frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

The pitfall of Open-weight LLMs

1•hiddenest•1m ago•0 comments

Swift Android Workgroup

https://www.swift.org/android-workgroup/
1•gok•3m ago•0 comments

Puerto Rico's Solar Microgrids Beat Blackout

https://spectrum.ieee.org/puerto-rico-solar-microgrids
1•ohjeez•4m ago•0 comments

Multi-Agent Systems Hands on in Python: Full 4-HR Workshop Feat. MCP and CrewAI

https://www.youtube.com/watch?v=LSk5KaEGVk4
1•jonkrohn•5m ago•0 comments

I made a history timeline to learn what events happened around the same time

https://seanhollen.com/1300-2000/
1•Akranazon•8m ago•0 comments

Fannie Mae Freddie Mac ordered to consider crypto an asset when buying mortgages

https://apnews.com/article/mortgages-crypto-fannie-mae-freddie-mac-housing-285fad5490a59c3476f7908f444e9fe9
1•healsdata•8m ago•0 comments

ENTS – Extendable Nested Tagging Schema

https://diegocabello.com/ents/
1•dxcab•9m ago•0 comments

ICE Has No Right to Anonymity

https://www.nytimes.com/2025/06/25/opinion/trump-ice-arrests-los-angeles.html
2•whack•11m ago•0 comments

Docs for AI Agents

https://technicalwriting.dev/ai/agents/
1•kaycebasques•14m ago•0 comments

OpenRouter Raises $40M

https://www.wsj.com/articles/openrouter-a-marketplace-for-ai-models-raises-40-million-168073de
1•ent101•14m ago•0 comments

Meta wins artificial intelligence copyright case in blow to authors

https://www.ft.com/content/6f28e62a-d97d-49a6-ac3b-6b14d532876d
2•sega_sai•14m ago•1 comments

AI market analysis tool, Limited spots for testers

https://aique.markets
1•ensgoat•15m ago•1 comments

Trump Considers Naming Next Fed Chair Early in Bid to Undermine Powell

https://www.wsj.com/economy/central-banking/trump-considers-naming-next-fed-chair-early-in-bid-to-undermine-powell-d3edcb9c
1•cempaka•15m ago•0 comments

The Waste Musk Created

https://www.nytimes.com/2025/06/21/opinion/waste-musk-trump.html
1•archagon•15m ago•1 comments

The Android Workgroup

https://forums.swift.org/t/announcing-the-android-workgroup/80666
1•MBCook•17m ago•0 comments

QEMU: Define policy forbidding use of AI code generators

https://github.com/qemu/qemu/commit/3d40db0efc22520fa6c399cf73960dced423b048
16•todsacerdoti•18m ago•4 comments

PEM Fatigue Can Shatter a Person

https://www.theatlantic.com/health/archive/2023/07/chronic-fatigue-long-covid-symptoms/674834/
2•mitchbob•21m ago•2 comments

Spineless Traversal for Layout Invalidation

https://dl.acm.org/doi/10.1145/3729322
1•djoldman•24m ago•0 comments

Learn – Computer-Aided Instruction on Unix

https://wolfram.schneider.org/bsd/7thEdManVol2/learn/learn.html
2•foresto•25m ago•0 comments

Anomalous radio signals detected in Antarctica coming upward from Earth

https://www.popularmechanics.com/science/environment/a65089793/mysterious-signals-antarctica-physics/
1•Jimmc414•25m ago•0 comments

The scam that is Visa Account Updater

6•mountainriver•28m ago•1 comments

Project Indigo, a Google Pixel-like computational photography camera app

https://research.adobe.com/articles/indigo/indigo.html
1•phsilva•28m ago•1 comments

The Tail at Scale

https://cacm.acm.org/research/the-tail-at-scale/
2•ekiauhce•30m ago•0 comments

Fred Espenak, Astrophysicist Known as Mr. Eclipse, Dies at 73

https://www.nytimes.com/2025/06/25/science/space/fred-espenak-dead.html
2•sohkamyung•30m ago•1 comments

