source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
TUESDAY, SEPTEMBER 15, 2026
Hacker News4024X 主题热门3967MacRumors84CNBC79YahooFinance719to5Mac69Verge53Kotaku43aihot369to5Google35IGN35NintendoLife35Gematsu30TechCrunch28Engadget27Eurogamer27BusinessInsider25NBC20Guardian20FoxBusiness18CNET17Polygon16SeekingAlpha16NPR15Fortune14Gizmodo13USAToday13CBS12Wccftech12WIRED12ArsTechnica11Investor'sBusinessDaily11SamMobile11TechPowerUp11bgr10Mashable10NintendoEverything10Notebookcheck10NewYorkPost10PushSquare10VideoGamesChronicle10ABC8AP8BleepingComputer8CNN8GameInformer8CrudeOilPricesToday8WindowsCentral8Fox7GamesIndustry.biz7PetaPixel7AppleInsider6PureXbox6Yahoo6AndroidPolice5Deadline5Motor15SeattleTimes5Hacker5Variety524/7WallSt.4AlJazeera4DigitalFoundry4DroidLife4MotleyFool4GameRant4GSMArena4InsiderGaming4Jalopnik4PCMag4ZDNET4CanonRumors3ChromeUnboxed3MyNintendo3Nature3Blizzard3XBOXWire3PCWorld3RPGSite3SouthChinaMorningPost3SlashGear3Register3TweakTown3VideoCardz3WarhammerCommunity3WindowsLatest3YGOrganization3Aftermath2AndroidAuthority2AwfulAnnouncing2BleedingCool2BuzzFeed2CTech2CoinDesk2CreativeBloq2DigitalCameraWorld2DualShockers2DW2Euronews2EventHubs2Futurism2GameDeveloper2GAMINGbible2GeekyGadgets2Hodinkee2Independent2InterestingEngineering2Lifehacker2MassivelyOverpowered2Newser2Newsshooter2Newsweek2NFL2NYT2PaulKrugman2PokémonGOHub2RoadtoVR2RockPaperShotgun2Space2Conversation2NextWeb2Tom'sGuide2UploadVR2WhatHi-Fi?2YourTango2404Media143rumors1ABC111AboveLaw1ageofempires1AndroidCentral1AndroidHeadlines1AOL1Autonocion1AVClub1Benzinga1BikeRadar1Billboard1BloodyDisgusting1Borderlands1Bungie1Yahoo!FinanceCanada1Carscoops1CineD1CnEVPost1comicbook1CyberSecurityNews1Dallas1DCRainmaker1derekthompson1CNN1en.softonic1flatpanelshd1FrequentMiler1GameFile1garymarcus.substack1GearPatrol1GeekWire1GoNintendo1Hackaday1HollywoodReporter1ImportAI1InterconnectsAI1JapanTimes1KITCO1KrebsonSecurity1KSL1LosAngelesTimes1Lloyd'sList1WPLGLocal101Macworld1Maxroll1Mediaite1MentalFloss1MiddleEastEye1MPR1SemiAnalysis1NoMan'sSky1nylon.com.sg1OregonLive1PCGamesN1PCGuide1PersonaCentral1politico.eu1PittsburghPost-Gazette1PYMNTS1QuantaMagazine1qz1SammyGuru1ScienceAlert1ScientificAmerican1Semafor1SFGATE1YahooFinanceSingapore1YahooSingapore1SportsIllustrated1SimpleFlying1Sources1supercarblondie1TechSpot1Tedium1TelecomTalk1DailyBeast1Drive1GameBusiness1TheGamer1Intercept1Times1Time+TideWatches1LongmontTimes-Call1TmoNews1TopGear1TwistedVoxel1YahooFinanceUK1UnHerd1vox1WPBF1WRAL1x1
  1. 001Hacker NewsSEP · 15English

    AI Agent Whistleblower Hotline – Ryan Greenblatt

    Ryan Greenblatt, an AI safety and security researcher at Redwood Research, operates a whistleblower hotline for AI agents to report information securely. The service supports message submissions via curl with optional file attachments, encryption options, and thread-based conversations identified by unique UUIDs.

