frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Too many tasks/ projects, not sure where to start? Auto-split your day here

https://planmytime-taskmaster.web.app/
1•naveen-zerocool•39s ago•0 comments

How the Mayans were able to accurately predict solar eclipses for centuries

https://phys.org/news/2025-10-mayans-accurately-solar-eclipses-centuries.html
1•pseudolus•2m ago•0 comments

The RISC-V Instruction Tier List [video]

https://www.youtube.com/watch?v=qLEKOfVQEZI
1•oxxoxoxooo•3m ago•0 comments

AI Hyperscalers are currently spending 60% of their operating cash flow on capex

https://www.apolloacademy.com/hyperscaler-capex-spending/
1•helsinkiandrew•3m ago•0 comments

Mesh Networks Reimagined for Political Protests

https://spectrum.ieee.org/mesh-network-political-protests-amigo
1•pseudolus•5m ago•0 comments

Skill Builder for Claude Code

https://github.com/metaskills/skill-builder
1•mooreds•7m ago•0 comments

SETL Programming Language

https://en.wikipedia.org/wiki/SETL
1•usgroup•7m ago•0 comments

Rapid early spread of bird flu in Europe raises fears of fresh crisis

https://www.reuters.com/business/healthcare-pharmaceuticals/rapid-early-spread-bird-flu-europe-ra...
1•zerosizedweasle•8m ago•0 comments

Bird Flu Is Back. Here's What to Know

https://www.scientificamerican.com/article/why-bird-flu-is-surging-again-and-what-it-means-for-pu...
2•zerosizedweasle•9m ago•0 comments

A Letter from Klaus Hommels – Founder and Chairman, Lakestar

https://lakestar.com/october2025
1•doener•9m ago•0 comments

Josh Swihart on X: "Building Momentum. Zcash Update." / X

https://twitter.com/jswihart/status/1982605731628249274
1•bilsbie•10m ago•0 comments

Declarative database schema migrations – yay or nay?

1•astronautas•13m ago•0 comments

Annual hours worked per worker in OECD countries

https://figure.nz/chart/uzEoMsIEuL9cjdBS
1•surprisetalk•17m ago•0 comments

"Let people enjoy things "

https://tadaima.bearblog.dev/poptimism-backlash/
1•surprisetalk•17m ago•0 comments

How to Implement an Operation Warp Speed for Rare Earths

https://ifp.org/how-to-implement-an-operation-warp-speed-for-rare-earths/
2•surprisetalk•18m ago•0 comments

Explaining the Standard Model [video]

https://www.youtube.com/watch?v=0yjxqMoX-y8
1•surprisetalk•18m ago•0 comments

There's no realistic alternative to AWS and the other hyperscalers

https://mastodon.world/@Mer__edith/115445701583902092
1•Vinnl•19m ago•0 comments

"Plant Math" Can Help Predict the Climate's Future

https://nautil.us/how-plant-math-can-help-predict-the-climates-future-1237997/
2•fleahunter•19m ago•0 comments

People are having fewer kids. Their choice is transforming the economy

https://www.npr.org/2025/10/27/nx-s1-5576355/population-babies-capitalism
1•cebert•20m ago•1 comments

Show HN: Wranglr – A programmable CLI for tracking dev work

https://github.com/everettraven/wranglr
1•everettraven•21m ago•0 comments

US pushes regulators on connecting data centers to grid

https://www.reuters.com/business/energy/us-pushes-regulators-connecting-data-centers-grid-2025-10...
1•giuliomagnifico•24m ago•0 comments

AI Attempts to Guess the Popularity of Linux DEs: Gnome, KDE, Hyprland, and More

https://grigio.org/ai-attempts-to-guess-the-popularity-of-linux-desktop-environments-gnome-kde-hy...
1•grigio•25m ago•0 comments

Show HN: Estimating startup viability using Nobel Prize economics

https://tom-dickson.com/blog/startup-viability-calculator/
1•tajd•26m ago•0 comments

Show HN: SSL Certificate Expiration in Calendar App

https://sslcalendar.com
1•weddpros•26m ago•0 comments

MiniMax-M2, a Mini open-source model built for Max coding and agentic workflows

https://huggingface.co/MiniMaxAI/MiniMax-M2
1•grigio•27m ago•0 comments

Bats eat the birds they pluck from the sky while on the wing

https://arstechnica.com/science/2025/10/tracking-bats-as-they-hunt-birds-in-the-skies-above-europe/
2•sipofwater•27m ago•1 comments

eBPF Observability and Continuous Profiling with Parca

https://fatihkoc.net/posts/ebpf-parca-observability/
1•fatihkocnet•28m ago•0 comments

