惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Full Disclosure
Recorded Future
Recorded Future
T
Tenable Blog
S
Securelist
C
CERT Recently Published Vulnerability Notes
T
Threatpost
S
Schneier on Security
A
Arctic Wolf
The Hacker News
The Hacker News
C
CXSECURITY Database RSS Feed - CXSecurity.com
Know Your Adversary
Know Your Adversary
P
Privacy International News Feed
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
The Register - Security
The Register - Security
Cisco Talos Blog
Cisco Talos Blog
AWS News Blog
AWS News Blog
K
Kaspersky official blog
T
True Tiger Recordings
T
Threat Research - Cisco Blogs
V
Vulnerabilities – Threatpost
P
Palo Alto Networks Blog
T
The Exploit Database - CXSecurity.com
小众软件
小众软件
B
Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Microsoft Azure Blog
Microsoft Azure Blog
Cyberwarzone
Cyberwarzone
C
Cybersecurity and Infrastructure Security Agency CISA
T
Tor Project blog
Spread Privacy
Spread Privacy
Malwarebytes
Malwarebytes
P
Proofpoint News Feed
F
Fox-IT International blog
F
Fortinet All Blogs
P
Privacy & Cybersecurity Law Blog
G
GRAHAM CLULEY
量子位
Latest news
Latest news
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 叶小钗
Project Zero
Project Zero
T
Tailwind CSS Blog
N
Netflix TechBlog - Medium
Martin Fowler
Martin Fowler
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
I
Intezer
博客园_首页
腾讯CDC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
D
Darknet – Hacking Tools, Hacker News & Cyber Security

