frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

The essential Reinhold Niebuhr: selected essays and addresses

https://archive.org/details/essentialreinhol0000nieb
1•baxtr•12s ago•0 comments

Rentahuman.ai Turns Humans into On-Demand Labor for AI Agents

https://www.forbes.com/sites/ronschmelzer/2026/02/05/when-ai-agents-start-hiring-humans-rentahuma...
1•tempodox•1m ago•0 comments

StovexGlobal – Compliance Gaps to Note

1•ReviewShield•4m ago•0 comments

Show HN: Afelyon – Turns Jira tickets into production-ready PRs (multi-repo)

https://afelyon.com/
1•AbduNebu•5m ago•0 comments

Trump says America should move on from Epstein – it may not be that easy

https://www.bbc.com/news/articles/cy4gj71z0m0o
2•tempodox•6m ago•0 comments

Tiny Clippy – A native Office Assistant built in Rust and egui

https://github.com/salva-imm/tiny-clippy
1•salvadorda656•10m ago•0 comments

LegalArgumentException: From Courtrooms to Clojure – Sen [video]

https://www.youtube.com/watch?v=cmMQbsOTX-o
1•adityaathalye•13m ago•0 comments

US moves to deport 5-year-old detained in Minnesota

https://www.reuters.com/legal/government/us-moves-deport-5-year-old-detained-minnesota-2026-02-06/
2•petethomas•16m ago•1 comments

If you lose your passport in Austria, head for McDonald's Golden Arches

https://www.cbsnews.com/news/us-embassy-mcdonalds-restaurants-austria-hotline-americans-consular-...
1•thunderbong•21m ago•0 comments

Show HN: Mermaid Formatter – CLI and library to auto-format Mermaid diagrams

https://github.com/chenyanchen/mermaid-formatter
1•astm•37m ago•0 comments

RFCs vs. READMEs: The Evolution of Protocols

https://h3manth.com/scribe/rfcs-vs-readmes/
2•init0•43m ago•1 comments

Kanchipuram Saris and Thinking Machines

https://altermag.com/articles/kanchipuram-saris-and-thinking-machines
1•trojanalert•43m ago•0 comments

Chinese chemical supplier causes global baby formula recall

https://www.reuters.com/business/healthcare-pharmaceuticals/nestle-widens-french-infant-formula-r...
1•fkdk•46m ago•0 comments

I've used AI to write 100% of my code for a year as an engineer

https://old.reddit.com/r/ClaudeCode/comments/1qxvobt/ive_used_ai_to_write_100_of_my_code_for_1_ye...
1•ukuina•48m ago•1 comments

Looking for 4 Autistic Co-Founders for AI Startup (Equity-Based)

1•au-ai-aisl•59m ago•1 comments

AI-native capabilities, a new API Catalog, and updated plans and pricing

https://blog.postman.com/new-capabilities-march-2026/
1•thunderbong•59m ago•0 comments

What changed in tech from 2010 to 2020?

https://www.tedsanders.com/what-changed-in-tech-from-2010-to-2020/
2•endorphine•1h ago•0 comments

From Human Ergonomics to Agent Ergonomics

https://wesmckinney.com/blog/agent-ergonomics/
1•Anon84•1h ago•0 comments

Advanced Inertial Reference Sphere

https://en.wikipedia.org/wiki/Advanced_Inertial_Reference_Sphere
1•cyanf•1h ago•0 comments

Toyota Developing a Console-Grade, Open-Source Game Engine with Flutter and Dart

https://www.phoronix.com/news/Fluorite-Toyota-Game-Engine
1•computer23•1h ago•0 comments

Typing for Love or Money: The Hidden Labor Behind Modern Literary Masterpieces

https://publicdomainreview.org/essay/typing-for-love-or-money/
1•prismatic•1h ago•0 comments

Show HN: A longitudinal health record built from fragmented medical data

https://myaether.live
1•takmak007•1h ago•0 comments

CoreWeave's $30B Bet on GPU Market Infrastructure

https://davefriedman.substack.com/p/coreweaves-30-billion-bet-on-gpu
1•gmays•1h ago•0 comments

Creating and Hosting a Static Website on Cloudflare for Free

https://benjaminsmallwood.com/blog/creating-and-hosting-a-static-website-on-cloudflare-for-free/
1•bensmallwood•1h ago•1 comments

"The Stanford scam proves America is becoming a nation of grifters"

https://www.thetimes.com/us/news-today/article/students-stanford-grifters-ivy-league-w2g5z768z
4•cwwc•1h ago•0 comments

Elon Musk on Space GPUs, AI, Optimus, and His Manufacturing Method

https://cheekypint.substack.com/p/elon-musk-on-space-gpus-ai-optimus
2•simonebrunozzi•1h ago•0 comments