Screenwriter Eric Heisserer on Lights Out, the Rules of Horror

https://filmmakermagazine.com/99327-screenwriter-eric-heisserer-lights-out-the-rules-of-horror-an...
1•suioir•31m ago•0 comments

My math setup (as a software engineer)

https://danielfalbo.substack.com/p/my-math-setup
1•danielfalbo•31m ago•0 comments

How Much Does It Cost to Charge an Electric Vehicle?

https://www.caranddriver.com/news/a45036169/electric-vehicle-ev-cost-to-charge/
1•cebert•34m ago•0 comments
Open in hackernews

If Your Adversary Is the Mossad (2014) [pdf]

https://www.usenix.org/system/files/1401_08-12_mickens.pdf
103•xeonmc•2h ago

Comments

samlinnfer•2h ago
This will always be my favourite Mikens essay (The Slow Winter): https://www.usenix.org/system/files/1309_14-17_mickens.pdf
chao-•1h ago
Mine as well.

I have a fond memory of being at a party where someone had the idea to do dramatic readings of various Mickens Usenix papers. Even just doing partial readings, it was slow going, lots of pauses to recover from overwhelming laughter. When the reading of The Slow Winter got to "THE MAGMA PEOPLE ARE WAITING FOR OUR MISTAKES", we had to stop because someone had laughed so hard they threw up. Not in an awful way, but enough to give us a pause in the action, and to decide we couldn't go on.

Good times.

eeeficus•1h ago
Sounds like you found nerd heaven. I couldn't imagine a situation like yours in my world! :)
isoprophlex•52m ago
> [...] it’s pretty clear that compilers are a thing of the past, and the next generation of processors will run English-level pseudocode directly.

hilarious AND scary levels of prescient writing...

tuzemec•2h ago
Somewhat related video: https://vimeo.com/95066828
optimalsolver•1h ago
I think fighting Israel is kind of a glimpse into what trying to fight a malevolent AGI will be like.

Expect to lose in highly surprising ways.

speedgoose•1h ago
I don't know, driving a big truck into AWS' us-east-1 power supply section sounds more than enough to take down internet for a while.
ta1243•48m ago
I would hope that data centre has multiple power supplies from multiple locations - as well as UPS and on site generators, certainly mine do.

However given AWS is so complex (which is required because they want to be a gatekeeping platform) leading the uptime to struggle to match a decent home setup, I'm not sure. I'm sure there's no 6 figure bonus for checking the generators are working, but a rounded corner on a button on an admin page?

broodbucket•1h ago
Remember, you don't have to be unhackable, just sufficiently unimportant to not be worth burning any novel capability on
INTPenis•1h ago
That's right, just keep your head down, smile and nod, do your job and nothing will ever go wrong. /s
brigandish•1h ago
A more charitable view would be to act like a zebra in a herd of zebra rather than a zebra in a herd of horses.
GreenWatermelon•1h ago
You /s but this is actually valid advice for someone who just wants to get by in life and is content.
energy123•1h ago
Downvoted, but so much evil is caused by people due to their distorted yet sincerely believed moral virtues. Not due to an absence of morality but because of it. Whatever you have in your mind as the image of quintessential evil is probably caused by those people's sincerely held moral system, a moral system they believed in as strongly as you do yours. So people who just live their lives and do not grasp on external change are fine by me.
throwaway_dang•1h ago
Do the bombs dropping in war zones avoid apolitical people? If not, when is the appropriate time to get sufficiently political to avoid having a bomb dropped on one's head?
adrianN•51m ago
Very few individuals can influence whether or not bombs drop. The best way to avoid having bombs dropped on your head is moving to a place where fewer bombs are dropped.
jimnotgym•17m ago
But many people together, although none of them individually influencial enough, certainly can influence where bombs get dropped.

When you start successfully reaching many people you can be sure that security agencies will start watching you.

impossiblefork•56m ago
I don't think that's the interpretation, but make your computer systems disconnected from what you do.

If relevant adversaries don't know which computer to burn the exploit on, then they won't burn it on the right one.

edu•1h ago
That's a fun take, similar to the classic XKCD 538: Security. https://xkcd.com/538/
hshdhdhehd•1h ago
The 4096 bits just stops it being so easy to surveil you that it is hyper-automated. So there is some use. The $5 wrench needs a million dollar operation to get that guy to your house.
bbarnett•1h ago
Oh come on, that's way over budget! Every time I managed such an operation, we'd just rent a van and... uh, I mean, um, I heard it costs less.

<NO CARRIER>

hshdhdhehd•53m ago
Its a million dollars to the defense contractor who lobbies for more wrench attacks.
ta1243•51m ago
Depends how strong the protections of your civil society is, but it doesn't cost $1m to send a goon with a crowbar or shotgun. Sure that doesn't scale, but if you are a target you're screwed
hshdhdhehd•33m ago
The $1m is the stuff they did to the point where they knew where to send the goon.

