frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Rampart: Browser native on-device PII radaction

https://ndstudio.gov/posts/say-hello-to-rampart
15•nateb2022•22h ago

Comments

iAMkenough•29m ago
So that’s why big ballz stole our PII via DOGE’s starlink terminal
sgnelson•19m ago
The skeptic in me really can't trust our current government to protect my information.
BowBun•15m ago
Good thing you don't need much trust in this case. Source available here - https://github.com/nationaldesignstudio/rampart

I suppose the model could be doing stuff, but you can also switch that out for your own with the source.

goodmythical•4m ago
I mean, it can be run locally, so you don't necessarily have to trust it, unless there's been any model-as-a-vector CVE.

That hasn't happened yet, has it? Where running a model from HF directly compromises the machine as opposed to some breakout or exfil done by the model after the fact?

That said, if you're filing your taxes or have a 'real' ID, the government already has all pertinent information required to fuck you over either deliberately or via a leak, so...

dwa3592•2m ago
I have worked in this field and I am the author of this package - https://github.com/deepanwadhwa/zink

A few things jump out since this is done by the government:

- the lowest hanging fruit for this problem is to clearly tell people (citizens) not to share any personal info with chatbots which can cause financial harm or identity theft. the example on the page shows a person sharing their SNN with a chatbot to help them find an apartment - "My name is Maria Garcia, my Social Security number is 123-45-6789, and I make $1,950 a month. Can you help me find affordable housing?" - why?? this is the opposite of what i would expect a government to advise their citizens.

- it's never too late for a good policy; the government should have extended HIPPA and other data privacy laws to AI companies - the AI company must not store anyone's SSN, no matter how stupid the user is. It should be on the AI company to not store it; so this type of layer should be on the AI company's side.

- technical; there are quasi identifiers of privacy (that's what my package targets) that are asymptotically hard to to deal with - meaning - if you remove everything that can leak your privacy the text would become meaningless. i don't think rampart can solve for that either and it should be clearly said on the website.

bob1029•2m ago
I have presented approaches like this to banking clients and they are still not very interested. The only thing that makes these people happy is zero data retention and deterministic redaction at the source. Regex over arbitrary string literals does not represent determinism in this context.

If your product is handling natural language conversations from end customers, there is not much you can do to prevent the occasional PII leak without ruining the rest of the pie. ZDR is your best mitigation if you actually want the magical AI experience to work the way the investors hope it can.

PII can often become disclosed by way of many correlated factors that are not considered PII on their own. Even a perfect AI system cannot capture all of these relationships. You could probably locate where I live within a 20 mile radius if you spent enough time analyzing my HN comments over the years. Not one of these comments on their own would trigger a PII filter.

Bitwarden Dual License Model

https://community.bitwarden.com/t/published-version-update-in-app-stores/102750
107•Cider9986•1h ago•50 comments

Talorys – A self-hosted personal AI agent on Cloudflare's free tier

https://github.com/rociiu/talorys
121•rociiu•5h ago•62 comments

Rampart: Browser native on-device PII radaction

https://ndstudio.gov/posts/say-hello-to-rampart
15•nateb2022•22h ago•7 comments

REA Reverse – Engineer Anything

https://rea.tools/
562•modinfo•15h ago•245 comments

Telegram Desktop vulnerability allowed any user's file to be stolen

https://beaksec.github.io/posts/telegram-desktop-one-click-account-takeover/
294•g-b-r•12h ago•148 comments

Cloudflare acquires Deno

https://deno.com/blog/cloudflare
1301•ilreb•1d ago•669 comments

Triple-A Minesweeper

https://minesweeper.mikelacher.com/
1186•robin_reala•1d ago•233 comments

`123456' password used in Danish CPR data breach

https://cphpost.dk/2026-10-10/news/round-up/123456-password-used-in-massive-danish-cpr-data-breach/
296•baal80spam•6h ago•166 comments

