frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

NanoClaw's Architecture Is a Masterclass in Doing Less

https://jonno.nz/posts/nanoclaw-architecture-masterclass-in-doing-less/
33•timbilt•2h ago

Comments

juancn•1h ago
"Perfection is finally attained, not when there's nothing else to add, but when there's nothing else to remove"

- Antoine de Saint-Exupéry

grim_io•1h ago
Could have started with his name, jeez.

jk

jFriedensreich•1h ago
The "permissions as access/visibility" is unfortunately not holding up in practice. As nice as a simplification like this would be: No one wants to configure up front what permissions are needed. Users will run into annoyances and then just overcommit resource access the same way they choose to run yolo mode. Limiting access for security is a great part of a capability based system but a system that will be used in the way intended needs the following properties, which are mostly missing from the tools we have (apparmor, seccomp, oss VMs, seatbelt, docker, bubblewrap etc.)

- pause execution for a policy engine or user input

- variable scope permissions independent of what was requested. eg user needs to allow just this request to /test/myfile.txt or grant /test/* in that moment

- add (ideally also remove) capabilities based on dynamic user input or engine decisions without up front configuration

- not need application support, if apps need to support it the moment the harness uses an external tool the model breaks

deno, workerd and maybe a vm/docker solution with an webdav proxy mount and web-proxy are the only environments i am aware of where systems like this could be build at all, even there, with limitations. (Not writing this to sound absolute but to learn about other options I am missing.)

tao_oat•33m ago
Unfortunately this has all the hallmarks of AI writing, which made me a lot less motivated to read it.
alasano•30m ago
I stopped reading at the first em dash
nyrikki•21m ago
> The agent inside the container runs with bypassPermissions — it can use Bash, write files, do whatever it wants. But "whatever it wants" is constrained by what the OS lets it see. No application-level permission checks needed.

While containers can be useful for reducing privileges, that assumption isn’t safe, remember that the only thing namespaces away is that which supports namespaces and that by themselves, namespaces are not security features.

A super critical part I didn’t see or missed is the importance of changing UID, the last line of [0] will show one reason.

Remember that the container users has elevated privileges unless you the user explicitly drop this privileges.

I applaud the effort at hardening, but containers have mostly been successful because the most popular apps like nginx operate under a traditional cohosting system and take responsibility for privilege dropping.

There are tons of kernel calls, ldpreload tricks etc… that are well known and easily to find with exploration.

Even dropping elevated privileges and setting no new priv, still isn’t a jail.

Without using separate UIDs don’t expect any real separation at all.

[0] https://www.kernel.org/doc/html/latest/admin-guide/namespace...

torrienaylor•21m ago
I really like solving the prompt injection credential exfiltration risk by never giving the container real keys in the first place. I wonder how prolific that pattern will become.
BeetleB•18m ago
It's been about a month since I last looked at nanoclaw, but comparing with openclaw seems silly. It's like comparing pi.dev with Claude Code. nanoclaw has a lot fewer capabilities than openclaw, with the expectation that you'll essentially build your own features on top of it (and likely end up as buggy as openclaw).

Show HN: Brutalist Concrete Laptop Stand (2024)

https://sam-burns.com/posts/concrete-laptop-stand/
390•sam-bee•5h ago•147 comments

Cloudflare targets 2029 for full post-quantum security

https://blog.cloudflare.com/post-quantum-roadmap/
58•ilreb•2h ago•20 comments

Moving fast in hardware: lessons from lab to $100M ARR

https://blog.zacka.io/p/simplify-then-add-lightness-bc4
25•rryan•1h ago•4 comments

We found an undocumented bug in the Apollo 11 guidance computer code

https://www.juxt.pro/blog/a-bug-on-the-dark-side-of-the-moon/
275•henrygarner•5h ago•143 comments

Good Taste the Only Real Moat Left

https://rajnandan.com/posts/taste-in-the-age-of-ai-and-llms/
22•speckx•22m ago•8 comments

Dropping Cloudflare for Bunny.net

https://jola.dev/posts/dropping-cloudflare
220•shintoist•2h ago•100 comments

Claude Code is locking people out for hours

https://github.com/anthropics/claude-code/issues/44257
143•sh1mmer•1h ago•142 comments