Show HN: Anagnorisis, local data-management with trainable recommendation engine

https://github.com/volotat/Anagnorisis
1•volotat•37m ago•0 comments

Ultimadownloader

https://www.ultimadownloader.xyz
1•robertprogram•39m ago•0 comments

The Hollow Men of Hims

https://www.alexkesin.com/p/the-hollow-men-of-hims
8•quadrin•46m ago•0 comments

A Clean Break: A New Strategy for Securing the Realm

https://en.wikipedia.org/wiki/A_Clean_Break:_A_New_Strategy_for_Securing_the_Realm
1•handfuloflight•47m ago•0 comments

Roblox's back end scales to 30M concurrent players and over 21M for a experience

https://corp.roblox.com/newsroom/2025/06/roblox-infrastructure-supporting-record-breaking-games
2•ak009•47m ago•2 comments

Why Did the Novel-Reading Man Disappear?

https://www.nytimes.com/2025/06/25/style/fiction-books-men-reading.html
2•mykowebhn•49m ago•0 comments
Open in hackernews

Libxml2's "no security embargoes" policy

https://lwn.net/SubscriberLink/1025971/73f269ad3695186d/
98•jwilk•4h ago

Comments

zppln•1h ago
Very sad read. Much of the multi-billion dollar project I work on is built on top of libxml2 and my company doesn't have a clue. Fuck, even most of my colleagues working with XML every day don't even know it because they only interface indirectly with it via lxml.
mschuster91•1h ago
> Fuck, even most of my colleagues working with XML every day don't even know it because they only interface indirectly with it via lxml.

Relevant XKCD: https://xkcd.com/2347/

DeepYogurt•1h ago
It'd be great if some of these open source security initiatives could dial up the quality of reports. I've seen so so many reports for some totally unreachable code and get a cve for causing a crash. Maintainers will argue that user input is filtered elsewhere and the "vuln" isn't real, but mitre don't care.
mschuster91•1h ago
> I've seen so so many reports for some totally unreachable code and get a cve for causing a crash.

There have been a lot of cases where something once deemed "unreachable" eventually was reachable, sometimes years later, after a refactoring and now there was an issue.

DeepYogurt•1h ago
At what rate though? Is it worth burning out devs we as a community rely upon because maybe someday 0.000001% of these bugs might have real impact? I think we need to ask more of these "security researchers". Either provide a real world attack vector or start patching these bugs along with the reports.
bigfatkitten•1h ago
“PoC or GTFO” is an entirely reasonable response.
marcusb•1h ago
Also a wonderful zine!
duped•27m ago
"PR or payment to fix or GTFO" is also a reasonable response
mschuster91•1h ago
IMHO, at least the foundations of what makes the Internet tick - the Linux kernel, but also stuff like SSL libraries, format parsers, virtualization tooling and the standard libraries and tools that come installed by default on Linux systems - should be funded by taxpayers. The EU budget for farm subsidies is about 40 billion euros a year - cut 1% off of it, so 400 million euros, and invest it into the core of open source software, and we'd get an untold amount of progress in return.
charcircuit•5m ago
It's not the government's job to subsidize people's bad business models.
selfhoster11•1h ago
Better yet - they could contribute a patch that fixes the issue.
kibwen•1h ago
> Ariadne Conill, a long-time open-source contributor, observed that corporations using open source had responded with ""regulatory capture of the commons"" instead of contributing to the software they depend on.

I'm only half-joking when I say that one of the premier selling points of GPL over MIT in this day and age is that it explicitly deters these freeloading multibillion-dollar companies from depending on your software and making demands of your time.

xxpor•1h ago
Why bother open sourcing if you're not interested in getting people to use it?
itsanaccount•1h ago
you seem to have mistaken corporations for people.
kortilla•1h ago
You seem to think corporations aren’t made of people
dsr_•1h ago
Sheds are made of wood, but they aren't trees.
bigfatkitten•1h ago
So that if they find it useful, they will contribute their own improvements to benefit the project.

I don’t think many projects see acquiring unpaying corporate customers as a goal.

meindnoch•1h ago
Trillion dollar corporations are not "people".
gizmo686•1h ago
A decent part of my job is open source. Our reason for doing it is simple: we would rather have people who are not us do the work instead of us.

