frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Steganography in floating point data with NaN payloads

https://github.com/kjordahl/steganan
1•dynm•1m ago•0 comments

The Retrofit and the Built Environment Starter Pack from Heat Pumps to Financing

https://climatedrift.substack.com/p/the-retrofit-and-the-built-environment
1•ssuds•1m ago•0 comments

Red Hat just expanded free access to RHEL for business developers

https://www.zdnet.com/article/red-hat-expands-free-access-to-rhel-for-business-developers/
1•thunderbong•3m ago•0 comments

Be History or Do History?

https://contraptions.venkateshrao.com/p/be-history-or-do-history
1•OgsyedIE•6m ago•0 comments

Java Criminally Underhyped? Not Back in 1997. (2021)

https://dylanbeattie.net/2021/07/01/java-is-criminally-underhyped.html
1•1317•7m ago•0 comments

Writing a simple JIT Compiler in about 1000 lines of C

https://kuterdinel.com/writing-a-very-simple-jit-compiler-in-about-1000-lines-of-c.html
1•Bogdanp•12m ago•0 comments

Amazon gets serious with AI Safety

https://arxiv.org/abs/2507.06260
2•prizeon•13m ago•0 comments

Escaping Groupthink

https://www.thetransmitter.org/animal-behavior/escaping-groupthink-what-animals-behavioral-quirks-reveal-about-the-brain/
1•wjb3•17m ago•0 comments

Southeast Asia's Last Culinary Frontier: The 17,000 Islands of Indonesia

https://www.youtube.com/watch?v=dr3Hsa8Fam4
2•bane•23m ago•0 comments

Show HN: Buzz0.com – Daily curated Show HN posts

https://buzz0.com/
1•Airyisland•23m ago•0 comments

Doing More Is Often Easier

https://www.raptitude.com/2025/04/doing-more-is-often-easier/
3•_vaporwave_•28m ago•1 comments

Civilian hackers in China's military cyber strategy

https://margin.re/mobilizing-cyber-power-the-growing-role-of-cyber-militias-in-chinas-network-warfare-force-structure-2/
3•aaronsdevera•31m ago•0 comments

Deep Dive into Rails Database Connection Pools

https://www.prateekcodes.dev/rails-database-connection-pooling-explained/
1•prateekkish•31m ago•0 comments

Arguing About Woodworking More Popular Hobby Than Woodworking (2013)

http://www.closegrain.com/2013/04/arguing-about-woodworking-more-popular.html
2•ecliptik•34m ago•0 comments

TikTok prepares US app with its own algorithm and user data

https://www.reuters.com/world/china/tiktok-prepares-us-app-with-its-own-algorithm-user-data-2025-07-09/
1•mfiguiere•34m ago•1 comments

Your Prize for Saving Time at Work with AI: More Work

https://www.wsj.com/lifestyle/careers/ai-work-free-time-51c8c92a
10•petethomas•44m ago•5 comments

The case for building operator interfaces before AI agents

https://www.henrypray.com/writings/the-only-saas-feature-you-should-be-building
2•henrypray•48m ago•0 comments

Type-C To Type-C Scented Cable 48in

https://www.fivebelow.com/products/up-tech-type-c-to-type-c-scented-cable-48in-9184770
2•rendx•48m ago•1 comments

Show HN: ColorConJ – Explore Spanish color names by letter

https://colorconj.com/
1•lur0913•49m ago•0 comments

Eval AI jobs new market for Mercor

https://www.gardinercolin.com/p/marketplace-memo-13
1•predogger•50m ago•0 comments

In search of more efficient learning algorithms, researchers look to infants

https://www.thetransmitter.org/neuroai/the-babylm-challenge-in-search-of-more-efficient-learning-algorithms-researchers-look-to-infants/
3•domofutu•53m ago•0 comments

HIV-1 latency reversal via ectopic expression of a viral antisense transcript

https://www.science.org/doi/10.1126/sciadv.adu8014
2•PaulHoule•54m ago•0 comments

Our Missing Pieces

https://docs.google.com/document/d/1-KSIE89xHnipRBm8T6BRbxEQb5_byr5CwkB-S7XIwjQ/edit?tab=t.0
1•jger15•54m ago•1 comments

Claude Code OAuth Authentication Fails - "OAuth account information not found

https://github.com/anthropics/claude-code/issues/1484
1•rakken•56m ago•0 comments

CatchIdeas – Find High-Traffic Keywords for Product and Content Ideas

https://catchideas.com
1•labubulive•56m ago•0 comments

Fact Sheet: Autism Prevalence

https://www.thetransmitter.org/spectrum/prevalence-autism-u-s-remains-steady-new-data-suggest/
2•domofutu•58m ago•0 comments

No Tax on Overtime Calculator

https://notaxonovertimecalculators.org/
1•dond1986•58m ago•0 comments

V0 Platform API now in beta

https://vercel.com/changelog/v0-platform-api-now-in-beta
1•tzury•59m ago•0 comments

Research suggests electricity markets are using suboptimal pricing

https://arxiv.org/abs/2507.06035
2•cfata•1h ago•1 comments

Thoughts on Motivation and My 40-Year Career

https://charity.wtf/2025/07/09/thoughts-on-motivation-and-my-40-year-career/
4•zdw•1h ago•0 comments
Open in hackernews

Unpatchable Vulnerabilities in Windows 10/11: Security Report 2025

https://zenodo.org/records/15850090
4•vinhatson•7h ago

Comments

vinhatson•7h ago
This comprehensive security report investigates unpatchable vulnerabilities in Windows 10 and 11, focusing on systemic flaws that resist traditional patching due to their deep integration into the operating system’s architecture, hardware dependencies, and legacy compatibility require ments. These vulnerabilities, rooted in fundamental design choices and ecosystem constraints, pose significant challenges to securing millions of Windows devices worldwide. The report ex amines three critical vulnerabilities: legacy BIOS/UEFI firmware weaknesses, kernel memory management flaws, and backward compatibility with legacy protocols. It provides a detailed technical analysis, exploitation vectors, detection challenges, and comprehensive mitigation strategies. With Windows 10 approaching its end-of-support deadline in October 2025, these flaws pose heightened risks, necessitating proactive defenses. This report adheres to responsi ble disclosure principles and aims to support Microsoft’s efforts to strengthen Windows security in 2025.
p_ing•7h ago
Interesting that the report calls out SMBv1 which is disabled by default in Windows 11. I suppose you could have an exploit that triggered SMBv1 optional feature install, but you already have local admin rights at that point.

SMBv1 has effectively been removed for modern clients and thus is not 'unpatchable'.

Encryption is on-by-default with SMBv3, I believe.

So some of these mitigations are already in place. I'm sure the UEFI issues will always persist, that's not a Microsoft issue per se, and I assume the kernel memory management potential vulnerabilities are still present, though the author doesn't offer any concrete proof in the report that these are exploitable as of today.

vinhatson•7h ago
This is my first public article on security. I have several reports certified by MSRC as unpatchable vulnerabilities. However, from a legal standpoint, I'm not yet clear on the reasonable limits of technical detail for publishing these reports. Therefore, I'm just testing the waters first. I will find a way to gradually publish them from an academic perspective but am currently considering how to avoid legal consequences.
p_ing•2h ago
Ah yep, follow your NDAs/refer to a lawyer.

Good luck, I like the report format! Hopefully we hear from you again on the truly nasty vulnerabilities.

vinhatson•7h ago
Thank you