frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

France's homegrown open source online office suite

https://github.com/suitenumerique
469•nar001•4h ago•224 comments

British drivers over 70 to face eye tests every three years

https://www.bbc.com/news/articles/c205nxy0p31o
156•bookofjoe•2h ago•137 comments

Start all of your commands with a comma (2009)

https://rhodesmill.org/brandon/2009/commands-with-comma/
447•theblazehen•2d ago•161 comments

Leisure Suit Larry's Al Lowe on model trains, funny deaths and Disney

https://spillhistorie.no/2026/02/06/interview-with-sierra-veteran-al-lowe/
33•thelok•2h ago•2 comments

Software Factories and the Agentic Moment

https://factory.strongdm.ai/
33•mellosouls•2h ago•27 comments

Hoot: Scheme on WebAssembly

https://www.spritely.institute/hoot/
93•AlexeyBrin•5h ago•17 comments

OpenCiv3: Open-source, cross-platform reimagining of Civilization III

https://openciv3.org/
782•klaussilveira•20h ago•241 comments

First Proof

https://arxiv.org/abs/2602.05192
42•samasblack•2h ago•28 comments

StrongDM's AI team build serious software without even looking at the code

https://simonwillison.net/2026/Feb/7/software-factory/
26•simonw•2h ago•24 comments

Stories from 25 Years of Software Development

https://susam.net/twenty-five-years-of-computing.html
36•vinhnx•3h ago•4 comments

Reinforcement Learning from Human Feedback

https://arxiv.org/abs/2504.12501
59•onurkanbkrc•5h ago•3 comments

The Waymo World Model

https://waymo.com/blog/2026/02/the-waymo-world-model-a-new-frontier-for-autonomous-driving-simula...
1034•xnx•1d ago•583 comments

Coding agents have replaced every framework I used

https://blog.alaindichiappari.dev/p/software-engineering-is-back
180•alainrk•4h ago•255 comments

A Fresh Look at IBM 3270 Information Display System

https://www.rs-online.com/designspark/a-fresh-look-at-ibm-3270-information-display-system
27•rbanffy•4d ago•5 comments

Vocal Guide – belt sing without killing yourself

https://jesperordrup.github.io/vocal-guide/
171•jesperordrup•10h ago•65 comments

Vinklu Turns Forgotten Plot in Bucharest into Tiny Coffee Shop

https://design-milk.com/vinklu-turns-forgotten-plot-in-bucharest-into-tiny-coffee-shop/
10•surprisetalk•5d ago•0 comments

72M Points of Interest

https://tech.marksblogg.com/overture-places-pois.html
16•marklit•5d ago•0 comments

Unseen Footage of Atari Battlezone Arcade Cabinet Production

https://arcadeblogger.com/2026/02/02/unseen-footage-of-atari-battlezone-cabinet-production/
107•videotopia•4d ago•27 comments

What Is Stoicism?

https://stoacentral.com/guides/what-is-stoicism
7•0xmattf•1h ago•1 comments

Show HN: Look Ma, No Linux: Shell, App Installer, Vi, Cc on ESP32-S3 / BreezyBox

https://github.com/valdanylchuk/breezydemo
266•isitcontent•20h ago•33 comments

Making geo joins faster with H3 indexes

https://floedb.ai/blog/how-we-made-geo-joins-400-faster-with-h3-indexes
152•matheusalmeida•2d ago•43 comments

Monty: A minimal, secure Python interpreter written in Rust for use by AI

https://github.com/pydantic/monty
278•dmpetrov•20h ago•148 comments

Ga68, a GNU Algol 68 Compiler

https://fosdem.org/2026/schedule/event/PEXRTN-ga68-intro/
36•matt_d•4d ago•11 comments

Hackers (1995) Animated Experience

https://hackers-1995.vercel.app/
546•todsacerdoti•1d ago•264 comments

Sheldon Brown's Bicycle Technical Info

https://www.sheldonbrown.com/
421•ostacke•1d ago•110 comments

Show HN: I spent 4 years building a UI design tool with only the features I use

https://vecti.com
365•vecti•22h ago•166 comments

What Is Ruliology?

https://writings.stephenwolfram.com/2026/01/what-is-ruliology/
65•helloplanets•4d ago•69 comments

Show HN: If you lose your memory, how to regain access to your computer?

https://eljojo.github.io/rememory/
338•eljojo•23h ago•209 comments

An Update on Heroku

https://www.heroku.com/blog/an-update-on-heroku/
460•lstoll•1d ago•303 comments

Microsoft open-sources LiteBox, a security-focused library OS

https://github.com/microsoft/litebox
373•aktau•1d ago•194 comments
Open in hackernews

Passing the Torch – My Last Root DNSSEC KSK Ceremony as Crypto Officer 4

https://technotes.seastrom.com/2025/11/23/passing-the-torch.html
72•greyface-•2mo ago

Comments

shruubi•2mo ago
Not sure how geographically diverse it is to have two "highly secure sites" on the same continent.
ggm•2mo ago
Several people either in this circuit or close by made submissions to this effect to ICANN recently.

It's very hard to get traction on this story because there is a lot of "don't prod the bear" regarding things ICANN can and should ask Department of State about, and things which really have moved into "self managed, independent international body" space. The reason there are two HSM east and west coast was because of this kind of national-strategic sensitivity. It would be a low bar (only money) decision to duplicate the investment in Singapore and Geneva, two locations which ICANN has existing investment in, with good secure facilities and accepted by the wider public as "neutral" points.

