frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Show HN: Tripwire: A new anti evil maid defense

https://github.com/fr33-sh/Tripwire
19•DoctorFreeman•1d ago•10 comments

Show HN: Autofix Bot – Hybrid static analysis and AI code review agent

9•sanketsaurav•16h ago•1 comments

Show HN: Sim – Apache-2.0 n8n alternative

https://github.com/simstudioai/sim
214•waleedlatif1•21h ago•46 comments

Show HN: Epstein's emails reconstructed in a message-style UI (OCR and LLMs)

https://github.com/Toon-nooT/epsteins-phone-reconstructed
14•toon-noot•1h ago•0 comments

Show HN: 360css CSS library inspired by the xbox360 dashboard

https://tarmo1.github.io/360css/
3•Tarmo362•1h ago•0 comments

Show HN: Workmux – Parallel development in tmux with Git worktrees

https://github.com/raine/workmux
4•rane•3h ago•0 comments

Show HN: Local Privacy Firewall-blocks PII and secrets before ChatGPT sees them

https://github.com/privacyshield-ai/privacy-firewall
103•arnabkarsarkar•2d ago•52 comments

Show HN: Jottings; Anti-social microblog for your thoughts

https://jottings.me/
13•vishalvshekkar•5h ago•10 comments

Show HN: A minimum viable Markov gibberish generator in 32 lines of Python

https://github.com/susam/mvs
3•susam•3h ago•0 comments

Show HN: Wirebrowser – A JavaScript debugger with breakpoint-driven heap search

https://github.com/fcavallarin/wirebrowser
64•fcavallarin•1d ago•15 comments

Show HN: An endless scrolling word search game

https://endless-wordsearch.com
23•marcusdev•1d ago•13 comments

Show HN: GPULlama3.java Llama Compilied to PTX/OpenCL Now Integrated in Quarkus

22•mikepapadim•22h ago•5 comments

Show HN: Gotui – a modern Go terminal dashboard library

https://github.com/metaspartan/gotui
36•carsenk•17h ago•12 comments

Show HN: A 2-row, 16-key keyboard designed for smartphones

https://k-keyboard.com/Why-QWERTY-mini
79•QWERTYmini•1d ago•67 comments

Show HN: Gemini Pro 3 imagines the HN front page 10 years from now

https://dosaygo-studio.github.io/hn-front-page-2035/news
3314•keepamovin•2d ago•956 comments

Show HN: Automated license plate reader coverage in the USA

https://alpranalysis.com
235•sodality2•1d ago•142 comments

Show HN: I want to democratise Bloomberg Terminal

https://www.aulico.com/workspaces/new
2•lalalerodas•10h ago•1 comments

Show HN: AlgoDrill – Interactive drills to stop forgetting LeetCode patterns

https://algodrill.io
177•henwfan•3d ago•105 comments

Show HN: I built a system for active note-taking in regular meetings like 1-1s

https://withdocket.com
173•davnicwil•3d ago•130 comments

Show HN: Search the lyrics of 500 HÖR Berlin techno sets

https://hor.greg.technology/
2•gregsadetsky•12h ago•2 comments

Show HN: The world's least deterministic programming language

https://github.com/andr3wV/VibeScript
4•andr3wV•12h ago•0 comments

Show HN: Forecaster Arena – Testing LLMs on real events with prediction markets

https://forecasterarena.com/
3•setrf•13h ago•0 comments

Show HN: A Real-Time 4D Fractal Explorer in the Browser Using WebGPU

https://bryanjj.github.io/nebula/
2•bryan0•16h ago•1 comments

Show HN: A lightweight Git history explorer written in Go

https://github.com/thiagokokada/gitk-go
3•kokada•16h ago•0 comments

Show HN: I used Gemini 3 to turn 42 books into interactive webpages in 2 weeks

https://www.vibary.art/en
8•Rand_cat•19h ago•2 comments

Show HN: DuckDB for Kafka Stream Processing

https://sql-flow.com/docs/tutorials/intro/
76•dm03514•3d ago•13 comments

Show HN: Mycodosing.wtf – Research‑Informed Psychedelic Dosage Calculator

https://mycodosing.wtf/
5•ing-norante•20h ago•2 comments

Show HN: Open-source UI components for apps that run inside ChatGPT

https://ui.manifest.build
3•stosssik•20h ago•0 comments

Show HN: I built a WebMIDI sequencer to control my hardware synths

https://www.simplychris.ai/droplets
2•simplychris•20h ago•0 comments

Show HN: MCPShark – Traffic Inspector for Model Context Protocol

33•mywork-dev•1d ago•4 comments
Open in hackernews

Show HN: Tripwire: A new anti evil maid defense

https://github.com/fr33-sh/Tripwire
19•DoctorFreeman•1d ago
If you have heard of [Haven](https://github.com/guardianproject/haven), then Tripwire fills in the void for a robust anti evil maid solution after Haven went dormant.