X (Twitter) is back with a new X API Pay-Per-Use model

https://developer.x.com/
3•eeko_systems•1h ago•0 comments

Zlob.h 100% POSIX and glibc compatible globbing lib that is faste and better

https://github.com/dmtrKovalenko/zlob
3•neogoose•1h ago•1 comments

Show HN: Deterministic signal triangulation using a fixed .72% variance constant

https://github.com/mabrucker85-prog/Project_Lance_Core
2•mav5431•1h ago•1 comments

Scientists Discover Levitating Time Crystals You Can Hold, Defy Newton’s 3rd Law

https://phys.org/news/2026-02-scientists-levitating-crystals.html
3•sizzle•1h ago•0 comments
Open in hackernews

Critical vulnerability in AI coding platform Base44 allowing unauthorized access

https://www.wiz.io/blog/critical-vulnerability-base44
122•waldopat•6mo ago

Comments

steveBK123•6mo ago
I only know Base44 from the bombardment of YouTube ads for them I receive. Glad to hear its going well.
steveBK123•6mo ago
Just checking back in here to note I am legitimately considering a Youtube sub just to make the Base44 ads go away. So the ads are having some impact!
koakuma-chan•6mo ago
Why not use an Adblock?
swyx•6mo ago
oh interesting. do you think that was a big part of their growth strategy pre acquisition or did the ads only pick up post acquisition?
toddmorey•6mo ago
This is so true. I've ONLY heard them mentioned from their own ads, never even once in the wild. Must be one hell of an ad budget.
Frieren•6mo ago
For AI companies visibility is more important than the actual product. This is a characteristic of many bubbles were getting the word out is the only thing needed to get investors. Investors are scrambling to put as much money in AI as possible, so quality is not a concern for "entrepreneurs".
esafak•6mo ago
It looks like they blew their budget on ads instead of engineers :)
xdfgh1112•6mo ago
Me too. They make it seem like you can vibe code an entire web shop in one prompt. In reality they charge by the token so if you hit a wall trying to get the AI to do stuff you run up a huge bill but it's too late to get out.
zamalek•6mo ago
Hot on the wheels on the vibe-coded Tea breach. Things are looking great for vibe coding.

Don't get me wrong, I have been been more hands off (though not completely, and very prescriptive) with an SPA side project and it's going great. Claude makes way better looking UIs than my dog ugly developer UIs. But vibing auth? That should seriously count as _legal_ gross negligence.

IanCal•6mo ago
Nothing here says auth was vibe coded. It’s a platform for vibe coding.
loupol•6mo ago
There's also nothing saying they are not dog fooding at least a little bit.
bee_rider•6mo ago
I wonder to what extent the vibe coding folks are dogfooding. Their platforms seem too basically work in the sense that they spit out some kind of code, so I guess there must not be too much dogfooding going on.
IanCal•6mo ago
There’s nothing saying they didn’t do this deliberately, but it’d still be an unsubstantiated accusation to say that’s why there was a problem with auth.
JohnMakin•6mo ago
You don’t think they dog food their own app dev? Interesting
zahlman•6mo ago
Dogfooding doesn't normally produce artifacts that end up in production, surely?
zamalek•6mo ago
From the founder himself: https://www.lennysnewsletter.com/p/the-base44-bootstrapped-s...
_fat_santa•6mo ago
I'm not sure I would even call what happened with Tea a breach. They just straight up didn't have any authentication around those endpoints.
belter•6mo ago
"Vulnerability discovered in Google Gemini CLI, patch required" - https://www.techzine.eu/news/security/133402/vulnerability-d...
sunaookami•6mo ago
The Tea breach was not due to vibe-coding btw, the code was from the beginning of 2024 when vibe coding wasn't even possible.
ryandrake•6mo ago
Whether it's strictly Vibe Coding™ or traditional coding by an incompetent amateur, the result is the same: defective and vulnerable slop.
Sherveen•6mo ago
Oh great, let's just say terms whenever, as long as they are adjacent in meaning to whatever we really mean. SMART!
dingnuts•6mo ago
By Karpathy's definition it still isn't possible. But I've definitely been hearing about AI generated code being just as good as my code since 2022.

Don't gaslight us about timelines. The boosters have been telling us amateurs can code and we're all worthless for three and a half years now.

When ChatGPT was launched, they said we'd all be on the streets by now.

