frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Veracrypt Project Update

https://sourceforge.net/p/veracrypt/discussion/general/thread/9620d7a4b3/
252•super256•3h ago•64 comments

The Git Commands I Run Before Reading Any Code

https://piechowski.io/post/git-commands-before-reading-code/
56•grepsedawk•1h ago•4 comments

Revision Demoparty 2026: Razor1911 [video]

https://www.youtube.com/watch?v=Lw4W9V57SKs&t=5716s
172•tetrisgm•4h ago•67 comments

Project Glasswing: Securing critical software for the AI era

https://www.anthropic.com/glasswing
1300•Ryan5453•16h ago•646 comments

Lunar Flyby

https://www.nasa.gov/gallery/lunar-flyby/
724•kipi•19h ago•180 comments

Show HN: We built a camera only robot vacuum for less than 300$ (Well almost)

https://indraneelpatil.github.io/blog/2026/robot-vacuum/
27•indraneelpatil•2d ago•2 comments

Protect your shed

https://dylanbutler.dev/blog/protect-your-shed/
165•baely•7h ago•46 comments

System Card: Claude Mythos Preview [pdf]

https://www-cdn.anthropic.com/53566bf5440a10affd749724787c8913a2ae0841.pdf
705•be7a•16h ago•505 comments

Slightly safer vibecoding by adopting old hacker habits

http://addxorrol.blogspot.com/2026/03/slightly-safer-vibecoding-by-adopting.html
113•transpute•5d ago•61 comments

Škoda DuoBell: A bicycle bell that penetrates noise-cancelling headphones

https://www.skoda-storyboard.com/en/skoda-world/skoda-duobell-a-bicycle-bell-that-outsmarts-even-...
104•ra•1h ago•119 comments

GLM-5.1: Towards Long-Horizon Tasks

https://z.ai/blog/glm-5.1
535•zixuanlimit•17h ago•221 comments

Native Americans had dice 12k years ago

https://www.nbcnews.com/science/science-news/native-americans-dice-games-probability-study-rcna26...
65•delichon•4d ago•26 comments

How to get better at guitar

https://www.jakeworth.com/posts/how-to-get-better-at-guitar/
342•jwworth•2d ago•168 comments

Cambodia unveils statue to honour famous landmine-sniffing rat

https://www.bbc.com/news/articles/c0rx7xzd10xo
389•speckx•17h ago•88 comments

S3 Files

https://www.allthingsdistributed.com/2026/04/s3-files-and-the-changing-face-of-s3.html
302•werner•14h ago•91 comments

Show HN: An interactive map of Tolkien's Middle-earth

https://middle-earth-interactive-map.web.app/
206•frasermarlow•13h ago•40 comments

A truck driver spent 20 years making a scale model of every building in NYC

https://www.smithsonianmag.com/smart-news/a-truck-drive-spent-20-years-making-this-astonishing-sc...
331•1659447091•2d ago•54 comments

Binary obfuscation used in AAA Games

https://blog.farzon.org/2026/04/binary-obfuscation-that-doesnt-kill-lto.html
98•noztol•2d ago•38 comments

Hobby CNC machining and resin casting (2015)

https://lcamtuf.coredump.cx/gcnc/
14•achierius•3d ago•3 comments

Your File System Is Already A Graph Database

https://rumproarious.com/2026/04/04/your-file-system-is-already-a-graph-database/
4•alxndr•2d ago•1 comments

A database of analog cameras that can be 3D printed

https://printed.analogcamera.space/
105•thomasjb•5d ago•15 comments

The Clock

https://blog.senko.net/the-clock
73•senko•4d ago•27 comments

US and Iran agree to provisional ceasefire

https://www.theguardian.com/us-news/2026/apr/07/trump-iran-war-ceasefire
486•g-b-r•11h ago•1424 comments

Cloudflare targets 2029 for full post-quantum security

https://blog.cloudflare.com/post-quantum-roadmap/
333•ilreb•20h ago•99 comments

Xilem – An experimental Rust native UI framework

https://github.com/linebender/xilem
99•Levitating•10h ago•32 comments

JSIR: A High-Level IR for JavaScript

https://discourse.llvm.org/t/rfc-jsir-a-high-level-ir-for-javascript/90456
58•nnx•9h ago•13 comments

Rescuing old printers with an in-browser Linux VM bridged to WebUSB over USB/IP

https://printervention.app/details
199•gmac•17h ago•85 comments

Show HN: Gemma 4 Multimodal Fine-Tuner for Apple Silicon

https://github.com/mattmireles/gemma-tuner-multimodal
179•MediaSquirrel•14h ago•24 comments