The GitHub repo describes both the concept and the setup process in great details. For a quick overview, read up to the demo video.

There is also a presentation of Tripwire available on the Counter Surveil podcast: https://www.youtube.com/watch?v=s-wPrOTm5qo

Comments

sandworm101•1h ago
This isnt a tripwire. This is a canary. You have to actively check a canary. A tripwire would send notifications in real time without the user needing to check.

An evolution of this would be to put a server on a different network, a remote location, and have it pump out warnings the moment movement was detected and/or contact with the "tripwire" system was lost.

But the best way of preventing evil maid attacks remains knowing your hardware. Anyone trying to swap out my laptop, or open it, is going to have a problem replicating my scratch marks, my non-standard OS boot screen, or prying out the glue holding in the ram modules (to prevent cold boot attacks).

ramses0•28m ago
I was sure I'd made a comment like this before, but I'd love some sort of home-spun setup like this: https://news.ycombinator.com/item?id=2465687 ...hood, tuck, john. (2x local, 1x remote) which constantly rotated roles as to who was primary/secondary.

Basically core "chaos-infra" for your home setup(s). Hood/Tuck switch between primary and secondary, always trying to stay in touch with "John" (offsite), maybe like a primitive etcd for home automation/monitoring/backup/file-serving. Green==3good, Yellow=degraded[local|remote], Red=single-point-of-failure, Black=off/not-serving.

Other funsie to think about is getting a thumbprint/PIN-locked USB-drive to hold/unlock `~/.passwordstore/*.gpg` so that even on power-outage/reboot you'd need to physically "re-auth" to unlock important secrets.

Something like this would fit nicely into this (imaginary) setup!

sandworm101•7m ago
I had a professor once ask about the strip of duct tape across the back of my brand new laptop. "Well, thieves cannot pawn electronics with cracked cases. So all my laptops have at least some tape so they think it may be cracked." The next lecture, the prof had a strip of masking tape on his laptop too.

But slap a tux logo and an "i l9ve truecrypt" banner on you device and nobody short of the NSA would even attempt a maid attack.

voxadam•1h ago
For a second I thought Tripwire, Inc.[0] had risen from the dead with a new IDS.

[0] https://en.wikipedia.org/wiki/Tripwire_(company)

Eduard•1h ago
I guess this is actually not an anti evil maid defense.

It's rather an anti evil maid tool, or an evil maid defense. :)

sorry for being pedantic, but with the arms race within cybersecurity, "anti something defense" sounds like double negation to me.

bflesch•50m ago
The bullet point stating that tripwire was built for "High-ranking officials in businesses/organizations" should be removed, because that group is very unlike the "Developers of critical software", "Investigative journalists", and "Attorneys with high-profile clients" which are also mentioned.

Everybody who had the pleasure to work with "high-ranking officials in businesses/organizations" knows that this group is the one who overrides many technically optimal decisions and thinks internal policies do not apply to them. Their lives are not affected if a device is compromised because they are financially stable and can just blame an intrusion on the IT team.

neuralkoi•37m ago
The author did an excellent job explaining what an evil maid attack is, but a very poor job of explaining how their proposal mitigates such attack.

I think the classic "Detecting unauthorized physical access with beans, lentils and colored rice" [0] approach is simpler to understand and simpler to implement. It doesn't rely on any hardware, such as a Raspberry Pi or otherwise technology which can be more easily subject to scrutiny via Ken Thompson's "Reflections on Trusting Trust".

[0] https://dys2p.com/en/2021-12-tamper-evident-protection.html

guerrilla•13m ago
Just so you know, this name is already taken by a famous security product for intrusion detection.

https://en.wikipedia.org/wiki/Tripwire_(company)

https://en.wikipedia.org/wiki/Open_Source_Tripwire

QuadmasterXLII•4m ago
as well as https://en.wikipedia.org/wiki/Tripwire ;)
pyrolistical•4m ago
For high sec people, they should have an internal sec camera system. They are have come down in price over time