frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Demonstrably Secure Software Supply Chains with Nix

https://nixcademy.com/posts/secure-supply-chain-with-nix/
26•todsacerdoti•2h ago

Comments

beardedwizard•45m ago
The bummer about lots of supply chain work is that it does not address the attacks we see in the wild like xz where malicious code was added at the source, and attested all the way through.

There are gains to be had through these approaches, like inventory, but nobody has a good approach to stopping malicious code entering the ecosystem through the front door and attackers find this much easier than tampering with artifacts after the fact.

yencabulator•38m ago
I think a big part of the push is just being able to easily & conclusively answer "are we vulnerable or not" when a new attack is discovered. Exhaustive inventory already is huge.
XiZhao•37m ago
I run a sw supply chain company (fossa.com) -- agree that there's a lot of low hanging gains like inventory still around. There is a shocking amount of very basic but invisible surface area that leads to downstream attack vectors.

From a company's PoV -- I think you'd have to just assume all 3rd party code is popped and install some kind of control step given that assumption. I like the idea of reviewing all 3rd party code as if its your own which is now possible with some scalable code review tools.

sollewitt•12m ago
Valuably you also get demonstrable _insecure_ status - half the pain for our org of log4js was figuring out where it was in the stacks, and at which versions. This kind of accounting is really valuable when you're trying to figure out if and where you are affected.

An update on the OSU-OSL funding situation

https://discourse.osgeo.org/t/re-hosting-future-of-osl-in-jeopardy/146960
2•zinekeller•2m ago•0 comments

DuckDB: H3

https://duckdb.org/community_extensions/extensions/h3.html
1•tosh•6m ago•0 comments

Create a new type of PKM for everyone

https://www.vetis.ai/
1•AiVetis•11m ago•0 comments

Several conferences relocate north of the border as Canadians refuse U.S. travel

https://www.cbc.ca/lite/story/1.7531255
1•colinprince•12m ago•0 comments

We built C1 – an OpenAI-compatible LLM API that renders real UI instead of md

1•rabisg•14m ago•0 comments

Linux Kernel Exploitation Series

https://r1ru.github.io/categories/linux-kernel-exploitation/
1•hkopp•18m ago•0 comments

Rescission of Recordkeeping on Restricted Pesticides by Certified Applications

https://www.federalregister.gov/documents/2025/05/12/2025-08220/rescission-of-recordkeeping-on-restricted-use-pesticides-by-certified-applications
1•impish9208•18m ago•0 comments

Byte Latent Transformer: Patches Scale Better Than Tokens

https://arxiv.org/abs/2412.09871
1•dlojudice•21m ago•1 comments

Hacker News Dark Mode (Chrome Extension)

https://chromewebstore.google.com/detail/hacker-news-dark-mode/jnmbfobflanbemhhphppnjmfhhfdkegd
2•michalpleban•21m ago•0 comments

The USA's First Pope

https://www.amazingfacts.org/media-library/first-usa-pope
1•afaxwebgirl•22m ago•1 comments

Show HN: UsePRD-Plan new features with full codebase context- drop into Cursor

https://useprd.com
1•hotrod46•24m ago•1 comments

A new type of AI is helping police skirt facial recognition bans

https://www.technologyreview.com/2025/05/12/1116295/how-a-new-type-of-ai-is-helping-police-skirt-facial-recognition-bans/
1•gnabgib•24m ago•1 comments

Combine Hash and Limited Preimage Data to Improve Security of Password Hash

https://github.com/OWASP/www-community/issues/901
1•Edmond•24m ago•0 comments

Why Magician David Blaine Fasts for Days Before His Shows

https://www.wsj.com/style/david-blaine-stunt-magic-national-geographic-do-not-attempt-c5c48582
1•elsewhen•26m ago•1 comments

Ask HN: Can On-device AI solve projected energy crisis?

1•vkkhare•29m ago•1 comments

Fingers wrinkle in the same pattern every time

https://www.binghamton.edu/news/story/5547/do-your-fingers-wrinkle-the-same-way-every-time-youre-in-the-water-too-long-new-research-says-yes
1•geox•32m ago•0 comments

Perplexity wrapping talks to raise $500M at $14B valuation

https://www.cnbc.com/2025/05/12/perplexity-funding-round-comet.html
1•mfiguiere•36m ago•1 comments

If Everyone Has Trauma, Everyone Has Trauma

https://freddiedeboer.substack.com/p/if-everyone-has-trauma-everyone-has
2•paulpauper•37m ago•0 comments

I hacked a dating app (and how not to treat a security researcher)

https://alexschapiro.com/blog/security/vulnerability/2025/04/21/startups-need-to-take-security-seriously
63•bearsyankees•37m ago•18 comments

At least five interesting things: Requiem for capitalism edition (#63)

https://www.noahpinion.blog/p/at-least-five-interesting-things-b5d
1•paulpauper•38m ago•0 comments

Show HN: Shorts Stopper – Block YouTube Shorts on Safari iOS

https://apps.apple.com/us/app/shorts-stopper/id6745517488
1•abyesilyurt•38m ago•0 comments

We built AI-powered Root Cause Analysis that works

https://coroot.com/blog/we-built-ai-powered-root-cause-analysis-that-actually-works/
2•ekiauhce•39m ago•0 comments

Microsoft shares rare look at Windows 11 Start menu designs it explored

https://www.windowscentral.com/software-apps/windows-11/microsoft-shares-rare-look-at-radical-windows-11-start-menu-designs-it-explored-before-settling-on-the-least-interesting-one-of-the-bunch
1•taubek•39m ago•1 comments

How the Net Was Won – University of Michigan Heritage Project

https://heritage.umich.edu/stories/how-the-net-was-won/
1•rbanffy•40m ago•0 comments

The Internet 1997 – 2021

https://www.opte.org/the-internet
2•smusamashah•41m ago•0 comments

Ex-UK Special Forces break silence on 'war crimes' by colleagues

https://www.bbc.com/news/articles/cj3j5gxgz0do
31•tartoran•42m ago•3 comments

Spall: A code profiler that runs in the browser

https://gravitymoth.com/spall/spall-web.html
2•surprisetalk•43m ago•0 comments

Why So Many in Gen Z Are Choosing the Creator Economy over Degrees in India

https://www.outlookbusiness.com/magazine/gen-z-is-ghosting-degrees-and-day-jobs-to-go-all-in-on-the-creator-economy-in-india
1•yarapavan•44m ago•0 comments

Show HN: I built a system to make ChatGPT brutally honest with you

https://www.honestprompts.com/
1•moobuilds•44m ago•0 comments

RIP Usenix ATC

https://bcantrill.dtrace.org/2025/05/11/rip-usenix-atc/
12•joecobb•48m ago•0 comments