frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

After 27 years within budget Austria open 6thlongest railway tunnel in the world

https://infrastruktur.oebb.at/en/projects-for-austria/railway-lines/southern-line-vienna-villach/...
207•fzeindl•3h ago•87 comments

4 billion if statements (2023)

https://andreasjhkarlsson.github.io//jekyll/update/2023/12/27/4-billion-if-statements.html
198•damethos•5d ago•73 comments

SQLite JSON at Full Index Speed Using Generated Columns

https://www.dbpro.app/blog/sqlite-json-virtual-columns-indexing
21•upmostly•56m ago•2 comments

From text to token: How tokenization pipelines work

https://www.paradedb.com/blog/when-tokenization-becomes-token
32•philippemnoel•23h ago•1 comments

The tiniest yet real telescope I've built

https://lucassifoni.info/blog/miniscope-tiny-telescope/
159•chantepierre•6h ago•35 comments

Fedora: Open-source repository for long-term digital preservation

https://fedorarepository.org/
14•cernocky•58m ago•8 comments

The Tor Project is switching to Rust

https://itsfoss.com/news/tor-rust-rewrite-progress/
118•giuliomagnifico•1h ago•54 comments

GPT-5.2

https://openai.com/index/introducing-gpt-5-2/
1064•atgctg•20h ago•931 comments

Nokia N900 Necromancy

https://yaky.dev/2025-12-11-nokia-n900-necromancy/
376•yaky•14h ago•138 comments

Show HN: Tripwire: A new anti evil maid defense

https://github.com/fr33-sh/Tripwire
19•DoctorFreeman•1d ago•10 comments

Google de-indexed Bear Blog and I don't know why

https://journal.james-zhan.com/google-de-indexed-my-entire-bear-blog-and-i-dont-know-why/
256•nafnlj•13h ago•102 comments

Guarding My Git Forge Against AI Scrapers

https://vulpinecitrus.info/blog/guarding-git-forge-ai-scrapers/
75•todsacerdoti•6h ago•45 comments

Show HN: Autofix Bot – Hybrid static analysis and AI code review agent

9•sanketsaurav•16h ago•1 comments

What folk can do

https://folk.computer/guides/what-folk-can-do
18•luu•4d ago•10 comments

CRISPR fungus: Protein-packed, sustainable, and tastes like meat

https://www.isaaa.org/kc/cropbiotechupdate/article/default.asp?ID=21607
205•rguiscard•13h ago•116 comments

He set out to walk around the world. After 27 years, his quest is nearly over

https://www.washingtonpost.com/lifestyle/2025/12/05/karl-bushby-walk-around-world/
148•wallflower•4d ago•115 comments

Rivian Unveils Custom Silicon, R2 Lidar Roadmap, and Universal Hands Free

https://riviantrackr.com/news/rivian-unveils-custom-silicon-r2-lidar-roadmap-universal-hands-free...
331•doctoboggan•20h ago•453 comments

Training LLMs for Honesty via Confessions

https://arxiv.org/abs/2512.08093
13•arabello•3h ago•2 comments

The highest quality codebase

https://gricha.dev/blog/the-highest-quality-codebase
580•Gricha•3d ago•363 comments

Denial of service and source code exposure in React Server Components

https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-comp...
305•sangeeth96•17h ago•190 comments

Octo: A Chip8 IDE

https://github.com/JohnEarnest/Octo
21•tosh•6d ago•2 comments

Smartphone without a battery (2022)

https://yaky.dev/2022-09-06-smartphone-without-battery/
53•MYEUHD•6h ago•16 comments

Programmers and software developers lost the plot on naming their tools

https://larr.net/p/namings.html
336•todsacerdoti•20h ago•444 comments

An SVG is all you need

https://jon.recoil.org/blog/2025/12/an-svg-is-all-you-need.html
282•sadiq•18h ago•114 comments

Spirograph style Lego drawing machine

https://jkbrickworks.com/simple-drawing-machine/
27•ensocode•4d ago•5 comments

BehindTheMedspeak: A Spinal Tap

https://bookofjoe2.blogspot.com/2025/10/behindthemedspeak-this-is-spinal-tap.html
3•surprisetalk•4d ago•0 comments

Auto-grading decade-old Hacker News discussions with hindsight

https://karpathy.bearblog.dev/auto-grade-hn/
629•__rito__•1d ago•259 comments

Litestream VFS

https://fly.io/blog/litestream-vfs/
323•emschwartz•20h ago•78 comments

Stoolap: High-performance embedded SQL database in pure Rust

https://github.com/stoolap/stoolap
91•murat3ok•13h ago•29 comments

Craft software that makes people feel something

https://rapha.land/craft-software-that-makes-people-feel-something/
312•lukeio•1d ago•154 comments
Open in hackernews

Show HN: Tripwire: A new anti evil maid defense

https://github.com/fr33-sh/Tripwire
19•DoctorFreeman•1d ago
If you have heard of [Haven](https://github.com/guardianproject/haven), then Tripwire fills in the void for a robust anti evil maid solution after Haven went dormant.