A whole boss fight in 256 bytes

https://hellmood.111mb.de//A_whole_boss_fight_in_256_bytes.html
112•HellMood•2d ago•41 comments

Running out of disk space in production

https://alt-romes.github.io/posts/2026-04-01-running-out-of-disk-space-on-launch.html
205•romes•4d ago•112 comments
Open in hackernews

Veracrypt Project Update

https://sourceforge.net/p/veracrypt/discussion/general/thread/9620d7a4b3/
252•super256•3h ago

Comments

dizhn•2h ago
Microsoft disabled the developer's certificate so no windows releases can be made.
jonathanstrange•1h ago
As someone who is just planning to publish signed desktop software for Windows, this is deeply worrying. What reasons could there be for cancelling a certificate, especially when it has been used for years and the identity is already established?

Are there some ways to combat such decisions legally?

politelemon•1h ago
This is a concern and risk that has realised itself multiple times over the past decades. There have been multiple stories linked to multiple developers in the past.

If you publish to any closed platform including ios, mac, win, android, this is the risk you run and a condition of operating you will need to accept.

shelled•1h ago
Realistically speaking - anything could be a reason. A shakedown or blocking based on some "nudge" (this might come across as tin-foiled though). Some flag/trip-wires going wrong, more worryingly due to a bug/false alarm - and this is more worrying because in this case semi-incompetent large orgs like MSFT find it really hard to accept it, fix, and move on. Some change in OP's account that either they don't see or haven't realised - some edge case, you never know.

And of course, it doesn't affect their earnings and there are no consequence, or significant, so they won't care and won't respond or tell what went wrong.

Can one move legally? Sure. But then it effectively is a combo of who blinks first and who can hold their breath longer.

technion•53m ago
There's more to it. Signed desktop software can be signed by any CA.

Veracrypt has kernel drivers. Microsoft's ability to control what you can sign is specific to kernel drivers, and Microsoft's trigger finger around bans exists in the world where bad drivers BSOD machines.

In general this isn't your problem.

Gareth321•51m ago
We can still install, right? It just comes up with a scary warning. Still not great but at least we aren't locked out.
Strom•38m ago
You can, but it's more than a warning. VeraCrypt has a signed kernel driver, which has higher requirements. You'll need to boot into a special Windows mode and disable Driver Signature Enforcement.
HauntingPin•23m ago
Afaict, you can't disable driver signature enforcement permanently without disabling secure boot.
ErroneousBosh•2h ago
Jesus, sourceforge is still on the go?
SXX•2h ago
Might be it even not using all your code to train AI. Or at least not asking your explicit permission to do it.
karel-3d•1h ago
sourceforge was always very scummy, I think they would definitely use the code for that if they could
mbreese•1h ago
It wasn’t always scummy… but there was a definite shift after they got bought. It’s kept getting worse since then.

Then again, this was something like 20 years ago. Back then, Sourceforge was something closer to GitHub today. It was the de facto public source repository. You could even get an on-premise version, IIRC.

Actually, this is sounding a lot like GitHub these days… not sure what that means.

JimDabell•1h ago
Not every conversation has to be a conversation about AI.
egorfine•1h ago
And unfortunately some projects exclusively use sourceforge. Which breaks some of my CI pipelines.
kome•1h ago
yeah, it just works
tvbusy•18m ago
I understand that most people want to move to other more modern tools, it's up to you. However, what baffled me is why the author's choice not to move is a problem? Did we pay them to move and they did not move as promised? Was there some crowd funding to move that was not fulfilled?
firen777•2h ago
It's like LibreOffice all over again: https://www.neowin.net/news/microsoft-bans-libreoffice-devel...
SeanDav•27m ago
This is worrying on many levels. So Microsoft force you to create an account to use Windows and then they reserve the right to block you from your own account, thereby potentially making you lose access to all your OWN data. This is crazy and yet another reason to stop using Windows as soon as possible.
xorcist•13m ago
It's not your own data anymore if you gave it away.
pogue•2h ago
They need to get some tech site like Arstechnica to write about it, like they did when neocities couldn't get ahold of bing. The only way to contact these tech companies to speak to a real human being and not a chatbot is if you know somebody who works there or if the media writes about it.
CR1337•1h ago
I blew the lid on X today:

https://x.com/i/status/2041698657368703484

ninjagoo•1h ago
Looks like Linux and some of the BSDs are the only remaining truly open OSes.
krylon•50m ago
True, however, that has been the case for quite a while. This particular incident doesn't change that, except for the VeraCrypt developer, who is in a crappy situation now (not just regarding VeraCrypt, he mentions he was using the certificate for his main job as well, so this sucks a lot for him).
sph•47m ago
Well, of course. Have the other commercial offerings every been "truly open OSes"?
Aachen•8m ago
So far I haven't had much concrete reason for my family to switch away from Windows. The updates maybe, needing to pay for a new license and the UI changes are like pulling the chair out from under them, especially as they get older (Windows 7 was hard for my grandma, thankfully they left 10 mostly alone but 11 is quite different again so she's currently staying on 10 — not that her hardware supports 11 anyway but that's fixable), but it's either learning the new Windows UI, let's say ten storypoints of newness, or learning some Linux desktop environment, even if it's Mint which is similar to 7/XP it's not quite the same either and probably like 15 storypoints at minimum, even if then you're done for much longer

But if OSes are being locked down and software has trouble distributing security updates through official repositories for Windows... that's a good reason to finally make the switch. Same as why my family is on Android: I can install f-droid, disable the google store, and don't have to worry about them installing malware / spyware / adware

There's different degrees of openness. Android till 2026 was an acceptable compromise (let's see how it goed forwards). Windows is also on the decline with their account policy, not sure about this certificate revocation thing (thankfully haven't had to deal with it yet; I'm not a user myself) but it sounds like they're moving to a walled garden also

When the degree changes and gets even less open, yeah you can say "well of course, they were never truly open, they're commercial" but it's still a change and might lead people to alter their choices

SeanDav•18m ago
Except compulsory age verification in Linux is now becoming a real threat. Some Linux distros are actively against this but many are not seemingly interested in fighting it: CachyOS, Ubuntu, Fedora and others.

Age Verification is the thin end of a much bigger wedge in "open" OS's

akimbostrawman•7m ago
the current law requires no verification at all simple attestation, you could put in _any_ age. it also does not effect linux distros as a whole, only distros in jurisdictions with the laws.
xorcist•9m ago
Until Microsoft decides to no longer sign the Linux boot loader shim (for IBM/Red Hat, no less).
nixpulvis•1h ago
We need a better way to sign and verify software. Clearly companies like Microsoft and Apple have not been good for the open source communities and are inhibiting innovation.
PunchyHamster•1h ago
Just add code cert generation to letsencrypt, it's not like MS validates the code that you sign used certs from them anyway
mr_mitm•1h ago
What would be the point? How would you prevent malware from being signed? Currently, code signatures are used as a signal for trustworthiness of the code.
Eldt•59m ago
Misplaced trustworthiness?
duskdozer•12m ago
Is it some entirely different process than providing hashes and a GPG signature?
iamniels•1h ago
We need better OSes such that signing of software is not required to keep your computer safe.
realusername•17m ago
I think this is fundamentally an unsolvable problem and I'm not even sure it's worth pursuing.

Any large scale signing platform will have large oversights and be rendered useless. See the appstore / play store/windows...

speedgoose•1h ago
It's perhaps naive, but could he create a new organisation, like a "TotallyNotVeraCrypt" French loi 1901 association, at a different address, and create a new microsoft account by making sure it passes all the requirements.
orbital-decay•55m ago
That's what VeraCrypt is, a fork of the original TrueCrypt after all drama, security doubts, and eventual discontinuation. It took a long time and two independent audits to establish trust in it.
subscribed•49m ago
Probably not French though, give how hostile it appears to be to encryption/security related projects (GrapheneOS had a good arguments re: that)
repelsteeltje•47m ago
Yeah but isn't the point of these certificates to express trust?

The point isn't (or: shouldn't be) to forcefully find your way through some back alley to make it look legit. It's to certify that the software is legit.

Trust goes both ways: we ought to trust Microsoft to act as a responsible CA. Obfuscating why they revoked trust (as is apparently the case) and leaving the phone ringing is hurting trust in MS as a CA and as an organization.

fg137•17m ago
And Microsoft will be happy to shut that one down because their incompetence.

So we'd better find a real solution now.