On some of our projects this has been a great success. We have some strong outside contributors doing work on our project without us needing to pay them. In some cases, those contributors are from companies that are in direct competition with us.

On other projects we've open sourced, we've had people (including competitors) use, without anyone contributing back.

Guess which projects stay open source.

OkayPhysicist•1h ago
We have a solution to this. It's called the (L)GPL. If people would stop acting like asking for basic (zero cost) decency in exchange for their gift is tantamount to armed robbery, we could avoid this whole mess.
lelandbatey•1h ago
You can want to be helpful without wanting to have power or responsibility.

I'm interested in people (not companies, or at least I don't care about companies) being able to read, reference, learn from, or improve the open source software that I write. It's there if folks want it. I basically never promote it, and as such, it has little uptake. It's still useful though, and I use it, and some friends use it. Hooray. But that's all.

OkayPhysicist•1h ago
The GPL does not prohibit anyone from using a piece of software. It exclusively limits the actions of bad faith users. If all people engaged with FOSS in good faith, we wouldn't need licenses, because all most FOSS licenses require of the acceptors is to do a couple of small, free activities that any decent person would do anyway. Thank/give credit to the authors who so graciously allowed you to use their work, and if you make any fixes or improvements, share alike.

Security issues like this are a prime example of why all FOSS software should be at least LGPLed. If a security bug is found in FOSS library, who's the more motivated to fix it? The dude who hacked the thing together and gave it away, or the actual users? Requesting that those users share their fixes is farrr from unreasonable, given that they have clearly found great utility in the software.

charcircuit•10m ago
GPL doesn't force people to share their fixes and improvements. And there is nothing bad faith about not sharing all your hardwork for free.
freeone3000•24m ago
What’s the point in people using it if all that profit ends up in someone else’s pockets?
ben0x539•16m ago
When I, as a little child (or at least that is how it feels now), got excited about contributing to open source, it was not the thought that one day my code might help run some giant web platform's infrastructure or ship as part of some AAA videogame codebase that motivated me. The motivation was the idea that my code might be useful to people even with no corporation or business having to be involved!
arp242•1h ago
A lot of these "security bugs" are not really "security bugs" in the first place. Denial of service is not resulting in people's bank accounts being emptied or nude selfies being spread all over the internet.

Things like "panics on certain content" like [1] or [2] are "security bugs" now. By that standard anything that fixes a potential panic is a "security bug". I've probably fixed hundreds if not thousands of "security bugs" in my career by that standard.

Barely qualifies as a "security bug" yet it's rated as "6.2 Moderate" and "7.5 HIGH". To say nothing of gazillion "high severity" "regular expression DoS" nonsense and whatnot.

And the worst part is all of this makes it so much harder to find actual high-severity issues. It's not harmless spam.

[1]: https://github.com/gomarkdown/markdown/security/advisories/G...

[2]: https://rustsec.org/advisories/RUSTSEC-2024-0373.html

nicce•1h ago
> A lot of these "security bugs" are not really "security bugs" in the first place. Denial of service is not resulting in people's bank accounts being emptied or nude selfies being spread all over the internet.

That is not true at all. Availability is also critical. If nobody can use bank accounts, bank has no purpose.

bogeholm•1h ago
Security and utility are separate qualities.

You’re correct that inaccessible money are useless, however one could make the case that they’re secure.

nicce•1h ago
I think you are only considering the users - for the business provider the availability has larger meaning because the lack of it can bankrupt your business. It is about securing operations.
leni536•1h ago
Virtually all bugs have some cost. Security bugs tend to be more expensive than others, but it doesn't mean that all very expensive bugs are security bugs.
em-bee•58m ago
not paying rent can get you evicted. and not paying your medical bill can get you denied care. (in china most medical care is not very expensive, but every procedure has to be paid in advance. you probably won't be denied emergency care so your life would not be in immediate danger, but sometimes an optional scan discovers something life threatening that you weren't aware of so not being able to pay for it can put you at risk)
arp242•52m ago
If a panic or null pointer deref in some library causes your entire business to go down long enough that you go bankrupt, then you probably deserve to go out of business because your software is junk.
nicce•34m ago
I believe you know well that bankrupt is the worst case. Many business functions can be so critical that 24h disturbance is enough to cause high financial damages or even loss of life. A bug in the car's brakes that prevents their usage is also denial of service.
arp242•21m ago
Or 24h disturbance. Or indeed taking the entire system down at all.

