frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Gorge (2022)

https://qntm.org/gorg
1•Rygian•1m ago•0 comments

Like Game-of-Life, but on Growing Graphs, with WASM and WebGL

https://znah.net/graphs/
1•znah•2m ago•0 comments

Show HN: agent-ledger – prevent double side effects when AI agents retry

https://github.com/rune0-dev/agent-ledger
1•itsimri•2m ago•0 comments

Gemini responds to request to turn on lights with hallucinated jailbreak prompt

https://www.reddit.com/r/googlehome/s/Lh3dYqccgB
1•visviva•4m ago•0 comments

RustCast -open-source Raycast-style launcher written in Rust

https://github.com/unsecretised/rustcast
1•todsacerdoti•4m ago•0 comments

Why Do Olympic Athletes Bite Their Medals?

https://www.thv11.com/article/sports/olympics/winter-games-iq/why-athletes-bite-medals-olympics/5...
1•RickJWagner•4m ago•0 comments

Mdash – Markdown in URL

https://kamilmac.github.io/mdash/
1•kmacinski•6m ago•0 comments

Brings your family memories now

https://familymemories.video
1•tareq_•6m ago•0 comments

Travel to Cheap Destinations

https://nomagicpill.substack.com/p/travel-to-cheap-destinations
1•surprisetalk•8m ago•0 comments

Rebuilding my home network with VLANs and 10Gbps

https://clintonboys.com/projects/homelab/03-network/
1•mtsolitary•8m ago•0 comments

Show HN: RepoSherlock – repo onboarding in minutes (map, run, risks)

1•kemal-arslan•10m ago•0 comments

Going Through Snowden Documents, Part 2

https://libroot.org/posts/going-through-snowden-documents-part-2/
1•stareatgoats•11m ago•0 comments

Can Europe get kids off social media?

https://www.ft.com/content/cf465c21-4789-490b-b328-41f6383567d7
2•thm•14m ago•0 comments

I Built a NAS (Buildlog)

https://arne.me/blog/buildlog-nas
2•abahlo•14m ago•0 comments

Making Software: How do computers store data?

https://www.makingsoftware.com/chapters/how-is-data-stored
2•Garbage•16m ago•0 comments

A timeline of claims about AI/LLMs

https://blog.nethuml.xyz/posts/2026/02/timeline-of-claims-about-ai-llms/
2•nethuml•18m ago•0 comments

Freeciv 3D with hex map tiles and WebGPU renderer

https://freecivworld.net/
1•roschdal•20m ago•0 comments

SpaceX-xAI Merger: Nobody's Talking About the von Neumann Elephant in the Room

1•juanpabloaj•23m ago•1 comments

Smart Homes Are Terrible

https://www.theatlantic.com/ideas/2026/02/smart-homes-technology/685867/
6•aarghh•28m ago•0 comments

Ask HN: Would you use an ESLint-like tool for SEO that fails your CI/CD build?

1•YannBuilds•29m ago•0 comments

Praise for Price Gouging

https://www.grumpy-economist.com/p/praise-for-price-gouging
1•mhb•32m ago•0 comments

Open source infra orchestrator agent clanker CLI

https://github.com/bgdnvk/clanker
1•tekbog•33m ago•0 comments

Lance table format explained simply, stupid (Animated)

https://tontinton.com/posts/lance/
1•tontinton•34m ago•0 comments

Solving Soma

https://anekstein.com/posts/2026-02-01-blocker
1•davidanekstein•35m ago•0 comments

We built a cloud platform for agentic software (our virtualization, etc.)

https://agentuity.com/
1•rblalock•35m ago•2 comments

Show HN: WLM-SLP – A 0D-27D Structural Language for Multi-Agent Alignment

https://github.com/gavingu2255-ai/WLM-Open-Source/blob/main/README.md
1•WujieGuGavin•35m ago•0 comments

Former Tumblr Head Jeff D'Onofrio Steps in as Acting CEO at the Washington Post

https://www.theverge.com/tech/875433/tumblr-jeff-donofrio-ceo-washington-post-layoffs
3•bookofjoe•38m ago•1 comments

Bounded Flexible Arrays in C

https://people.kernel.org/kees/bounded-flexible-arrays-in-c
1•fanf2•38m ago•0 comments

The Invisible Labor Force Powering AI

https://cacm.acm.org/news/the-invisible-labor-force-powering-ai/
1•pseudolus•41m ago•0 comments

Reading Recursion via Pascal

https://journal.paoloamoroso.com/reading-recursion-via-pascal
1•AlexeyBrin•41m ago•0 comments
Open in hackernews

Reports of Gmail security issue are inaccurate

https://blog.google/products/workspace/gmail-security-protections/
44•pentagrama•5mo ago

Comments

spectraldrift•5mo ago
It's wild how quickly this rumor spread across major news sources, and yet I was unable to find a primary source at all. I wonder how this started.
greatgib•5mo ago
I was also confused. Thinking that it was a rumor, like the usual dump of credentials found in internet.

