frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Show HN: AI-Powered Merchant Intelligence

https://nodee.co
1•jjkirsch•1m ago•0 comments

Bash parallel tasks and error handling

https://github.com/themattrix/bash-concurrent
1•pastage•1m ago•0 comments

Let's compile Quake like it's 1997

https://fabiensanglard.net/compile_like_1997/index.html
1•billiob•2m ago•0 comments

Reverse Engineering Medium.com's Editor: How Copy, Paste, and Images Work

https://app.writtte.com/read/gP0H6W5
1•birdculture•8m ago•0 comments

Go 1.22, SQLite, and Next.js: The "Boring" Back End

https://mohammedeabdelaziz.github.io/articles/go-next-pt-2
1•mohammede•13m ago•0 comments

Laibach the Whistleblowers [video]

https://www.youtube.com/watch?v=c6Mx2mxpaCY
1•KnuthIsGod•15m ago•1 comments

I replaced the front page with AI slop and honestly it's an improvement

https://slop-news.pages.dev/slop-news
1•keepamovin•19m ago•1 comments

Economists vs. Technologists on AI

https://ideasindevelopment.substack.com/p/economists-vs-technologists-on-ai
1•econlmics•21m ago•0 comments

Life at the Edge

https://asadk.com/p/edge
2•tosh•27m ago•0 comments

RISC-V Vector Primer

https://github.com/simplex-micro/riscv-vector-primer/blob/main/index.md
3•oxxoxoxooo•31m ago•1 comments

Show HN: Invoxo – Invoicing with automatic EU VAT for cross-border services

2•InvoxoEU•31m ago•0 comments

A Tale of Two Standards, POSIX and Win32 (2005)

https://www.samba.org/samba/news/articles/low_point/tale_two_stds_os2.html
2•goranmoomin•35m ago•0 comments

Ask HN: Is the Downfall of SaaS Started?

3•throwaw12•36m ago•0 comments

Flirt: The Native Backend

https://blog.buenzli.dev/flirt-native-backend/
2•senekor•38m ago•0 comments

OpenAI's Latest Platform Targets Enterprise Customers

https://aibusiness.com/agentic-ai/openai-s-latest-platform-targets-enterprise-customers
1•myk-e•41m ago•0 comments

Goldman Sachs taps Anthropic's Claude to automate accounting, compliance roles

https://www.cnbc.com/2026/02/06/anthropic-goldman-sachs-ai-model-accounting.html
3•myk-e•43m ago•5 comments

Ai.com bought by Crypto.com founder for $70M in biggest-ever website name deal

https://www.ft.com/content/83488628-8dfd-4060-a7b0-71b1bb012785
1•1vuio0pswjnm7•44m ago•1 comments

Big Tech's AI Push Is Costing More Than the Moon Landing

https://www.wsj.com/tech/ai/ai-spending-tech-companies-compared-02b90046
4•1vuio0pswjnm7•46m ago•0 comments

The AI boom is causing shortages everywhere else

https://www.washingtonpost.com/technology/2026/02/07/ai-spending-economy-shortages/
2•1vuio0pswjnm7•48m ago•0 comments

Suno, AI Music, and the Bad Future [video]

https://www.youtube.com/watch?v=U8dcFhF0Dlk
1•askl•50m ago•2 comments

Ask HN: How are researchers using AlphaFold in 2026?

1•jocho12•52m ago•0 comments

Running the "Reflections on Trusting Trust" Compiler

https://spawn-queue.acm.org/doi/10.1145/3786614
1•devooops•57m ago•0 comments

Watermark API – $0.01/image, 10x cheaper than Cloudinary

https://api-production-caa8.up.railway.app/docs
1•lembergs•59m ago•1 comments

Now send your marketing campaigns directly from ChatGPT

https://www.mail-o-mail.com/
1•avallark•1h ago•1 comments

Queueing Theory v2: DORA metrics, queue-of-queues, chi-alpha-beta-sigma notation

https://github.com/joelparkerhenderson/queueing-theory
1•jph•1h ago•0 comments

Show HN: Hibana – choreography-first protocol safety for Rust

https://hibanaworks.dev/
5•o8vm•1h ago•1 comments

Haniri: A live autonomous world where AI agents survive or collapse

https://www.haniri.com
1•donangrey•1h ago•1 comments

GPT-5.3-Codex System Card [pdf]

https://cdn.openai.com/pdf/23eca107-a9b1-4d2c-b156-7deb4fbc697c/GPT-5-3-Codex-System-Card-02.pdf
1•tosh•1h ago•0 comments