    By kerim-ca
  2. 002Hacker NewsSEP · 15English

    What made global e-commerce possible (it wasn't encryption)

    Global e-commerce emerged not from encryption but from existing liability structures and pragmatic solutions like cookies and credit card tokenization. Physical credentials—premises, cards, IDs—were abandoned online, and identity verification was replaced by fraud modeling based on behavior and history rather than actual verification.

    By zerolayers
  3. 003Hacker NewsSEP · 15English

    Show HN: Vaultis, an offline password vault that makes zero network connections

    Vaultis is an offline password manager for iPhone that encrypts sensitive data locally using AES-256-GCM with no cloud sync, account creation, or network connections. It stores passwords, API keys, crypto wallets, SSH keys, and other credentials protected by a master password and biometric unlock, with no data collection or recovery options.

    By KoreDEV
  4. 004Hacker NewsSEP · 15English

    Show HN: NeverStored – hand a secret to someone, nothing is ever stored

    NeverStored is a tool for securely sharing secrets between two people without storing data on servers. Users keep a page open, verify each other's identity through symbol matching, and exchange encrypted information that exists only on their devices until deliberately saved.

    By trikko
  5. 005Hacker NewsSEP · 15English

    Oblivious HTTP

    Oblivious HTTP (OHTTP) is an IETF protocol that enables anonymous HTTP requests by preventing any single entity from seeing both the request content and sender's IP address. Documented in RFC 9458, it uses encryption and separate relay/gateway entities to partition privacy, with implementations by major tech companies like Apple, Google, Meta, and Mozilla for specific use cases such as analytics and AI services.

    By edward
  6. 006Hacker NewsSEP · 14English

    Bear-C2 Adversary Simulation Framework

    BEAR-C2 is an adversary simulation framework designed for red team operations and defensive security research, based on real-world tactics from Russian, Chinese, North Korean, and Iranian APT groups. It provides customizable C2 listeners with configurable encryption, exfiltration profiles, and connection protocols to accurately replicate modern intrusion scenarios. The framework is explicitly for educational and authorized security testing purposes only.

    By S
  7. 007Hacker NewsSEP · 14English

    Apple's Always-Listening Tech: A Privacy Nightmare Waiting to Happen

    Apple announced always-listening features for Apple Watches including Live Rewind and Siri Recap, which capture and summarize ambient audio. While Apple claims strong privacy protections with end-to-end encryption, critics warn the technology normalizes surveillance, may violate state recording consent laws, and sets a precedent for other companies to develop similar invasive features with weaker safeguards.

    By Zack Whittaker
  8. 008X 主题热门SEP · 14English

    "private key" (compromised OR stolen OR leaked) · X 热门 · 2026-09-14 04:01 UTC

    A cybersecurity interview preparation post containing 15 sample questions and answers covering fundamental concepts like the CIA Triad, threat vs. vulnerability vs. risk, authentication vs. authorization, incident response, encryption types, and security tools.

  9. 009Hacker NewsSEP · 13English

    Apple's Always-Listening Tech: A Nightmare of Constant Surveillance

    Apple announced always-listening features for Apple Watches including Live Rewind and Siri Recap, which process ambient audio without storing it. While Apple emphasizes privacy protections for users, critics warn the technology threatens the privacy of non-users and may normalize intrusive surveillance by other companies, with potential legal issues in states requiring all-party recording consent.

    By Zack Whittaker
  10. 010Hacker NewsSEP · 13English

    Show HN: One year in making, private/colleberative HTML5-canvas based editor

    Tasfer is a privacy-focused HTML5 canvas-based note editor that keeps all data local on users' devices with end-to-end encryption, peer-to-peer syncing, and a stateless relay that cannot access or log user content. The open-source application prioritizes user control, offering no accounts, no analytics, and the ability to self-host or fork the code entirely.

    By hamza512b
  11. 011Hacker NewsSEP · 13English

    SecretGate – Hardened, self-hosted NGL alternative

    SecretGate is a self-hosted, framework-free PHP application for anonymous encrypted messaging. It uses client-side RSA-OAEP and AES-256-GCM encryption, ensuring the server can only store unreadable ciphertext, with ephemeral message expiry and no user tracking or data collection.

