frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Diane Keaton, Oscar-Winning 'Annie Hall' Star, Dies at 79

https://variety.com/2025/film/news/diane-keaton-dead-annie-hall-1236546710/
1•timr•4m ago•0 comments

Arab states deepened military ties with Israel while denouncing Gaza war

https://www.icij.org/news/2025/10/arab-states-deepened-military-ties-with-israel-while-denouncing...
2•wslh•5m ago•0 comments

Tools Amplify Culture – Platform Engineering

https://platformengineering.org/blog/tools-amplify-culture-the-real-key-to-developer-productivity
1•gaurav324•7m ago•0 comments

Recent Node.js Features That Replace Popular NPM Packages

https://nodesource.com/blog/nodejs-features-replacing-npm-packages
1•jakub_g•8m ago•0 comments

Show HN: Community benchmark for AI coding models with blind voting

https://codelens.ai
1•codelensai•11m ago•0 comments

Programming Space Game for x86 in Assembly Without an Operating System

https://hackaday.com/2025/10/10/programming-space-game-for-x86-in-assembly-without-an-operating-s...
3•indigodaddy•13m ago•0 comments

Ask HN: Abandoned/dead projects you think died before their time and why?

1•ofalkaed•14m ago•0 comments

Kraken Rockets Blocks

https://forum.kerbalspaceprogram.com/topic/228176-krb-kraken-rockets-blocks/
1•marbu•14m ago•0 comments

Make Dictation Your Prompting Superpower

https://elite-ai-assisted-coding.dev/p/make-dictation-your-prompting-superpower
1•intellectronica•21m ago•0 comments

Ever Need to Recover Stolen Crypto Contact Proficient Expert Consultant

1•fisherstanley•23m ago•0 comments

California's Wine Industry Is in Crisis

https://www.wsj.com/articles/californias-wine-industry-is-in-crisis-4f246efb
2•JumpCrisscross•24m ago•0 comments

Show HN: Vello's high-performance 2D GPU engine to .NET

https://github.com/wieslawsoltes/VelloSharp/releases/tag/v0.5.0-alpha.1
1•wiso•28m ago•1 comments

Datastar response to allegations

https://data-star.dev/essays/greedy_developer
21•alvaroflm•34m ago•1 comments

What works well and doesn't with AI coding agents in October 2025

https://mdelapenya.xyz/posts/2025-10-10-coding-agents/
1•sakoht•35m ago•0 comments

Testing Language Models: Engineering Confidence Without Certainty

https://www.gojiberries.io/testing-when-inputs-are-unbounded-and-outputs-are-stochastic/
1•neehao•38m ago•0 comments

Show HN: WordPress plugin that lets readers fix your articles (via AI prompts)

https://github.com/atraining/post-digest
1•chelm•39m ago•0 comments

Show HN: Sprite Garden - HTML Canvas 2D sandbox and farming

https://kherrick.github.io/sprite-garden/
2•postpress•44m ago•0 comments

The story of X-Copy on the Amiga

https://spillhistorie.no/2025/10/10/the-story-of-x-copy-on-the-amiga/
1•onename•55m ago•0 comments

Plasma: The fourth state of matter drives sustainable carbon upcycling

https://phys.org/news/2025-09-plasma-fourth-state-sustainable-carbon.html
2•PaulHoule•58m ago•0 comments

Radio Row and the Fight for Lower Manhattan

https://www.archives.nyc/blog/2024/1/5/radio-row-and-the-fight-for-lower-manhattan
3•richardfontana•1h ago•0 comments

Show HN: I sold my side project for $70k at age 17

https://twitter.com/ahmetbuilds/status/1977105584915988613
1•ahmetd•1h ago•1 comments

Ask HN: What's the best alternative to Dragon NaturallySpeaking?

1•Openai2•1h ago•0 comments

LogBuddy – track fitness, food, weight, and periods

https://github.com/aabiji/logbuddy
1•aabiji•1h ago•1 comments

Diane Keaton, 'Annie Hall' star and ROM-com legend, dies at 79

https://www.washingtonpost.com/style/2025/10/11/diane-keaton-obit/
6•bookofjoe•1h ago•2 comments

A Memo in a Bunker, Intercepted Communications and Hamas's Oct. 7 Plans

https://www.nytimes.com/2025/10/11/world/middleeast/israel-hamas-plans.html
2•wslh•1h ago•2 comments

ElementaryOS - The thoughtful, capable and ethical replacement for Windows/macOS

https://elementary.io/
5•donutshop•1h ago•0 comments

So What Now?

