frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

India Opens Up Its Stock Market to Millions for $3/Month

https://www.bloomberg.com/news/videos/2025-10-10/india-opens-up-its-stock-market-to-millions-for-...
1•thelastgallon•40s ago•0 comments

Show HN: The Kernel-Registry Challenge: Algorithm for Semantic Hashing

https://github.com/vocoder-na/V-Code-Protocol-Manifest/blob/main/protocols/V_KERNEL_ALGORITHM_CHA...
1•lokutlout•1m ago•0 comments

Moving on from XML? A teaser for a possible alternative

https://genodians.org/nfeske/2024-12-20-moving-on-from-xml
1•ioasuncvinvaer•3m ago•0 comments

All fluffed up: modern balls spark injury worries and frustration in tennis

https://www.theguardian.com/sport/2025/oct/10/all-fluffed-up-why-modern-balls-are-causing-frustra...
1•randycupertino•4m ago•0 comments

AI: Mad Maths?

https://www.thecapitalcycle.co.uk/episodes/ai-mad-maths
1•fny•6m ago•0 comments

Show HN: Open-Source, a Vision Agents by Stream

https://github.com/GetStream/Vision-Agents
1•TheAnkurTyagi•9m ago•0 comments

One Reddit Mod Cripples $23.5M Company [video]

https://www.youtube.com/watch?v=2jMoYOYjTUc
1•nomilk•10m ago•3 comments

Show HN: OpenRun – Declarative web app deployment

https://github.com/openrundev/openrun
1•ajayvk•10m ago•0 comments

Intranasal Delivery of Ivermectin Nanosystems as an Antitumor Agent

https://pubs.acs.org/doi/10.1021/acsbiomaterials.5c00642
1•bilsbie•11m ago•1 comments

Hacking Group Claims to Have Breached Nintendo

https://www.thegamer.com/nintendo-hacking-group-claims-to-have-breached/
1•mikhael•11m ago•0 comments

Effect-Ts Visual Representation

https://effect.kitlangton.com/
1•kadelka•16m ago•0 comments

Taproot – web interface for editing data in your ATProto PDS manually

https://atproto.at
1•xeonmc•20m ago•0 comments

The Controversial Hinge Dating App Hack Going Viral

https://www.thecut.com/article/how-to-hack-hinge-rose-jail.html
2•randycupertino•22m ago•5 comments

Automate YouTube channel downloads with NFO/cover art for media servers

https://github.com/DialmasterOrg/Youtarr
4•dialmaster•23m ago•2 comments

Writing regex is pure joy. You can't convince me otherwise

https://triangulatedexistence.mataroa.blog/blog/writing-regex-is-almost-pure-joy-you-cant-convinc...
3•signa11•26m ago•0 comments

GNU Health

https://www.gnuhealth.org/about-us.html
7•smartmic•27m ago•1 comments

Show HN: I Created a Hacker News as Sticky Notes Pages

https://hackernewssticky.pages.dev/
1•paperplaneflyr•29m ago•2 comments

Show HN: Booking.com Fake Rating Detector

https://chromewebstore.google.com/detail/bookingcom-fake-rating-de/gehaigkcidkagdnjjclbjoemkolbobna
2•deeteeess•30m ago•1 comments

Innovative Recommendation Applications Using Two Tower Embeddings at Uber

https://www.uber.com/blog/innovative-recommendation-applications-using-two-tower-embeddings/
1•mfiguiere•30m ago•0 comments

Chinese phishing kit helps scammers send fake texts impersonate TikTok, others

https://www.theregister.com/2025/10/10/chinese_phishing_kit_fraud/
1•Bender•32m ago•1 comments

OCaml 5.4.0 Released

https://ocaml.org/changelog/2025-10-09-ocaml-540
2•mkhattab•34m ago•0 comments

Stryker Mutator

https://github.com/stryker-mutator
1•sltr•38m ago•0 comments

FastStream 0.6 Release unlocks support for new event brokers

https://github.com/ag2ai/faststream/releases/tag/0.6.0
1•Lancetnik•39m ago•1 comments

7x faster JSON in SQL: a deep dive into Variant data type

https://www.e6data.com/blog/faster-json-sql-variant-data-type
2•samyaks•39m ago•0 comments

Ask HN: What's missing in today's fundraising tools for founders?