Mxc: Microsoft Execution Containers version 1.0.0

https://blogs.windows.com/windowsdeveloper/2026/10/07/microsoft-execution-containers-policy-drive...
29•smokel•1d ago•1 comments

My personal AI agent posted my bank details on company Slack

https://www.businessinsider.com/personal-ai-agent-grok-bot-posted-bank-details-company-slack-2026-10
26•bhrlady•1h ago•21 comments

Eye of Sauron: Long-Range Hidden Spy Camera Detection (2024)

https://www.usenix.org/conference/usenixsecurity24/presentation/zhang-qibo
237•ortusdux•2d ago•49 comments

WSL3 Performance is about 5-60% faster than WSL2 depending on the workload

https://tonym.us/wsl2-vs-wsl3-benchmarks.html
158•tonymet•2d ago•119 comments

Chernobyl particles reveal unexpectedly stable nuclear fuel after 40 years

https://phys.org/news/2026-10-chernobyl-particles-reveal-unexpectedly-stable.html
64•geox•3d ago•16 comments

Apple/macOS silently removed from official Unix registry

https://www.opengroup.org//openbrand/register/
118•john_alan•4h ago•121 comments

Can you use autoregressive diffusion to generate market data?

https://blog.janestreet.com/can-you-use-autoregressive-diffusion-to-generate-market-data/
144•jsomers•1d ago•41 comments

Noto means "no tofu": fixing dotted circles in Myanmar text

https://www.datocms.com/blog/handling-less-common-scripts
35•steffoz•3d ago•20 comments

Show HN: Carrier-Explode: iPhone, Pixel and Galaxy carrier settings decoded

https://carrierexplode.com/
377•simplyalec•21h ago•45 comments

Compiling Rust to readable C with Eurydice

https://lwn.net/Articles/1055211/
114•peter_d_sherman•16h ago•33 comments

Whooping Cranes Learned to Migrate by Following Costumed Pilots

https://theverifiedpost.com/article/whooping-cranes-ultralight-costumed-pilots-operation-migration
5•kgolubic•1d ago•0 comments

How to head into VR without wearing a headset

https://www.kyushu-u.ac.jp/en/researches/view/414/
57•Betelbuddy•3d ago•27 comments

Clinical trial of a prion disease drug candidate begins enrolling participants

https://www.broadinstitute.org/news/clinical-trial-prion-disease-drug-candidate-begins-enrolling-...
125•luu•16h ago•31 comments

Typesafe AI raises $870M at $7.5B

https://typesafe.ai/blog/series-ai
412•tosh•22h ago•326 comments

What mathematicians should know about the Lean Theorem Prover: reliability & AI

https://terrytao.wordpress.com/2026/10/09/what-mathematicians-should-know-about-the-lean-theorem-...
162•matt_d•22h ago•42 comments

Computers Cannot Make Decisions

https://wiki.cateat.fish/art:computers_cannot_make_decisions
161•heavensteeth•10h ago•135 comments

Cube Type – Isometric Typography Generator

https://typeincube.com/
44•eustoria•1d ago•10 comments

Pointing AI at archives found a forgotten meteorite, lost rhinos, and more

https://jessewaites.com/blog/post/i-pointed-ai-at-400-years-of-archives/
172•piratebroadcast•1d ago•88 comments

C for Rust Programmers

https://bd103.dev/blog/2026-10-07-c-for-rust-programmers/
71•xyproto•2d ago•61 comments

Timestamping a Giant Record of the Web

https://projecttimestamper.org/blog/common-crawl/
14•arthuredelstein•1d ago•0 comments

'Wallace and Gromit,' 90% Alone

https://animationobsessive.substack.com/p/wallace-and-gromit-90-alone
259•vinhnx•1d ago•41 comments

Show HN: Proton Drive for Linux

https://oss.lsantos.dev/proton-drive-linux-fs/
110•khaosdoctor•2d ago•39 comments