Show HN: A cartographer's attempt to realistically map Tolkien's world

https://www.intofarlands.com/atlasofarda
92•intofarlands•4h ago•16 comments

Every GPU That Mattered

https://sheets.works/data-viz/every-gpu
239•jonbaer•7h ago•129 comments

You can't cancel a JavaScript promise (except sometimes you can)

https://www.inngest.com/blog/hanging-promises-for-control-flow
38•goodoldneon•2h ago•26 comments

9 Mothers (YC P26) Is Hiring – Lead Robotics and More

https://jobs.ashbyhq.com/9-mothers?utm_source=x8pZ4B3P3Q
1•ukd1•2h ago

Identify a London Underground Line just by listening to it

https://tubesoundquiz.com/
132•nelson687•6h ago•41 comments

Global Physics Photowalk: 2025 winners revealed

https://www.quantamagazine.org/global-physics-photowalk-2025-winners-revealed-20260401/
10•ibobev•3d ago•1 comments

SQLite in Production: Lessons from Running a Store on a Single File

https://ultrathink.art/blog/sqlite-in-production-lessons
78•thunderbong•3d ago•57 comments

My Experience as a Rice Farmer

https://xd009642.github.io/2026/04/01/My-Experience-as-a-Rice-Farmer.html
287•surprisetalk•5d ago•134 comments

Wi-Fi That Can Withstand a Nuclear Reactor: This receiver chip can take it

https://spectrum.ieee.org/robotics-in-nuclear-industry
53•voxadam•4d ago•2 comments

DeiMOS – A Superoptimizer for the MOS 6502

https://aransentin.github.io/deimos/
51•Aransentin•5h ago•15 comments

Show HN: Stop paying for Dropbox/Google Drive, use your own S3 bucket instead

https://locker.dev
181•Zm44•5h ago•146 comments

Blackholing My Email

https://www.johnsto.co.uk/blog/blackholing-my-email/
122•semyonsh•7h ago•13 comments

Haunting Photos Show the Aftermath of the Kursk Submarine Disaster in 2000

https://rarehistoricalphotos.com/kursk-submarine-disaster-photos/
96•mooreds•4d ago•22 comments

Show HN: Pion/handoff – Move WebRTC out of browser and into Go

https://github.com/pion/handoff
63•Sean-Der•4h ago•11 comments

Running Out of Disk Space in Production

https://alt-romes.github.io/posts/2026-04-01-running-out-of-disk-space-on-launch.html
110•romes•4d ago•50 comments

12k Tons of Dumped Orange Peel Grew into a Landscape Nobody Expected (2017)

https://www.sciencealert.com/how-12-000-tonnes-of-dumped-orange-peel-produced-something-nobody-im...
22•pulisse•29m ago•1 comments

AI may be making us think and write more alike

https://dornsife.usc.edu/news/stories/ai-may-be-making-us-think-and-write-more-alike/
170•giuliomagnifico•4h ago•163 comments

Breaking the console: a brief history of video game security

https://sergioprado.blog/breaking-the-console-a-brief-history-of-video-game-security/
64•sprado•6h ago•18 comments

Sam Altman may control our future – can he be trusted?

https://www.newyorker.com/magazine/2026/04/13/sam-altman-may-control-our-future-can-he-be-trusted
1785•adrianhon•1d ago•729 comments

Show HN: Ghost Pepper – Local hold-to-talk speech-to-text for macOS

https://github.com/matthartman/ghost-pepper
432•MattHart88•20h ago•190 comments

Record wind and solar saved UK from gas imports worth £1B in March 2026

https://www.carbonbrief.org/analysis-record-wind-and-solar-saved-uk-from-gas-imports-worth-1bn-in...
85•mindracer•4h ago•56 comments

Floating point from scratch: Hard Mode

https://essenceia.github.io/projects/floating_dragon/
72•random__duck•2d ago•16 comments

Three hundred synths, 3 hardware projects, and one app

https://midi.guide/blog/three-hunded-synths-one-app/
103•ductionist•11h ago•13 comments