frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Show HN: Rewhois.com – RDAP Lookup Tool

https://rewhois.com
1•Airyisland•5m ago•0 comments

AMD Ryzen AI Max+ Pro 395 Linux Benchmarks: Outright Performance

https://www.phoronix.com/review/amd-ryzen-ai-max-pro-395
1•transpute•6m ago•0 comments

Ann, the Small Annotation Server

https://mccd.space/posts/design-pitch-ann/
1•todsacerdoti•18m ago•0 comments

Make the Prompt Public

https://blog.ai-futures.org/p/make-the-prompt-public
1•fosco•23m ago•0 comments

Microsoft's NLWeb and Agentic AI could trigger the resurgence of RS

https://conoroneill.net/2025/05/20/microsofts-nlweb-and-agentic-ai-could-trigger-the-resurgence-of-rss/
1•conoro•35m ago•0 comments

Microsoft Edit

https://github.com/microsoft/edit
2•kermatt•39m ago•1 comments

Where does your weather forecast come from?

https://text.npr.org/nx-s1-5389593
2•mooreds•40m ago•0 comments

macOS Survival Guide

https://medium.com/@sergiointoronto/macos-survival-guide-8461c9d9e9b3
1•SergioInToronto•44m ago•0 comments

The Garwin Archive

https://rlg.fas.org/
1•greesil•46m ago•0 comments

A Scientist Fighting Nuclear Armageddon Hid a 50-Year Secret

https://www.nytimes.com/2025/05/19/science/richard-garwin-hydrogen-bomb.html
4•greesil•47m ago•1 comments

Biff – a batteries-included web framework for Clojure

https://biffweb.com
2•TheWiggles•50m ago•0 comments

BasecoatUI - All of the shadcn/UI magic, none of the React

https://basecoatui.com/
3•vyrotek•52m ago•0 comments

Ask HN: Is OpenAI's Operator a Bust?

2•kippinitreal•53m ago•1 comments

Thomas Keller asked me to leave the French Laundry

https://www.sfchronicle.com/food/restaurants/article/thomas-keller-french-laundry-20290670.php
1•ultrasaurus•56m ago•0 comments

Collaboration Headwind

https://komoroske.com/slime-mold/
1•veqq•57m ago•0 comments

How the Indian Media Amplified Falsehoods in the Drumbeat of War

https://www.nytimes.com/2025/05/17/world/asia/india-news-media-misinformation.html
2•suraci•59m ago•0 comments

India needs a national bullet train system (2024)

https://www.high-capacity.com/p/india-needs-a-national-bullet-train
2•mooreds•1h ago•1 comments

Show HN: A free, privacy preserving, archive of public Discord servers

https://searchcord.io
7•searchcord•1h ago•0 comments

The FCC Must Reject Efforts to Lock Up Public Airwaves

https://www.techdirt.com/2025/05/19/the-fcc-must-reject-efforts-to-lock-up-public-airwaves/
2•WarOnPrivacy•1h ago•0 comments

Texas considers allowing treated fracking water released into rivers

https://www.texastribune.org/2025/05/19/texas-legislature-produced-water-legal-protections-oil-gas/
4•geox•1h ago•1 comments

Trams – The Absolute Best Transportation for Cities [video]

https://www.youtube.com/watch?v=bNTg9EX7MLw
1•CHB0403085482•1h ago•0 comments

Show HN: Paste Keyboard – Insert saved text with one tap

https://apps.apple.com/us/app/paste-keyboard-auto-paste/id6744092980
1•noteable•1h ago•0 comments

Still Booting: People Stuck Using Ancient Windows Computers

https://www.bbc.com/future/article/20250516-the-people-stuck-using-ancient-windows-computers
6•andrewl•1h ago•1 comments

Inter-Agent Communication on MCP

https://aws.amazon.com/blogs/opensource/open-protocols-for-agent-interoperability-part-1-inter-agent-communication-on-mcp/
1•ke4qqq•1h ago•0 comments

Bomb Pulse

https://en.wikipedia.org/wiki/Bomb_pulse
1•izuchukwu•1h ago•0 comments

Modal's Serverless KV Store Now Scales to Infinity

https://modal.com/blog/cache-dict-launch
2•birdculture•1h ago•0 comments

Show HN: Bobber Game (Go Down to Go Up)

https://stan-stani.github.io/minigames/?game=bobber
2•EstanislaoStan•1h ago•0 comments

Delta Air Lines can sue CrowdStrike over outage

https://www.itnews.com.au/news/delta-air-lines-can-sue-crowdstrike-over-computer-outage-617292
6•Khaine•1h ago•1 comments

"Copilot" bot user exempted from GitHub blocks

https://mastodon.social/@mcc/114536667832141959
2•luu•1h ago•0 comments

Ask HN: When will managers be replaced by AI?

25•GianFabien•1h ago•16 comments
Open in hackernews

DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

https://micahflee.com/ddosecrets-publishes-410-gb-of-heap-dumps-hacked-from-telemessages-archive-server/
217•micahflee•3h ago

Comments

Aurornis•2h ago
So one of their servers had a /heapdump endpoint that publicly served a heap dump of the server? This whole saga is out of control.