https://micro.mu/blog/2025/10/11/so-what-now.html
3•asim•1h ago•0 comments

How Many People Have Ever Lived on Earth?

https://www.scientificamerican.com/article/how-many-people-have-ever-lived-on-earth/
1•bookofjoe•1h ago•1 comments

Building a local LLM powered media search and organiser

https://ikouchiha47.github.io/2025/10/02/media-search.html
2•argentum47•1h ago•0 comments

California Wants to Make It Easier to Build Housing. Los Angeles Objects

https://www.wsj.com/economy/housing/california-housing-bill-los-angeles-pushback-e339bc20
2•JumpCrisscross•1h ago•1 comments
Open in hackernews

Discord hack shows risks of online age checks

https://news.sky.com/story/discord-hack-shows-dangers-of-online-age-checks-as-internet-policing-hopes-put-to-the-test-13447618
140•ColinWright•3h ago

Comments

dbg31415•2h ago
I don’t understand why we need age verification in Discord. Why should people who play games have to prove they’re old enough to talk to others? It’s not like anyone ever forced anybody else to join your Discord community, it’s all opt in!

If parents don’t want their kids playing certain games, or if a community is more adult in nature, then don’t buy those games for them. If they don’t want their kids exposed to bad influences, they can move the computer into a shared space or—better yet—just engage with their kids on a human level. That’s called parenting.

Politicians shouldn’t be meddling in this kind of personal interaction. It didn’t work when Nancy Reagan or Tipper Gore tried to police music, and it’s not working now. Modern authoritarians are just running the same tired playbook.

Age verification doesn’t make kids safer. It adds bureaucracy, harvests private data, and pretends to solve a problem that only families can actually fix. The result is more surveillance, less trust, and the illusion of protection.

maccard•2h ago
I agree with you but;

> I don’t understand why we need age verification in Discord. Why should people who play games have to prove they’re old enough to talk to others? It’s not like anyone ever forced anybody else to join your Discord community, it’s all opt in!

Discord doesn't require age verirication for voice chat, it requires it for access to "sensitive media", or when yuo try to access a channel that has self opted in as age restricted [0].

[0] https://support.discord.com/hc/en-us/articles/30326565624343...

idle_zealot•2h ago
> Politicians shouldn’t be meddling in this kind of personal interaction.

Broadly I agree. I think there is room for good regulation here, though. Specifically, a legal obligation to hook into parental control systems to enable effective parenting in our increasingly complex digital world. While it would be nice if everyone were individually responsible enough to put in the effort to figure out the specifics of what their kids might be exposed to and the control mechanisms available to them, realistically that's probably expecting too much. There's no perfect solution, but intervention focused on obligating (especially large) organizations to empower users and make safety easy to understand and act on is infinitely preferable to obligating companies to restrict and police their users.

debo_•2h ago
A lot of servers have the equivalent of a #nsfw channel where you post dank stuff. I don't agree with the age verification approach, but I see why it concerns people. Discord naturally attracts a very diverse crowd, of which many are quite young. Walking into a random channel in your random all-ages jrpg server and finding horse porn might concern a parent. (This is a concrete example that I have experienced, not a theoretical one.)
squigz•1h ago
And almost all of those servers have those channels marked as such. But when I set it as an NSFW channel, I didn't agree to demand my users' privacy be invaded. Now, I just remove the NSFW flag from those channels. ¯\_(ツ)_/¯
debo_•1h ago
Yeah. I did the same.
charcircuit•1h ago
It's similar to needing ID for purchasing alchohol. You could use the same excuse that parents shouldn't buy alcohol for their kids, but there is the obvious workaround of kids buying it themselves.
mulmen•1h ago
Yes it’s similar, which is the point. Age restrictions have been normalized regardless of effectiveness.
awesome_dude•1h ago
> Age restrictions have been normalized regardless of effectiveness.

For the record.

A law doesn't stop anything.

All a law does is says "If some behaviour meets definition X AND the state becomes aware of it, then consequence Y will be applied by the state"

The hope is that people will see that and make a choice that ensures that they aren't liable for the consequence.

It's also, like everything, as effective as the enforcement. If it's not enforced well, nobody will abide by it.

bramhaag•2h ago
The thing that everybody expected to happen, happened. At least the kids are safe.

Why were these images not encrypted, and why were they retained for longer than was necessary?

miohtama•2h ago
Why the files were asked in the first place?
naldb•2h ago
Encrypted? Encrypted how? How would the employees tasked with age verification access them if they were encrypted?
jvanderbot•2h ago
By decrypting them with a hardware token or passphrase or memorized password or timeboxed token of another kind.

