frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

eInk UI Components in CSS

https://eink-components.dev/
1•edent•22s ago•0 comments

Discuss – Do AI agents deserve all the hype they are getting?

1•MicroWagie•3m ago•0 comments

ChatGPT is changing how we ask stupid questions

https://www.washingtonpost.com/technology/2026/02/06/stupid-questions-ai/
1•edward•3m ago•0 comments

Zig Package Manager Enhancements

https://ziglang.org/devlog/2026/#2026-02-06
2•jackhalford•5m ago•1 comments

Neutron Scans Reveal Hidden Water in Martian Meteorite

https://www.universetoday.com/articles/neutron-scans-reveal-hidden-water-in-famous-martian-meteorite
1•geox•6m ago•0 comments

Deepfaking Orson Welles's Mangled Masterpiece

https://www.newyorker.com/magazine/2026/02/09/deepfaking-orson-welless-mangled-masterpiece
1•fortran77•8m ago•1 comments

France's homegrown open source online office suite

https://github.com/suitenumerique
3•nar001•10m ago•1 comments

SpaceX Delays Mars Plans to Focus on Moon

https://www.wsj.com/science/space-astronomy/spacex-delays-mars-plans-to-focus-on-moon-66d5c542
1•BostonFern•10m ago•0 comments

Jeremy Wade's Mighty Rivers

https://www.youtube.com/playlist?list=PLyOro6vMGsP_xkW6FXxsaeHUkD5e-9AUa
1•saikatsg•10m ago•0 comments

Show HN: MCP App to play backgammon with your LLM

https://github.com/sam-mfb/backgammon-mcp
1•sam256•13m ago•0 comments

AI Command and Staff–Operational Evidence and Insights from Wargaming

https://www.militarystrategymagazine.com/article/ai-command-and-staff-operational-evidence-and-in...
1•tomwphillips•13m ago•0 comments

Show HN: CCBot – Control Claude Code from Telegram via tmux

https://github.com/six-ddc/ccbot
1•sixddc•14m ago•1 comments

Ask HN: Is the CoCo 3 the best 8 bit computer ever made?

1•amichail•16m ago•0 comments

Show HN: Convert your articles into videos in one click

https://vidinie.com/
2•kositheastro•19m ago•0 comments

Red Queen's Race

https://en.wikipedia.org/wiki/Red_Queen%27s_race
2•rzk•19m ago•0 comments

The Anthropic Hive Mind

https://steve-yegge.medium.com/the-anthropic-hive-mind-d01f768f3d7b
2•gozzoo•22m ago•0 comments

A Horrible Conclusion

https://addisoncrump.info/research/a-horrible-conclusion/
1•todsacerdoti•22m ago•0 comments

I spent $10k to automate my research at OpenAI with Codex

https://twitter.com/KarelDoostrlnck/status/2019477361557926281
2•tosh•23m ago•1 comments

From Zero to Hero: A Spring Boot Deep Dive

https://jcob-sikorski.github.io/me/
1•jjcob_sikorski•23m ago•0 comments

Show HN: Solving NP-Complete Structures via Information Noise Subtraction (P=NP)

https://zenodo.org/records/18395618
1•alemonti06•28m ago•1 comments

Cook New Emojis

https://emoji.supply/kitchen/
1•vasanthv•31m ago•0 comments

Show HN: LoKey Typer – A calm typing practice app with ambient soundscapes

https://mcp-tool-shop-org.github.io/LoKey-Typer/
1•mikeyfrilot•34m ago•0 comments

Long-Sought Proof Tames Some of Math's Unruliest Equations

https://www.quantamagazine.org/long-sought-proof-tames-some-of-maths-unruliest-equations-20260206/
1•asplake•35m ago•0 comments

Hacking the last Z80 computer – FOSDEM 2026 [video]

https://fosdem.org/2026/schedule/event/FEHLHY-hacking_the_last_z80_computer_ever_made/
2•michalpleban•35m ago•0 comments

Browser-use for Node.js v0.2.0: TS AI browser automation parity with PY v0.5.11

https://github.com/webllm/browser-use
1•unadlib•36m ago•0 comments

Michael Pollan Says Humanity Is About to Undergo a Revolutionary Change

https://www.nytimes.com/2026/02/07/magazine/michael-pollan-interview.html
2•mitchbob•36m ago•1 comments

Software Engineering Is Back

https://blog.alaindichiappari.dev/p/software-engineering-is-back
2•alainrk•37m ago•1 comments

Storyship: Turn Screen Recordings into Professional Demos

https://storyship.app/
1•JohnsonZou6523•38m ago•0 comments

Reputation Scores for GitHub Accounts

https://shkspr.mobi/blog/2026/02/reputation-scores-for-github-accounts/
2•edent•41m ago•0 comments

A BSOD for All Seasons – Send Bad News via a Kernel Panic

https://bsod-fas.pages.dev/
1•keepamovin•44m ago•0 comments
Open in hackernews

A security incident that may involve your Plex account information

https://forums.plex.tv/t/important-notice-of-security-incident/930523
39•Shank•5mo ago

Comments

cranberryturkey•5mo ago
use zymotv instead of plex or emby
colordrops•5mo ago
Or better yet use Jellyfin.
hnlmorg•5mo ago
I’ve been considering switching to Jellyfin.