Hacker News: Show HN

Show HN: I built a tool to auto-accept AI slop and bigtech devs loves it GitHub - Flowtriq/ftagent-lite: Lightweight open-source DDoS traffic monitor. Stdout output, no account required Permly — Notification Manager for Android GitHub - srijanpatel/arq-dashboard: A dashboard for ARQ built with FastAPI Show HN: CredWork – a simple project tracking and showcasing tool GitHub - clark-labs-inc/clark-agent: A small, typed, hookable agent loop. Provider-agnostic, sandbox-agnostic, tooling-agnostic. Battle tested on clarkchat.com GitHub - alebeck/rhymesum: Hash files into LLM-generated poems locally GitHub - bitcreed/gsd-meta-manager: TUI command center for managing multiple GSD projects from a single terminal GitHub - oeo/monkdev: A holy, minimalist CLI toolkit and MCP server designed exclusively for LLM coding agents. Introducing vtermux – M.C. Pantz Flow Simulator Show HN: Free DNS propagation checker – 40 resolvers, TTL and response times GitHub - hamsterbase/llm-translator SetupHub - Share Your IDE Setup with the World Show HN: Zt – Expose local services via Cloudflare Zero Trust in one command Mirror — Record your workflow. Generate docs in one click. GitHub - NikhilSKashyap/interviewsignal: AI-native broad-interviewing. Share a code, capture thought process, auto-grade on submit. pip install, zero setup cost, pure signal. Stumbleback - Chrome 应用商店 OACP — Open Agent Coordination Protocol GitHub - mplsllc/macsurf: A modern web browser for Classic Mac OS 9 PowerPC. Real CSS3, ES5 JavaScript, native HTTPS — built with CodeWarrior on the Carbon API. yavchn GitHub - rishavsunny12/harvestGuard: Lets see how claude code creatively creates a project for me NES, SNES, Genesis, VirtualBoy, and PSX | A journey with AI and Recompilation GitHub - avencera/speakrs: Speaker diarization in Rust. 312–912x realtime on Apple Silicon, 50–121x on CUDA. Matches pyannote accuracy. Free Trust Center & Security Questionnaire Automation | Sekorti Open Source Windows Sandbox in Python: Run Windows 11 on Linux with SmolVM | Celesto AI Blog RetryFi — Automated Payment Recovery for Stripe Show HN: Audiogen – a new take on generative music AI Radiccio Server Show HN: A website that tracks every stock trade Congress makes Show HN: MurrDB: A RocksDB-based NVMe/S3 cache for AI inference workloads Logline Archetype Matcher: Find the Right Story Structure | Quanten Arc Préparer l'internat GitHub - ynnk-research/-NeuroFlow: Official PyTorch implementation of NeuroFlow: EMA-Gated Temporal Sequence Compression for Vision Transformers. Achieves up to 55.8x wall-clock speedup for video inference via semantic surprise routing and a training-free Dual-Memory Reconstruction Protocol. GitHub - ivoputzer/testbump: The versioning tool that will tell you if you broke your own contracts. Show HN: Vibeshub – Git for your vibe code transcripts GitHub - hieunc229/mailflare: Email client with custom domain based on Cloudflare Show HN: Private social media feed with posts only from friends GitHub - mbbill/mind-expander: A shared visual workspace for understanding and steering code with AI agents. Introducing Chunk sidecars: Inner loop validation that keeps up with your agents Cantible Show HN: Clean Gigabytes of Junk from Your Mac Show HN: We made a cinematic heist trailer with 4 AI models for $60 Show HN: MCPs aren't enough, give Codex/Claude accurate memory of everything GitHub - bogdanr/fono: Press a key, speak, text lands at your cursor. Press another, get a spoken answer. Local-first, lightweight voice dictation and assistant for Linux. Gravel · Cross-team prompt updates for vertical agents GitHub - SynapCores/synapcores-agent: Real, framework-free AI support agent where SynapCores is the brain — memory, RAG, tool routing, generation in one database. Browser chat widget + live Brain debug sidebar. Fork and run in 30s. Release v0.4.19 - Harbor Launch · av/harbor Stratus Show HN: Local-first PDF redaction for permanently removing data Kakeibo — The Mindful Budgeting App | Spend on What Matters Show HN: Compile-time model-id validation with declared capability GitHub - av/naiou: Yes/no agent Copywriting after AI Show HN: Perga, an open-source daily planner with notes Private Field Search with Local Recovery Show HN: WYSIWYG markdown editor for any GitHub repo Show HN: Raft in Rust Show HN: Treats Human and AI the Same Sifter Show HN: TypistStories Show HN: A Story Show HN: Swift-Markdown-engine – A Native macOS Markdown editor on TextKit 2 Show HN: PrismCat – Local transparent proxy and debugging console for LLM APIs Show HN: Run RL agents in the browser with WebGPU Show HN: Lavern: an open-source multi-agent legal system (Apache 2.0) Show HN: Burnrate $1M a month, backwards through time GitHub - SkepticCTO/decoding_the_language_machine: Documentation, Prompts, and Media for the "Decoding the Language Machine" series GitHub - xqb64/X: The X programming language GitHub - compuficial/apery: Synthetic Data Generator for Agents elio – Terminal File Manager with Rich Previews Rogue-Bench GitHub - mikebmac86/pviz-parser: Analyze your codebase's dependency graph and export a structured bundle — nodes, edges, metrics, and cycle detection across multiple languages Show HN: I built a tool to estimate AI agent costs before you ship Show HN: The product is (usually) SnakeOil MetaStrip — Strip Hidden Metadata from Files Show HN: My Day – daily planner to get things done Show HN: CodeGuard – defence-in-depth SSH security in one Python file Vendorlobby — Vendor pitches, on autopilot AiAffList — The Biggest AI Affiliate Programs List GitHub - its-monotype/jobzap: Chrome extension to filter irrelevant LinkedIn jobs RemotePilot — Your Private Remote Job Pilot (macOS) Show HN: Agent Launch – One CLI for Codex, Claude Code, Cursor, Gemini, OpenCode Marketing Manager Jobs | Live marketing manager roles Typerion: The coherence system for software development GitHub - NoteDance/parallel-saver: High-performance parallel save/load for large NumPy arrays using shared memory and multiprocessing GitHub - WillTaylor22/self-managing-codebase GitHub - JustVugg/judicex: Open-source Legal AI workspace for evidence-grounded legal drafting, matter analysis and verifiable answers. GitHub - hushhq/hush: End-to-end encrypted messaging, voice, and video. Entry point that orchestrates every public component. GitHub - Secure-Code-HQ/audit: Open-source CLI agent for automated Linux VPS security auditing. One command, 25 checks, zero install. GitHub - kwanUm/open-feed: Your personal dev news feed, assembled entirely in your browser. No backend, no account, no telemetry. Show HN: A small game where you have to guess the stars of GitHub repositories GitHub - rduffyuk/engineering-memory-benchmark: Empirical study: layered retrieval (typed→semantic→grep) scores 0.954 for LLM-generated engineering artifacts. 5 conditions, 3 model tiers, 36 generated ADRs, 23 score files. GitHub - lc-at/atproxy: A program to transparently proxy an Android app TCP traffic via using iptables to an HTTP proxy server upstream AI Agent Token Cost Calculator - TinyOps Studio Show HN: Presentforme.ai – Make slide decks explain themselves Show HN: A high-performance audio visualizer using Rust, WASM, and React BYOW(Build Your Own Wallet) : A Field Guide to Building MPC Wallets in 2026 - Part 1 Show HN: GPTFortress, a 24/7 live-stream playing Dwarf Fortress with GPT-5 Riot · OCaml stack
GitHub - xilioscient/troskji: Post-quantum multi-path tunnel — Hybrid KEM (X25519+Kyber-1024) · Shamir 3-of-5 SSS · BLAKE3 · XDP/eBPF cover traffic · Rust
xilioscient · 2026-05-27 · via Hacker News: Show HN

