frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

JumpServer: Open-Source Privileged Access Management

https://github.com/jumpserver/jumpserver
22•neitsab•2h ago

Comments

denysvitali•1h ago
I will never understand why SSH in such tools isn't native but always via some weird web UI...

I used to work for a company who allowed SSH only after jumping through Citrix => RDP => Putty => Jumphost => Target server.

Incredibly painful, also considering that each layer had a different keymap

booi•1h ago
I think that's because what you're really looking for isn't a jump server but a zero-trust network like cloudflare access or beyondcorp. You want authorized native connections, not proxies in the typical sense (although they do end up being proxies but more like a L3 proxy not L7)
jasongill•51m ago
I've been in the industry for a long, long time, and I would say that use of bastion hosts ranks #2 on my list of things that tell me your environment is not secure (right behind "we use fail2ban to protect us" as the #1 clue).

I've bought a bunch of companies and seriously evaluated hundreds of them, and the ones where people had a bastion host set up commonly seemed to act as if it protected them from everything, to the point where they just stopped worrying about security otherwise.

It gives a false sense of security and makes people put their guard down - like "OK, we have everything secured behind the firewall and only people who can log in to the bastion host, so there's no need for firewall rules or policies on the servers inside our firewall perimeter". Which inevitably breaks down over time as things get opened up to the internet, employees come and go, etc.

I can't tell you the number of companies where I look at their setup and their bastion host itself is root owned - since those hosts are always being used (and are tied to everything so you can't easily reboot or replace them), and are considered nothing more than a "tool" that you rarely actually have to look at, they don't get updated nearly enough and are neglected.

Not saying that bastion hosts are a bad idea - but just like any easy to use, easy to forget, high risk part of the stack, they are often a sign of inexperience and neglect elsewhere in the architecture.

(Yes, I know that there are plenty of big companies that use jump boxes without issue, and this jumpserver product is different, but I'm specifically talking about the idea of having one little machine that is open to SSH and then you bounce off of that to get into the "secured" machines, and all of this just based on my own experience and may not reflect yours)

observationist•19m ago
At one of the top tier 1 ISPs in the world, there was a bastion host that allowed 2 teams of network engineers unfettered access to everything; once your permissions allowed you access to the bastion, you had everything. 50 some people with trivial credentialed access to network infrastructure that the world ran on; fatfinger a bgp config and you could take down countries. Swathes of cities were regular casualities of config mistakes, and if you locked yourself out without setting a reload in 5, it'd take an hour to get someone deployed.

That experience shattered my idea that the world was being operated by competent engineers and technicians, governed by sane policies, under the watchful care of good, knowledgable people.

The world is held together by beliefs and expectations and bubblegum and duct tape, and a few thousand people madly scrambling to keep it all running.

Rocketlab acquires Iridium

https://investors.rocketlabcorp.com/news-releases/news-release-details/rocket-lab-acquire-iridium...
308•everfrustrated•6h ago•176 comments

Qwen 3.6 27B is the sweet spot for local development

https://quesma.com/blog/qwen-36-is-awesome/
404•stared•4h ago•362 comments

Ornith-1.0: self-improving open-source models for agentic coding

https://github.com/deepreinforce-ai/Ornith-1
97•danboarder•3h ago•16 comments

A native graphical shell for SSH

https://probablymarcus.com/blocks/2026/06/28/native-graphical-shell-for-SSH.html
183•mrcslws•5h ago•76 comments

WATaBoy: JIT-Ing Game Boy Instructions to WASM Beats a Native Interpreter

https://humphri.es/blog/WATaBoy/
151•energeticbark•6h ago•18 comments

JumpServer: Open-Source Privileged Access Management

https://github.com/jumpserver/jumpserver
26•neitsab•2h ago•5 comments

Wallace the 6 inch f/2.8 telescope, building it, and hiking with it

https://lucassifoni.info/blog/hiking-with-wallace/
65•chantepierre•3d ago•7 comments