When the KSK ceremonies started up, several people also pointed out that this "diverse locations" thing was a bit hokey. The response above is my re-write of the kinds of things said to me, at the time. If somebody wants to deny State or any other US federal agency influenced the decision I have no formal proof.

I should add as a declaration of interest I was at Rob's goodbye KSK event, I am a TCR, and I made such a submission this year. I have not received any indication it was understood or read, despite asking for some acknowledgement, but the process wheels in an agency like ICANN run to their own time.

tptacek•2mo ago
What would "poking the bear" do here? What's the risk?
ggm•2mo ago
The risk is being told no, and inviting dissent into the independence of ICANN. Not asking, means no risk of being told "no, you do as you're told" which would endanger the whole 3 legged stool. the GAC would immediately question the assumption the US government had that level of signoff, the money flows and lawyers would fire up, it would be come a shitstorm in a teacup.

The least likely outcome of asking the department of state if ICANN is "permitted" to add an HSM outside the USA, is a positive answer.

The most likely path to doing it, is not to assume you have to ask.

tptacek•2mo ago
Interesting. Thanks!
ggm•2mo ago
It's my personal opinion from beer convos with people in the circuit. As I said I have no firm proofs and you should hedge belief in this by the lack of verifyable facts.
jacquesm•2mo ago
Don't we have the '98 DNS ROOT incident as a nice example of what could happen when the bear gets poked?
ggm•2mo ago
Yes, but we're a long way down "our hands are off it's ICANN now". The exception might be DNSSEC and the verisign contract continuance. I have no complaint against verisign, far from it: their staff are excellent and they are amazingly diligent and risk averse.

But at a contractual level you could ask is there another company which could tender to operate the root publication function, and meet all stakeholder requirements? And, could that company be legally constituted outside the USA?

jacquesm•2mo ago
CERN?

Given that they contributed one of the key components that made the internet into the success that it is as well as being internationally respected.

ggm•2mo ago
Possibly. Ex CERN staff have indicated they were dismayed when the address management function went elsewhere in Europe. I know people both sides of this divide, it's ancient history in some ways.

I worked in another RIR. I still contract there.

dc396•2mo ago
Asking the US Dept. of State would almost certainly result in "huh?" from the folks there. The part of the USG that plays in the ICANN kiddie pool is US Dept. of Commerce (NTIA) and they no longer have a veto on what ICANN does.

One of the issues is section 4.2 of the IANA Naming Functions contract:

"[...] Contractor must be able to demonstrate that all primary operations and systems will remain within the United States (including the District of Columbia). [...]"

The Key Management Facilities are considered a part of the "primary operations and systems". IIRC, this clause was included in order to move the transition of the IANA functions forward in the face of some resistance within the US government.

Until that bit of legalese is revised, there will be no movement on creating a non-US key management facility. I believe changing the IANA Functions contract requires the Customer Standing Committee. As far as I am aware, no one within the CSC thought it worth the effort, i.e., "if it ain't broke, don't fix it".

Perhaps under the current US administration, that feeling as changed, but I haven't heard of any significant efforts in that regard.

charcircuit•2mo ago
There are security concerns having sites outside of America. I prefer keeping them only within my home country.
shmel•2mo ago
Equally there are security concerns having sites inside the US.
blibble•2mo ago
I'd rather have it somewhere stable like Switzerland

I suspect the only reason this hasn't been used as part of "deal leverage" is because the US regime doesn't know of its existence

monkey_monkey•2mo ago
The USA has shown, over the last 12 months, what a security-conscious country it is. The Defense Secretary's almost fanantical regard for messaging security should be held up as an object lesson for all future generations.
0x50000000•2mo ago
KMF-East is the Gegenvorschlag, or counterproposed key-management for the resolution of TCP/IP ICANN domain certifications.

DNSSEC requires cycling existing TCR for AES-256 symmetric encryptions or leveraging localised key share cycles.

teddyh•2mo ago
He should probably update his “About” page on his blog to remove ”I sign the DNSSEC root”, then.
tptacek•2mo ago
If you're looking to correct people about random parts of their website, perhaps it'd be a better idea to mail them than to comment here, where they're never going to see it. What was the point of this comment, other than mean-spiritedness?
teddyh•2mo ago
So you think I should e-mail somebody out of the blue, bothering them personally, to complain about their personal web site? Do you think that most people would react well if they recieved such a message?

HN is a quote well-known community. It is very common that people read the discussion on HN when their project or themselves are featured. And if they are that interested in what others think, they would then likely see comments such as mine. And if they are not the type to want to read comments, they won’t see my comment and therefore not be bothered by it.

I am baffled when trying to imagine why you think this is “mean-spirited”. On the contrary, this is the most respectful way to offer a minor suggestion that I can think of.

tptacek•2mo ago
Or just kept it to yourself.
teddyh•2mo ago
Why? This is a discussion forum, meant for comments.
gorgoiler•2mo ago
I enjoyed reading the ceremony log itself, a lot! It’s linked at the bottom of the article.

https://technotes.seastrom.com/assets/2025-11-23-passing-the...

Hypothetically, is there a way to know that those present were not under duress? I am guessing that duress is the only viable attack against the ceremony protocol — everyone present appears to play their part but, offscreen and visible only to the participants, are the villains and some hostages.