frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

America's Semiconductor Boom is Real [video]

https://www.youtube.com/watch?v=T-jt3qBzJ4A
1•zdw•1m ago•0 comments

Why long-form writing and blogs will continue to thrive in spite of AI

https://greyenlightenment.com/2025/10/12/why-content-production-continues-to-thrive-in-spite-of-ai/
1•paulpauper•2m ago•0 comments

example.com was updated on 2025-10-09

https://web.archive.org/web/20251009174438/http://www.example.com/
1•divbzero•6m ago•1 comments

The company Discord blamed for its recent breach says it wasn't hacked

https://www.engadget.com/cybersecurity/the-company-discord-blamed-for-its-recent-breach-says-it-w...
1•baobun•8m ago•1 comments

Experiences with GPT-5-Codex

https://www.johndcook.com/blog/2025/10/16/experiences-with-gpt-5-codex/
1•ibobev•9m ago•0 comments

Success Isn't About Choosing the Right Frameworks

https://chatbotkit.com/reflections/success-isnt-about-choosing-the-right-frameworks
1•_pdp_•9m ago•0 comments

What GPU pricing can tell us about how the AI bubble will pop

https://www.ft.com/content/d49707ae-5d6b-473e-9e2b-487d318e6fe9
2•sega_sai•11m ago•1 comments

NASA Graphics Standards Manual (1976) [pdf]

https://www3.nasa.gov/sites/default/files/atoms/files/nasa_graphics_manual_nhb_1430-2_jan_1976.pdf
1•helterskelter•12m ago•0 comments

Windows Inside a Docker Container

https://github.com/dockur/windows
1•transpute•14m ago•0 comments

MXene current collectors could reduce size, improve recyclability of batteries

https://techxplore.com/news/2025-10-mxene-current-collectors-size-recyclability.html
1•PaulHoule•15m ago•0 comments

History's shaming fascination for the so-called 'idiot savant'

https://aeon.co/essays/historys-shaming-fascination-for-the-so-called-idiot-savant
2•bookofjoe•17m ago•0 comments

Ask HN: How do I use LLMs to generate test cases for groundedness benchmarks?

https://devblogs.microsoft.com/ise/intuitive-evaluation-framework-for-agentic-chatbots/
1•this_steve_j•17m ago•1 comments

U.S. Chamber of Commerce sues over Trump's $100k H-1B visa fee

https://www.reuters.com/world/major-us-business-group-sues-over-trumps-100000-h-1b-visa-fee-2025-...
5•petethomas•20m ago•0 comments

Show HN: Played – Music Player Skin

https://github.com/sidhyatikku/music-player-skin
1•sidhyatikku•20m ago•0 comments

Harvard endowment swells to nearly $57B, donations reach a record

https://www.reuters.com/world/us/harvard-endowment-swells-nearly-57-billion-donations-reach-recor...
2•petethomas•21m ago•1 comments

Legal's Jane Street

https://tritium.legal/blog/jane
1•piker•21m ago•0 comments

Ace Frehley Dies at 74

https://variety.com/2025/music/news/ace-frehley-kiss-lead-guitarist-dead-1236554943/
6•FillardMillmore•22m ago•1 comments

Show HN: ETA Guesser (real-time traffic guessing game)

https://etaguesser.com/
1•justbobbydylan•23m ago•0 comments

RFK Jr.'s MAHA wants to make chemtrail conspiracy theories great again

https://arstechnica.com/health/2025/10/rfk-jr-s-maha-wants-to-make-chemtrail-conspiracy-theories-...
5•ndsipa_pomu•23m ago•1 comments

Doom modders' new engine in protest of GZDoom leadership and use of ChatGPT

https://www.rockpapershotgun.com/doom-modders-fall-into-civil-war-as-devs-launch-new-engine-in-pr...
2•CharlesW•24m ago•0 comments

Banks' Trio of Alleged Frauds Spark Fears of Broader Issues

https://www.bloomberg.com/news/articles/2025-10-16/banks-trio-of-alleged-frauds-spark-fears-of-br...
2•zerosizedweasle•27m ago•0 comments

I built a human-AI visual layer for product photos

https://lume.pics/
1•emrahsaglik•27m ago•1 comments

Goldman's Waldron Cautions on Fallout from Credit 'Explosion'

https://www.bloomberg.com/news/articles/2025-10-16/goldman-s-waldron-cautions-on-fallout-from-cre...
1•zerosizedweasle•28m ago•0 comments

Show HN: TechRex – client-side PDF editor (no upload, no watermark)

