frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

The Future of Systems

https://novlabs.ai/mission/
1•tekbog•44s ago•1 comments

NASA now allowing astronauts to bring their smartphones on space missions

https://twitter.com/NASAAdmin/status/2019259382962307393
2•gbugniot•5m ago•0 comments

Claude Code Is the Inflection Point

https://newsletter.semianalysis.com/p/claude-code-is-the-inflection-point
1•throwaw12•6m ago•1 comments

MicroClaw – Agentic AI Assistant for Telegram, Built in Rust

https://github.com/microclaw/microclaw
1•everettjf•7m ago•2 comments

Show HN: Omni-BLAS – 4x faster matrix multiplication via Monte Carlo sampling

https://github.com/AleatorAI/OMNI-BLAS
1•LowSpecEng•7m ago•1 comments

The AI-Ready Software Developer: Conclusion – Same Game, Different Dice

https://codemanship.wordpress.com/2026/01/05/the-ai-ready-software-developer-conclusion-same-game...
1•lifeisstillgood•9m ago•0 comments

AI Agent Automates Google Stock Analysis from Financial Reports

https://pardusai.org/view/54c6646b9e273bbe103b76256a91a7f30da624062a8a6eeb16febfe403efd078
1•JasonHEIN•13m ago•0 comments

Voxtral Realtime 4B Pure C Implementation

https://github.com/antirez/voxtral.c
1•andreabat•15m ago•0 comments

I Was Trapped in Chinese Mafia Crypto Slavery [video]

https://www.youtube.com/watch?v=zOcNaWmmn0A
1•mgh2•21m ago•0 comments

U.S. CBP Reported Employee Arrests (FY2020 – FYTD)

https://www.cbp.gov/newsroom/stats/reported-employee-arrests
1•ludicrousdispla•23m ago•0 comments

Show HN: I built a free UCP checker – see if AI agents can find your store

https://ucphub.ai/ucp-store-check/
2•vladeta•28m ago•1 comments

Show HN: SVGV – A Real-Time Vector Video Format for Budget Hardware

https://github.com/thealidev/VectorVision-SVGV
1•thealidev•30m ago•0 comments

Study of 150 developers shows AI generated code no harder to maintain long term

https://www.youtube.com/watch?v=b9EbCb5A408
1•lifeisstillgood•30m ago•0 comments

Spotify now requires premium accounts for developer mode API access

https://www.neowin.net/news/spotify-now-requires-premium-accounts-for-developer-mode-api-access/
1•bundie•33m ago•0 comments

When Albert Einstein Moved to Princeton

https://twitter.com/Math_files/status/2020017485815456224
1•keepamovin•34m ago•0 comments

Agents.md as a Dark Signal

https://joshmock.com/post/2026-agents-md-as-a-dark-signal/
2•birdculture•36m ago•0 comments

System time, clocks, and their syncing in macOS

https://eclecticlight.co/2025/05/21/system-time-clocks-and-their-syncing-in-macos/
1•fanf2•37m ago•0 comments

McCLIM and 7GUIs – Part 1: The Counter

https://turtleware.eu/posts/McCLIM-and-7GUIs---Part-1-The-Counter.html
2•ramenbytes•40m ago•0 comments

So whats the next word, then? Almost-no-math intro to transformer models

https://matthias-kainer.de/blog/posts/so-whats-the-next-word-then-/
1•oesimania•41m ago•0 comments

Ed Zitron: The Hater's Guide to Microsoft

https://bsky.app/profile/edzitron.com/post/3me7ibeym2c2n
2•vintagedave•44m ago•1 comments

UK infants ill after drinking contaminated baby formula of Nestle and Danone

https://www.bbc.com/news/articles/c931rxnwn3lo
1•__natty__•45m ago•0 comments

Show HN: Android-based audio player for seniors – Homer Audio Player

https://homeraudioplayer.app
3•cinusek•45m ago•2 comments

Starter Template for Ory Kratos

https://github.com/Samuelk0nrad/docker-ory
1•samuel_0xK•47m ago•0 comments

LLMs are powerful, but enterprises are deterministic by nature

2•prateekdalal•50m ago•0 comments

Make your iPad 3 a touchscreen for your computer

https://github.com/lemonjesus/ipad-touch-screen
2•0y•56m ago•1 comments

Internationalization and Localization in the Age of Agents

https://myblog.ru/internationalization-and-localization-in-the-age-of-agents
1•xenator•56m ago•0 comments

Building a Custom Clawdbot Workflow to Automate Website Creation

https://seedance2api.org/
1•pekingzcc•58m ago•1 comments

Why the "Taiwan Dome" won't survive a Chinese attack

https://www.lowyinstitute.org/the-interpreter/why-taiwan-dome-won-t-survive-chinese-attack
2•ryan_j_naughton•59m ago•0 comments

Xkcd: Game AIs

https://xkcd.com/1002/
2•ravenical•1h ago•0 comments

Windows 11 is finally killing off legacy printer drivers in 2026

https://www.windowscentral.com/microsoft/windows-11/windows-11-finally-pulls-the-plug-on-legacy-p...
2•ValdikSS•1h ago•0 comments
Open in hackernews

The Windows Registry Adventure #7: Attack surface analysis

https://googleprojectzero.blogspot.com/2025/05/the-windows-registry-adventure-7-attack-surface.html
64•todsacerdoti•8mo ago

Comments

smnc•8mo ago
Previous posts in the series:

https://googleprojectzero.blogspot.com/2024/04/the-windows-r...

https://googleprojectzero.blogspot.com/2024/04/the-windows-r...

https://googleprojectzero.blogspot.com/2024/06/the-windows-r...

https://googleprojectzero.blogspot.com/2024/10/the-windows-r...

https://googleprojectzero.blogspot.com/2024/12/the-windows-r...

https://googleprojectzero.blogspot.com/2025/04/the-windows-r...