1•paulwilsonn•40m ago•0 comments

Making a Modern Metal/D3D12/Vulkan RHI

https://amelieheinrich.com/post.html?id=rhi
2•iparaskev•42m ago•0 comments

Rare earth gambit reveals next phase of economic warfare

https://www.politico.com/news/2025/10/11/chinas-rare-earth-gambit-reveals-the-next-phase-of-its-e...
2•InTheArena•42m ago•1 comments

We Love Automation but Hate AI, What UX Teaches Us About Control and Trust

https://medium.com/design-bootcamp/we-love-automation-but-hate-ai-what-ux-teaches-us-about-contro...
2•corlynne•44m ago•0 comments

delightful-commons – curated lists of free software

https://codeberg.org/socialcoding/delightful-commons
2•smartmic•45m ago•0 comments

Agentic web browsing can't scale with cloud LLMs

1•djh1995•45m ago•0 comments
Open in hackernews

Hackers leak Qantas data on 5M customers after ransom deadline passes

https://www.theguardian.com/business/2025/oct/11/hackers-leak-qantas-data-containing-5-million-customer-records-after-ransom-deadline-passes
75•breve•2h ago

Comments

Workaccount2•2h ago
>customers’ email addresses, phone numbers, birth dates and frequent flyer numbers

So all things that have likely been leaked 30 times already? Perhaps except the fly miles

amelius•2h ago
Yes, it's a sad situation we're in. We need am indirection step in addresses. So companies don't have our actual address but instead have a handle they can use to interact with that address. And then the actual addresses should be guarded with more responsibility.
sidpatil•2h ago
Japan Post is rolling out such a system: https://news.ycombinator.com/item?id=44117779
ceejayoz•1h ago
Apple also does it via “hide my email”.
dns_snek•1h ago
But that's just an identifier which you can easily update when you move, like a domain=>IP mapping? Businesses still have your physical address.

A system where they didn't get our address at all would be great but I think we would also need alternative payment providers that don't share any billing-related address information with the business.

atonse•1h ago
I love this idea, but then doesn’t it create a centralized target for hackers?

I suppose that’s still better cuz then it also creates a centralized point and resources for securing the database.

LPisGood•1h ago
It’s weird to think that just a few years ago your phone number and address were shared with tens of thousands of people in a massive book.

I feel like if you have someone’s name, it’s not hard at all to find their birthday

esseph•1h ago
More details further in there, but they also leaked passport data.
bn-l•2h ago
Is this from the Salesforce breach?
edm0nd•1h ago
Yes
linhns•2h ago
Haven’t they sold that to some dubious partners already?
Noumenon72•1h ago
I don't see why a company would pay a ransom to protect their customers from identity theft -- the losses are public, while the costs to them are a very small number of customers that read about this, think they're likely to lose the data again, didn't already lose their data in this leak, remember this story at the time of purchase, and value that more than things like ticket time or ticket price. I don't think the hackers should be making any money this way.
bwfan123•1h ago
We have public agencies like the police that are paid for by the tax-payers for securing property. Are there similar agencies who are incentivized to stop these situations. During the pipeline breaches several years back, I recall aggressive action to disrupt the money-trail.
dablya•1h ago
To the extent these situation are as illegal as property theft, public agencies tasked with law enforcement, like the police, are in the same position to secure your data as they are to secure your property, no?
Bairfhionn•1h ago
The only thing that would prevent this from happening would be if the companies make their stuff safe.

You can't police the world.

shiandow•1h ago
I think ransom is also a bit of a misnomer that the hackers deliberately use to frame the transaction in a more positive light.

I mean, it's just extortion. Nothing is being ransomed, you don't get something back and you can't really secure something already lost. It suffers from the same problems as other forms of extortion, namely that you can't really trust the other party to do what you want and really they have no incentive to do so.

chii•1h ago
but the parent post's point still stands - extortion (or ransom) requires something important to be held. If the private data of customers is not actually important, it cannot be used as a threat in the extortion.
praash•1h ago
I don't think data leak extortioners have any incentive to even pretend they won't keep asking further payment.

Why not just offer a monthly subscription "service"?

LadyCailin•56m ago
At that point, the company should just pay for an actual security team.
gessha•51m ago
Great, now even crime groups are following consultancy advice. \s
jacquesm•1h ago
It's much simpler: paying will result in more crime like this.
hmottestad•1h ago
You never know. Pay them enough and they might retire to an island somewhere instead.
lotsofpulp•1h ago
Islands are pretty expensive to live on. If anything, retiring on the island will require more crime.
billy99k•1h ago
The only reason these persist is because companies pay out and they can receive it in untraceable crypto currency in countries that are nearly to prosecute them in.

Appeasement has never worked.

gnfargbl•1h ago
The current groups, sure, but the existence of a functioning market tends to bring in more participants. Or to put it another way, there are plenty of smart people in the world who found themselves born in a less-than-ideal country and are willing to solve their problems through crime.

The only sustainable solution is to make crime no longer pay. Nothing else will work.

bilekas•23m ago
If you send me 200 million I will put that to the test for you.
hollerith•22m ago
He wrote "more crime like this", not "more crime like this committed by the same group".
makeitdouble•1h ago
That's the official stance, but if it really mattered they'd pay.