And no one is talking about safety-critical systems. You are moving the goalposts. Does a gas pedal use a markdown or XML parser? No.

marcusb•1h ago
https://www.sentinelone.com/cybersecurity-101/cybersecurity/...
antonymoose•1h ago
I routinely handle regex DoS complaints on front-end input validation…

If a hacker wants to DoS their own browser I’m fine with that.

Onavo•58m ago
Until the same library for their "isomorphic" backend..
nicce•53m ago
This depends on the context to be fair. Front-end DoS can suddenly expand into botnet DDoS if you can trigger it by just serving a specific kind of URL. E.g. search goes into endless loop that makes requests into the backend.
arp242•59m ago
Many of these issues are not the type of issues that will bring down an entire platform; most are of the "if I send wrong data, the server will return with a 500 for that request" or "my browser runs out of memory if I use a maliciously crafted regexp". Well, whoopdeedoo.

And even if it somehow could, it's 1) just not the same thing as "I lost all my money" – that literally destroys lives and the bank not being available for a day doesn't. And 2) almost every bug has the potential to do that in at least some circumstances – circumstances with are almost never true in real-world applications.

nicce•45m ago
> Many of these issues are not the type of issues that will bring down an entire platform; most are of the "if I send wrong data, the server will return with a 500 for that request" or "my browser runs out of memory if I use a maliciously crafted regexp". Well, whoopdeedoo.

I wouldn't personally classify these as denial of service. They are just bugs. 500 status code does not mean that server uses more resources to process it than it typically does. OOMing your browser has no impact to others. These should be labeled correctly instead of downplaying the significance of denial of service.

Like I said in my other comment, there are two entities - the end-user and the service provider. The service provider/business loses money too when customers cannot make transactions (maybe they had promise to keep specific uptime and now they need to pay compensations). Or they simple get bankrupted because they lost their users.

Even customers may lose money or something else when they can't make transactions. Or maybe identification is based on bank credentials on some other service. The list goes on.

icedchai•1h ago
Everything is a "security bug" in the right (wrong?) context, I suppose.
cogman10•46m ago
Well, that's sort of the problem.

It's true that once upon a time, libxml was a critical path for a lot of applications. Those days are over. Protocols like SOAP are almost dead and there's not really a whole lot of new networking applications using XML in any sort of manor.

The context where these issues could be security bugs is an ever-vanishing usecase.

Now, find a similar bug in zlib or zstd and we could talk about it being an actual security bug.

Aurornis•1h ago
I empathize with some of the frustrations, but I'm puzzled by the attempts to paint the library as low-quality and not suitable for production use:

> The viewpoint expressed by Wellnhofer's is understandable, though one might argue about the assertion that libxml2 was not of sufficient quality for mainstream use. It was certainly promoted on the project web site as a capable and portable toolkit for the purpose of parsing XML. Open-source proponents spent much of the late 1990s and early 2000s trying to entice companies to trust the quality of projects like libxml2, so it is hard to blame those companies now for believing it was suitable for mainstream use at the time.

I think it's very obvious that the maintainer is sick of this project on every level, but the efforts to trash talk its quality and the contributions of all previous developers doesn't sit right with me.

This is yet another case where I fully endorse a maintainer's right to reject requests and even step away from their project, but in my opinion it would have been better to just make an announcement about stepping away than to go down the path of trash talking the project on the way out.

rectang•59m ago
I think Wellnhofer is accurate in his assessment of the current state of the library and its support infrastructure institutions. Software without adequate ongoing maintenance should not be used in production.

