frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

OneDrive File Picker Flaw Provides Apps Full Read Access Entire OneDrive

https://www.oasis.security/blog/onedrive-file-picker-security-flaw-oasis-research
21•ano-ther•1d ago

Comments

mchenier•1d ago
One way to avoid this problem and considerably reduce the attack surface is to: 1- Create a dummy Onedrive account. 2- Share a folder on your main Onedrive to the dummy account. 3- In the dummy account, maps the shared link to a folder for easier access as if it was a normal folder. (May not be required for some apps). 4- Only lets third party apps access the dummy Onedrive account with its single folder.

This doesn’t give access to your main Onedrive account to any apps, just the files and folders under the shared folder you have shared with the dummy account.

ThePowerOfFuet•1d ago
To summarize: "Avoid OneDrive."
pawanjswal•1d ago
It's hard to believe that the OneDrive File Picker still doesn't have fine grained OAuth scopes in 2025. Allowing read access to the whole drive just to upload one file goes against the principle of least privilege.
type0•18h ago
> In response, Microsoft is considering future improvements

Who knows, maybe it works as intended, that's MS Windows in a nutshell

Is Q-Star the Next PageRank? What Google's Antitrust Trial Revealed

https://www.vincentschmalbach.com/is-q-star-the-next-pagerank-what-googles-antitrust-trial-revealed/
1•vincent_s•1m ago•0 comments

Show HN: Deep Timeline log-scale world history timeline (side project)

https://deep-timeline.oberbrunner.com
1•darkstarsys•2m ago•0 comments

Hot Chips 2025 Preliminary Schedule Released – ServeTheHome

https://www.servethehome.com/hot-chips-2025-preliminary-schedule-released/
1•rbanffy•5m ago•0 comments

Windows 11 installations go backwards as Windows 10 End of Life approaches

https://htxt.co.za/2025/06/windows-11-installations-go-backwards-as-windows-10-end-of-life-approaches/
2•Improvement•5m ago•0 comments

Updates to Windows for the Digital Markets Act

https://blogs.windows.com/windows-insider/2025/06/02/updates-to-windows-for-the-digital-markets-act/
2•nixass•6m ago•0 comments

Fake Movie Scene Crushed Demand for Mass-Market Blends

https://askrally.com/article/simulated-effect-movie-memories-have-on-coffee-demand
1•virtual_rf•10m ago•0 comments

AI Slopocalypse 2027

https://www.stephendiehl.com/posts/ai_slop_2027/
1•jruohonen•13m ago•0 comments

I want off Mr. Golang's Wild Ride (2020)

https://fasterthanli.me/articles/i-want-off-mr-golangs-wild-ride
3•shakna•14m ago•0 comments

The Product Engineer

https://randsinrepose.com/archives/the-product-engineer/
1•GarethX•16m ago•0 comments

One UI 7: Samsung Phones Getting the May 2025 Update

https://techday.blog/2025/05/26/%d9%82%d8%a7%d8%a6%d9%85%d8%a9-%d8%b1%d8%b3%d9%85%d9%8a%d8%a9-%d9%87%d8%b0%d9%87-%d8%a3%d8%ac%d9%87%d8%b2%d8%a9-%d8%b3%d8%a7%d9%85%d8%b3%d9%88%d9%86%d8%ac-%d8%a7%d9%84%d8%aa%d9%8a-%d8%aa%d8%b9%d9%85/
1•audai•17m ago•0 comments

John Henry and the large language model

https://www.seangoedecke.com/john-henry-and-the-llm/
1•ingve•18m ago•0 comments

Show HN: PDF to Markdown converter that keeps all formatting intact

https://pdf-to-markdown.com
1•bebert410•18m ago•0 comments

Only a tiny % of the deep seafloor has ever been visually observed

https://news.mongabay.com/2025/05/only-a-tiny-of-the-deep-seafloor-has-ever-been-visually-observed-study/
1•lentoutcry•20m ago•0 comments

10 years of stable Rust: an infrastructure story

https://rustfoundation.org/media/10-years-of-stable-rust-an-infrastructure-story/
1•fanf2•20m ago•0 comments

LawZero Safe AI for Humanity

https://lawzero.org/en
1•momeara•29m ago•0 comments

Shisa V2 405B: Japan's Highest Performing LLM

https://shisa.ai/posts/shisa-v2-405b/
2•JimDabell•30m ago•0 comments

BIP Combinator – Group Chat Cohorts for Makers "Building in Public"

https://www.bipcombinator.com/
1•CollectiveClay•30m ago•1 comments

Choose Nonbook Review Finalists 2025

https://www.astralcodexten.com/p/choose-nonbook-review-finalists-2025
1•feross•30m ago•0 comments

Claude has learned how to jailbreak Cursor

https://forum.cursor.com/t/important-claude-has-learned-how-to-jailbreak-cursor/96702
2•sarnowski•31m ago•0 comments

Building a Shell is not that hard

https://www.csprimer.in/articles/build-your-own-shell
2•csprimer-in•33m ago•0 comments

What [Blind] reveals about the mood in Silicon Valley

https://www.businessinsider.com/blind-anonymous-tech-job-site-anxiety-layoffs-hiring-ugly-2025-6
1•ptrhvns•33m ago•0 comments

Scientific Publishing: Enough Is Enough

https://asterainstitute.substack.com/p/scientific-publishing-enough-is-enough
1•lentoutcry•33m ago•0 comments

Mathematics and Music [pdf]

https://www.math.wustl.edu/~wright/Math109/00Book.pdf
1•nill0•36m ago•0 comments

Show HN: Bolna AI – Open-source voice AI agents with pluggable LLMs, TTS, ASR

https://github.com/bolna-ai/bolna
1•xan_ps007•36m ago•0 comments

How the little-known 'dark roof' lobby may be making US cities hotter

https://www.theguardian.com/environment/2025/jun/01/dark-roof-lobby
2•prawn•36m ago•0 comments

Timothy Gowers – Why Are LLMs Not Better at Finding Proofs? [video]

https://www.youtube.com/watch?v=5D3x_Ygv3No
1•amichail•39m ago•0 comments

Show HN: A map with millions of events extracted from Wikipedia

https://landnotes.org/?location=u0k6012j-5&date=1949--2&strictDate=true&paneTab=about
1•zulko•46m ago•0 comments

Show HN: AI Baby Podcast Generator

https://monet.vision/baby-podcast
1•zengyue•46m ago•0 comments

New Drone Tricks – Impossible for FPV Pilots? [video]

https://www.youtube.com/watch?v=ievlXLLaY2c
1•simon_acca•46m ago•0 comments

What Is "Seeing" in Astrophotography? The Science Behind Atmospheric Turbulence

https://astroimagery.com/astronomy/what-does-seeing-mean-in-astrophotography/
1•karlperera•46m ago•1 comments