But no, Google had a major leak due to a lack of security on their side. And I have a strong suspicion that they released conflicting info over the past week in order to be fuzzy enough to defuse the blame. The "nothing to see there" while at the same time covering their ass by being able to say that they were transparent about it.

Here is a summary about what happened: https://news.trendmicro.com/2025/08/26/google-data-breach-gm...

There was also an official post in Google blog about that, that conveniently is not easy anymore to find un Google search despite using all the right keywords...

So Google is using Salesforce to manage their Google ad leads and the database of their salesforces instances was breached. And despite the database not holding the passwords or credentials to your account, they have all the details about you, and your interactions with Google if you ever interacted with google ads. Like a few million persons.

And using that, it looks like hackers were able to craft more convincing than real emails looking like coming from Google, to scam people and still their credentials this time.

trod1234•5mo ago
Rumor-mongering is primarily what the Chinese PLC and other state apparatus on their side does these days; at least much of the public facing after-math, its called irregular warfare or 5GW.

While I'm not familiar with the specific of this particular incident the fact I mention must always be considered.They are quite good at what they do.

For a bit of background checkout the Mandiant ORB Networks talk.

creatonez•5mo ago
No, random unsubstantiated conspiracy theories must not "always be considered". Especially when, per your own admission, you don't know any of the details
immibis•5mo ago
If China is trying to take down Google and it's working, I say good.
usr1106•5mo ago
Completely useless corporate speech. The whole text contains zero more information than the headline. I would have expected at least some information what are the false claims.
paulddraper•5mo ago
> Several inaccurate claims surfaced recently that incorrectly stated that we issued a broad warning to all Gmail users about a major Gmail security issue. This is entirely false.
RandomBacon•5mo ago
> Several inaccurate claims surfaced recently

>> So did some accurate claims, but we won't talk about those.

> we issued a broad warning to all Gmail users

>> we issued a narrow warning to some Gmail users

> a major Gmail security issue

>> we consider it a minor issue

> This is entirely false.

>> So technically we're correct!

paulddraper•5mo ago
Hm, I would take big issue with "This is entirely false."

That means there is no kernel of truth.

RandomBacon•5mo ago
Yep.

I'm curious, do people think I was supporting Google or something with my above comment? Should I have italicized instead of >>?

paulddraper•5mo ago
No idea, HN is pretty random.
zaptheimpaler•5mo ago
Don't know what the news says, but today morning I got a call from a "James Wilson" claiming to be from Google. He knew my email address (and phone number obviously) and told me that someone was attempting to change my phone number. He wanted to do a security authorization or something where I guess I would have been asked to divulge more information about my account.

When I asked him to prove he was from Google, he didn't seem fazed at all and said he would send me an email from a google.com email to prove it, and gave me his name and "employee ID". We kept talking and he said the email should show up and it was sent from his side, but the email never came. I then said I'd call google support and ask to speak with him instead - he was still unfazed. I did call Google support (im on Google One for Gemini access so luckily I actually have access to a phone number I can call), and they said it was likely a phishing attempt. I did suspect scam from the start, but it did seem a tad more professional and polished than the usual scams - the person really sounded professional, good voice quality, there wasn't a whole lot of noise in the background, they weren't fazed by my attempts at verification and just tried to dodge them hoping I wouldn't notice instead, they didn't try any pressure/urgency tactics like scammers often do.

So this news is real.. as far as I can tell they were able to connect my email address to my phone number via a leak from Google. They were trying to escalate that into further access.

conception•5mo ago
You’ve never hit a breach from https://haveibeenpwned.com before that included your email and phone number?
zaptheimpaler•5mo ago
I checked and I have a year+ ago, I just thought the timing is pretty coincidental to be the same day Google posts this. The recent breach is real, and oddly the scammers have an incentive to spread the news further because it actually supports their story when calling a victim.
shaftway•5mo ago
I was able to break through the scam veneer on one of these calls. It was remarkably professional up until I outright called him out and told him how I knew it was a scam (the email "from Google" didn't have the right headers, he missed a bit of the terminology, didn't recognize a term, and the caller ID number was listed as being used for this scam).

I asked where he got my information, and he claimed he pulled it from Github and cross-referenced it with a large public dump.

evulhotdog•5mo ago
I think it’s a lot likelier that some other company which has both your phone and email was breached, and conveniently the domain in your email tells them who you use as your email provider, which they can then pose as.
delfinom•5mo ago
>While it’s always the case that phishers are looking for ways to infiltrate inboxes, our protections continue to block more than 99.9% of phishing and malware attempts from reaching users.

Let's see, things that bypass the filters:

1. Using <yourgmailaddressfirstpart>@google.com which causes a mail delivery error bot bounce to @gmail.com with the spam/malware content

2. Using thousands of bot created gmail.com accounts because the gmail domain has immediate reputation within gmail