Labyrinth-Mesh

labyrinth logo

Post-quantum resilient multi-path tunnel — Hybrid KEM (X25519 + Kyber-1024) · BLAKE3 auth · Shamir 3-of-5 SSS · XDP/eBPF cover traffic · Dilithium3 identity


What it does

Labyrinth-Mesh takes any payload, splits it into 5 shares using Shamir Secret Sharing over GF(2⁸), authenticates each share with BLAKE3, negotiates the session key via Hybrid KEM (X25519 + Kyber-1024 combined), and dispatches shares over N separate UDP paths with variable jitter and independent per-share timing. The receiver needs only 3 of the 5 shares to reconstruct the original plaintext.

The session key combines X25519 and Kyber-1024 — secure against both classical and quantum adversaries. Replay protection uses a 128-bit sliding window that tolerates out-of-order UDP delivery. Each share is sent from a dedicated socket with a random delay to resist timing correlation attacks.

An optional CBR engine (XDP/eBPF, Linux ≥ 5.15) holds the bitrate constant regardless of whether real traffic is being sent.


Quickstart (3 terminals)

# T1 — receiver
labyrinth recv --ctrl 0.0.0.0:8199 --udp 0.0.0.0:8200 --mgmt 0.0.0.0:9090

# T2 — live TUI
labyrinth-tui --mgmt 127.0.0.1:9090

# T3 — sender (Ctrl+D to close)
labyrinth send --to 127.0.0.1:8199

With Docker:

./quickstart.sh          # build + start, GUI at http://localhost:8080
./quickstart.sh --stop   # stop all containers

Binaries

Binary Description
labyrinth CLI: send recv status setup
labyrinth-tui Ratatui TUI dashboard, 500ms polling
labyrinth-server Standalone management plane
labyrinth_mesh Legacy binary configured via env vars
dashboard Legacy TUI

CLI — labyrinth

labyrinth send

--to <addr>        Receiver ctrl address (hybrid KEM)  [default: 127.0.0.1:8199]
--file, -f <path>  File to send (default: stdin)
--remotes <list>   Comma-separated UDP destinations  [default: 127.0.0.1:8200]
--receiver-key     Dilithium3 fingerprint of receiver (TOFU if omitted)
--jitter-min <ms>  Minimum inter-batch jitter  [default: 200]
--jitter-max <ms>  Maximum inter-batch jitter  [default: 1200]
--stagger <ms>     Max per-share random delay (parallel send)  [default: 5]
--mgmt <addr>      Start management plane on this address

Examples:

labyrinth send --to 192.168.1.10:8199 --file secret.pdf
labyrinth send --to 192.168.1.10:8199 --remotes 192.168.1.10:8200,192.168.1.11:8200
echo "hello" | labyrinth send --to 127.0.0.1:8199

labyrinth recv

--ctrl <addr>        TCP listen for KEM key exchange  [default: 0.0.0.0:8199]
--udp <addr>         UDP listen  [default: 0.0.0.0:8200]
--output, -o <path>  Output file (default: stdout)
--sign               Generate Dilithium3 keypair and print fingerprint
--mgmt <addr>        Start management plane on this address

Examples:

labyrinth recv --output /tmp/received.pdf --mgmt 0.0.0.0:9090
labyrinth recv --sign   # prints fingerprint for --receiver-key on sender side

labyrinth status

labyrinth status
labyrinth status --mgmt 10.0.0.5:9090 --format json

labyrinth setup

labyrinth setup    # interactive wizard

TUI — labyrinth-tui

labyrinth-tui --mgmt 127.0.0.1:9090
Key Action
q / Ctrl+C Quit
p Pause / resume polling
f Failover popup (show paths)
09 Toggle path in popup
Esc Close popup
r Reset local delta counters

Web GUI

The SvelteKit GUI is available via Docker at http://localhost:8080. Shows live metrics via SSE, process logs and per-path controls (pause/resume). Supports Bearer token authentication for the management plane.