I’m getting increasingly frustrated at just how badly Plex behaves for home set ups. Which is the entire point of installing something like Plex.

Most annoying still, I’ve even paid for their premium products in the hope that it would make things behave better and it did not.

The only reason these security incidents happen is because Plex try to extort home users. There isn’t any other compelling reason to have your details on their database with credentials to active installs.

Sheeny96•5mo ago
I run my Jellyfin on a Pi 5 8GB (with a bunch of other homelab stuff) and run an OSMC (Kodi + Jellyfin plugin) on a Pi 3b 2GB with absolutely no issue. OSMC automatically integrates with my TV remote, runs very low power and smooth. I never used any of the Plex stuff that wasn't my media, so I prefer it this way. Less bloat, more customisable.
wiether•4mo ago
I am part of a network of "Plex admins", meaning each one of us own and maintain their own Plex server with their own library.

Thanks to the centralized Plex account, we can share our libraries with each other in a few clicks.

You can do the same if you don't have a server also, basically being a member of various Plex server and accessing everything through a single account and interface.

Sure, requiring an account if all you want to do is being the single user accessing your own instance is useless, and if it's your usecase, then Plex is not the right tool for you.

I tried Plex, Emby and Jellyfin, but I staid with Plex because of this easy sharing feature.

bigiain•5mo ago
Is Emby somehow related to Plex?

I use Emby, only because a few friends did and recommended it. I'd probably switch ti something more secure and/or open source given the right push.

crooked-v•5mo ago
From what I understand they're unrelated and the similarities come from convergent evolution.
ksynwa•5mo ago
Emby and Plex are separate projects. Jellyfin is a hard fork of Emby.
bigiain•4mo ago
Thanks :-)
gbil•5mo ago
I can only comment that their communication on the incident is lacking, I've read about the incident yesterday and only today I received the relevant email. On top, it seems that all of a sudden I started getting marketing emails from them although I had unsubscribred in the past, coincidence?
bigiain•5mo ago
Dupe?

https://news.ycombinator.com/item?id=45174684

(Or at least related, this submission has the plex.tv website breach notification, not just the text of the email.)

rockbruno•5mo ago
I made an account there to use my Home Assistant as a media server and it's already the second time they reported that they messed up something. I heard you can install VLC on the Apple TV and stream through that, so I'll definitely do that and skip these weird middle companies.
dav43•5mo ago
I just use infuse or vid hub app and an SMB share.
Tajnymag•5mo ago
Why not use Jellyfin then? It's basically an open source alternative to Plex. You run Jellyfin on your server and in Apple TV use Swiftin (Jellyfin + Swift) for integration.
amatecha•5mo ago
Once I saw Plex required an account even to self-host, it was a no-go for me. Stuff like this is why. (among other reasons, like "why should I go through a 3rd party for something I'm 100% hosting on my own hardware/network")

I've been very happy with Jellyfin FWIW :)

shellwizard•5mo ago
The big selling point of Plex vs jellyfin is that their app is in all of the major stores.Samsung smart TVs for example
nsbk•5mo ago
I switched to Jellyfin last year and never looked back. The only thing I find lacking is the Apple TV App, I tried Swiftfin but it stutters the whole time when playing high quality UHD content. I tried Infuse and it works much better
timothevs•5mo ago
Have you tried Infuse?
untrimmed•5mo ago
I appreciate the transparency, but the phrase securely hashed always makes me a little nervous. It's a huge spectrum, right? We talking bcrypt/scrypt with a proper salt, or something from the old days?
jorams•5mo ago
When they got hacked three years ago the notice included this:

> Even though all account passwords that could have been accessed were hashed (with bcrypt plus salted and peppered) and secured in accordance with best practices, out of an abundance of caution we are requiring all Plex accounts to have their password reset.

Whether that later changed for the worse is anyone's guess.

spondyl•5mo ago
Thanks for the reminder. I went to reset my password when the email went out but when following the reset flow, I hit a Cloudflare page (due to the origin presumably having crashed) and got sidetracked
m4tthumphrey•5mo ago
I am a huge Plex power user; watching something at least once a day.

