frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Listen to Mixtapes from Before

https://intertapes.net/
1•poniko•1m ago•0 comments

My First Impressions of MeshCore Off-Grid Messaging

https://mtlynch.io/first-impressions-of-meshcore/
1•mtlynch•2m ago•0 comments

I built a tool to restore old family photos without ruining them with AI

https://forevi.ai
1•poznerd•2m ago•1 comments

Designing Electronics That Works

https://nostarch.com/designingelectronics
1•0x54MUR41•3m ago•0 comments

Most LLM cost isn't compute – it's identity drift (110-cycle GPT-4o benchmark)

https://github.com/sigmastratum/documentation/blob/main/sigma-runtime/SR-EI-03/benchmark_report_S...
1•teugent•3m ago•1 comments

Show HN: PlanEat AI, an AI iOS app for weekly meal plans and smart grocery lists

1•franklinm1715•4m ago•0 comments

A Post-Incident Control Test for External AI Representation

https://zenodo.org/records/17921051
1•businessmate•4m ago•1 comments

اdifference gbps overview find answers

1•shahrtjany•5m ago•0 comments

Measuring Impact of Early-2025 AI on Experienced Open-Source Dev Productivity

https://arxiv.org/abs/2507.09089
1•vismit2000•7m ago•0 comments

Show HN: Lazy Demos

http://demoscope.app/lazy
1•admtal•8m ago•0 comments

AI-Driven Facial Recognition Leads to Innocent Man's Arrest (Bodycam Footage) [video]

https://www.youtube.com/watch?v=B9M4F_U1eEw
1•niczem•8m ago•1 comments

Annual Production of 1/72 (22mm) scale plastic soldiers, 1958-2025

https://plasticsoldierreview.com/ShowFeature.aspx?id=27
1•YeGoblynQueenne•9m ago•0 comments

Error-Handling and Locality

https://www.natemeyvis.com/error-handling-and-locality/
1•Theaetetus•11m ago•0 comments

Petition for David Sacks to Self-Deport

https://form.jotform.com/253464131055147
1•resters•11m ago•0 comments

Get found where people search today

https://kleonotus.com/
1•makenotesfast•13m ago•1 comments

Show HN: An early-warning system for SaaS churn (not another dashboard)

https://firstdistro.com
1•Jide_Lambo•14m ago•1 comments

Tell HN: Musk has never *tweeted* a guess for real identity of Satoshi Nakamoto

1•tokenmemory•14m ago•2 comments

A Practical Approach to Verifying Code at Scale

https://alignment.openai.com/scaling-code-verification/
1•gmays•16m ago•0 comments

Show HN: macOS tool to restore window layouts

https://github.com/zembutsu/tsubame
1•zembutsu•19m ago•0 comments

30 Years of <Br> Tags

https://www.artmann.co/articles/30-years-of-br-tags
2•FragrantRiver•26m ago•0 comments

Kyoto

https://github.com/stevepeak/kyoto
2•handfuloflight•26m ago•0 comments

Decision Support System for Wind Farm Maintenance Using Robotic Agents

https://www.mdpi.com/2571-5577/8/6/190
1•PaulHoule•27m ago•0 comments

Show HN: X-AnyLabeling – An open-source multimodal annotation ecosystem for CV

https://github.com/CVHub520/X-AnyLabeling
1•CVHub520•30m ago•0 comments

Penpot Docker Extension

https://www.ajeetraina.com/introducing-the-penpot-docker-extension-one-click-deployment-for-self-...
1•rainasajeet•30m ago•0 comments

Company Thinks It Can Power AI Data Centers with Supersonic Jet Engines

https://www.extremetech.com/science/this-company-thinks-it-can-power-ai-data-centers-with-superso...
1•vanburen•33m ago•0 comments

If AIs can feel pain, what is our responsibility towards them?

https://aeon.co/essays/if-ais-can-feel-pain-what-is-our-responsibility-towards-them
3•rwmj•37m ago•5 comments

Elon Musk's xAI Sues Apple and OpenAI over App Store Drama

https://mashable.com/article/elon-musk-xai-lawsuit-apple-openai
1•paulatreides•40m ago•1 comments

Ask HN: Build it yourself SWE blogs?

1•bawis•40m ago•1 comments

Original Apollo 11 Guidance Computer source code

https://github.com/chrislgarry/Apollo-11
3•Fiveplus•46m ago•0 comments

How Did the CIA Lose Nuclear Device?

https://www.nytimes.com/interactive/2025/12/13/world/asia/cia-nuclear-device-himalayas-nanda-devi...
1•Wonnk13•47m ago•1 comments
Open in hackernews

MCP: May Cause Pwnage – Backdoors in Disguise

https://blog.jaisal.dev/articles/mcp
5•yk•7mo ago

Comments

mirzap•7mo ago
Lol. Can't believe I've read this. It's like saying "REST: may cause pwnage". Everything the author found troubling can be said for any API server under certain implementation (or even some frameworks and their defaults), and everything is an implementation choice, not a protocol vulnerability.
AtomicByte•7mo ago
I really don't want to waste my time explaining this to someone with clearly a subpar understanding of cybersecurity so I'll get an "AI" to:

The blog post "MCP: May Cause Pwnage" highlights critical security vulnerabilities in the Model Context Protocol (MCP) and its associated tools, such as the Inspector. These issues include default configurations that expose services to external networks by binding to 0.0.0.0, the use of GET requests for executing commands—making them susceptible to CSRF attacks—and the potential for DNS rebinding exploits due to the use of Server-Sent Events (SSE). While some may argue these are merely implementation flaws, the fact that these insecure practices are present in official SDKs and tools suggests systemic oversights in the protocol's design and default settings. Given MCP's growing adoption among major AI providers, addressing these vulnerabilities at the protocol level is crucial to ensure secure deployment and operation.

Security experts have echoed these concerns. For instance, in a podcast discussion, professionals highlighted the simplicity and severity of these exploits, emphasizing that such vulnerabilities are inherent in the protocol and its tools, not just in individual implementations. Critical Thinking - Bug Bounty Podcast

Do your research first, kids

mirzap•6mo ago
I bet you used AI to write something that sounds smart, but trust me kid, it doesn't sound that way at all.