1970-01-01•8mo ago
The Windows registry is a massive 30+ year modern labyrinth that is still under construction. Deadly traps, hidden treasures, and secret doors thoroughly litter it. I recently discovered yet another of secret within it: Setting some critical kernel mode drivers to silently fail will allow one to continue booting the system if that kernel driver has been corrupted. Great write-up, thanks for sharing.
simoncion•8mo ago
"OS continues to boot when you tell it to make failure to load a driver a warning, rather than a catastrophic error." seems to me to be the system working as intended.

Triply so if you have to be on the other side of the airtight hatchway (as it were) to instruct the OS to do this. What am I missing? [0]

[0] NOTE: "It shouldn't permit a full computer administrator to let this happen!" is not a valid argument. Full admins have full control (and -often- physical access) to the machines they administer. If you don't trust your full admins, you've already lost.

pixl97•8mo ago
This is where Windows gets messy on what the idea of an admin is. It came from a history of 'full admin by default' instead of a "you never use root unless ___".

If your grandma had a Windows XP box with a default user, it was a 'full admin', but most likely grandma had no idea of how to administer it. So you ended up with a SYSTEM privilege that is even above admin. The full admin needs to promote themselves (run as) temporarily to that priv to change some things.

hulitu•8mo ago
System was there also in NT4. And "at" also. It helped me a lot.
mananaysiempre•8mo ago
> [W]ith registry hives, the initial refcount values are loaded from disk, from a file that we assume is controlled by the attacker.

As far as I remember, new hives are only mountable with administrator privileges (perhaps even only with Local System ones?..); and it’s long been Microsoft’s position that the administrator/kernel boundary is not a security one—and thus, for example, a driver signing bypass is not a security vulnerability[1]. That would imply that hive files are trusted as well, wouldn’t it? (At least as far as security is concerned, it would of course still be wise to check them because of possible disk corruption.)

I have mixed feelings regarding Microsoft’s policy and I am not trying to defend it here, to be clear, I’d just like to know if it has changed in recent years.

[1] https://github.com/ionescu007/r0ak

ack_complete•8mo ago
Windows allows loading process-private registry hives without elevation using the RegLoadAppKey() function. This is used by Visual Studio.

https://visualstudioextensions.vlasovstudio.com/2017/06/29/c...

mananaysiempre•8mo ago
Yeah, several paragraphs down TFA mentions that unprivileged (and docunented) hive loading was introduced in Vista. Which checks out as far as my knowledge cutoff regarding Windows :)
zelon88•8mo ago
Considering how terrible Android and ChromeOS and GCP is in every conceivable way, I'm surprised Google even has time to quantify the quality of Microsoft products.
hulitu•8mo ago
This is normal propaganda: make the other one look worse.

TBH, the quality of both Windows and Android is quite the same.

somat•8mo ago
I find the windows registry a fascinating mystery, why does something that sounds like such a good idea (hey lets put all the config into one place, a database for configs.) end up being so miserable to be around in practice?

As a good unixaphile My conclusion is that it is because now you have two trees, a main database tree that has excellent ergonomics and tooling(the filesystem). and the registry tree where all the access patterns are special and different and the tooling sort of sucks.

I feel this article could make the same conclusion about the main filesystem if it wanted to. But I do note that because the main filesystem is not the redheaded stepchild tree, any problems with it tend to be fixed.

As a humorous footnote, I really appreciate the plan9 mindset, that single minded devotion to "The One True Tree" that when they wanted a web browser they said "hey the DOM is a tree structure. throw it in the filesystem" those glorious crazy bastards.

https://man.cat-v.org/plan_9/4/webfs

pathartl•8mo ago
I've been working a lot with older games and a big issue I see is developer discipline.

Take LOTR: Battle for Middle Earth II Rise of the Witch King: https://www.regfiles.net/registry/the-lord-of-the-rings-the-...

Not only does it have "Electronic Arts/Electronic Arts", the same game doesn't even follow its own standard!

Surely it's just that one game right? Nope! Here's the Sims 3 https://www.regfiles.net/registry/the-sims-3-steam-registry

And Battlefield 1942 on Origin https://www.regfiles.net/registry/battlefield-1942-ea-origin...

There's also developers that throw everything they can in HKLM when HKCU is almost always more appropriate.

It was also complicated with the introduction of WoW64, and then the introduction of the VirtualStore. Don't get me wrong, segmenting off all of those prevented a ton of potential collisions, but I feel like there's a more elegant way to handle it. Personally, I've been working on writing a library to hook every registry call and read from a text config file instead.

cedws•8mo ago
The reason the registry sucks is the same reason desktop operating systems generally suck: it isn’t sandboxed. Applications should not have a global view of the system and other applications. They should have their own container where they can do stuff, like write registry keys, write files, do stuff with whatever is exposed to the container. When the app is removed, everything inside that container goes with it. Of course, this is how mobile operating systems work, and they’re rock solid compared to Windows.

When you remove an app on Windows a bunch of garbage just gets orphaned on your system to the end of time.

hulitu•8mo ago
> When the app is removed, everything inside that container goes with it.

We don't work that way. Applications must stay there and remember their configuration. What an i** thought is a good idea, to make me redo the configuration, every time he has an update ?