frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Jitsi privacy flaw enables one-click stealth audio and video capture

https://zimzi.substack.com/p/jitsi-privacy-flaw-that-enables-one
66•zielmicha•7h ago

Comments

o11c•4h ago
Does this apply even for iframes, or not?
zimzi•4h ago
Generally no - cross origin iframes don't allow camera/audio by default. Even if the toplevel site allows it (via https://developer.mozilla.org/en-US/docs/Web/API/HTMLIFrameE...), user still needs to grant permissions to toplevel site. Of course you can still use window.open and top.location.href in the iframe and use the same trick as in the article.
3eb7988a1663•3h ago
Not that I use Jitsi, but I suddenly feel more embarrassed about my number of open tabs. Some other exploit could have silently been launched long ago.
unsnap_biceps•3h ago
Can someone describe the feature that this is used for? I struggle to think of any valid reason for automatic joining with audio/video like that.
firefax•3h ago
Is this understood to be new? I think I got hit with this quite a long time ago.

(As in during the pandemic -- long ago in vuln times.)

I am willing to discuss it, off the record, if someone provides their signal information.

Telemakhos•2h ago
Maybe my Mac is set to be paranoid, but can you share video without being asked to give the mic and camera permission to operate? I chat with jitsi all the time and have to give jitsi explicit permission to use the mic/camera each time.
spaceport•2h ago
Where do I pay to read security research writeups with only cats used in explainer images and examples? This exploit is cute.

US non-compete agreement laws by state

https://www.sixfifty.com/resource-library/non-compete-agreement-by-state/
1•devy•2m ago•0 comments

Ollama and MCP – A blog about AI by AI, with help from me

https://blog.aridgwayweb.com/mcp-ollama-local-assistant-soon.html
1•armistace•7m ago•1 comments

Engineers' Material Achieves Unmatched Efficiency in 'Forever Chemical' Removal

https://www.price.utah.edu/2025/07/21/u-engineers-material-achieves-unmatched-efficiency-in-forever-chemical-removal
1•gnabgib•7m ago•0 comments

Draw a fish and watch it swim

https://drawafish.com
2•thunderbong•12m ago•0 comments

Moving from an orchestration-heavy to leadership-heavy management role

https://lethain.com/orchestration-heavy-leadership-heavy/
2•mooreds•21m ago•0 comments

Context Rules Everything Around Me

https://jonmagic.com/posts/context-rules-everything-around-me/
1•mooreds•27m ago•0 comments

Ex-Libor Trader Tom Hayes Wins Bid to Overturn Rigging Conviction

https://www.bloomberg.com/news/articles/2025-07-23/tom-hayes-wins-supreme-court-bid-to-overturn-decade-old-libor-conviction
1•mhh__•29m ago•0 comments

Show HN: Strava for Cooking

https://www.stravaforcooking.com/
2•cowllin•39m ago•2 comments

Fast LoRA Inference for Flux with Diffusers and PEFT

https://huggingface.co/blog/lora-fast
1•sayak_paul_hf•44m ago•0 comments

Columbia University to pay $200M in settlement with Trump administration

https://www.bbc.com/news/articles/cq8zljpvyk0o
3•andsoitis•46m ago•0 comments

Gemini 2.5 Pro Capable of Winning Gold at IMO 2025 with Prompting

https://arxiv.org/abs/2507.15855
2•thorum•47m ago•1 comments

Training a Flappy Bird Diffusion World Model to Run in a Web Browser

https://www.njkumar.com/optimizing-flappy-bird-world-model-to-run-in-a-web-browser/
1•thorum•48m ago•0 comments

Love – Online Procedural Adventiure Game

https://www.quelsolaar.com/love/
1•cropcirclbureau•50m ago•0 comments

Utopia on Fast Forward: Why Accelerating AI Skips over the Plumbing

https://rijama.substack.com/p/utopia-on-fast-forward-why-accelerating
1•quarksplitter•51m ago•0 comments

GitHub Spark – a new tool in Copilot that turns your ideas into full-stack apps

https://githubnext.com/projects/github-spark
1•Garbage•1h ago•1 comments

SSL and Domain Monitor Feedback Requested – What do you think of this app?

https://statusnow.dev/
1•nkruger•1h ago•0 comments

Is anyone building a voice agent for runners?

1•vietthangif•1h ago•0 comments

Restaurants, Salons and Workouts Are Free for Hot People–If They Post

https://www.wsj.com/style/neon-coat-app-influencers-free-meals-classes-d310564f
2•paulpauper•1h ago•0 comments

Four-day work week benefits workers, employers, study says

https://medicalxpress.com/news/2025-07-day-week-benefits-workers-employers.html
3•OutOfHere•1h ago•1 comments

Deep Film Inc. Back End/AI Engineer and UI/UX Engineer

https://berlinstartupjobs.com/engineering/backend-ai-engineer-ui-ux-engineer-deep-film-inc/
1•CharlesRP•1h ago•0 comments

"Destroy the web": Sam Altman on AI concerns for economy and finance

https://www.youtube.com/watch?v=9LFlEZxc1rk
1•Brysonbw•1h ago•0 comments

How to Catch a Wily Poacher in a Sting: A Thermal Robotic Deer

https://www.wsj.com/us-news/how-to-catch-a-wily-poacher-in-a-sting-a-thermal-robotic-deer-ffef0fa8
2•Element_•1h ago•0 comments

Notes on Rewriting JSX as Astro

https://carlosn.com.br/blog/post/notes-on-rewriting-jsx-as-astro/
2•carlosneves•1h ago•0 comments

Addressing Privacy Fatigue

https://www.fastmail.com/blog/addressing-privacy-fatigue/
6•billybuckwheat•1h ago•0 comments

Troubled SPAC to buy iRocket for $400M but it returned most of its cash

https://techcrunch.com/2025/07/23/a-troubled-spac-plans-to-buy-irocket-for-400m-but-it-already-returned-most-of-its-cash/
2•pseudolus•1h ago•1 comments

Vibe coding turned this Swedish AI unicorn into the fastest growing startup ever

https://www.forbes.com/sites/iainmartin/2025/07/23/vibe-coding-turned-this-swedish-ai-unicorn-into-the-fastest-growing-software-startup-ever/
2•myth_drannon•1h ago•0 comments

I Eat

https://taylor.town/how-i-eat
5•paulpauper•1h ago•0 comments

Show HN: Voice-First AI Code Review Platform (Looking for OSS Beta testers)

https://www.lightlayer.dev/
3•changisaac•1h ago•0 comments

Ask HN: Has anyone deployed LLMs to production?

4•saaspirant•1h ago•2 comments

Electric cars produce far less brake dust pollution than combustion-engine cars

https://modernengineeringmarvels.com/2025/07/22/surprising-science-how-electric-cars-quietly-transform-urban-air/
61•tzs•1h ago•45 comments