Micro-Agent: Beat Frontier Models with Collaboration Inside Model API

https://vllm.ai/blog/2026-06-29-micro-agent-frontier-models
25•matt_d•3h ago•4 comments

US Supreme Court rules geofence warrants require constitutional protections

https://www.theguardian.com/us-news/2026/jun/29/supreme-court-geofence-warrants-case-decision
313•cdrnsf•5h ago•138 comments

What happens when you run a CUDA kernel?

https://fergusfinn.com/blog/what-happens-when-you-run-a-gpu-kernel/
176•mezark•7h ago•15 comments

.self: A new top-level domain designed to support self-hosting

https://hccf.onmy.cloud/2026/06/21/reclaiming-our-digital-selves-hccfs-vision-for-a-human-centere...
54•HumanCCF•1h ago•58 comments

.garden TLD's change to a bad neighborhood

https://discourse.ifin.network/t/garden-tlds-change-to-a-bad-neighborhood/627
23•speckx•2h ago•16 comments

European ISPs Want Rightsholders Held Accountable for Overblocking Damage

https://torrentfreak.com/european-isps-want-rightsholders-held-accountable-for-overblocking-damage/
263•Brajeshwar•5h ago•67 comments

You Don't Know Jack About Formal Verification

https://queue.acm.org/detail.cfm?id=3819084
71•eatonphil•6h ago•24 comments

The Radiation Exposure Lie

https://worksinprogress.co/issue/how-to-lie-about-radiation/
96•duffydotsvg•4h ago•59 comments

Sandia National Labs SA3000 8085 CPU

https://www.cpushack.com/2026/06/03/sandia-national-labs-sa3000-8085-cpu/
137•rbanffy•10h ago•38 comments

Venetian Bridge Brawls in 17th and 18th Century Art

https://publicdomainreview.org/collection/venice-bridge-fights/
48•pepys•3d ago•27 comments

Font-Family Recommendations

https://chrismorgan.info/font-family
29•birdculture•2d ago•7 comments

The Return of Aspect Oriented Programming

https://thomaswc.com/blog/the_return_of_aop.html
67•thomaswc•3d ago•48 comments

The Permission Slip

https://www.cringely.com/2026/05/28/the-permission-slip/
3•B1FF_PSUVM•2d ago•2 comments

Halvar's Guide to Entrepreneurship

https://thomasdullien.github.io/guides/entrepreneurship/
181•nekitamo•4d ago•42 comments

ACL 1.0: A source-available commercial license for the AI era

https://www.auditablelicense.org/
11•ilreb•1d ago•6 comments

Instagram is incorporating users' photos in ads for Meta Glasses

https://twitter.com/i/status/2071277885646868536
278•notRobot•7h ago•127 comments

Rebuilding the Computer Room

https://alexwlchan.net/2026/computer-room/
76•ingve•9h ago•41 comments

Samsung, SK Hynix, Micron Sued in US over Memory Price Fixing

https://en.sedaily.com/international/2026/06/29/samsung-sk-hynix-micron-sued-in-us-over-memory-pr...
278•donohoe•9h ago•141 comments

The CEO of Mullvad is the main financer of the Swedish Örebro party

https://det.social/@lostgen/116820546568940358
461•Risse•10h ago•996 comments

Tidal AI Policy

https://tidal.com/ai-policy
277•hn8726•7h ago•307 comments

Pollen tried to remove my article and Google is assisting with it

https://blog.pragmaticengineer.com/pollen-tried-to-remove-my-article-about-callum-negus-fancey-an...
827•taubek•11h ago•118 comments

CachyOS June 2026 Release

https://cachyos.org/blog/2606-june-release/
117•simonpure•7h ago•59 comments

Building Principia for Windows XP

https://voxelmanip.se/2026/06/28/building-principia-for-windows-xp/
102•LorenDB•7h ago•29 comments