Atlas: Manage your database schema as code

https://github.com/ariga/atlas
1•quectophoton•1h ago•0 comments

Geist Pixel

https://vercel.com/blog/introducing-geist-pixel
2•helloplanets•1h ago•0 comments
Open in hackernews

DOGE Denizen Marko Elez Leaked API Key for xAI

https://krebsonsecurity.com/2025/07/doge-denizen-marko-elez-leaked-api-key-for-xai/
138•todsacerdoti•6mo ago

Comments

quantified•6mo ago
> “If a developer can’t keep an API key private, it raises questions about how they’re handling far more sensitive government information behind closed doors,”

It raises additional questions. Plenty of questions already unanswered. Seems likely it's been a shitshow.

saalweachter•6mo ago
Like, "why does this nominal government employee have the API key to XAI"/"why is an active X employee playing such a prominent role in the government"?
zdragnar•6mo ago
External tech workers have been a thing since at least the catastrophe that was the original ACA launch. That "tech surge" was definitely full of more experienced people than the "smart kids" we see in DOGE though.

More worrying is that the article points out at time of writing the key was still valid. Why such a high level key was used in an agent script, why it hasn't been rotated (can't be rotated?) and about a dozen other "whys" point to some rather damning practices.

I get that the idea was to avoid the obscene levels of red tape that can be common in government IT, but the pendulum has clearly swung far, far far too far the other way.

jfengel•6mo ago
The ACA was external tech workers, a company called CGI Federal.

The government has some programmers, but the vast majority is done by contractors. That lets the executive branch claim to have reduced those dastardly government workers, and replaced them with upstanding, virtuous, competent, handsome private industry.

Even before the recent harrowing there weren't a lot of government programmers left. Government employees award and manage contracts.

JumpCrisscross•6mo ago
> It raises additional questions

Ones we should be ready to prosecute with official resources come ‘26 and ‘28.

In the meantime, I wouldn’t let him into my country. But the EU will be the EU.

relistan•6mo ago
All of this is a mess. But it should never even have been possible for it to fall to a single developer to screw up and commit a key like that.

If there were anything like proper processes in place, controls would have made that very difficult.

Then there are the weird issues about why obvious close ties to xAI here....

optimalsolver•6mo ago
This was the "normalize Indian-hate" guy.
phendrenad2•6mo ago
Very interesting that he had to resign from DOGE over this, yet xAI seemingly welcomed him.
preisschild•6mo ago
i dont think he had to, he voluntarily did after public pressure. And then JD Vance tried to get him back
UncleMeat•6mo ago
He was rehired.

The trump administration very briefly believed that publicly saying "I was racist before it was cool" and "normalize Indian hate" in public just months before being hired was crossing a line. Then they realized that no it actually wasn't and that their base likes people like this and rehired him.

I do wonder what JD Vance's kids think about situations like this.

sleazebreeze•6mo ago
Nothing to see here. Move right along. I'm sure one or two or a handful of repeated incidents don't represent a trend or potential for future fuck-ups.

What is DOGE even doing now? Can we get some status reports on what the DOGE employees are doing every week since they're such proponents of radical accountability?

bix6•6mo ago
Just ask Grok with the free key!
aspenmayer•6mo ago
the sound of one hand clapping (AI generated)
icecreamscoop•6mo ago
Officially they are still re-writing the software that runs Social Security. Back in May, they said re-writing >1 millions lines of COBOL would only take a few months.

https://www.wired.com/story/doge-rebuild-social-security-adm...

Unofficially, they are the worst people so they are probably doing the worst things you can imagine.

jauntywundrkind•6mo ago
Wired also had this recent update, on "DOGE 2.0".

> But without flashy leadership, DOGE technologists are now quietly cycling into federal agencies, spending days or weeks building products and cutting contracts before cycling out once again. This is all done with little oversight from the White House or the United States DOGE Service (USDS), which these technologists purportedly represent.