1•Maaz-Sohail•32m ago•0 comments

Oh-My-God Particle

https://en.wikipedia.org/wiki/Oh-My-God_particle
1•mieubrisse•32m ago•0 comments

Claude Skills are awesome, maybe a bigger deal than MCP

https://simonwillison.net/2025/Oct/16/claude-skills/
3•keybits•36m ago•0 comments

Absci Accelerates Drug Trials for Hair Loss–Is Its AI Pipeline Turning a Corner?

https://simplywall.st/stocks/us/pharmaceuticals-biotech/nasdaq-absi/absci/news/absci-absi-acceler...
1•randycupertino•37m ago•1 comments

The Emulator's Gambit: Executing Code from Non-Executable Memory

https://redops.at/en/blog/the-emulators-gambit-executing-code-from-non-executable-memory
2•thewavelength•39m ago•1 comments

When Bots Pump Your OTPs – My Take on SMS Pumping Fraud

https://gsociety.fr/when-bots-pump-your-otps-sms-pumping/
1•guisch•41m ago•0 comments

Speculations on arenas and non-trivial destructors

https://nullprogram.com/blog/2025/10/16/
2•zdw•42m ago•0 comments
Open in hackernews

Cloudflare Sandbox SDK

https://sandbox.cloudflare.com/
74•bentaber•2h ago

Comments

fishmicrowaver•2h ago
Is there some sort of competition for awful looking websites going on?
Svoka•1h ago
I thought it was cute and easy to read.
fishmicrowaver•1h ago
They didn't test it with FF apparently.
sim0n•1h ago
Looks perfectly fine in FF 144.0 on Mac OS.
fidotron•1h ago
This bizarre anti-aesthetic has been pushed in the web devex space for a few years now to appeal to other web devex companies.
_pdp_•1h ago
Looks nice.

We rolled out our own that does pretty much the same thing but perhaps more because our solution can also mount persistent storage that can be carried between multiple runners. It does take 1-5 seconds to boot the environment (firecracker vms). If this sandbox is faster I will instruct the team to consider for fast starup.

This is also very similar to Vercel's sandbox thing. The same technology?

What I don't like about this approach is the github repo bootstrap setup. Is it more convenient compared to docker images pushed to some registry? Perhaps. But docker benefits from having all the artefacts prebuilt in advance, which in our case is quite a bit.

_pdp_•1h ago
I browsed through the documents but it does not seem to be possible to auto destroy a sandbox after certain amount of idle time. This forces who ever is implementing this to do their own cleanup. It is kind of missed opportunity if you ask me as this is a big pain. It is sold as fire and forget but it seems that more serious workflows will require also a lot of supporting infrastructure.
alooPotato•57m ago
You can easily set an alarm in the durable object to check if it should be killed and then call destroy yourself. Just a couple lines of code.
_pdp_•55m ago
Nice. Thanks for the tip. I did not know that this was a thing. I will look it up.
ATechGuy•1h ago
> It does take 1-5 seconds to boot the environment (firecracker vms).

I'd say 1-5 secs is fast. Curious to know what use cases require faster boot up, and today suffer from this latency?

_pdp_•1h ago
When your agent performs 20 tasks saving seconds here and there becomes a very big deal. I cannot even begin to describe how much time we've spent on optimising code paths to make the overall execution fast.

Last week I was on a call with a customer. They where running OpenAI side-by-side with our solution. I was pleased that we managed to fulfil the request under a minute while OpenAI took 4.5 minutes.

The LLM is not the biggest contributor to latency in my opinion.

ATechGuy•1h ago
Thanks! While I agree with you on "saving seconds" and overall latency argument, according to my understanding, most agentic use cases are asynchronous and VM boot up time may just be a tiny fraction of overall task execution time (e.g., deep research and similar long running tasks in the background).
fidotron•1h ago
Does this relate to workerd in any way or is it something else entirely?
whoiskatrin•1h ago
If anyone is curious, more details on our SDK can be found here actually https://github.com/cloudflare/sandbox-sdk
ChrisArchitect•1h ago
These CF website relaunches are just that right? Workers last week (https://workers.cloudflare.com) and now this one yesterday. I mean, if CF has something newsworthy here they should do a blog post announcing it because otherwise it's just a refreshed website. It's hard to tell if there's anything new here.

It's the same SDK stuff from earlier this year right? https://developers.cloudflare.com/changelog/2025-06-24-annou...

whoiskatrin•1h ago
it barely had any features then, this version is full of new functionality: streaming logs, long running processes, code interpreter and lots of other things and full docs site as well
simonw•1h ago
Looks like there's one feature missing from this that I care about: I'd like more finely grained control over what outbound internet connections code running on the box can make.