This group didn’t really “publish” anything, though. They’re offering access to journalists through a request form. They’re also not saying how much actual message content they have because the 410GB of heap dumps makes for a bigger headline number.

barbazoo•2h ago
Aren’t those Israeli software companies all supposed to be top notch, ex Mossad, yadda yadda? Doesn’t sound like it.

I hope the message dump is juicy.

Calwestjobs•2h ago
MOSSAD is great, they wanted to hack Czech telecom company but accidentally disabled train security systems and switches were not switchin, in Czechia :

https://www.bbc.com/news/articles/ce982zpz1k3o

basilgohar•1h ago
This article doesn't mention Mossad, though. Do you have any other sources?
MPSFounder•49m ago
Israelis could murder americans in broad daylight and live stream it, and our representatives would apologize on their behalf. Never forget everything NSA does HAS to be shared with Israel [1]. As an American, I always wince at how weak our people are because of their fear of our masters. We shit on our first amendment on their behalf, and excuse their genocide of children and women, and their murder of American navymen [USS Liberty], because of the power they hold over us through AIPAC. Very despicable

[1] https://www.theguardian.com/world/2013/sep/11/nsa-americans-...

viraptor•2h ago
That's not a great generalisation for the whole country. How many ex Mossad people interested in doing actual implementation in tech companies do you think there are? It's like "aren't those US software companies all supposed to be top notch, ex NSA yadda yadda?"
conradev•1h ago
They do start a lot of tech companies specifically: https://en.wikipedia.org/wiki/Unit_8200#Companies_founded_by...

The US only has voluntary military service, so the dynamics are different

lysp•24m ago
The CEO/Founder of TeleMessage Guy Levit was the head of the Planning and Development Department of an elite technical unit in the Intelligence Corps of the IDF according to bio.
gruez•1h ago
I thought Israel has mandatory military service, so ex-mossad or ex-military signals intelligence doesn't really say much? Presumably they're directing people based on their skill set, so you'd expect most hackers to end up in mossad for their mandatory service.
oceanplexian•25m ago
One problem that smart people tend to make is in thinking that being really smart in one area is generalizable to all others. Just because they're good at AppSec doesn't mean they're good at networking or operating a webserver.
msy•21m ago
And SBF of FTX fame was ex-Jane St so obviously was a serious finance professional. This is why using past employers as a shorthand for capability is unwise.
mingus88•2h ago
Can you imagine co-opting a trusted and secure (and free) bit of software and just making it worse at seemingly every turn?

And charging for it?!

I’m not sure what is more embarrassing: to be the company or to be a user.

hypeatei•1h ago
Why would the company be embarrassed? The users (i.e. high level U.S. officials) did no due diligence. Of course a private company is going to take the easiest and cheapest route. If it goes bad, just shut down and spin up a new entity.

Some speculate this was intentional intelligence gathering by the Israelis which is plausible too.

dylan604•1h ago
>Some speculate this was intentional intelligence gathering by the Israelis which is plausible too.

Which does not bode well for the customers' counter intelligence abilities

n2d4•1h ago
> Some speculate this was intentional intelligence gathering by the Israelis which is plausible too.

How does this make sense? If they were gathering data, why would they add a public download? Surely the Israeli officials would not want foreign powers to access this?

Per Hanlon's razor, I don't think this is attributable to anything other than incompetence.

g-b-r•1h ago
I mean, it could theoretically have been to provide plausible deniability, but it seems extremely more likely to have been incompetence and carelessness (and if they were also sending everything to Israel, it was probably through some unencrypted ftp upload).
barbazoo•42m ago
Two things can be true at once. Them using their access to unencrypted messages for nefarious purposes and them being incompetent at the same time leaving that endpoint open.
notpushkin•40m ago
I mean, the one doesn’t preclude the other. This could be an incompetent intentional intelligence gathering.
jojohohanon•40m ago
There’s room for both sides of the razor. The heapdumpz could be there maliciously, but incompetently made globally accessible.
pigbearpig•26m ago
From the Wired article: "The archive server is programmed in Java and is built using Spring Boot, an open source framework for creating Java applications. Spring Boot includes a set of features called Actuator that helps developers monitor and debug their applications. One of these features is the heap dump endpoint,"

So the heapdumps being available is a Spring Boot feature so it does not appear to be malicious.

kube-system•1h ago
The changes to the application are intentional by all parties because message archiving was required by law.
brookst•1h ago
Sure, but they were not required to be done incompetently and insecurely.
_kb•58m ago
Well, I suppose technically this /heapdump endpoint does satisfy that archive requirement.
jfim•1h ago
Sounds like someone had a Java app and mistakenly exposed all of the JMX endpoints over HTTP. It's not the default configuration, and likely done out of carelessness.
0xbadcafebee•1h ago
Or intentionally. There could be an APM agent which just lets you run heap dumps any time you want, or they enabled heap-dump-on-crash, or had a heap dump shutdown hook, etc. There's a lot of ways to trigger dumps. If we're talking about a full dump, and the apps were using most of the memory allocated to their container/VM/etc, 410GB is actually not that many dumps (we're probably talking uncompressed). At 4GB/dump, that's around 100, over possibly several years.