Management Plane HTTP API

Endpoint Method Description
/health GET {"status":"ok"/"degraded"/"critical", ...}
/metrics GET Session, fragment, ratchet, replay counters
/metrics/paths GET Per-path bytes/packets array
/metrics/stream GET SSE JSON stream every 1s
/metrics/rtt/p95 GET RTT 95th percentile
/logs GET Last 500 process log entries
/path/{idx}/activate POST Reactivate path idx
/path/{idx}/deactivate POST Deactivate path idx
curl 127.0.0.1:9090/health
curl 127.0.0.1:9090/metrics
curl -H "Authorization: Bearer TOKEN" 127.0.0.1:9090/metrics/stream
curl -X POST 127.0.0.1:9090/path/1/deactivate

Security Stack

Payload
  │
  ▼
GF(2⁸) Shamir SSS        n=5 shares, k=3 threshold — each byte is a point on a degree-2 polynomial
  │
  ▼
Hybrid KEM                X25519 (classical) + Kyber-1024 (post-quantum) combined
  │                        key = BLAKE3-derive(kyber_ss ‖ x25519_ss)
  │  + BLAKE3 auth tag    8 bytes per fragment, constant-time verification
  │  + Key ratchet        key rotation every 10,000 packets via BLAKE3-KDF
  │  + Replay window      128-bit bitmap: tolerates UDP out-of-order delivery
  │  + Dilithium3         optional sender identity (post-quantum signature)
  ▼
UDP multi-path            round-robin across paths, 200–1200ms jitter
  │  + parallel send      each share: dedicated socket + random delay
  ▼
XDP/eBPF cover traffic    constant bitrate (optional, Linux ≥ 5.15)

Threat model: protects against on-path DPI, temporal traffic analysis (with CBR enabled), inter-share timing correlation, replay attacks, and adversaries with quantum computers. Does not protect against physical access to the host.


Build

cargo build --workspace                   # debug
cargo build --release --workspace         # release (LTO + codegen-units=1)
cargo test -p labyrinth-core --lib        # unit tests

Key dependencies:

pqcrypto-kyber     = "0.7"   Kyber-1024 KEM (NIST PQC Level 5)
x25519-dalek       = "2"     X25519 ECDH (hybrid KEM)
pqcrypto-dilithium = "0.5"   Dilithium3 post-quantum signatures
blake3             = "1.5"   Auth tags + KDF + ratchet
sharks             = "0.5"   Shamir Secret Sharing
aes-gcm-siv        = "0.11"  Nonce-reuse resistant AEAD
aya                = "0.12"  eBPF userspace loader
axum               = "0.7"   Management plane HTTP
tokio              = "1"     Async runtime

Environment Variables

Variable Default Description
LABYRINTH_MODE send send or recv (legacy only)
LABYRINTH_CTRL 0.0.0.0:8199 TCP listen for KEM (receiver)
LABYRINTH_RECV_CTRL 127.0.0.1:8199 TCP connect for KEM (sender)
LABYRINTH_UDP_LISTEN 0.0.0.0:8200 UDP listen (receiver)
LABYRINTH_REMOTES 127.0.0.1:8200 UDP destinations, comma-separated
LABYRINTH_JITTER_MIN_MS 200 Minimum inter-batch jitter (ms)
LABYRINTH_JITTER_MAX_MS 1200 Maximum inter-batch jitter (ms)
LABYRINTH_SHARE_STAGGER_MS 5 Max per-share random delay (ms)
LABYRINTH_CBR_ENABLED false 1 → enable XDP cover traffic
LABYRINTH_CBR_BPS 0 (= 2 Mbps) CBR rate in bit/s
DMPOT_MGMT_ADDR (off) Start HTTP management plane
LABYRINTH_BIND 0.0.0.0:9090 labyrinth-server bind address

Repository Structure

labyrinth-core/        Core library
  src/
    v2/                Hybrid KEM, Shamir, BLAKE3, ratchet, replay window
    phase1/            GF(2⁸) arithmetic
    phase2/            Onion Kyber encryption
    phase3/            Protocol morphing engine (TLS1.3/QUIC/HTTP2)
    phase4/            XDP/eBPF + MultiPathController
    phase5/            Anti-debug, memory integrity
    management_plane/  Axum HTTP API + SSE
    metrics/           SharedMetrics, DashboardMetrics
    file_transfer/     FileSender / FileReceiver + BLAKE3 verify
    log_capture/       500-entry ring buffer

labyrinth-cli/         `labyrinth` CLI (clap subcommands)
labyrinth-tui/         `labyrinth-tui` TUI
labyrinth-server/      `labyrinth-server` standalone management plane

labyrinth-gui/         SvelteKit + TailwindCSS v4 web dashboard

docker-compose.yml     Backend + GUI via nginx
quickstart.sh          One-liner bootstrap