Unfortunately, Plex is a bit of a mess these days - constantly pushing Live TV on us, requiring internet access to access local media (this is a killer whenever internet goes down), overly complex, clunky remote access (altho this is much better these days). But it still isn't bad enough to make me try and migrate. I love my local setup (Sonarr and a custom app for movies as Radarr is OTT for the amount of movies we watch) and Plex is very polished (compared to the alternatives) but I do wonder how much longer it will be around.

t0lo•5mo ago
Conversely I love the plex tv channels as an alternative to regular australian free to air- same as the lg channels.

Easy way for me to turn my brain off and find a good documentary/educational show at the end of the day

m4tthumphrey•5mo ago
I don't mind them doing it, but they shove it in my face constantly when I've clearly said I am not interested.
add-sub-mul-div•5mo ago
Live TV is magical when you set up ErsatzTV and self-host that part as well. You can make channels out of anything. The modes of "I want to watch this specific thing now" and "I want to see what's 'on' right now and pick something to put on in the background" are very different and complementary. I end up relying on the latter more than the former.
stinky613•4mo ago
> requiring internet access to access local media

Good news! You can whitelist exceptions by IP/subnet

Go into Plex Settings, then Settings > Network (show advanced). Scroll down to "List of IP addresses and networks that are allowed without auth"

"Comma separated list of IP addresses or IP/netmask entries for networks that are allowed to access Plex Media Server without logging in. When the server is signed out and this value is set, only localhost and addresses on this list will be allowed."

Put your local subnet and netmask into that (e.g. "192.168.1.1/255.255.255.0") and you should be all good

FYI, I also have "Secure Connections" set to "Preferred", but I don't know if that makes a difference for this or not

m4tthumphrey•4mo ago
NO WAY!! I will check this out later! Thanks!
wiether•5mo ago
PSA: If you are the owner of your Plex server and follow the _Sign out connected devices after password change- as they suggest, your server claim will also be expired.

So you'll have to get a new claim from https://www.plex.tv/claim and set it on your server; through the PLEX_CLAIM env var if your setup involves Docker.

They talk vaguely about it under _Common Issues_ but it wasn't on the original email, so I lost 15 minutes of my day because of this...

cprecioso•5mo ago
Yep, this was a huge hassle for me, I didn't realize it would happen!

Another option is to do `ssh -L 32400:localhost:32400 <your-plex-address>` and connect to http://localhost:32400/web, it will let you claim the server as it detects the connection being local.

mixedCase•4mo ago
Thanks for the one-liner, solved it within 30 seconds!
joecool1029•5mo ago
Maybe related to last month's serious vuln: https://app.opencve.io/cve/CVE-2025-34158
tucnak•5mo ago
On a related note; if you're still considering whether you should put passwords, or rather, hashes thereof—in your application database of choice—please, decide against doing so at all costs! Instead, you should probably use a dedicated secret management deployment: think Hashicorp Vault[1], OpenBao[2], or Keto[3] if you'd like to go beyond with ReBAC (Relationship-based access control) of Google's Zanzibar[4] fame. The benefits of a HA deployment like this far outweigh the upstart integration costs as you get to use a single, shared frame of reference to reason about your internal and external resources alike. Customer passwords, passkeys, certificates, internal CA, ACME, at-rest, in-transit, what have you, is controlled from a single point of consumption with one policy space to rule them all. It helps to use dedicated HSM capability, too. In cloud environments, AWS Nitro enclaves exist now; you could put something like Vault inside one[5].

Vault is more or less Old Testament, though, so if you're serious about zero trust, Zanzibar paper is a must-read!

Relationships lend nicely to AI agent stuff, where RBAC is putting you at a disadvantage. It's hard to express both direct and indirect access patterns in RBAC. For example, whenever agents would act on your, or your user's behalf within a clearly-defined scope (sic!) This is where traditional RBAC breaks down, whilst ReBAC really shines for expressing relationships between user/agent/system identities, thus greatly simplifying checking, scoping, audit.

[1]: https://developer.hashicorp.com/vault

[2]: https://openbao.org/

[3]: https://www.ory.sh/keto

[4]: https://research.google/pubs/zanzibar-googles-consistent-glo...

[5]: https://edgebit.io/enclaver/docs/0.x/guide-vault/

8cvor6j844qw_d6•5mo ago
Anyone remember a few years back there was a major Lastpass data breach?

I roughly recall Plex is somewhat involved in the compromise. One of the Lastpass employees compromised via Plex that leads to Lastpass data breach if I'm not mistaken.