Hacker News

New stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. LensVLM: Compressing long context as images, expanding only relevant pages(huggingface.co)
    discuss
  2. Ask HN: Do you offload your coding to AI, or keep your skills sharp?
    discuss
  3. Can internal model transparency tame the AI race?(karthiktadepalli.com)
    discuss
  4. The meta-harness for coding agents(soloterm.com)
    discuss
  5. Show HN: Jev-mice – mouse colony simulation using Jev and deterministic engine(carsonsweet.com)
    discuss
  6. Discover Solo: The Ultimate AI-Integrated Control Panel(master.dev)
    discuss
  7. Steam Frame Teardown(ifixit.com)
    discuss
  8. SpaceX Starshield(wikipedia.org)
    discuss
  9. Mexican Navy's tall ship Cuauhtémoc will be at the Embarcadero all week(kqed.org)
    discuss
  10. A Worthwhile Trade(nejm.org)
    discuss
  11. Loopjacking in A2A Implementations: Hijacking Human-in-the-Loop Approvals(adithyanak.com)
    discuss
  12. How AI Helps and Hampers Junior Workers(nominalnews.com)
    discuss
  13. Jackrong/Qwopus3.8-27B-Flash-V2(huggingface.co)
    discuss
  14. Nemotron 3 Diarization(huggingface.co)
    discuss
  15. CKKS – Encryption and Decryption(jeremykun.com)
    discuss
  16. What AI pays the people who train it(dpdns.org)
    discuss
  17. Cloud Agents Are Inevitable AI Prisons(normanponte.io)
    discuss
  18. Ask HN: Why so many dead comments lately?
    discuss
  19. Illinois, California governors fast-track AI safety measures with EOs(transparencycoalition.ai)
    discuss
  20. Gvnr(gvnr.io)
    discuss
  21. HySparse2: Hybrid Sparse Attention with Two-Level KV Sharing(arxiv.org)
    discuss
  22. The Vigilante Who's Taking Down Recruitment Scammers, One Fake Job Ad at a Time(wsj.com)
    1comments
  23. Pretraining data, not verifiability, is why LLMs are good at math (and coding)(lesswrong.com)
    discuss
  24. Microsoft Publisher will no longer be supported after October 2026(support.microsoft.com)
    1comments
  25. When AI makes challenging last-minute requests no human client cares about(twitter.com/lauren_wilford)
    discuss
  26. Facing Congressional Scrutiny, Flock Details New Search Guardrails(wsj.com)
    discuss
  27. A quadruped robot designed to complete a marathon on a single battery charge(nature.com)
    discuss
  28. Swap, ZRAM, Zswap and Hibernate on NixOS(matthewbrunelle.com)
    discuss
  29. Claude discovers a novel enzyme system with CRISPR-like repeats(anthropic.com)
    discuss
  30. Introducing HLE-Diamond – Humanity's Last Exam(lastexam.ai)
    discuss

Radicle: Disclosure of Vulnerability in the Network Protocol

64 pointsby 3h agoradicle.dev
22 comments
2h agoHN ↗

I honestly thought there would be some elaborate chain there, not "we forgot to use encryption"...

2h agoHN ↗

Honestly issues like this crop up pretty commonly. JWT alg:none for example. Or even older people forcing SSL to downgrade to encryption null.

In any system that provides security it should only be designed to run if the security is in use, and to fail immediately with no further action if the security is not used.

1h agoHN ↗

And not using authentication.

Peer authentication in the connection handshake is broken and allows impersonation. An attacker can connect to your node and present a Node ID that is not its own. Private repositories are shared only with allow-listed Node IDs. An attacker who fakes an allow-listed Node ID can fetch a private repository directly, without being on the network path. This was reported to us by cryptocode on 2026-08-12. We proposed a fix upstream, see this pull request.

They are trying to sweet write it as much as possible. But basically there is neither encryption nor authentication. The person who made the protocol/program simply didn't care.

1h agoHN ↗

I find this to be very telling about what kind of people they are. If you make a mistake this big you need to own up to it. BS all you want, maybe you think that works for you.. but people see through it.

2h agoHN ↗

My main wish is if radicle had a way to make issues online, without installing the software. Runing a piece of software is a high barrier of entry to make a bug report, which the entire reason I use codeberg instead.

2h agoHN ↗

That's a downside of all decentralised software, isn't it? If there's a convenient access point, that access point is also a point of centralisation. To be distributed, you have to be running the software yourself. The big problem is that the software always ends up being inconvenient. People have no problem using bittorrent because the software is actually usable.

1h agoHN ↗

Like onion/ipfs/many others, I'd expect gateways to pop up if it grows relatively popular. If LLM scrapers don't destroy them immediately, at least.

2h agoHN ↗

This was reported to us by Konstantinos Maninakis on 2026-06-24.

announcement 3 months later is not super great, considering that the current advice is "Stop using private repositories (over the network) until the security update is released."

55m agoHN ↗

I was floored that they emailed me about it for the first time today saying "of course you already know all the details from the blog post".

Me: "No!"

1h agoHN ↗

you're right! i can't believe i only noticed that just now, thanks!

1h agoHN ↗

Is there a risk that other projects that may be using the same cyphernet-labs/netservices.rs code, like Nym & Farcaster, have also been expecting authentication & encryption where it hasn't been happening?

1h agoHN ↗

This whole project reads like amateur hour. Still using curl pipe to shell install and everything. Plus this lax security disclosure with just an outstandingly foolish security flaw. Gross.

31m agoHN ↗

It's a team of 3. It's not like they have a security team, dedicated testers. They were for very long released beta software. That in fact already worked.

1h agoHN ↗

The fact that this was reported three months ago and the "workaround" is to stop using private repos and assume they are all pwnd is quite something. How do you not notice that cross-node traffic is not encrypted when building something like this?

55m agoHN ↗

What is the issue?

Network traffic between nodes is not encrypted and not authenticated.

Oh.

After all of the work they put into using cryptographic identities and decentralization tricks, how did they forget to do anything about the network traffic?

Was this a case of thinking they'd handle it later, but then it fell off the TODO list?

34m agoHN ↗

Reading the blog, it sounds more like they were depending on libraries (both by Cyphernet, interestingly) and implicitly trusting them, instead of verifying.

Which I can understand to an extent with large, high-traffic dependencies but these were really low traffic projects with like 10 stars on github and barely any development... Well, hindsight is 20/20.

10m agoHN ↗

Glad to hear they are moving to iroh instead of a custom protocol. This is the problem with rolling your own stuff.

As a bonus, this should help camouflage the traffic. (Iroh is becoming more common.)