As far as I can tell it's all or nothing right now:

  this.ctx.container.start({
    enableInternet: false,
  });
I want to run untrusted code (from users or LLMs) in these containers, and I'd like to avoid someone malicious using my container to launch attacks against other sites from them.

As such, I'd like to be able to allow-list just specific network points. Maybe I'm OK with the container talking to an API I provide but not to the world at wide. Or perhaps I'm OK with it fetching data from npm and PyPI but I don't want it to be able to access anything else (a common pattern these days, e.g. Claude's Code Interpreter does this.)

paxys•1h ago
This simple feature bumps up the complexity of such a firewall by several orders of magnitude, which is why no similar runtime (like Deno) offers it.

Networking as a whole can easily be controlled by the OS or any intermediate layer. For controlling access to specific sites you need to either filter it at the DNS level, which can be trivially bypassed, or bake something into the application binary itself. But if you are enabling untrusted code and giving that code access to a TCP channel then it is effectively impossible to restrict what it can or cannot access.

navanchauhan•1h ago
At least on macOS, there is a third way where you can control the network connection on the PID/binary level by setting up a network system extension and then setting up a content filter so you can allow/deny requests. It is pretty trivial to set this up, but the real challenge is usually in how you want to express your rules.

Little Snitch does this pretty well: https://www.obdev.at/products/littlesnitch/index.html

simonw•1h ago
The most convincing implementation I've seen of this so far is to lock down access to just a single IP address, then run an HTTP proxy server at that IP address which can control what sites can be proxied to.

Then inject HTTP_PROXY and HTTPS_PROXY environment variables so tools running in the sandbox know what to use.

ashishbijlani•1h ago
I’m extending Packj sandbox for agentic code execution [1]. You can specify allowlist for network/fs.

1. https://github.com/ossillate-inc/packj/blob/main/packj/sandb...

masterj•19m ago
Cloudflare has Outbound Workers for exactly this use-case: https://developers.cloudflare.com/cloudflare-for-platforms/w...

If these aren't enabled for containers / sandboxes yet, I bet they will be soon

eis•1h ago
Cloudflare Containers (and therefore Sandbox) pricing is way too expensive. The pricing is a bit cumbersome to understand by being inconsistent with pricing of other Cloudflare products in terms of units and split between memory, cpu and disk instead of combined per instance. The worst is that it is given in these tiny fractions per second.

Memory: $0.0000025 per additional GiB-second vCPU: $0.000020 per additional vCPU-second Disk: $0.00000007 per additional GB-second

The smaller instance types have super low processing power by getting a fraction of a vCPU. But if you calculate the monthly cost then it comes to:

Memory: $6.48 per GB vCPU: $51.84 per vCPU (!!!) Disk: $0.18 per GB

These prices are more expensive than the already expensive prices of the big cloud providers. For example a t2d-standard-2 on GCP with 2 vCPUs and 8GB with 16GB storage would cost $63.28 per month while the standard-3 instance on CF would cost a whopping $51.84 + $103.68 + $2.90 = $158.42, about 2.5x the price.

Cloudflare Containers also don't have peristent storage and are by design intended to shut down if not used but I could then also go for a spot vm on GCP which would bring the price down to $9.27 which is less than 6% of the CF container cost and I get persistent storage plus a ton of other features on top.

What am I missing?

ATechGuy•56m ago
Startups would build on big tech, so are likely to add their margins. Have you looked into (bulk) discounts from GCP/AWS?
alooPotato•55m ago
There is an open question about how file persistence works.

The docs claim they persist the filesystem even when they move the container to an idle state but its unclear exactly what that means - https://github.com/cloudflare/sandbox-sdk/issues/102

SparkyMcUnicorn•15m ago
To me, the docs answer it pretty clearly. The defined directories persist until you destroy().

The part that's unclear to me is how billing works for a sandbox's disk that's asleep, because container disks are ephemeral and don't survive sleep[2] but the sandbox pricing points you to containers which says "Charges stop after the container instance goes to sleep".

https://developers.cloudflare.com/sandbox/concepts/sandboxes...

https://developers.cloudflare.com/sandbox/concepts/sandboxes...

[2] https://developers.cloudflare.com/containers/faq/#is-disk-pe...

jasonriddle•53m ago
This looks interesting.

Instead of having to code this up using typescript, is there an MCP server or API endpoint I can use?

Basically, I want to connect an MCP server to an agent, tell it it can run typescript code in order to solve a problem or verify something.

orliesaurus•39m ago
How much `power` do they have?