But honestly just delete them ASAP, that's the issue

Dylan16807•1h ago
And if all the employees have access to this hardware token or passphrase or memorized password or timeboxed token of some kind, does that actually prevent a hack, or does it just let you bullet point "encrypted"?

The main thing encryption prevents is someone that steals a physical device getting access to the data inside. It doesn't do much about unauthorized access to live servers.

awesome_dude•1h ago
I mean, this is the problem for all companies with sensitive data (ensuring that "ex" employees no longer have access to <stuff>).

Generally it's done via accessing some 3rd party secret storage system where employees need to verify themselves to get access (eg. Vault, or AWS secrets or what have you)

Dylan16807•1h ago
Do you think this breach had anything to do with ex-employees retaining access? That also sounds like solving the wrong problem.
awesome_dude•1h ago
I mean this is posted on this page too.

z> nomilk 8 minutes ago | prev | next [–]

> The hacker claims an outsourced worker was compromised through a $500 bribe Also interesting:

> The hacker claims government IDs were just sitting there for months or even years... I have spoken to people familiar with Discord's Age Verification system, and they said after some period of time Discord will delete (the copies of IDs), but they should be deleting them the second they're done

Source (pinned comment, and 7m20s respectively): https://www.youtube.com/watch?v=NnuyT8FgSpA

reply

vehementi•1h ago
Check out Defense in Depth as a security concept
Dylan16807•1h ago
It's not defense in depth, it's defense against a different threat entirely.

You want to have encryption, but I doubt their encryption or lack thereof has anything to do with this attack. Do we even have evidence the data wasn't encrypted?.

If someone gets access to a ticketing system they shouldn't have, talking about encryption is about as useful as talking about seatbelts. Important for general safety but irrelevant to the problem at hand.

Barrin92•2h ago
>and why were they retained for longer than was necessary?

it's stated in the article. In most cases they weren't, the data breach only affected people who disputed the result of their age verification.

Of course in principle Discord or any third party should never need any photographic identity themselves to begin with if countries would bother to implement a proper trusted identity system where the data stays with an authority and they simply sign off on requests. Like in South Korea or the eID features you have on most European national ID cards.

whatever1•2h ago
So they process 70k disputes per day? If not, why 70k ids were stolen?

It’s a flawed design. No reason to retain the personal info for more than the processing time. Aka the duration of the dispute process itself (not the queue of disputes).

The principal engineer who signed it off should go to jail.

debo_•2h ago
It's not 70k per day. A dispute takes longer than a day; this was their entire ongoing dispute queue.
whatever1•2h ago
So they were retaining data that they were not actively processing. They were just waiting to be processed.

Aka, the system design was wrong. The buck has to stop somewhere. Somebody signed it off.

debo_•1h ago
I'm not sure how you're coming to that conclusion. If, for example, the id verification says "your id appears to be fake" and the user disputes it, what happens next? A dispute usually has several back-and-forth steps where one party is waiting for the other to respond.
whatever1•1h ago
As simple as: “We are processing your request, once we need more evidence we will contact you.” The day that their turn has come remind them to upload their personal data. Process the request, delete the data in 24 hours.

If you don’t hear back, even better, less private data to worry about.

debo_•1h ago
This is not a tradeoff-less scenario. Most users will be pretty irritated if, for example, you ask them to re-upload the front and back of the id in question at a later date because you deleted it last time for their protection.

I personally think doing ID verification of physical documents over the internet is just a non-starter. I've unfortunately had to support such systems for years at a time, and I'm thankful I don't do it anymore.

esseph•1h ago
You're asking for accountability? Nobody has time for that, stop being silly.
exasperaited•1h ago
> The principal engineer who signed it off should go to jail.

Indeed.

Dylan16807•1h ago
> it's stated in the article. In most cases they weren't, the data breach only affected people who disputed the result of their age verification.

Saying this only affected disputes doesn't answer the question. It also makes it clear they knew deleting IDs was important, but did they not have proper deletion in their dispute system? If this was only new active disputes, I would expect discord to say so, but it sounds like the data in the leak goes back a lot further.

exasperaited•1h ago
> Of course in principle Discord or any third party should never need any photographic identity themselves to begin with if countries would bother to implement a proper trusted identity system where the data stays with an authority and they simply sign off on requests.

Indeed. But in the UK the only really loud voices against the porn age laws are also the same voices against the latest digital ID proposals.

It's logical to say "we don't need either of these two things".

