frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Unknown novel by writer who charted Hitler's rise becomes German bestseller

https://www.theguardian.com/world/2025/jun/24/sebastian-haffner-abschied-unknown-novel-published
1•Bluestein•1m ago•0 comments

Ask HN: Do AI companies use PageRank to influence their training?

1•amichail•3m ago•0 comments

TrendHarvester Pro

https://trendharvester.netlify.app
1•simondoes•3m ago•1 comments

Harley Finkelstein: Why You Must Requalify for Your Role–Every Year [The

https://fs.blog/knowledge-project-podcast/harley-finkelstein/
1•feross•3m ago•0 comments

Race and Gender Bias as an Example of Unfaithful Chain of Thought in the Wild

https://www.lesswrong.com/posts/me7wFrkEtMbkzXGJt/race-and-gender-bias-as-an-example-of-unfaithful-chain-of
1•ibobev•4m ago•0 comments

Show HN: Director – The MCP gateway you wish existed

https://director.run
1•bwm•5m ago•0 comments

Apple looked into building its own AWS competitor

https://9to5mac.com/2025/07/03/report-apple-looked-into-building-its-own-aws-competitor/
1•pier25•5m ago•0 comments

PayPal's 11-Year API Disaster: We Built Workarounds While They Ignored Us

https://forwardemail.net/en/blog/docs/paypal-api-disaster-11-years-missing-features-broken-promises
2•skeptrune•7m ago•0 comments

The 10x "Overemployed" Engineer

https://newsletter.pragmaticengineer.com/p/the-10x-overlemployed-engineer
1•jonfw•7m ago•0 comments

Released the schematics and PCB of my transputer ISA board

https://nanochess.org/transputer_board.html
1•nanochess•7m ago•0 comments

Show HN: I built a website to customize and export Unicode symbols or copy-paste

https://copysymbol.cool/
1•liquid99•8m ago•0 comments

Large-scale processing of within-bone nutrients by Neanderthals, 125kya

https://www.science.org/doi/10.1126/sciadv.adv1257
1•rntn•9m ago•0 comments

LinkedIn Hates Me

https://ideasofhakki.com/linkedin-hates-me.html
1•hrkucuk•9m ago•1 comments

US founder calls out Indian techie for 'scamming' multiple startups

https://www.msn.com/en-in/news/other/us-founder-calls-out-indian-techie-for-scamming-multiple-startups-i-fired-this-guy-in-1-week/ar-AA1HOKcT
2•rmason•10m ago•1 comments

Welcome to Genesys Demo

https://genesys.allen.ai/
1•Bluestein•10m ago•0 comments

Addictive screen habits, not hours online, linked to worsening mental health

https://www.nytimes.com/2025/06/18/health/youth-suicide-risk-phones.html
1•bdev12345•11m ago•0 comments

Dow jumps over 300 points, S&P 500 sets new record after strong June jobs report

https://www.cnbc.com/2025/07/02/stock-market-today-live-updates.html
2•hiatus•11m ago•1 comments

Weekly oncology newsletter: biotech breakthroughs and clinical trials summarized

https://sagelyhealth.substack.com/p/new-in-oncology-july-3-2025
1•peerless-app•12m ago•0 comments

High-latitude peat and forest fires could shape the future of Earth's climate

https://theconversation.com/how-high-latitude-peat-and-forest-fires-could-shape-the-future-of-earths-climate-258721
2•PaulHoule•12m ago•0 comments

Call of Duty: WWII Game Pass Launch Stained by Reports of RCE Attacks

https://cyberinsider.com/call-of-duty-wwii-game-pass-launch-stained-by-reports-of-rce-attacks/
1•steptwo•13m ago•0 comments

Sketched Out: An Illustrator Confronts His Fears About A.I. Art

https://www.nytimes.com/interactive/2025/06/23/magazine/ai-art-artists-illustrator.html
1•twalichiewicz•14m ago•0 comments

Charkoal: Visualize Any Codebase

https://charkoal.ai/
1•handfuloflight•15m ago•0 comments

What Is DevContainer and Why Every Developer Will Use It Soon (2025 Guide)

1•devtechinsights•15m ago•0 comments

Ad Free Citation Generation

https://www.bibuddy.org
1•jwatermelon•16m ago•0 comments

Household name employers where workers rely on payday loans the most

https://priceonomics.com/the-companies-where-employees-most-often-get/
1•bdev12345•16m ago•0 comments

Sunwise

https://en.wikipedia.org/wiki/Sunwise
2•thunderbong•16m ago•0 comments

Infrasim

https://github.com/infrasimorg/main
1•aarong11•17m ago•2 comments

Ask HN: Do you have a BYD car or driven one? What do you think about it?

