frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ask HN: How do you deal with the fear of installing potentially risky tools?

1•easypancakes•1h ago
There are some open-source tools—popular and widely used—that I’m honestly a bit scared to run on my work laptop (since it has access to credentials, production servers, etc.). For example, I always feel a little nervous about installing something like k9s.

This all started after the xz backdoor incident. Since then, I can’t shake the thought that if I install the wrong thing, it could mess things up really badly. At the same time, these tools could make my life at work so much easier.

Emacs is another example. With or without packages, it installs a bunch of stuff I don’t really understand. Because of that, I usually just stick to the basics: VS Code, Terraform, kubectl—tools I feel safer with because they come from well-known sources.

So I’m curious: how do you deal with this? Do you ever worry about your work machine getting compromised because of an open-source tool you installed? Any advice is appreciated.

Comments

0x3f•1h ago
IMO it's up to the company to have a posture about this stuff. If the team expects you to use dependencies at the level of left-pad without any further scrutiny, then that's their risk appetite. Of course you can argue for or against this as part of the normal course of things.

In an average startup/mid-size (i.e. a place with no enforced controls) I really doubt the soft expectation would be for you as a random engineer to pre-empt something like the xz backdoor. Or be worried about something as well-used as k9s/emacs.

Of course, some companies are special cases with different expectations and requirements, ymmv.

The modern text rendering pipeline: Unicode, bidi, segmentation, shaping

https://www.newroadoldway.com/text1.html
1•fanf2•18s ago•0 comments

Google Play Integrity Device Recall Beta

https://developer.android.com/google/play/integrity/device-recall
1•gjsman-1000•1m ago•0 comments

Show HN: I track electric car company moves through hiring patterns and patents

https://devlisten.com/
2•userium•2m ago•0 comments

Put a ring on it: a lock-free MPMC ring buffer

https://h4x0r.org/ring/
2•todsacerdoti•2m ago•0 comments

From Kyiv to the Suwałki Gap, bogs return as Europe's defensive shield

https://www.politico.eu/article/russia-defense-kyiv-ukraine-nato-eu-bogs-poland-war-germany/
1•danielam•4m ago•0 comments

Letting a team of AI agents manage my crypto portfolio

https://timothyej.com/letting-a-team-of-ai-agents-manage-my-crypto-portfolio/
1•gitmagic•4m ago•0 comments

China's Share in Global Display Capacity to Reach 75% in 2028

https://display.counterpointresearch.com/press-release/chinas-share-in-global-display-capacity-to...
3•ksec•6m ago•0 comments

Gold, Frankincense, and Silicon

https://daringfireball.net/2025/08/gold_frankincense_and_silicon
2•frizlab•8m ago•0 comments

YOTA: Building a roadmap for Yottascale computing by 2040

https://medium.com/@ersun.warncke/yota-building-a-roadmap-for-yottascale-computing-by-2040-de5ee4...
1•frozenseven•9m ago•0 comments

Show HN: My 90s TV

https://90s.myretrotvs.com
1•seyz•9m ago•0 comments

A free searchable cybersecurity stats database

https://www.cybersecstats.com/database/
3•legitimatejim•9m ago•0 comments

Generic Types: Adding Math Puzzles to Your Code (2021)

https://patshaughnessy.net/2021/11/6/generic-types-adding-math-puzzles-to-your-code
1•pansa2•10m ago•0 comments

Show HN: Arabic Vocab API

https://egyptian-arabic-vocab-selmetwa.koyeb.app/
3•selmetwa•10m ago•0 comments

Margaux Blanchard, the fake AI journalist

https://dispatch-media.com/margaux-blanchard-the-journalist-who-didnt-exist/
1•comradino123•11m ago•0 comments

In Search of AI Psychosis

https://www.astralcodexten.com/p/in-search-of-ai-psychosis
1•venkii•11m ago•0 comments

429 Too Many Requests from registry.npmjs.org

1•mirekrusin•11m ago•0 comments

Wubular: Rubular Reimagined in Ruby+WASM

https://rubyelders.com/writings/2025-08-wubular-1.html
2•thunderbong•11m ago•0 comments

Why I'm All-In on Context Engineering

https://old.reddit.com/r/ContextEngineering/comments/1n02gxw/why_im_allin_on_context_engineering/
1•cgvas•11m ago•0 comments

IBM and AMD partner on quantum computing with end-of-decade goal

https://www.axios.com/2025/08/26/ibm-amd-quantum-computing
2•voxadam•13m ago•0 comments

Microsoft Mosaic: Replace laser/copper links with MicroLEDs

https://www.microsoft.com/en-us/research/publication/mosaic-breaking-the-optics-versus-copper-tra...
2•est•14m ago•0 comments

Developers lose focus 1,200 times a day – how MCP could change that

https://venturebeat.com/ai/developers-lose-focus-1200-times-a-day-how-mcp-could-change-that/
1•sylvainkalache•15m ago•0 comments

Compositional Datalog on SQL: Relational Algebra of the Environment

https://www.philipzucker.com/compose_datalog/
3•Bogdanp•18m ago•0 comments

Visual AI flow manager for Genkit

https://flowshapr.ai/
3•colibris•19m ago•1 comments

Why AI Probably Won't Help Your Team Ship More Product

https://chaoticgood.management/why-ai-probably-wont-help-your-team-ship-more-product/
2•rellid•19m ago•0 comments

Gemini 2.5 Flash Image, our image model

https://developers.googleblog.com/en/introducing-gemini-2-5-flash-image/
18•dmotz•21m ago•1 comments

Modular LLM framework inspired by Linux – aiming for a one-GPU future

1•openkame•22m ago•0 comments

Spotify Is Adding DMs

https://www.theverge.com/news/765771/spotify-messages-dms-audio-sharing-feature
1•achristmascarl•22m ago•0 comments

96% jump in number of people coming from US to live in Ireland

https://www.rte.ie/news/business/2025/0826/1530216-cso-population-figures/
1•s_dev•22m ago•0 comments

Spotify launches a messaging feature in a bid to become more social

https://techcrunch.com/2025/08/26/spotify-launches-a-messages-feature-in-a-bid-to-become-more-soc...
2•toomuchtodo•22m ago•1 comments

AT&T to buy wireless spectrum licenses from EchoStar for $23B

https://www.reuters.com/en/att-buy-wireless-spectrum-licenses-echostar-23-billion-2025-08-26/
2•sgerenser•23m ago•0 comments