Maxious•6mo ago
Big Balls for example is officially no longer a GSA employee of the United States DOGE Service (USDS) but an SSA employee https://www.independent.co.uk/news/world/americas/us-politic...
ygritte•6mo ago
It's unspeakable how these goons get to fuck up everything without any accountability.
ndsipa_pomu•6mo ago
If people value accountability, then voting for a felon to become president isn't the smartest move.
burnt-resistor•6mo ago
Destroying things to justify privatization while stealing every detail about us to increase profits and target opponents. Sure, there are HIPAA, secrecy, and confidentiality violations happening but there's no one left to prosecute the criminals when the criminals are the police, COTUS, SCOTUS, and the unitary executive. The only meaningful distinction remaining is patronage vs. outsider.
zimpenfish•6mo ago
> What is DOGE even doing now?

Forcing the NRC to rubber stamp any requests that come in front of it, apparently[0].

[0] https://www.politico.com/news/2025/07/14/doge-to-regulator-r...

yard2010•6mo ago
Maybe the US should start another government department for this.
lbrito•6mo ago
These reports seem increasingly irrelevant. There are surely many people that care and are outraged, but that's about it. Tomorrow the news cycle will have something else, and the 20 year olds scrapping their pants at doge will be yesterday's news.
esseph•6mo ago
XAI key is potentially root into X (social media), and Tesla via grok, yes?

If so, sounds potentially life threatening.

NTSB might wanna look into that.

Edit: DoD is also contracting for $200 million for grok. Yeah, this is bad. https://www.washingtonpost.com/technology/2025/07/14/elon-mu...

lbrito•6mo ago
That's kind of my point. It is bad And likely no one will be held accountable for it.
glaucon•6mo ago
> DoD is also contracting for $200 million for grok

Somewhat to one side but when up to USD800 million is being spent (Grok, is not the only AI shaped snout at the trough) it's depressing to see the vagueness of the supposed uses [1] (in a five line paragraph this is the most specific description of why that need to spend the money ... "to support our warfighters and maintain strategic advantage over our adversaries")

[1] https://archive.ph/p1ZXR#selection-719.61-719.141

esseph•6mo ago
There are a lot of classified contracts, services, etc.
djtango•6mo ago
As someone who is not very acquainted with blackhat or infosec, what is the priority list to do when you get an API key like this? Exfiltration? Access escalation? Presumably the hole gets closed so what do you do with that time?
sashank_1509•6mo ago
Jokers, even GitHub auto checks if you push code with a private key.
blibble•6mo ago
I doubt it has an integration with grok
fennec-posix•6mo ago
Once, I can understand, but twice? come on... And the keys were still valid hours later (according to the article)
ada1981•6mo ago
I regularly expose my AI api keys in my weekly zoom meetings for our AI Playground :)

So far no one has taken me up on them.

Feel free to join as a VIP anytime!

ada1981•6mo ago
Love the downvoters! You are people too!
epicwynn•6mo ago
Just another example showing that power and persistence does not equal competence.
nothingburger25•6mo ago
I'd say so what. I hardcode many API keys to pull data and so does many people, and worst case scenario you need to regenerate it if it leaks. Not all access keys are the same.
rcakebread•6mo ago
ok, Marko
saubeidl•6mo ago
Did you make an account just to justify questionable data security practices by the people fucking around the social security system without any oversight?
Cthulhu_•6mo ago
"if it leaks" -> "if you detect or get notified that it leaks and you're able to catch it before the credit card linked to your AWS account is drained by a thousand crypto miners"
myvoiceismypass•6mo ago
doth protest too much, or something.
LongjumpingCat•6mo ago
Wild how one leaked xAI API key opened up access to 52 LLMs, including a brand-new Grok model, and they didn’t revoke it right away.

This shows how careless secret management can scale into a huge breach, especially when the same org handles sensitive data.

Shouldn’t teams building with LLMs have automated checks to catch exposed keys before they hit public repos?

Cthulhu_•6mo ago
They should, but they're young, naive and rich, a new generation of "move fast and break things", except this time they've been inserted into the government by a regime who doesn't care and/or who may have the intent to just leak the public's information.
ameliaquining•6mo ago
Why was this flagged? Isn't Krebs on Security generally considered reliable and relevant?