frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Start all of your commands with a comma (2009)

https://rhodesmill.org/brandon/2009/commands-with-comma/
289•theblazehen•2d ago•95 comments

Software Engineering Is Back

https://blog.alaindichiappari.dev/p/software-engineering-is-back
20•alainrk•1h ago•10 comments

Hoot: Scheme on WebAssembly

https://www.spritely.institute/hoot/
34•AlexeyBrin•1h ago•5 comments

Reinforcement Learning from Human Feedback

https://arxiv.org/abs/2504.12501
14•onurkanbkrc•1h ago•1 comments

OpenCiv3: Open-source, cross-platform reimagining of Civilization III

https://openciv3.org/
717•klaussilveira•16h ago•217 comments

The Waymo World Model

https://waymo.com/blog/2026/02/the-waymo-world-model-a-new-frontier-for-autonomous-driving-simula...
978•xnx•21h ago•562 comments

Vocal Guide – belt sing without killing yourself

https://jesperordrup.github.io/vocal-guide/
94•jesperordrup•6h ago•35 comments

Omarchy First Impressions

https://brianlovin.com/writing/omarchy-first-impressions-CEEstJk
11•tosh•1h ago•8 comments

Making geo joins faster with H3 indexes

https://floedb.ai/blog/how-we-made-geo-joins-400-faster-with-h3-indexes
138•matheusalmeida•2d ago•36 comments

Unseen Footage of Atari Battlezone Arcade Cabinet Production

https://arcadeblogger.com/2026/02/02/unseen-footage-of-atari-battlezone-cabinet-production/
74•videotopia•4d ago•11 comments

Ga68, a GNU Algol 68 Compiler

https://fosdem.org/2026/schedule/event/PEXRTN-ga68-intro/
16•matt_d•3d ago•4 comments

What Is Ruliology?

https://writings.stephenwolfram.com/2026/01/what-is-ruliology/
46•helloplanets•4d ago•46 comments

Show HN: Look Ma, No Linux: Shell, App Installer, Vi, Cc on ESP32-S3 / BreezyBox

https://github.com/valdanylchuk/breezydemo
242•isitcontent•16h ago•27 comments

Monty: A minimal, secure Python interpreter written in Rust for use by AI

https://github.com/pydantic/monty
242•dmpetrov•16h ago•128 comments

Cross-Region MSK Replication: K2K vs. MirrorMaker2

https://medium.com/lensesio/cross-region-msk-replication-a-comprehensive-performance-comparison-o...
4•andmarios•4d ago•1 comments

Show HN: I spent 4 years building a UI design tool with only the features I use

https://vecti.com
344•vecti•18h ago•153 comments

Hackers (1995) Animated Experience

https://hackers-1995.vercel.app/
510•todsacerdoti•1d ago•248 comments

Sheldon Brown's Bicycle Technical Info

https://www.sheldonbrown.com/
393•ostacke•22h ago•101 comments

Show HN: If you lose your memory, how to regain access to your computer?

https://eljojo.github.io/rememory/
309•eljojo•19h ago•192 comments

Microsoft open-sources LiteBox, a security-focused library OS

https://github.com/microsoft/litebox
361•aktau•22h ago•187 comments

An Update on Heroku

https://www.heroku.com/blog/an-update-on-heroku/
437•lstoll•22h ago•286 comments

The AI boom is causing shortages everywhere else

https://www.washingtonpost.com/technology/2026/02/07/ai-spending-economy-shortages/
32•1vuio0pswjnm7•2h ago•31 comments

PC Floppy Copy Protection: Vault Prolok

https://martypc.blogspot.com/2024/09/pc-floppy-copy-protection-vault-prolok.html
73•kmm•5d ago•11 comments

Was Benoit Mandelbrot a hedgehog or a fox?

https://arxiv.org/abs/2602.01122
26•bikenaga•3d ago•13 comments

Dark Alley Mathematics

https://blog.szczepan.org/blog/three-points/
98•quibono•4d ago•22 comments

How to effectively write quality code with AI

https://heidenstedt.org/posts/2026/how-to-effectively-write-quality-code-with-ai/
278•i5heu•19h ago•227 comments

Female Asian Elephant Calf Born at the Smithsonian National Zoo

https://www.si.edu/newsdesk/releases/female-asian-elephant-calf-born-smithsonians-national-zoo-an...
43•gmays•11h ago•14 comments

I now assume that all ads on Apple news are scams

https://kirkville.com/i-now-assume-that-all-ads-on-apple-news-are-scams/
1088•cdrnsf•1d ago•469 comments

Understanding Neural Network, Visually

https://visualrambling.space/neural-network/
312•surprisetalk•3d ago•45 comments

Delimited Continuations vs. Lwt for Threads

https://mirageos.org/blog/delimcc-vs-lwt
36•romes•4d ago•3 comments
Open in hackernews

Passing the Torch – My Last Root DNSSEC KSK Ceremony as Crypto Officer 4

https://technotes.seastrom.com/2025/11/23/passing-the-torch.html
72•greyface-•2mo ago

Comments

shruubi•2mo ago
Not sure how geographically diverse it is to have two "highly secure sites" on the same continent.
ggm•2mo ago
Several people either in this circuit or close by made submissions to this effect to ICANN recently.

It's very hard to get traction on this story because there is a lot of "don't prod the bear" regarding things ICANN can and should ask Department of State about, and things which really have moved into "self managed, independent international body" space. The reason there are two HSM east and west coast was because of this kind of national-strategic sensitivity. It would be a low bar (only money) decision to duplicate the investment in Singapore and Geneva, two locations which ICANN has existing investment in, with good secure facilities and accepted by the wider public as "neutral" points.