What I don't understand is the gleeful receipt of that news by some programmers

bluefirebrand•6mo ago
> What I don't understand is the gleeful receipt of that news by some programmers

I know there are very likely programmers that are gleeful about it, but I suspect that many of the gleeful voices we hear online are not programmers and are resentful of that fact

I see this a lot with the type of people who are making AI "artwork". They often lacked the discipline to practice and learn to make art themselves, they seem to bear an underlying resentment to people who do make art. They are the sort of people who think making art is tied to some innate talent and not something that you can practice. Now they are gleeful about AI generators because it lets them create the pictures in their head without the effort of learning a skill, and they are celebrating that they no longer suffer under the tyranny of people who actually enjoy drawing and painting

janalsncm•6mo ago
Pretty much. We are almost four years into “LLMs will make SWEs obsolete in 6 months” now. Turns out, most tools that let amateurs write bad code let pros write better code.
bluefirebrand•6mo ago
Just because no one had coined the term vibe coding yet doesn't mean people weren't trying what would eventually be called vibe coding

We had LLMs in 2024 that you could certainly try vibe coding with, but probably shouldn't have

Just like we have LLMs today that you can certainly try vibe coding with but probably shouldn't

cwmoore•6mo ago
Wasn’t that default public-accessible Firebase?
sunaookami•6mo ago
Yes which is why the other comments don't make any sense because everyone just reads headlines.
QuadmasterXLII•6mo ago
Vibe coding started working in summer 2023, see e.g. https://github.com/HastingsGreer/jstreb/blob/1ccedf82ec463dc...

the spectacular overcommenting has been here the whole time

Progress since then has mostly been people and tools catching up to the models, the limit of what the models can code has been pretty stagnant the last couple years

jerf•6mo ago
At the moment, I would call "writing secure code that can be put on the internet" to be a super-human task. That is, even our most highly skilled human beings currently can't be blindly trusted to accomplish it; it requires review by teams of experts. We already don't even trust humans, so trusting AIs for the forseeable future (as much as "the forseeable future" may be contracting on us) is not something we should be doing.

And so as to avoid the reader binning this post into "oh just some human triumphalist AI denier", remember I just said I don't trust individual humans on this point either. Everyone, even experts at coding secure code, should be reviewed by other experts at this point.

I suspect this is going to prove to be something that LLMs can't do reliably, by their architecture. It's going to be a next-generation AI thing, whatever that may prove to be.

FiniteIntegral•6mo ago
Agreed. Security is a task that not even a group of humans can perform with upmost scrutiny or perfection. 'Eternal vigilance is the price of liberty' and such. People want to move fast and break things without the backing infrastructure/maintenance (like... actually checking what the AI wrote).
runlaszlorun•6mo ago
Ah yes... Move face and break things. Well Facebook didn't overpromise on that one...
j45•6mo ago
It was only a few months old, how can technical debt and discoveries not be expected?

Wix was probably acquiring a growing userbase.

waldopat•6mo ago
That's my take too. Perhaps $80M for free organic users was a steal?

I do think credit is due to the founder, because he was able to single handedly build and market a valuable solution. That said, he also pushed code every day without code reviews. This is how you get technical debt and security vulnerabilities so fast.

j45•6mo ago
For sure, shipping and iterating quickly to solve a problem people had vs just one's own vision and interpretation is really commendable.

The scary and exciting thing is it's still possible today with other needs.

htrp•6mo ago
Wonder if Wix had any contractual reps/warranties around the state of the Base44 codebase.
financetechbro•6mo ago
I would expect so to some degree. Part of acquisition process is tech diligence usually done by a third party firm. But it’s not the deepest review. They run some code scans and dig into security policies and procedures, and then create a report with their findings which is used for R&W, insurance, etc.
DonHopkins•6mo ago
"Vibe Diligence"
ryandrake•6mo ago
HA HA but seriously: I predict someone's going to start a Venture Fund where all the DD is "done by AI" with equally predicable results. I'm calling it now. Bookmark this comment.
tracker1•6mo ago
Security analysis via AI...
swyx•6mo ago
soo Wiz found a vuln in Wix?

this is israeli on israeli violence

toddmorey•6mo ago
"The vulnerability we discovered was remarkably simple to exploit - by providing only a non-secret app_id value to undocumented registration and email verification endpoints." So you could sign yourself up as editor / collaborator on any app once you knew the app's ID.

Jeez, that's sloppy. My colleague in 2000 discovered you could browse any account on his bank's website by just changing the (sequential!) account IDs in the URL. In a lot of ways we've made great strides in security over the last 25 years... and in many ways, we haven't.

subw00f•6mo ago
Prepare for a whole new era of step backs when everyone is a “prompt engineer”.
andersa•6mo ago
How nice to know they will be implementing the mandatory age verification systems for this new generation of the internet!
Cthulhu_•6mo ago
At least they're costly mistakes that a new generation of decision makers will hopefully learn from.
srcport56445•6mo ago
Have we really made "progress" ? Even in 2000 I doubt people were allowed to walk into a bank and look at everyone's account details.
dpoloncsak•6mo ago
...How long did it take a transfer to settle in the 2000s
manquer•6mo ago
Well…

cash was and is still instant.