I just wonder where they were storing them all? At one place I worked, we jiggered up an auto shutdown dump that then automatically copied the compressed dump to an S3 bucket (it was an ephemeral container with no persistent storage). Wonder if they got in through excessive cloud storage policies and this was just the easiest way to exfiltrate data without full access to a DB.

pigbearpig•24m ago
From the Wired article, it may not have even been a mistake, depending on the version of Spring Boot.

"Spring Boot Actuator. “Up until version 1.5 (released in 2017), the /heapdump endpoint was configured as publicly exposed and accessible without authentication by default."

0xbadcafebee•1h ago
> Because the data is sensitive and full of PII, DDoSecrets is only sharing it with journalists and researchers.

Yeah I'm normally a big proponent of responsible disclosure, but in this case, I think the more painful, damaging leak is required.

Firstly, autocrats, fascists & oligarchs don't care that much if you hack them. They will just keep using these tools (or another one just like it) ignoring the correct procedure their government already wants them to use. The citizens of affected nations need to be made angry by their leaders' failure to do their jobs correctly, and that's only gonna happen when there are consequences for their actions. Their incompetence put their nations at risk, and now it's clear they have failed to keep their intel safe. They have failed hard, let them fail hard.

Second, journalists and researchers have almost completely lost their power. In a non-democratic world (we're nearly there, just give them a little more time), when a journalist exposes corruption or incompetency, that journalist/researcher is simply silenced by the government. Silence the journalists and nobody knows what's going on so oppression can continue unchecked. Every person who gets silenced has a greater chilling effect on the whole society; nobody wants to be next. This is how authoritarians gain power. Oppression with no resistance or consequence legitimizes the oppression.

If we were just talking about typical corporate incompetence re: security, and the only thing at stake is a single stock or individuals' data, I would say disclose responsibly. But when it comes to stopping autocracy, the gloves have to come off. They sure as shit aren't gonna play by any rules, so neither should we.

CobrastanJorji•56m ago
> The citizens of affected nations need to be made angry by their leaders' failure to do their jobs correctly, and that's only gonna happen when there are consequences for their actions.

This is a really dangerous line of thinking. It's the line of thought that slides forwards to "I love America so much, but to save America I have to get Americans to really feel the pain, and to do that I need to <horrible violence> to them to wake them up and make them see how things are bad."

Hurting people in order to make them see how they are being hurt is almost never the right call.

scheeseman486•42m ago
You're describing accelerationism and while the ethics behind it are iffy at best, history contends that it does work to help spur revolution.
fumeux_fume•16m ago
This is a really dangerous line of thinking. It's the line of thought that slides forwards to "I love America so much, but to save America I have lie and cover up the truth of the <horrible violence> being done to them so they'll never see how bad things have gotten."

Lying to people in order to make them never see how they are being hurt is almost never the right call.

protocolture•33m ago
Completely agree.

We had the Cabinet Leaks in Aus https://www.abc.net.au/news/2018-01-31/cabinet-files-reveal-...

The national broadcaster picked 2 things to report on, then gave the rest of it back to the government.

The act of helping cover this shit up likely changed the course of politics in this country for decades. Theres likely stuff in that cabinet that was well in the public interest and needed disclosure.

Signalgate or whatever is likely the same. And I dont care which party it harms or whatever. It seems relevant that people should have more information, not less considering everything that is happening.

yieldcrv•55m ago
beautiful, any prediction markets tied to this? I need to stop betting on those things, I’m so bad at it
goalieca•34m ago
Security standards need to start banning heap dumps.
GuinansEyebrows•28m ago
Something tells me that wouldn’t make a huge difference in some of these companies opsec.
guluarte•26m ago
cannot the pentagon with their billions in funding make a secure app?
hn_throwaway_99•19m ago
Yes, and they do. The fact that the leaders of our present kakistocracy don't use it should not be an indictment of the civil and military workers in the US military.
pigbearpig•19m ago
Not when "off the shelf" is the motto. They'd still have to outsource the development and at that point would be questioned why spending that much money when Telemessage sells the product.

Unfortunately, the financial structure doesn't really make it easy for custom DoD software.

loeg•22m ago
> I'm a member of the DDoSecrets collective.

Oof, you couldn't torture that out of me. Good luck, buddy.

greyface-•21m ago
It's been weeks since the initial TeleMessage revelation... has the Signal Foundation responded in any way to the news? They condemn open source third-party clients and threaten trademark litigation when people use the "Signal" name in interop projects. Meanwhile, total silence when a defense contractor does the same thing.
th0ma5•16m ago
You're making me wonder if Signal is the customer of the third party and not the government.
bob_theslob646•4m ago
Isn't it against the law in the United States to use outside channels for government communications? Wasn't this the whole scandal about Clinton? Please correct me if I am wrong.