(Disclosure: I'm a past collaborator with Nick on other projects. He's a fantastic engineer and a responsible and kind person.)

flomo•55m ago
Recall similar things were said about OpenSSL, and it was effective at getting corps to start funding the project.
wbl•34m ago
It was not however effective at getting the project to care about quality or performance.
bjourne•1h ago
So software released under the MIT license and maintainer now complains that corporate users are not helping improve it? I'd file this under Stallman told you so.
kayodelycaon•42m ago
No. He’s complaining about companies demanding he do free work for them.
JonChesterfield•1h ago
This is an alarming read. Not so much the "security bugs are bugs, go away" sentiment which seems completely legitimate, but that libxml2 and libxslt have been ~ solo dev passion projects. These aren't toys. They're part of the infrastructure computing is built on.
bryanlarsen•1h ago
> The point is that libxml2 never had the quality to be used in mainstream browsers or operating systems to begin with

I think that's seriously over-estimating the quality of software in mainstream browsers and operating systems. Certainly some parts of mainstream OS's and browsers are very well written. Other parts, though...

kstrauser•53m ago
> It includes a request for Wellnhofer to provide a CVE number for the vulnerability and provide information about an expected patch date.

“Three.”

“Like, the number 3? As in, 1, 2, …?”

“Yes. If you’re expecting me to pick, this will be CVE-3.”

tptacek•52m ago
I don't think this trend much matters. Serious vendors concerned about security will simply vendor things like libxml2 and handle security inbounds themselves; they'll become the real upstreams.
benced•46m ago
Do we need a more profound solution than what the maintainer is doing here? Any given bug is either:

a) nonsense in which case nobody should spend any time fixing this (I'm thinking things like the frontend DDOS CVEs that are common) b) an actual problem in which case a compliance person at one of these mega tech companies will tell the engineers it needs to be fixed. If the maintainer refuses to be the person fixing it (a reasonable choice), the mega tech company will eventually just do it.

I suppose the risk is the mega tech company only fixes it for their internal fork.

djoldman•44m ago
I really don’t understand solo unpaid maintainers who feel “pressure” from users. My response would always be: it’s my repo, my code, if you don’t like how I’m doing things, fork the code megashrug.

You owe them nothing. That fact doesn’t mean maintainers or users should be a*holes to each other, it just means that as a user, you should be grateful and you get what you get, unless you want to contribute.

Or, to put it another way: you owe them exactly what they’ve paid for!

msgodel•42m ago
The correct response to this kind of thing is an invoice IMO.
johnisgood•36m ago
Such a professional security researcher, looking for a missing check for NULL that in reality has zero impact. :D Pay the guy, or stop flooding.
kayodelycaon•31m ago
Your solution is exactly right, but let me try to help understanding the problem.

Many open source developers feel a sense of responsibility for what they create. They are emotionally invested in it. They may want to be liked or not be disliked.

You’re able to not care about these things. Other people care but haven’t learned how to set boundaries.

It’s important to remember, if you’re not understanding what a majority of people are doing, you are the different one. The question should be “Why am I different?” not “Why isn’t everyone else like me?”

“Here’s the solution” comes off far better than, “I don’t understand why you don’t think like me.”

michaelt•10m ago
> I really don’t understand solo unpaid maintainers who feel “pressure” from users.

Some open source projects which are well funded and/or motivated to grow are giddy with excitement at the prospect you might file a bug report [1,2]. Other projects will offer $250,000 bounties for top tier security bugs [3].

Other areas of society, like retail and food service, take an exceptionally apologetic, subservient attitude when customers report problems. Oh, sir, I'm terribly sorry your burger had pickles when you asked for no pickles. That must have made you so frustrated! I'll have the kitchen fix it right away, and of course I'll get your table some free desserts.

Some people therefore think doing a good job, as an open source maintainer, means emulating these attitudes. That you ought to be thankful for every bug report, and so very, very sorry to everyone who encounters a crash.

Needless to say, this isn't a sustainable way to run a one-person project, unless you're a masochist.

[1] https://llvm.org/docs/Contributing.html#id5 [2] https://dev.java/contribute/test/ [3] https://bughunters.google.com/about/rules/chrome-friends/574...

firesteelrain•27m ago
Understand the stance, but the big corps using it (Apple, Google, Microsoft) are using it and acknowledge it silently at risk. It's not entirely fair though, Google did make a donation.