When the KSK ceremonies started up, several people also pointed out that this "diverse locations" thing was a bit hokey. The response above is my re-write of the kinds of things said to me, at the time. If somebody wants to deny State or any other US federal agency influenced the decision I have no formal proof.

I should add as a declaration of interest I was at Rob's goodbye KSK event, I am a TCR, and I made such a submission this year. I have not received any indication it was understood or read, despite asking for some acknowledgement, but the process wheels in an agency like ICANN run to their own time.

tptacek•2mo ago
What would "poking the bear" do here? What's the risk?
ggm•2mo ago
The risk is being told no, and inviting dissent into the independence of ICANN. Not asking, means no risk of being told "no, you do as you're told" which would endanger the whole 3 legged stool. the GAC would immediately question the assumption the US government had that level of signoff, the money flows and lawyers would fire up, it would be come a shitstorm in a teacup.

The least likely outcome of asking the department of state if ICANN is "permitted" to add an HSM outside the USA, is a positive answer.

The most likely path to doing it, is not to assume you have to ask.

tptacek•2mo ago
Interesting. Thanks!
ggm•2mo ago
It's my personal opinion from beer convos with people in the circuit. As I said I have no firm proofs and you should hedge belief in this by the lack of verifyable facts.
jacquesm•2mo ago
Don't we have the '98 DNS ROOT incident as a nice example of what could happen when the bear gets poked?
ggm•2mo ago
Yes, but we're a long way down "our hands are off it's ICANN now". The exception might be DNSSEC and the verisign contract continuance. I have no complaint against verisign, far from it: their staff are excellent and they are amazingly diligent and risk averse.

But at a contractual level you could ask is there another company which could tender to operate the root publication function, and meet all stakeholder requirements? And, could that company be legally constituted outside the USA?

jacquesm•2mo ago
CERN?

Given that they contributed one of the key components that made the internet into the success that it is as well as being internationally respected.

ggm•2mo ago
Possibly. Ex CERN staff have indicated they were dismayed when the address management function went elsewhere in Europe. I know people both sides of this divide, it's ancient history in some ways.

I worked in another RIR. I still contract there.

dc396•2mo ago
Asking the US Dept. of State would almost certainly result in "huh?" from the folks there. The part of the USG that plays in the ICANN kiddie pool is US Dept. of Commerce (NTIA) and they no longer have a veto on what ICANN does.

One of the issues is section 4.2 of the IANA Naming Functions contract:

"[...] Contractor must be able to demonstrate that all primary operations and systems will remain within the United States (including the District of Columbia). [...]"

The Key Management Facilities are considered a part of the "primary operations and systems". IIRC, this clause was included in order to move the transition of the IANA functions forward in the face of some resistance within the US government.

Until that bit of legalese is revised, there will be no movement on creating a non-US key management facility. I believe changing the IANA Functions contract requires the Customer Standing Committee. As far as I am aware, no one within the CSC thought it worth the effort, i.e., "if it ain't broke, don't fix it".

Perhaps under the current US administration, that feeling as changed, but I haven't heard of any significant efforts in that regard.

charcircuit•2mo ago
There are security concerns having sites outside of America. I prefer keeping them only within my home country.
shmel•2mo ago
Equally there are security concerns having sites inside the US.
blibble•2mo ago
I'd rather have it somewhere stable like Switzerland

I suspect the only reason this hasn't been used as part of "deal leverage" is because the US regime doesn't know of its existence

monkey_monkey•2mo ago
The USA has shown, over the last 12 months, what a security-conscious country it is. The Defense Secretary's almost fanantical regard for messaging security should be held up as an object lesson for all future generations.
0x50000000•2mo ago
KMF-East is the Gegenvorschlag, or counterproposed key-management for the resolution of TCP/IP ICANN domain certifications.

DNSSEC requires cycling existing TCR for AES-256 symmetric encryptions or leveraging localised key share cycles.

teddyh•2mo ago
He should probably update his “About” page on his blog to remove ”I sign the DNSSEC root”, then.
tptacek•2mo ago
If you're looking to correct people about random parts of their website, perhaps it'd be a better idea to mail them than to comment here, where they're never going to see it. What was the point of this comment, other than mean-spiritedness?
teddyh•2mo ago
So you think I should e-mail somebody out of the blue, bothering them personally, to complain about their personal web site? Do you think that most people would react well if they recieved such a message?

HN is a quote well-known community. It is very common that people read the discussion on HN when their project or themselves are featured. And if they are that interested in what others think, they would then likely see comments such as mine. And if they are not the type to want to read comments, they won’t see my comment and therefore not be bothered by it.

I am baffled when trying to imagine why you think this is “mean-spirited”. On the contrary, this is the most respectful way to offer a minor suggestion that I can think of.

tptacek•2mo ago
Or just kept it to yourself.
teddyh•2mo ago
Why? This is a discussion forum, meant for comments.
gorgoiler•2mo ago
I enjoyed reading the ceremony log itself, a lot! It’s linked at the bottom of the article.

https://technotes.seastrom.com/assets/2025-11-23-passing-the...

Hypothetically, is there a way to know that those present were not under duress? I am guessing that duress is the only viable attack against the ceremony protocol — everyone present appears to play their part but, offscreen and visible only to the participants, are the villains and some hostages.