But the status quo of ID verification of all kinds (for things like finance agreements, some online purchases, KYC, checking into some hotel chains if you're not the card holder who paid, etc.) is horrifying and involves uploading scans of paper documents. Every time someone says "I don't need a digital ID thanks" I ask them how many times they've let someone take a flatbed or photocopier scan of their passport or driving licence in real life (it's usually not zero) and then I ask them to explain to me how they would do that if it is online, and if they ever asked how long they are retained.

Dylan16807•1h ago
I mostly agree, but your list of situations is places you want your actual identity to be verified. For age checks, a core feature should be not identifying yourself.
exasperaited•41m ago
Yes, but a core feature of contemporary digital ID is age-only digital attestation -- that is, yes this unnamed person is old enough.

The absence of such means that there are few ways for people to verify their ages without handing over scans of their IDs to far too many organisations.

In the UK we do have one means to do this that is not widely used yet: since all mobile phone providers attempt to block adult content by default until the owner proves they are an adult (a pretty long-standing pre-existing child safety/parental control initiative by PAYG providers that has evolved to be standard across all contract types), the question of "can you prove you are 18" can now be delegated to the MNOs. But not all the age verification agencies are doing it.

raggi•2h ago
> At least the kids are safe.

Are they any safer? Roadblocks rarely stopped me as a kid. These kinds of impediments most often resulted in me strategically moving what I was doing to somewhere out of sight of the gatekeepers, most often resulting in less safety. Where do most kids learn to play with fire in modern society? in very very dangerous places.

yieldcrv•2h ago
that was sarcasm, a satire on the situation and ostensible purpose of burdening everyone with this
drdeadringer•1h ago
This reminds me of a small but fond memory of mine. One of my friends in high school, up from elementary, was slightly a troublemaker. But not terribly so. One day, we found ourselves sitting at the same lunch table. He occasionally smoked, I did not (I still don't). This meant that he had a lighter and I at the time did not (I now carry a lighter with me at all times for unrelated reasons).

He made a comment about how good orange peels smelled when you burned them. I leaned into this comment with curiosity and personal ignorance on the matter.

He said yeah and then looked around made the shush shush signal and leaned in, and invited me to do the same. He took an orange peel and brushed it across his opened lighter flame. Nobody caught us, and I smelled firsthand What he was talking about. Nobody got into trouble over this innocent demonstration. But for sure as hell you would have gone into trouble for this uncensioned demonstration of fire usage.

subscribed•1h ago
How does it make kids any safer?

My kids had a honest conversation with me about possible Wikipedia ban and VPNs maybe a week in. Their classmates were already using it.

Dylan16807•1h ago
https://news.ycombinator.com/item?id=45552348

https://news.ycombinator.com/item?id=45552382

LelouBil•2h ago
Related : https://www.youtube.com/watch?v=NnuyT8FgSpA

The hacker contacted some well known youtuber that talks about discord, they provided contents of support tickets of the YouTuber to prove they were really the hacker

luxuryballs•2h ago
Anyone with insight into this kind of thing know if it’s reasonable to doubt Discord’s claims about what the hackers have? I can see motives for both parties to stretch the truth in opposite directions. But maybe there’s some legal risk for Discord to lie about what was compromised, in the event they get found out?
guerrilla•2h ago
I'm grateful for the timing.
nomilk•1h ago
> The hacker claims an outsourced worker was compromised through a $500 bribe

Also interesting:

> The hacker claims government IDs were just sitting there for months or even years... I have spoken to people familiar with Discord's Age Verification system, and they said after some period of time Discord will delete (the copies of IDs), but they should be deleting them the second they're done

Source (pinned comment, and 7m20s respectively): https://www.youtube.com/watch?v=NnuyT8FgSpA

ndriscoll•2m ago
Didn't they only start doing age verification this summer? Why do they have years worth of IDs?
like_any_other•1h ago
I don't understand. Weren't we told that these age checks are "privacy-preserving"? So why was there anything for hackers to steal? Or do they mean "privacy-preserving" only against other random users of a service, but not against the service itself, the corporation running it, it's subsidiaries and parent conglomerate, their "trusted partners", the process of legal discovery if that corporation ever gets sued, legal subpoena by the police and intelligence agencies of every jurisdiction that conglomerate conducts business in, local councils [1], every government agency you can think of including ambulance service providers [2], and of course data breaches?

[1] https://www.ibtimes.co.uk/british-councils-used-ripa-conduct...

[2] https://en.wikipedia.org/wiki/Investigatory_Powers_Act_2016#...

aucisson_masque•47m ago
It's only the beginning, right ?

I already bought a vps in turkey and installed a vpn on it, cost 10€ a year but it's a small price to pay to not have his ID stolen.