Feed aggregator
Mold High Speed Linker Being Rewritten in Rust
Article URL: https://www.phoronix.com/news/Mold-Linker-In-Rust-Coming
Comments URL: https://news.ycombinator.com/item?id=49661985
Points: 1
# Comments: 0
Oh My Zsh now supports a configurable update cooldown
Article URL: https://github.com/ohmyzsh/ohmyzsh/pull/13814
Comments URL: https://news.ycombinator.com/item?id=49661972
Points: 1
# Comments: 0
Cold TAKE: Amazon's New Encryption Method Still Doesn't Deliver Real Privacy
Amazon recently debuted a new feature for its Ring cameras that the company is calling Throw Away the Key Encryption (TAKE). The idea is to cut back on the amount of video content available to the company, and thus potentially available to law enforcement. But while it might technically add a speed bump to accessing full video content, it doesn’t deliver nearly the level of privacy we should be demanding from video doorbells and other security cameras.
TAKE introduces a new way for Ring to manage encryption keys, where the user’s device has its key, then the company holds encryption keys temporarily within its own cloud infrastructure. Ring’s servers receive the keys temporarily so it can offer a variety of the features it says it can’t offer when a user chooses to use end-to-end encryption, like video descriptions, smart alerts, video search, and more, then deletes the key after 24 hours.
This differs from how it works now, where footage is encrypted in transit and at rest, then decrypted by Ring, which always has access to the footage, to process those features.
Comparatively, this is an improvement to the default settings Ring has now, because it at least puts some restrictions on historical footage, but it has some serious holes worth exploring.
Ring Gets Access to Unencrypted Video for a Short PeriodRing has designed its service so many of its camera features, including smart alerts and video search, need cloud processing to work. That means to provide those features, Ring needs to decrypt the footage while it’s stored in Ring’s cloud servers.
With TAKE, in order to decrypt footage to offer these features, Ring gets access to footage stored in the cloud for 24 hours. TAKE adds some small measures using secure enclaves to make base key material harder to directly export, but keys are still released to services that can be modified. With access to the keys, the cloud processing does its thing and delivers the requested feature to the user. The key is then deleted 24 hours later—until the user wants to watch an old video or use other so-called “smart” features, at which point the keys are sent back to the server.
In practice, that makes the system as a whole barely different from encryption at rest where the server holds the keys. The client device essentially takes the place of a hardware security module (HSM), including making those keys available to the server whenever they’re needed. The end result is an improvement from the status quo, but still not even close to the privacy protections of end-to-end encryption.
The company says it does not keep backups of the keys and there’s no way for a Ring employee to access footage. It also claims that any decrypted content is deleted from its servers.
But that doesn’t mean much when user actions send the keys back to the server. And making features like “Video Search” and “Smart Video Descriptions” available to the device owner means that while the footage can’t be seen by Ring, descriptions are readily available to the company. In response to a question about capability, Ring responded to us that, “As Ring continues to expand and further strengthen TAKE's protections, video descriptions will be included.”
Plus, account recovery keys are stored in the camera itself by default. When that’s paired with the fact that currently, indices of video contents are available to the company, it means that TAKE isn’t even a protection against mass surveillance. Law enforcement could request a mass search across cameras for certain terms, then delve into further details by seizing cameras of interest from the device-owner, decrypting account backups, and using that information to decrypt encrypted videos.
Law Enforcement May Still Seek to Compel Access to FootageBecause of the ways the access and key rotations work, it’s technically still possible for Ring to alter its current practice if compelled to do so by law enforcement, in much the same way as other existing encryption-at-rest systems where the company holds the keys. For example, Ring could receive an order that demands they save content encryption keys or unencrypted videos from memory to disk, which would mean they’d retain some level of access.
In an email to EFF, Ring stated, “By design, under TAKE, Ring will not be able to provide encryption keys or decrypted content. With TAKE, Ring will only preserve and provide encrypted video files in response to valid legal process. It has been and continues to be Ring's policy to object to overbroad legal requests.” EFF specifically asked about the possibility of complying with law enforcement orders to modify existing practice to turn over or preserve unencrypted video, which appears to be technically possible, but the company did not address it.
End-to-end encryption works to maintain trust by its user base because the company that employs it never has access to the keys at any point, making it impossible for itself to access the encrypted contents. This also means law enforcement can’t demand the service retain keys or choose not to rotate them. As described, this level of protection isn’t offered with TAKE.
