended periods. It is in this milieu that Signal became established as an alternative way to communicate.

They required almost everyone to work at home without a plan for how that is supposed to work when most people don’t have a SCIF[0] in their house. As bad as it is that the US DoD converged on using Signal, there is an identical issue in many European countries with the pervasive use of WhatsApp for sensitive communication. It is a classic case of shadow IT taking over.

[0] https://en.wikipedia.org/wiki/Sensitive_compartmented_inform...

MattSayar•48m ago
Well, they're not even using Signal, but a wrapper that's less secure.

https://micahflee.com/tm-sgnl-the-obscure-unofficial-signal-...

setgree•26m ago
A friend who works for the FBI flagged this long ago as the origin story for Clinton's "but her emails!" woes. It's distinctly possible that if the NSA had just secured her Blackberry, there would never have been a president Trump. Funny how small things spiral out.

You might draw many possible lessons from this story, though. One is the lesson you draw, which is that the NSA should have secured her damn Blackberry. The second is that this was really about egos, and Clinton couldn't accept that she was less important, and deserved a less important phone, than Obama, so she went ahead anyway. A third is that if you want to be president someday, you can't cut corners, and you need to use whatever clunky tech the government gives you -- so that one day, you can be the boss, summon the head of the NSA into your office, and humiliate and then fire him in front of his peers. But Clinton didn't have that kind of patience: she had emails to send.

jabroni_salad•2h ago
this website also has some weirdly captivating articles about presidential desk phones in the sidebar.
traceroute66•2h ago
All seems rather cute when these days you can just chat about classified stuff with whoever you like on your presumably unsecured phone.

And then have an unsecured internet line connected to an unsecured computer in your Pentagon office[1]

[1] https://abcnews.go.com/Politics/hegseth-signal-app-connected...

tehjoker•58m ago
in fairness, since these guys are just doing war crime after war crime, it's a good thing if it leaks
yubblegum•50m ago
That does unfortunately add the element of incentive to win at all costs to the picture. c.f. PM of Israel.
VectorLock•1h ago
As a completely random aside the article mentions "This company was founded in October 2008 by W. Steven Garrett, who took the name from an item used in the 1986 computer game The Legend of Zelda." To my knowledge I don't think TLoZ had an item called a "genesis key." It has a "magic key" and the only references I could find for "the genesis key" on Google are a book that was published after the company was founded?
metadat•45m ago
Some dead linked content in TFA is resurrectable courtesy of archive.org (though I had to dig a bit, which is why I'm sharing):

Dubya's Sectera Edge, a BlackBerry-esque Ultra Secure PDA phone:

https://web.archive.org/web/20120922044930/http://www.gdc4s....

Product eventually deprecated in September, 2015:

https://web.archive.org/web/20150926124453/http://www.gdc4s....

The link finally died with a site redesign in Jan 2016:

https://web.archive.org/web/20160131082757/http://www.gdc4s....

Original (now deceased) link: http://www.gdc4s.com/sectera-edge-(sme-ped)-proddetail.html

P.s. The device was somewhat comically proportioned, with thick antenna and bezels, haha: https://gdmissionsystems.com/-/media/general-dynamics/cyber-...

A teardown and chip analysis would be interesting! Though I imagine these devices aren't easy to come by?