1•diggan•21m ago•1 comments

Steve Blank – Why Investors Don't Care About Your Business

https://steveblank.com/2025/07/01/why-investors-dont-care-about-your-business/
2•rmason•21m ago•0 comments

Detroit sues blockchain real estate firm that owns rentals with many violations

https://www.freep.com/story/news/local/michigan/detroit/2025/07/03/city-of-detroit-files-lawsuit-against-blockchain-real-estate-company-real-token-crypto-rentals/84443153007/
3•rmason•22m ago•0 comments
Open in hackernews

Tell HN: Google banned me for reporting CT vulns they fixed hours later

6•Eikon•7h ago
The Certificate Transparency system protects you from malicious HTTPS certificates. When CT logs have predictable private keys, the entire web PKI security model breaks down.

This compromises every certificate the log ever signed - past, present, and future.

I reported security vulnerabilities in Certificate Transparency infrastructure that Google Chrome trusts. They dismissed them as "not vulnerabilities," made my private report public without consent, then silently implemented my fixes hours later.

The discovery:

While benchmarking, I used echo " " > seed.bin (32 spaces). Sunlight accepted this and generated valid but predictable private keys for a CT log. No warnings, no errors.

Why this matters:

1. Operator correctly runs: cat /dev/urandom > seed.bin

2. Filesystem corruption fills seed with nulls/spaces (happens in production)

3. Sunlight silently generates predictable keys from corrupted seed

4. CT log operates "normally" - valid signatures, no errors

5. Anyone knowing about corruption can recreate the private keys

Without checksums, even perfect operators get silently compromised. This is PKI infrastructure that protects HTTPS certificates.

This isn't hypothetical - filesystem corruption is common in production systems. Power failures, kernel panics and storage failures regulary cause partial writes and null bytes.

Google's response:

- "Not a vulnerability": https://groups.google.com/a/chromium.org/g/ct-policy/c/qboz9s8b9j8/m/B6JXa2q1BAAJ

- Published my private security report without consent

- Implemented my exact fixes hours later

  - https://github.com/FiloSottile/sunlight/commit/f62f9084016c4c377d3855471720d7d0cdea3663

  - https://github.com/FiloSottile/sunlight/commit/32cc3ea2524e89f93febb967683c6467753f484d
- Banned me for pointing out the contradiction: https://groups.google.com/g/certificate-transparency/c/u8SsXgSFbz4/m/14ePyeCrBAAJ

Bonus vulnerability:

They authenticate using User-Agent strings. Anyone can spoof these headers to bypass rate limits and overwhelm the service:

- https://github.com/FiloSottile/sunlight/blob/main/cmd/skylight/skylight.go#L176

- https://github.com/FiloSottile/sunlight/blob/main/cmd/skylight/skylight.go#L148

This is production code, trusted by Google Chrome today (https://www.gstatic.com/ct/log_list/v3/all_logs_list.json) see the "sunlight" logs.

The exact email that got me banned is here https://groups.google.com/g/certificate-transparency/c/u8SsXgSFbz4/m/14ePyeCrBAAJ - judge for yourself if it violates any reasonable code of conduct.

Has anyone else experienced retaliation for responsible security disclosure? How do we fix a system where reporting vulnerabilities gets you banned while the issues get quietly patched?

Comments

data_yum_yum•7h ago
Just stay away from the toxicity that’s bringing a cultural decline in the tech world. When it’s relevant, you can inform the right people that you can trust and suggest solutions.

Enough companies hand out bounties to people who catch security vulnerabilities, some just categorize per seriousness but some go far enough to have assessed existing problems and put out a list of them with specific dollar mounts they’re willing to hand out.

I think this is the way to go honestly - creates a community, remain transparent which buys immense trust, and have a pretty neat way to attract talent.

I think at this point it’s a no-brainer that lot of big tech companies are going through a cultural decline, which explains the layoffs. AI is just an excuse for layoffs :)