frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

OAuth Device Flow Vulnerabilities: Analysis of 2024-2025 Attack Wave

https://guptadeepak.com/oauth-device-flow-vulnerabilities-a-critical-analysis-of-the-2024-2025-attack-wave/
1•guptadeepak•1h ago

Comments

guptadeepak•1h ago
This analysis dives into the recent surge of OAuth device flow attacks observed in 2024-2025, focusing on key protocol weaknesses and implementation gaps.

The critical issue stems from attacker exploitation of insufficient user code verification and token issuance processes, enabling device flow hijacking and abuse at scale. Notably, the challenge of securely binding device codes to legitimate users remains unresolved, especially in constrained input environments.

How are you addressing the trade-offs between user convenience and security in OAuth device flows?

Something weird is going on with Switch 2 game development

https://www.polygon.com/switch-2-development-kits-nintendo/
1•ezekg•2m ago•0 comments

Managing an Expert Team When You Can't Do Their Jobs

https://www.cybadger.com/they-know-more-than-i-do-managing-an-expert-team-when-you-cant-do-their-...
1•mooreds•3m ago•0 comments

Nvidia Announces Financial Results for Second Quarter Fiscal 2026

https://nvidianews.nvidia.com/news/nvidia-announces-financial-results-for-second-quarter-fiscal-2026
1•kgwgk•3m ago•0 comments

Verily is closing its medical device program, shifts resources to AI

https://techcrunch.com/2025/08/26/verily-is-closing-its-medical-device-program-as-alphabet-shifts...
1•blevinstein•4m ago•0 comments

The difference between your ID, online and offline

https://idiallo.com/blog/your-id-online-and-offline
2•firefoxd•6m ago•0 comments

Synthetic Users

https://www.syntheticusers.com/
1•mooreds•8m ago•0 comments

Quickstart Guide to Being a Digital Nomad

https://foundersconfidential418.substack.com/p/quickstart-guide-to-being-a-digital
2•DtNZNkLN•8m ago•0 comments

The Color of the Future: A history of blue

https://www.hopefulmons.com/p/the-color-of-the-future
1•prismatic•8m ago•0 comments

Musicians Can't Rely on Financial Institutions to Fund Them

https://www.jphfeeds.top/2025/08/musicians-cant-rely-on-financial.html
1•joshuarblog•10m ago•0 comments

Show HN: An AI productivity assistant to help you focus

https://www.deepwork.fit/
1•yumingh•10m ago•0 comments

Intel's PCI Vendor ID is 0x8086, There are more like that in the database

https://kubatyszko.com/2025/08/28/pci-vendor-id-rabbit-hole-musings/
1•kubatyszko•10m ago•1 comments

Show HN: PR-desc your AI Git and GitHub workflow assistant

https://github.com/danielddemissie/pr-desc-cli
1•daniddeme•12m ago•0 comments

Whatever Happened to the Self Driving Semi?

https://itcanthink.substack.com/p/whatever-happened-to-the-self-driving
2•danso•12m ago•1 comments

Light-based AI image generator uses almost no power

https://www.newscientist.com/article/2494141-light-based-ai-image-generator-uses-almost-no-power/
3•kPwn•14m ago•0 comments

LLM-system-design-and-model-selection

https://www.oreilly.com/radar/llm-system-design-and-model-selection/
1•rehman•14m ago•0 comments

In Tokyo, These Trains Jingle All the Way (3.5 Min Video)

https://www.youtube.com/watch?v=nSG5IkRA9BE
1•rmason•15m ago•0 comments

Compositional Datalog on SQL: Relational Algebra of the Environment

https://www.philipzucker.com/compose_datalog/
1•philzook•16m ago•0 comments

Injecting Java from native libraries on Android

https://octet-stream.net/b/scb/2025-08-03-injecting-java-from-native-libraries-on-android.html
1•PaulHoule•20m ago•0 comments

Collective alignment: public input on our Model Spec

https://openai.com/index/collective-alignment-aug-2025-updates/
1•davidbarker•20m ago•0 comments

From Airbnb to America's 'Chief Design Officer'

https://www.nytimes.com/2025/08/27/style/joe-gebbia-trump-design-officer-airbnb.html
1•01-_-•22m ago•0 comments

"Bitcoin Is Dead" – The #1 Database of Notable Bitcoin Skeptics

https://bitbo.io/dead/
1•frozenseven•22m ago•0 comments

4chan launches legal action against Ofcom in US

https://www.bbc.com/news/articles/clyjq40vjl7o
2•01-_-•22m ago•0 comments

Show HN: An ncurses CUDA-based fluid simulation

https://github.com/seanwevans/fluid-sims
1•goosethe•23m ago•0 comments

Beginning 1 September, we will need to geoblock Mississippi IPs

https://dw-news.dreamwidth.org/44429.html
8•AndrewDucker•23m ago•0 comments

Security researcher maps TeslaMate servers spilling Tesla vehicle data

https://techcrunch.com/2025/08/26/security-researcher-maps-hundreds-of-teslamate-servers-spilling...
1•rbanffy•26m ago•1 comments

New Study Rocks Jupiter's Giant Impact Theory – Universe Today

https://www.universetoday.com/articles/new-study-rocks-jupiters-giant-impact-theory
2•rbanffy•26m ago•0 comments

Can LLMs Dream of Electric Sheep?

https://sankalp.bearblog.dev/can-llms-dream-of-electric-sheep/
1•indigodaddy•26m ago•0 comments

Behind the Headlines of the MIT Study

https://www.tennr.com/resources/behind-the-headlines-of-the-mit-study
1•treyholterman•27m ago•1 comments

Foresight-32B Beats Frontier LLMs on Live Polymarket Predictions

https://blog.lightningrod.ai/p/foresight-32b-beats-frontier-llms-on-live-polymarket-predictions
4•bturtel•30m ago•0 comments

Seven common tropes used to deny Gaza's famine, debunked by an expert

https://www.telegraph.co.uk/global-health/terror-and-security/seven-common-tropes-used-to-deny-ga...
4•NomDePlum•31m ago•1 comments