frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

NPM in a box: Containerizing package managers for security. (2022)

https://supergeekery.com/blog/containerizing-npm-and-package-managers-for-security
1•brigham•35s ago•0 comments

Amazon's Zoox robotaxi opens to public with free service in Las Vegas

https://tech.yahoo.com/transportation/articles/amazons-zoox-robotaxi-opens-public-130401461.html
1•pilingual•38s ago•0 comments

Video Game Mixes Cleaning Movement with Horror Genre to Sell Consumer Products

https://www.core77.com/posts/138354/Video-Game-Mixes-Cleaning-Movement-with-Horror-Genre-to-Sell-...
1•surprisetalk•1m ago•0 comments

The Socratic Journal Method: A Simple Journaling Method That Works

https://mindthenerd.com/the-socratic-journal-method-a-simple-journaling-method-that-actually-works/
1•surprisetalk•1m ago•0 comments

The Lease Trap

https://mek.fyi/posts/the-lease-trap
1•surprisetalk•1m ago•0 comments

Unloved AI – does SaaS have a future?

https://unlovedai.com/blogs/is-there-a-future-for-software-subscriptions
1•nitishr•2m ago•0 comments

Show HN: I made a tool (and content) hub for developers

https://coderbud.dev
1•BambaDev•2m ago•0 comments

Two projects explore driverless electric mini-trains to repurpose old tracks

https://english.elpais.com/technology/2025-08-23/how-to-repurpose-abandoned-railway-tracks-two-pr...
1•PaulHoule•3m ago•0 comments

Power-Hungry Data Centers Are Warming Homes in the Nordics

https://www.bloomberg.com/news/features/2025-05-14/finland-s-data-centers-are-heating-cities-too
1•perihelions•5m ago•0 comments

George Bernard Shaw by G. K. Chesterton

https://www.gutenberg.org/ebooks/19535
1•lordleft•5m ago•0 comments

Automatically upload screenshots to remote SSH for Claude Code

https://github.com/mdrzn/claude-screenshot-uploader
1•mdrzn•6m ago•0 comments

Science is not Complex, just consider it as chain-of-thoughts

https://lightcapai.medium.com/science-is-not-complex-just-consider-it-as-chain-of-thoughts-1a613f...
1•WASDAai•6m ago•0 comments

US Investment in Spyware Is Skyrocketing

https://www.wired.com/story/us-spyware-investment/
4•manveerc•8m ago•0 comments

How to Find Early Adopters

1•firstusers•8m ago•0 comments

Braess' Paradox

https://en.wikipedia.org/wiki/Braess%27_paradox
2•Jimmc414•9m ago•0 comments

Refined GitHub, a browser extension that simplifies GitHub and adds features

https://github.com/refined-github/refined-github
1•rutierut•10m ago•0 comments

Oracle 2026 Q1 Results

https://investor.oracle.com/investor-news/news-details/2025/Oracle-Announces-Fiscal-Year-2026-Fir...
1•dzonga•11m ago•1 comments

Simple Licensing: Content licensing standard for the AI-first Internet

https://rslstandard.org/
1•kkliau•12m ago•0 comments

ICE awards Clearview AI $9.2M facial recognition contract

https://www.biometricupdate.com/202509/ice-awards-clearview-ai-9-2m-facial-recognition-contract
3•Improvement•12m ago•0 comments

Aulico – Wrapping LLMs around crypto and stock markets

https://www.aulico.com
1•local_phi•13m ago•0 comments

Can filtering seawater provide for a thirsty world?

https://www.washingtonpost.com/climate-solutions/2025/09/07/desalinization-water-crisis-agricultu...
1•paulpauper•14m ago•0 comments

Show HN: Stb_JSON header only JSON parser for C/C++

1•Forgret•14m ago•0 comments

Not smarter, just better

https://film42.substack.com/p/not-smarter-just-better
1•film42•14m ago•0 comments

Twilight of the Econs?

https://www.global-developments.org/p/twilight-of-the-econs
1•paulpauper•15m ago•0 comments

'Make Me Commissioner' Review: Is Baseball Broken?

https://www.wsj.com/sports/baseball/make-me-commissioner-review-is-baseball-broken-d6988ede
1•paulpauper•15m ago•0 comments

AZ inmate filed fake documents for years, then used them to get out of prison

https://www.kjzz.org/politics/2025-09-09/az-inmate-filed-fake-documents-for-years-before-official...
2•ljosa•15m ago•0 comments

Public Schools: Make Them Private – Milton Friedman [pdf]

https://www.cato.org/sites/cato.org/files/pubs/pdf/bp023.pdf
1•mhb•16m ago•0 comments

The Memory Paradox: Why Our Brains Need Knowledge in an Age of AI

https://arxiv.org/abs/2506.11015
2•speckx•17m ago•0 comments

Bending Spoons to Buy Vimeo in $1.38B All-Cash Deal

https://www.bloomberg.com/news/articles/2025-09-10/bending-spoons-to-buy-vimeo-in-1-38-billion-al...
2•thm•17m ago•0 comments

Evolution of Human-Accelerated Neuron Type May Underly High Autism Prevalence

https://academic.oup.com/mbe/article/42/9/msaf189/8245036
2•bookofjoe•18m ago•0 comments
Open in hackernews

Chromium browser tries to read sensitive files: –/.ssh –/.gnupg –/.dbus /boot

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1108642
11•400thecat•3h ago

Comments

400thecat•3h ago
Package: chromium Version: 138.0.7204.49-1~deb12u1

I am experiencing very weird and suspicious issue on debian 12.

For context, I am using grsecurity + RBAC, which gives me the possibility to see what files each program wants to access. My issue is not caused by RBAC. but RBAC brought my attention to this issue.

SO, I have upgraded chromium browser to: 138.0.7204.49

and suddenly when chromium starts, in addition to trying to access the usual files in my home, such as ~/.config/chromium or ~/.cache , it now tries to access sensitive folders on my system:

~/.ssh/ ~/.gnupg/ ~/.dbus/ /boot/

(while ~/.dbus is not as immediately alarming as the others, Chromium accessing this when it didn't before is still a change in behavior that deserves scrutiny)

this never happened before. I am sure, because the RBAC rules that I am using would have alerted me.

this is highly suspicious and potentially a serious security issue !

this issue was originally reported on chromium 138, fixed in next version, and now it's back in version 140.0.7339.80

akagusu•2h ago
Is it a problem with the Debian package or upstream?
400thecat•59m ago
I assume upstream. Hard to imagine that Debian would be adding this "feature" themselves.