RandomGerm4n•1h ago
That's especially ridiculous because this whole security mechanism that Microsoft is forcing on Windows user doesn't even work. There are tons of leaked certificates and on forums dedicated to game hacking you can find guides on how to get your hands on one yourself. People there use them to write kernel drivers for cheating in games. Game developers often blacklist these in their anti-cheat software so that the game no longer launches on a computer using a driver with that certificate. Microsoft however does not do this and malware developers can then simply use the certificates for their own purposes. So all this nonsense is basically just a restriction on regular users and honest developers while the “bad guys” can get around it.
shelled•1h ago
I am somewhat also concerned that this software was still being distributed on SourceForge.
frizlab•33m ago
I don’t even understand how SourceForge still exists!
reddalo•18m ago
Yes, I stopped using SourceForge after they started tampering with installers to put adware inside of them.

It's a bit worrying that a sensitive app such as VeraCrypt is still distributed there.

Pay08•4m ago
Why?
_s_a_m_•1h ago
Microsoft doing everything in their power to be assholes, as always
krylon•53m ago
As much as I like bashing Microsoft, never underestimate people's capacity for incompetence, especially where large organizations are involved. I don't see how they would gain anything from this move.
cm2187•15m ago
It doesn’t help that they do that sort of shits AND mandate a microsoft account for logging in to windows. Also how much trust can you have that if you move your business to azure they will not randomly kill it. Incompetence or malice, almost doesn’t matter to the average user.
saidnooneever•45m ago
maybe an old vulnerable signed driver can be used to load the new version :D. on a more seirous note, i think contact with a person at MS, likely via socials triggering that, might help here. It all depends on the reason for the ban/block/cancel.

if they had a reason other than 'oops mistake' its likely just going to remain in place. (sadly, that is how MS is. if you care for privacy maybe go to BSD)

a_paddy•17m ago
Who said vulnerable? Perhaps just a driver with less features.
zx2c4•29m ago
This is the same problem I'm currently facing with WireGuard. No warning at all, no notification. One day I sign in to publish an update, and yikes, account suspended. Currently undergoing some sort of 60 days appeals process, but who knows. That's kind of crazy: what if there were some critical RCE in WireGuard, being exploited in the wild, and I needed to update users immediately? (That's just hypothetical; don't freak out!) In that case, Microsoft would have my hands entirely tied.

If anybody within Microsoft is able to do something, please contact me -- jason at zx2c4 dot com.

teruakohatu•27m ago
I am astounded that the maintainer and inventor of Wireguard is in this position.

Microsoft even supports Wireguard in Azure Kubernetes Service.

onehair•26m ago
Now this is even more alarming! Wireguard's creator has their Microsoft account suspended...

<Tin foil hat on> Microsoft doesn't want to allow software that would allow the user to shield themselves, either by totally encrypting a drive, or by encrypting their network traffic! </Tin foil hat on>

ngetchell•9m ago
Or more likely, some automated security system flagged popular but suspicious apps for further review.
unicornporn•6m ago
> Microsoft doesn't want to allow software that would allow the user to shield themselves

I don't think Microsoft cares (about anything else than making money), but there are plenty of (state) actors that can influence the decision-making at Microsoft when it comes to these issues.

No tinfoil needed.

vstm•4m ago
> No tinfoil needed.

That's what Big Tinfoil wants you to believe!

gib444•21m ago
Y'all need to form an alliance or something, get some press coverage (wireguard, veracrypt, libreoffice)
duskdozer•9m ago
True, but really even if it gets resolved for them it should basically be a huge warning sign to everybody. Projects like those might get reinstated but it would only be because of how big they are that it would matter. Any person or small or 'undesirable' project would not get the same resolution.
jchw•11m ago
I tried to set up a partner account for driver signing last year (as a business entity) and it already seemed basically impossible. I think they're getting ready to just simply not allow it at all.

This is stupid. If Microsoft wants people to stop writing kernel drivers, that's potentially doable (we just need sufficient user mode driver equivalents...) but not doing that and also shortening the list of who can sign kernel drivers down to some elite group of grandfathered companies and individuals is the worst possible outcome.

But at this point I almost wish they didn't fix it, just to drive home the point harder to users how little they really own their computer and OS anymore.

tomgag•26m ago
Sorry to hear about this turn of events, but it was pretty much to be expected given the way the world is turning, and Microsoft being Microsoft.

Switch to Linux if you can, and come give Shufflecake a try ;)

https://shufflecake.net/

8cvor6j844qw_d6•26m ago
Seeing this kind of friction makes me more confident in VeraCrypt. The tools that never seem to run into trouble with platform gatekeepers are the ones I'd worry about.
bilekas•24m ago
And yet another example of companies turning actively hostile against their users.

The burden of usage/access is now solely on the customers and the feeling is that regular customers are just a nuisance to be ignored.