The GitHub repo describes both the concept and the setup process in great details. For a quick overview, read up to the demo video.

There is also a presentation of Tripwire available on the Counter Surveil podcast: https://www.youtube.com/watch?v=s-wPrOTm5qo

Comments

sandworm101•1h ago
This isnt a tripwire. This is a canary. You have to actively check a canary. A tripwire would send notifications in real time without the user needing to check.

An evolution of this would be to put a server on a different network, a remote location, and have it pump out warnings the moment movement was detected and/or contact with the "tripwire" system was lost.

But the best way of preventing evil maid attacks remains knowing your hardware. Anyone trying to swap out my laptop, or open it, is going to have a problem replicating my scratch marks, my non-standard OS boot screen, or prying out the glue holding in the ram modules (to prevent cold boot attacks).

ramses0•28m ago
I was sure I'd made a comment like this before, but I'd love some sort of home-spun setup like this: https://news.ycombinator.com/item?id=2465687 ...hood, tuck, john. (2x local, 1x remote) which constantly rotated roles as to who was primary/secondary.

Basically core "chaos-infra" for your home setup(s). Hood/Tuck switch between primary and secondary, always trying to stay in touch with "John" (offsite), maybe like a primitive etcd for home automation/monitoring/backup/file-serving. Green==3good, Yellow=degraded[local|remote], Red=single-point-of-failure, Black=off/not-serving.

Other funsie to think about is getting a thumbprint/PIN-locked USB-drive to hold/unlock `~/.passwordstore/*.gpg` so that even on power-outage/reboot you'd need to physically "re-auth" to unlock important secrets.

Something like this would fit nicely into this (imaginary) setup!

sandworm101•7m ago
I had a professor once ask about the strip of duct tape across the back of my brand new laptop. "Well, thieves cannot pawn electronics with cracked cases. So all my laptops have at least some tape so they think it may be cracked." The next lecture, the prof had a strip of masking tape on his laptop too.

But slap a tux logo and an "i l9ve truecrypt" banner on you device and nobody short of the NSA would even attempt a maid attack.

voxadam•1h ago
For a second I thought Tripwire, Inc.[0] had risen from the dead with a new IDS.

[0] https://en.wikipedia.org/wiki/Tripwire_(company)

Eduard•1h ago
I guess this is actually not an anti evil maid defense.

It's rather an anti evil maid tool, or an evil maid defense. :)

sorry for being pedantic, but with the arms race within cybersecurity, "anti something defense" sounds like double negation to me.

bflesch•50m ago
The bullet point stating that tripwire was built for "High-ranking officials in businesses/organizations" should be removed, because that group is very unlike the "Developers of critical software", "Investigative journalists", and "Attorneys with high-profile clients" which are also mentioned.

Everybody who had the pleasure to work with "high-ranking officials in businesses/organizations" knows that this group is the one who overrides many technically optimal decisions and thinks internal policies do not apply to them. Their lives are not affected if a device is compromised because they are financially stable and can just blame an intrusion on the IT team.

neuralkoi•37m ago
The author did an excellent job explaining what an evil maid attack is, but a very poor job of explaining how their proposal mitigates such attack.

I think the classic "Detecting unauthorized physical access with beans, lentils and colored rice" [0] approach is simpler to understand and simpler to implement. It doesn't rely on any hardware, such as a Raspberry Pi or otherwise technology which can be more easily subject to scrutiny via Ken Thompson's "Reflections on Trusting Trust".

[0] https://dys2p.com/en/2021-12-tamper-evident-protection.html

guerrilla•13m ago
Just so you know, this name is already taken by a famous security product for intrusion detection.

https://en.wikipedia.org/wiki/Tripwire_(company)

https://en.wikipedia.org/wiki/Open_Source_Tripwire

QuadmasterXLII•4m ago
as well as https://en.wikipedia.org/wiki/Tripwire ;)
pyrolistical•4m ago
For high sec people, they should have an internal sec camera system. They are have come down in price over time