frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

From Human Thought to Machine Coordination

https://www.psychologytoday.com/us/blog/the-digital-self/202602/from-human-thought-to-machine-coo...
1•walterbell•44s ago•0 comments

The new X API pricing must be a joke

https://developer.x.com/
1•danver0•1m ago•0 comments

Show HN: RMA Dashboard fast SAST results for monorepos (SARIF and triage)

https://rma-dashboard.bukhari-kibuka7.workers.dev/
1•bumahkib7•1m ago•0 comments

Show HN: Source code graphRAG for Java/Kotlin development based on jQAssistant

https://github.com/2015xli/jqassistant-graph-rag
1•artigent•7m ago•0 comments

Python Only Has One Real Competitor

https://mccue.dev/pages/2-6-26-python-competitor
2•dragandj•8m ago•0 comments

Tmux to Zellij (and Back)

https://www.mauriciopoppe.com/notes/tmux-to-zellij/
1•maurizzzio•9m ago•1 comments

Ask HN: How are you using specialized agents to accelerate your work?

1•otterley•10m ago•0 comments

Passing user_id through 6 services? OTel Baggage fixes this

https://signoz.io/blog/otel-baggage/
1•pranay01•11m ago•0 comments

DavMail Pop/IMAP/SMTP/Caldav/Carddav/LDAP Exchange Gateway

https://davmail.sourceforge.net/
1•todsacerdoti•11m ago•0 comments

Visual data modelling in the browser (open source)

https://github.com/sqlmodel/sqlmodel
1•Sean766•14m ago•0 comments

Show HN: Tharos – CLI to find and autofix security bugs using local LLMs

https://github.com/chinonsochikelue/tharos
1•fluantix•14m ago•0 comments

Oddly Simple GUI Programs

https://simonsafar.com/2024/win32_lights/
1•MaximilianEmel•14m ago•0 comments

The New Playbook for Leaders [pdf]

https://www.ibli.com/IBLI%20OnePagers%20The%20Plays%20Summarized.pdf
1•mooreds•15m ago•0 comments

Interactive Unboxing of J Dilla's Donuts

https://donuts20.vercel.app
1•sngahane•16m ago•0 comments

OneCourt helps blind and low-vision fans to track Super Bowl live

https://www.dezeen.com/2026/02/06/onecourt-tactile-device-super-bowl-blind-low-vision-fans/
1•gaws•18m ago•0 comments

Rudolf Vrba

https://en.wikipedia.org/wiki/Rudolf_Vrba
1•mooreds•18m ago•0 comments

Autism Incidence in Girls and Boys May Be Nearly Equal, Study Suggests

https://www.medpagetoday.com/neurology/autism/119747
1•paulpauper•19m ago•0 comments

Wellness Hotels Discovery Application

https://aurio.place/
1•cherrylinedev•20m ago•1 comments

NASA delays moon rocket launch by a month after fuel leaks during test

https://www.theguardian.com/science/2026/feb/03/nasa-delays-moon-rocket-launch-month-fuel-leaks-a...
1•mooreds•21m ago•0 comments

Sebastian Galiani on the Marginal Revolution

https://marginalrevolution.com/marginalrevolution/2026/02/sebastian-galiani-on-the-marginal-revol...
2•paulpauper•24m ago•0 comments

Ask HN: Are we at the point where software can improve itself?

1•ManuelKiessling•24m ago•1 comments

Binance Gives Trump Family's Crypto Firm a Leg Up

https://www.nytimes.com/2026/02/07/business/binance-trump-crypto.html
1•paulpauper•24m ago•1 comments

Reverse engineering Chinese 'shit-program' for absolute glory: R/ClaudeCode

https://old.reddit.com/r/ClaudeCode/comments/1qy5l0n/reverse_engineering_chinese_shitprogram_for/
1•edward•24m ago•0 comments

Indian Culture

https://indianculture.gov.in/
1•saikatsg•27m ago•0 comments

Show HN: Maravel-Framework 10.61 prevents circular dependency

https://marius-ciclistu.medium.com/maravel-framework-10-61-0-prevents-circular-dependency-cdb5d25...
1•marius-ciclistu•28m ago•0 comments

The age of a treacherous, falling dollar

https://www.economist.com/leaders/2026/02/05/the-age-of-a-treacherous-falling-dollar
2•stopbulying•28m ago•0 comments

Ask HN: AI Generated Diagrams

1•voidhorse•30m ago•0 comments

Microsoft Account bugs locked me out of Notepad – are Thin Clients ruining PCs?

https://www.windowscentral.com/microsoft/windows-11/windows-locked-me-out-of-notepad-is-the-thin-...
7•josephcsible•31m ago•1 comments

Show HN: A delightful Mac app to vibe code beautiful iOS apps

https://milq.ai/hacker-news
6•jdjuwadi•34m ago•1 comments

Show HN: Gemini Station – A local Chrome extension to organize AI chats

https://github.com/rajeshkumarblr/gemini_station
1•rajeshkumar_dev•34m ago•0 comments
Open in hackernews

The peril of unquoted Python strings, and how they caused CVE-2024-9287

https://pythonkoans.substack.com/p/koan-12-the-blacksmiths-hammer
4•meander_water•4mo ago

Comments

zahlman•4mo ago
This is not about "unquoted Python strings".

It is about unquoted shell arguments, in the context of invoking the shell using Python's `subprocess` standard library. The title is grossly misrepresentative, and the substance is missing the point. There is nothing special about Python here; causing a string to contain quotes works much the same way as in other popular languages. Besides, `subprocess.run` et. al. make use of the shell opt-in; the default behaviour is to pass arguments to a named executable directly. Typically, correct function requires those arguments not to have quotes (for the shell to remove them, among other processing, when the shell is used). The article then spends way too long, and too much formatting, on explaining what is really a very simple concept. We don't need a "part" for every few sentences and code example.

The "koan" presentation also strikes me as very strange for a simple warning about a practical security risk. There is no need for deep philosophical thinking here. Just recognize the problem and follow the associated best practices.

Regarding the CVE, it's hard to imagine a circumstance in which an "attacker-controlled virtual environment" isn't already game over. In fact, the exploit relies on the attacker being able to create a virtual environment, which in any normal situation already implies full shell access. An exploit like this is basically only relevant to a situation in which party A exposes an interface to party B for creating virtual environments, then expects party C to run code in the resulting environment. So, basically, people providing third-party CI systems, which are already fraught with trust and supply-chain issues. And even then, using virtual environments doesn't generally require the activation script at all, and well-written automation probably shouldn't use it, because it needlessly introduces a state dependency.