When doing large enough transactions that makes cash cumbersome, the slowness is a feature not a bug. We would want multiple reviews and time before it settled.

The value of $100 bill was much higher in 2000 and in 1969 when it became the highest denomination in circulation, so you could transact much higher value with a “wad of cash” than today.

Before 1969 we had bills up to $10,000 for a reason, they served like a credit note/T-Bill from the government, they were no longer needed after banking became robust enough for Cheques/P-Notes etc to replace them.

Paper Cash or Gold/silver coins before them are well understood solved problems, with thousands of years of experiments on size, security ,seigniorage and so on.

toast0•6mo ago
Wires have been fast, during banking hours, for a long time. Expensive, though.
NoPicklez•6mo ago
Well we have because that vulnerability in websites is formally recognized in OWASP and has been fairly well eradicated since then.
roozbeh18•6mo ago
20 years ago the school class enrollment website allowed just that by changing account IDs in URL, we were bypassing the priority enrollment. I had fun adding my friends and I to classes we wanted.
doawoo•6mo ago
Incredible, my university class reg system had un-sanitized input for the class search field so if you knew the SQL you could find exactly how full a class was and dump the whole table of classes without needing to wait for your reg to open.

And pretty sure you could insert your student ID into the class that way too :)

ashton314•6mo ago
Heck you could probably just kick people out of the class that you didn't want to take it with.
cj•6mo ago
I took a slightly different approach and simply wrote a script that checked availability every minute, and then sent me a text message alert when a seat opened up.

(Upperclassmen often switched their schedules around after the priority enrollment deadline ended)

Not as bullet proof as your approach!

cwmoore•6mo ago
That’s useful. But 30 years ago you could iterate Social Security Numbers.
captn3m0•6mo ago
I reported a security vulnerability yesterday, which amounts to a admin=true cookie bypass.
uponasmile•6mo ago
>he vulnerability was fixed in less than 24 hours

I wonder if they fixed it manually or used Base44 to fix it

galnagli•6mo ago
Happy to answer questions : )
waldopat•6mo ago
^^^ Hey YC Fam, this is the author
waldopat•6mo ago
I've got a question! I'd say what's happening with viebcoding is really an acceleration of move fast and break things. Uber and Snapchat both had major security vulnerabilities, resulting in millions of user records leaked, in their hey day of the mid 2010s. And that was WITH whatever DevOps pipeline, code review or other best practices likely in place.

What's unique about Tea or Base44 (or Replit founder deleting his codebase) is A) the disregard for security best practices and B) the speed at which they both grew and exposed vulnerabilities.

So my question is, how do you see the balance of cybersecurity and AI as everything moves faster than ever before?

galnagli•6mo ago
I see companies deploy and trust AI without really investing into security, it will be very easy in the near future to find simple, devastating bugs : )
jus3sixty•6mo ago
Every single day someone dies a wrongful death, a plane crashes, a serious data breach occurs, and someone slips on a banana peel.

None of these things will ever stop the billionaire gravy train because of something called “Risk Management.” I don’t think our “vibe-coded AI slopware” is an exception.

darepublic•6mo ago
These platforms feel like their authors just stick a big bow (uniquely branded ofc) on top of llms. I don't want to undervalue the importance of good glue code.. but that's all I see here. Doesn't deserve the glossy sheen or accolades imo.
zahlman•6mo ago
> Platforms like Loveable, Bolt, and Base44 > Wiz Research has been looking into the security posture > (recently acquired by Wix following an amazingly rapid rise)

Anyone else find all these names really surreal?

(Yeah, Google is kind of a dumb name too, but at least there's a cute story behind it.)

(Okay, I knew Wix had been around for quite some time, but I didn't expect it to be almost as old as YouTube....)

an0malous•6mo ago
It’ll get more surreal because the supply of domains is smaller than the growth of ideas
dangoodmanUT•6mo ago
80M to wix right?
sandeepkd•6mo ago
I might go to the extent of saying that this is classical example of security by obscurity, and for good or bad reasons, a lot of applications would fall into this category, one way or another.
oc1•6mo ago
This will be the golden age of hackers for lulz or money, security researchers and script kiddies (fka idea guys)
bgwalter•6mo ago
Fun facts: All of Wix, Wiz, base44 were founded by ex Unit 8200 members. Wix was used by the NSO group to create fake websites for targeting critics:

https://www.ynetnews.com/articles/0,7340,L-5461537,00.html

sschueller•6mo ago
I wonder how many of their executives can be directly linked to war crimes and/or crimes against humanity.
bitwize•6mo ago
Remember, the S in GenAI is for security.
crook123456•6mo ago
Base44 is just another builder.ai scam