frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Autoresearch on an old research idea

https://ykumar.me/blog/eclip-autoresearch/
158•ykumards•2h ago•47 comments

Local Stack Archived their GitHub repo and requires an account to run

https://github.com/localstack/localstack
84•ecshafer•2h ago•37 comments

iPhone 17 Pro Demonstrated Running a 400B LLM

https://twitter.com/anemll/status/2035901335984611412
372•anemll•6h ago•205 comments

How I'm Productive with Claude Code

https://neilkakkar.com/productive-with-claude-code.html
12•neilkakkar•23m ago•0 comments

Finding all regex matches has always been O(n²)

https://iev.ee/blog/the-quadratic-problem-nobody-fixed/
92•lalitmaganti•4d ago•21 comments

Trivy under attack again: Widespread GitHub Actions tag compromise secrets

https://socket.dev/blog/trivy-under-attack-again-github-actions-compromise
117•jicea•1d ago•41 comments

Dune3d: A parametric 3D CAD application

https://github.com/dune3d/dune3d
33•luu•1d ago•6 comments

BIO: The Bao I/O Coprocessor

https://www.bunniestudios.com/blog/2026/bio-the-bao-i-o-coprocessor/
86•zdw•3d ago•22 comments

American Aviation Is Near Collapse

https://www.theatlantic.com/newsletters/2026/03/aviation-failures-tsa-dhs-shutdown/686505/
56•JumpCrisscross•1h ago•37 comments

AI Risks "Hypernormal" Science

https://www.asimov.press/p/ai-science
29•mailyk•2h ago•16 comments

Two pilots dead after plane and ground vehicle collide at LaGuardia

https://www.bbc.com/news/articles/cy01g522ww4o
240•mememememememo•13h ago•397 comments

An incoherent Rust

https://www.boxyuwu.blog/posts/an-incoherent-rust/
47•emschwartz•5h ago•7 comments

I built an AI receptionist for a mechanic shop

https://www.itsthatlady.dev/blog/building-an-ai-receptionist-for-my-brother/
164•mooreds•10h ago•177 comments

An unsolicited guide to being a researcher [pdf]

https://emerge-lab.github.io/papers/an-unsolicited-guide-to-good-research.pdf
140•sebg•4d ago•20 comments

Bombadil: Property-based testing for web UIs

https://github.com/antithesishq/bombadil
204•Klaster_1•4d ago•79 comments

Bets on US-Iran ceasefire show signs of insider knowledge, say experts

https://www.theguardian.com/us-news/2026/mar/23/bets-us-iran-ceasefire-show-signs-of-insider-know...
33•trocado•47m ago•20 comments

Digs: Offline-first iOS app to browse your Discogs vinyl collection

https://lustin.fr/blog/building-digs/
30•rlustin•12h ago•13 comments

US and TotalEnergies reach 'nearly $1B' deal to end offshore wind projects

https://www.lemonde.fr/en/international/article/2026/03/23/us-and-totalenergies-reach-nearly-1-bi...
233•lode•3h ago•159 comments

Show HN: Threadprocs – executables sharing one address space (0-copy pointers)

https://github.com/jer-irl/threadprocs
56•jer-irl•5h ago•36 comments

Cyber.mil serving file downloads using TLS certificate which expired 3 days ago

https://www.cyber.mil/stigs/downloads
145•Eduard•5h ago•139 comments

Walmart: ChatGPT checkout converted 3x worse than website

https://searchengineland.com/walmart-chatgpt-checkout-converted-worse-472071
362•speckx•4d ago•238 comments

Is it a pint?

https://isitapint.com/
149•cainxinth•4h ago•126 comments

Migrating to the EU

https://rz01.org/eu-migration/
769•exitnode•10h ago•605 comments

“Collaboration” is bullshit

https://www.joanwestenberg.com/collaboration-is-bullshit/
235•mitchbob•19h ago•121 comments

The gold standard of optimization: A look under the hood of RollerCoaster Tycoon

https://larstofus.com/2026/03/22/the-gold-standard-of-optimization-a-look-under-the-hood-of-rolle...
555•mariuz•1d ago•153 comments

GitHub appears to be struggling with measly three nines availability

https://www.theregister.com/2026/02/10/github_outages/
403•richtr•10h ago•207 comments

General Motors is assisting with the restoration of a rare EV1

https://evinfo.net/2026/03/general-motors-is-assisting-with-the-restoration-of-an-1996-ev1/
78•betacollector64•3d ago•92 comments

Side-Effectful Expressions in C (2023)

https://blog.xoria.org/expr-stmt-c/
26•surprisetalk•5d ago•3 comments

If DSPy is so great, why isn't anyone using it?

https://skylarbpayne.com/posts/dspy-engineering-patterns/
189•sbpayne•6h ago•110 comments

Tin Can, a 'landline' for kids

https://www.businessinsider.com/tin-can-landline-kids-cellphone-cell-alternative-how-2025-9
293•tejohnso•3d ago•237 comments
Open in hackernews

Anchor: Hardware-based authentication using SanDisk USB devices

8•rewant•4d ago
Anchor is a cross-platform desktop application that provides hardware-based authentication using SanDisk USB devices. The application automatically detects USB connection/disconnection events and provides secure database access only when an authorized USB device is connected.

Github:https://github.com/TheEleventhAvatar/Anchor

Comments

KomoD•2d ago
To call this "security" is funny in my opinion, can't any application also fetch the serial number?

And also do they not get saved in logs like dmesg?

vivid242•1h ago
If you can restrict the software, this would be a good way for controlling physical user ‚presence‘ - like in the supermarket, when a supervisor needs to scan their card for a cash register to take out a wrongly scanned item. I like it!
alexpotato•1h ago
You could also use encrypted and signed keys on the devices to confirm that it's the correct drive.

Was recently watching a video on the RFID tags that Bambu Labs use on their spools and not only is the tag data encrypted, it's signed so even if you bypass the encryption, you still don't have a way to spoof the signature.

vel0city•57m ago
If they're just files on a flash drive, what stops someone from just copying the files to another drive? Its just moving the same issue up a level in the stack, and in many ways making it easier to clone it.

One of the whole points of authenticator devices is that the actual key material isn't directly readable. You shouldn't be able to trivially reproduce the device.

maximusdrex•58m ago
Calling this "hardware-based security" is somewhere between disingenuous and dangerously naive. Hardware-based security normally implies hardware with a dedicated secure element with cryptographic identities which are impossible to spoof. Security based on USB serial numbers can be defeated by any adversarial device claiming to use the same serial device as a device you have registered. There's no secure signatures or anything backing a USB serial number.

This is so, so much worse than that though, because the code doesn't even do what the AI-hallucinated documentation describes, because as far as I can tell the actual "serial number" is returned by the following line: Ok(Some(format!("{:?}", device.product_id()))) So the "serial number" is actually the USB product id, which generally corresponds to the "model", not even unique per-device. So you didn't even test this with multiple identical flash drives.

follie•48m ago
How else would you recover from a device failure?
Vexs•43m ago
You don't. The normal procedure here is to have multiple unique keys with multiple unique secrets. If one breaks that's it it's broken. This also allows you to revoke a key without removing all keys.
ImPostingOnHN•42m ago
You enroll up another hardware device (or 2) as a backup and securely store them in different places.

This is normal to do for yubikeys, for example.

The main point is that the secrets stored on the device are usually used to unlock other secrets stored elsewhere, and so themselves don't need to be synchronized often.