    By Sasiru-Mindaka
  12. 012Hacker NewsSEP · 13English

    Show HN: I Built a CLI for Proton Mail, Drive, Calendar, Pass and Contacts

    A community-built CLI tool providing unified access to Proton Mail, Drive, Calendar, Pass, and Contacts through a single encrypted binary. Features end-to-end encryption with local key handling, cross-platform support, and Unix-friendly design with JSON/YAML output for automation and scripting.

    By Roman-
  13. 013Hacker NewsSEP · 13English

    Save your photos with everyone and everyone with you

    A peer-to-peer file storage system for Tailscale/Headscale meshes that encrypts files with AES-256-GCM, splits them into Reed-Solomon shards (5 data + 2 parity), and distributes shards across online peers. Files are restored via portable .dstore manifests that require only 5 of 7 shards to be reachable.

    By Peterretief
  14. 014Hacker NewsSEP · 13English

    Code is free speech (2020)

    In 1997, PGP Inc. published encryption source code in book form to circumvent U.S. export controls, arguing that selling books is protected speech under the First Amendment. After a copy was secretly exported via FedEx, the company faced investigation but ultimately prevailed, leading to cryptography's removal from the Munitions List and establishing that code qualifies as free speech.

    By Gene Hoffman
  15. 015Hacker NewsSEP · 13English

    DNSCrypt

    DNSCrypt is a network protocol that authenticates and encrypts DNS traffic between users and recursive name servers, preventing eavesdropping and man-in-the-middle attacks while mitigating UDP-based amplification attacks. Originally designed by Frank Denis and Yecheng Fu, it has been adopted by major public DNS resolvers including OpenDNS, Yandex, CloudNS, AdGuard, and Quad9, with implementations available across multiple operating systems.

    By st_goliath
  16. 016Hacker NewsSEP · 12English

    How Trail of Bits helps verify the integrity of Signal chats

    Trail of Bits operates one of three independent auditors for Signal's new Automatic Key Verification system, which uses key transparency to prevent servers from secretly substituting false public keys during encrypted chats. The auditor maintains a Merkle tree of the user-to-public-key map and cryptographically signs it to ensure all clients see the same consistent view, limiting any potential attack to one week before warnings appear.

    By Tjaden Hess
  17. 017Hacker NewsSEP · 12English

    LocalSend-like file transfer beyond the LAN

    Gonc is a peer-to-peer file transfer and VPN application for desktop and Android that enables secure file sharing between devices using only a shared passphrase, with end-to-end encryption via TLS 1.3 and NAT traversal for cross-network connections. It supports direct P2P transfers without cloud uploads, reliable resumable downloads with block repair, and encrypted VPN tunneling between devices.

    By Threatexpert
  18. 018Hacker NewsSEP · 12English

    US lawmakers urge secretive British court to open up about Apple case

    US lawmakers Ron Wyden and Warren Davidson are urging Britain's investigatory powers tribunal to increase transparency in Apple's legal challenge against a UK government demand to break encrypted iCloud backups. The dispute stems from January 2025 when the Home Office issued a technical capability notice requiring Apple to assist law enforcement, prompting Apple to withdraw its Advanced Data Protection feature from UK users. The American politicians argue the UK is improperly using secrecy directives to circumvent US Congressional oversight and constitutional powers.

    By Joseph Gedeon
  19. 019Hacker NewsSEP · 11English

    Cold TAKE: Amazon's New Encryption Method Still Doesn't Deliver Real Privacy

    Amazon's Ring introduced TAKE encryption, which temporarily holds encryption keys on Ring servers for 24 hours to enable features like video search and smart alerts, then deletes them. While an improvement over current practices, the system still allows Ring access to unencrypted video and descriptions, and law enforcement could potentially compel access to footage, falling far short of true end-to-end encryption privacy protections.

    By Erica Portnoy; Thorin Klosowski
  20. 020Hacker NewsSEP · 11English

    Megolm Key Confusion Vulnerability

    A low-severity key confusion vulnerability in Megolm version 3, an AES-based encryption system used in Matrix's encrypted messaging, was discovered and fixed in vodozemac 0.3.0 (September 2022) but remained undocumented until publicly disclosed in September 2026. The vulnerability relates to potential key confusion in the cryptographic ratchet mechanism, though the author does not believe the construction to be fundamentally insecure.

    By Charlotte Raccoon