frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Why LLM Authorization is Hard

https://www.osohq.com/post/why-llm-authorization-is-hard
15•mathewpregasen•4h ago

Comments

pvg•4h ago
Ongoing discussion https://news.ycombinator.com/item?id=44502318
forks•4h ago
Just to make sure I'm following: that's ongoing discussion of the same issue, but not the same post, right?
meghan•4h ago
Yes, similar discussion across two separate articles: (1) article from General Analysis on "Supabase MCP can leak your entire SQL database" (2) article from Oso talking about why authorization in AI is hard, what to do about it, which references the General Analysis article
pvg•3h ago
Right, because otherwise you end up with a split discussion and people miss stuff, moderators end up having to merge them, etc. Immediate followups count as dupes (in HN's weird dupery algebra), they're better off linked in the active thread.
gneray•4h ago
Curious to hear from the community about this, esp in light of article on supabase
gsarjeant•3h ago
Hi, I'm the post writer. I have a habit of writing like a textbook author, but the things that jumped out at me while I was working on this with Oso were:

1. Least privilege can address a lot of these issues. We all know that, but in practice we don't really apply it because it can be a pain.

2. These applications are interesting because they can interpret meaning instead of rigidly following instructions, but that makes them prone to misunderstanding and manipulation. That breaks a lot of our assumptions about how software responds to input.

3. It's helpful to think of these applications in terms of impersonation. The user's rights should be the upper bound of the LLM's permissions when it acts on their behalf.

4. Ideally, we'd also constrain permissions according to the task being performed, but that's trickier.

The article goes into all that in exhaustive (some might say tedious) detail. It was a difficult write because this space moves so quickly and has so much hype, but it's been a good exercise to try to sift through that and think about it seriously.

(edited because I don't know how to make a legible list)

I made a TikTok video downloader website with no ads.. yet

https://www.tdown.app/
1•henrymuddleton•37s ago•0 comments

Bezos-funded climate satellite is lost in space

https://www.theverge.com/news/703091/methane-satellite-methanesat-lost-bezos-edf
1•Bluestein•2m ago•0 comments

AI Agents ≠ Zapier–A Better Mental Model

1•chandan_maruthi•3m ago•0 comments

Building Proactive AI Agents

https://substack.com/home/post/p-164375851
1•Mernit•3m ago•0 comments

Inertia.js in Rails: a new era of effortless integration (2024)

https://evilmartians.com/chronicles/inertiajs-in-rails-a-new-era-of-effortless-integration
2•mooreds•5m ago•0 comments

Show HN: DBUF

https://github.com/bintoca/dbuf
1•pierogitus•6m ago•0 comments

Tsukudani and hot rice: Still a go-to meal in Japan centuries after its creation

https://apnews.com/article/tsukudani-japan-side-tokyo-traditional-food-fa63e1f3f59d2b9e177a327f7c814ffe
1•petethomas•8m ago•0 comments

Building a timberframe home from scratch

https://massiehouse.blogspot.com/
1•xdfg13345•9m ago•0 comments

Robot surgery on humans could be trialled within decade after success on pigs

https://www.theguardian.com/science/2025/jul/09/robot-surgery-on-humans-could-be-trialled-within-decade-after-success-on-pig-organs
2•Bluestein•10m ago•0 comments

Unpatchable Vulnerabilities in Windows 10/11: Security Report 2025

https://zenodo.org/records/15850090
1•vinhatson•13m ago•1 comments

Show HN: A Nextflow ↔ Python Integration Plugin

https://github.com/royjacobson/nf-python
1•unddoch•14m ago•0 comments

TikTok Sans released under the OFL

https://fonts.google.com/specimen/TikTok+Sans
2•Tiberium•14m ago•0 comments

Managed Postgres Overview

https://fly.io/docs/mpg/overview/
1•sergiotapia•16m ago•0 comments

What are your dream companies to work at?

1•ssc23•16m ago•0 comments

A simple monthly injection allows mice to live 25% longer and free from diseases

https://english.elpais.com/science-tech/2024-07-17/a-simple-monthly-injection-allows-mice-to-live-25-longer-and-free-from-diseases.html
2•speckx•18m ago•0 comments

Symbolic 'science fair' showcases research cut by Trump team

https://www.nature.com/articles/d41586-025-02164-y
2•Bluestein•18m ago•0 comments

Scientists 3D print tumors for cancer research

https://www.tomshardware.com/3d-printing/scientists-3d-print-tumors-for-cancer-research-tissuetinker-using-3d-bioprinting-to-create-miniature-models-of-healthy-and-diseased-tissue-for-side-by-side-comparison-backed-by-mcgill
1•giuliomagnifico•19m ago•0 comments

Perplexity just launched Comet, an AI web browser

https://www.theverge.com/news/703037/perplexity-ai-web-browser-comet-launch
2•cpeterso•23m ago•0 comments

Ancient pathogen became deadlier when humans started wearing wool

https://www.nature.com/articles/d41586-025-01631-w
1•rntn•27m ago•0 comments

OpenAI to release web browser in challenge to Google Chrome

https://www.reuters.com/business/media-telecom/openai-release-web-browser-challenge-google-chrome-2025-07-09/
4•jmsflknr•28m ago•0 comments

LangChain is about to become a unicorn, sources say

https://techcrunch.com/2025/07/08/langchain-is-about-to-become-a-unicorn-sources-say/
3•clemo_ra•29m ago•0 comments

Finding PBHs Using the LSST Will Be a Statistical Challenge

https://www.universetoday.com/articles/finding-pbhs-using-the-lsst-will-be-a-statistical-challenge
1•rbanffy•30m ago•0 comments

<Now Go Bang > the REM-Arkable Misadventures of List

https://www.masswerk.at/nowgobang/2025/the-remarkable-misadventures-of-list
1•rbanffy•30m ago•0 comments

brotab: Control your browser's tabs from the command line

https://github.com/balta2ar/brotab
3•pseudalopex•31m ago•0 comments

Desktop Publishing Tools That Didn't Make It

https://tedium.co/2022/10/12/forgotten-desktop-publishing-tools-history/
2•rbanffy•31m ago•0 comments

The Hungry, Hungry AI Model

https://tomtunguz.com/input-output-ratio/
2•speckx•32m ago•0 comments

Show HN: Program for Framework 16 LED Matrix

https://boyne.dev/projects/fwmm.html
1•DedFishy•33m ago•1 comments

Strategic connection between JuliaHub, Dyad and Julia open source community

https://juliahub.com/blog/the-strategic-connection-between-juliahub-dyad-and-the-julia-open-source-community
1•darboux•34m ago•0 comments

Show HN: Browse Developer Portfolios

https://www.webportfolios.dev
1•yeahimjt•35m ago•0 comments

Generative Blocks World: Moving Things Around in Pictures

https://arxiv.org/abs/2506.20703
2•PaulHoule•38m ago•0 comments