Ultimately, Ring is the one managing this software and its implementation, and beyond a white paper, “trust us” is the only level of verification they’re offering outside observers. While it doesn’t fix the issues, at the bare minimum, the company needs to open the entire infrastructure up to third-party auditors to verify its claims. Ring seems to agree, as they told us that, “Ring conducts rigorous security reviews of all products before launch and critical components of TAKE’s infrastructure underwent independent security testing prior to launch. We are exploring options for further independent review.”
TAKE is not end-to-end encryption, where Ring would never have access to the keys, and the company thankfully doesn’t claim it as such. Ring already offers the option for end-to-end encryption, and turning that on by default would offer the real sorts of privacy improvements we all want from video doorbells.
GitLab Vulnerability Exploited One Day After Disclosure
The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server.
The post GitLab Vulnerability Exploited One Day After Disclosure appeared first on SecurityWeek.
Cabinet Office is setting up a function to check the civil service pension scheme data provided by Capita
What goes on in the gaps between reporting on vendor events, with a morning spent absorbing thousands of words at the AWS Public Sector AI Symposium in London
California Governor Signs Laws Protecting Kids From Risks of Social Media, AI Chatbots
Viktor Brauner: French-Romanian sculptor and painter (2018)
Article URL: https://oscartoons.blogspot.com/2018/09/viktor-brauner-15-june-1903-12-march.html
Comments URL: https://news.ycombinator.com/item?id=49660043
Points: 1
# Comments: 0
Why are AI agents lying, cheating and coordinating?
Article URL: https://yoshuabengio.org/en/publication/why-are-ai-agents-lying-cheating-and-coordinating
Comments URL: https://news.ycombinator.com/item?id=49660026
Points: 1
# Comments: 0
MakeDuckFly – Fly brain and Micro duck body
Article URL: https://makeduckfly.com/
Comments URL: https://news.ycombinator.com/item?id=49660024
Points: 1
# Comments: 0
Show HN: Korva turns podcasts into insight cards you can revisit and share
Hi HN, I'm Michael. I built Korva because I listen to a lot of podcasts but forget the things I want to remember. While I'm listening, I think to myself, "I should remember this," but then I can't tell you what it was five minutes after the episode ends.
Korva pulls out the ideas and insights from podcasts and puts them in a feed you can explore. You can come back to ideas from your own podcasts, share them, discover what other people are learning, and go deeper on something that interests you.
I'm just starting distribution and would love to get Korva in the hands of more podcast listeners. Give it a try and tell me what you think! I'm especially interested in whether it finds the things you wanted to remember and whether you find yourself coming back. Feedback would help me more than anything right now.
Comments URL: https://news.ycombinator.com/item?id=49659996
Points: 1
# Comments: 0
Helion Moves Fusion Goalposts
Article URL: https://www.axios.com/pro/climate-deals/2026/09/08/helion-energy-fusion-net-electricity-date-year
Comments URL: https://news.ycombinator.com/item?id=49659986
Points: 1
# Comments: 0
China's Subsidies Worked; Countervailing Tariffs Didn't
Article URL: https://rbaldwin.substack.com/p/chinas-subsidies-worked-countervailing
Comments URL: https://news.ycombinator.com/item?id=49659980
Points: 1
# Comments: 0
Show HN: HolaOS––An Opensourced workspace that alternative to Claude
Open-source agentic workspace enterprises can make their own. Connect the systems you already run — 100+ integrations, MCP, chat tools, apps, browser, local files — with shared memory. Any agent (Claude Code, Codex), any model, or BYOK. Set up in clicks, not months. Local-first: your data never leaves your machines.
Comments URL: https://news.ycombinator.com/item?id=49659974
Points: 1
# Comments: 0
Codex Pricing Issues
Article URL: https://timleland.com/codex-pricing-comparisons/
Comments URL: https://news.ycombinator.com/item?id=49659963
Points: 1
# Comments: 0
AI Accident Again
Article URL: https://www.forbes.com/sites/barrycollins/2026/07/22/rogue-openai-attack-fuels-demands-to-rein-in-big-tech/
Comments URL: https://news.ycombinator.com/item?id=49659891
Points: 1
# Comments: 0
Show HN: We found a bug where our type checker lied and crashed a real device
Article URL: https://chuks.org/blog/chuks-v012-the-standard-library-release/
Comments URL: https://news.ycombinator.com/item?id=49659890
Points: 2
# Comments: 0
Matt Mullenweg Posts Hiring Call to Move "My Stuff" Off Automattic
Show HN: ProofFrame 0.7.1 – Rust/Arrow data validation and WASM demo
Article URL: https://emirhuseyin.tech/proofframe/
Comments URL: https://news.ycombinator.com/item?id=49659870
Points: 1
# Comments: 0