And there's of course paths to pay without losing face, like hiring a negociator or a recovery firm that acts like a bridge for the money[0]. We came to accept that companies don't act ethically and will only maximize profit, yet the narrative is still stuck on that weird assumption they care about the future of society regarding ransomware.

[0] https://zendata.security/2025/07/08/ransomware-negotiator-sc...

ohyoutravel•1h ago
It’s even more dystopian than that. In Australia itself, Qantas is the only carrier between many cities. So if you decide to not book Qantas, you’re potentially driving across the Outback.
chronci739•1h ago
Pay the ransom, hackers then sell the data privately

Don’t pay the ransom, hackers release a subset to the public for free, then sell the rest privately

Good on Quantas for not negotiating, bad on them for shit security.

chii•1h ago
> Good on Qantas for not negotiating

they probably didnt feel that there was a threat, as privacy of their customer's data wasn't very high on their priority list - after all, they didnt secure that data very well in the first place leading to the stolen data!

stevetron•1h ago
I'd never heard of Quantas. I have heard of Salesforce. Nothing particularly glowing, though.
edm0nd•1h ago
That just means you arent Australian. Every Australian has heard of Quantas.
sammy2255•1h ago
Qantas*
hitarpetar•1h ago
Kwantas*
nomilk•1h ago
> The Qantas data, which was stolen from a Salesforce database in a major cyber-attack in June, included customers’ email addresses, phone numbers, birth dates and frequent flyer numbers. It did not contain credit card details, financial information or passport details.

Curious, what's the worst a bad actor do with name, email address, phone number and birth date?

jacquesm•1h ago
Apply for a credit card.
geor9e•1h ago
still need more info. SSN for one.
smallstepforman•1h ago
No SSN in Australia, who are the bulk of Qantas customers.
andsoitis•31m ago
To apply for a credit card in Australia, you need to supply at least two forms of ID, such as an Australian driver's license, passport, or Medicare card.
andsoitis•32m ago
Don’t you get correspondence or insights into credit card applications in your name?
spwa4•1h ago
Authenticate to phone banking in the name of a customer and request a personal loan. And in general, open a large line of credit in someone else's name.
SteveNuts•1h ago
Where can you do all that without a social security number?
whatevaa•1h ago
It's not like those numbers haven't already been leaked elsewhere.
sammy2255•1h ago
There's no concept of social security number in Australia
esseph•1h ago
I feel like I get about a notification every 2 months now for a service I used maybe once 5 or 10 years ago getting breached/extorted/leaked.
airstrike•1h ago
A SSN should never be used as a "password".
anonzzzies•1h ago
This you can do somewhere? My bank asks me 20 questions (many like my first pet name, the last transaction I did etc) and then calls me back on the registered phone number. That data alone should get you nothing really. For credit here , small or large, you have to prove you are you or you get a nice police escort. Most of these apps, even if you are already registered, want you to tap your passport to nfc and scan your face for anything serious.
LadyCailin•54m ago
Your bank, sure. But what about all the other banks? Just need to target the weakest link.
jvvw•21m ago
Surely name, email, phone and date of birth aren't enough to do this at any bank? That's not quite public info but near enough. I've filled that in on hundreds of forms during my life and it's info that any of my friends have.
pards•1h ago
And yet later in the article it states:

> global data was stolen between April 2024 and September 2025 and includes personal and contact information of the companies’ customers and employees, including dates of birth, purchase histories and passport numbers.

which contradicts the previous statement

zzzeek•1h ago
scam call you with further fake extortions like "I'm in jail mom you need to bail me out!" since they have birthdates they can target older people for this. my mom has received at least four of these calls, since I always get the "ARE YOU OK? WAS THAT A SCAM?" phone call afterwards. the first time it happened, they were about to go to the bank to wire money when dad said, "let's try calling his cell!"

we'd like to think these scams are stupid but unfortunately they work

esseph•1h ago
The breach included passport details ;)
hmottestad•1h ago
Phishing. Super easy now to send a fake email with a great offer, and have your name and loyalty programme number right there in the email. Much easier to trick someone when your email contains a bunch of personal info that you wouldn’t assume others to have.

«Happy birthday! As a loyal Quantas customer, we would like to offer you a sneak peek of our upcoming Black Friday deals. Consider it a little birthday present from us.»

bilekas•25m ago
This topic is always a mixed bag for me, on the one hand I don't think you should pay ransom groups as it encourages more, but also their security should be better.

> “No company wants to see, you know, hundreds of thousands, or, millions of records of their customers just on the internet,” Kirk said. “That’s awful. It’s awful for the companies. It’s awful for the people affected.”

This reads to me like : "Well yeah sorry to our customers, but we're not taking a loss for our incompetance"

There's no winners here.