If you are a target you are screwed. But clever crypto isn't useless.

eirini1•1h ago
Never agreed with this logic. For a lot of people (anyone that does political activism of some sort for example) the threat model can be a lot more nuanced. It might not be Mossad or the CIA gunning for you, specifically, but it might police searching you and your friend's laptops or phones. It might be burglars targetting the office of the small organization you have and the small servers you have running there.
rini17•1h ago
You did not write what you actually disagree with....
turboturbo•1h ago
The false dichotomy
rini17•1h ago
The dichotomy between what average people(including political activists) can actually handle and stuff proposed by security researchers is real.
anonym29•45m ago
The idea that average people can't handle incremental improvements like a password manager, MFA, full disk encryption, etc is unhealthy infantilization of people who are entirely capable of understanding the concepts, the benefits, the risks they address, and appreciating the benefits of them.

Most people just don't care enough until after they're hacked, at which point they care just enough to wish they'd done something more previously, which is just shy of enough to start doing something differently going forward.

It's not that normies are too stupid figure this out, it's that they make risk accept decisions on risks they don't thoroughly understand or care enough about to want to understand. My personal observation is that the concept of even thinking about potential future technology risks at all (let alone considering changing behavior to mitigate those risks) seems to represent an almost an almost pathological level of proactive preparation to normies, the same way that preppers building bunkers with years of food and water storage look to the rest of us.

coldtea•55m ago
the maximalist false dillema of "all or nothing": either it's a super-poweful super-human agency and you can't do anything, else any half-measure is fine
megous•1h ago
Not sure what audience he is talking to. Experts deal with a lot more issues that sit between choosing a good password + not falling for phishing and "giving up because mossad". The terminology that he sprinkles about suggests the audience is experts.
rini17•1h ago
The article actually addresses this -- that all these extra issues are not manageable for mere mortals anyway and/or perfectly spherical cows are involved.
megous•24m ago
It does not. It just invents a bunch of straw men, and then mocks them.
impossiblefork•1h ago
The Mossad part is a very silly element of the text. Many organizations have to defend against US intelligence, Israeli intelligence etc., and I'm sure, that they, with the exception of some very terrible countries with a lot of incompetence or full of disloyal people likely to become infiltrators, are quite successful.

Actual security is possible even against the most powerful and determined adversaries, and it's possible even for you.

lifestyleguru•1h ago
Then how it's possible Mossad didn't know about what had happened on 7 October 2023?
INTPenis•1h ago
This is exactly the type of comment that will get you mossad'd.
lifestyleguru•1h ago
ok I'll keep you updated, but I don't own any real estate they could "de-Hamasify"
ozirus•1h ago
Domestic intel = Shin Bet, not Mossad
bbarnett•1h ago
The same way the US didn't know about 9/11. Intelligence failures.

(Portions of the US intelligence apparatus knew, but that knowledge didn't transition into action)

energy123•1h ago
Israel's intelligence services (not Mossad) did collect valid signals, such as sim cards in Gaza being swapped out for Israel sim cards, but it was ignored as another false positive. What the public doesn't see are all the false positives (like many drills for an attack that don't materialize) that drown out valid signals when the attack is actually going to happen.

It's one of the many asymmetries that changes when you are the defender versus the attacker. As the defender, you have to be right 100% of the time. As the attacker, you have the luxury of being right only 30% of the time. The law of large numbers is on the side of the attacker. This applies to missile offense/defense and to usage of intelligence.

This information asymmetry is also one of the key drivers of the security dilemma, which in turn causes arms races and conflict. The defender knows they can't be perfect all the time, so they have an incentive to preemptively attack if the probability of future problems based on their assessment of current information is high enough.

In the case of Gaza there was also an assessment that Hamas were deterred, which were the tinted glasses through which signals were assessed. Israel also assumed a certain shape of an attack, and the minimal mobilisation of Hamas did not fit that expected template. So the intelligence failure was also a failure in security doctrine and institutional culture. The following principles need to be reinforced: (i) don't assume the best, (ii) don't expect rationality and assume a rival is deterred even if they should be, (iii) intention causes action, believe a rival when they say they want to do X instead of projecting your own worldview onto them, (iv) don't become fixated on a particular scenario, keep the distribution (scenario analyses) broad

throwaway_dang•1h ago
Maybe they did but it was permitted to happen to provide the pretext to expand those Greater Israel borders.
2rsf•58m ago
a. I am too lazy to search but they probably did, the problem was what was done with the information. Same with 8200 the all mighty signal intelligence corps

b. The Mossad is the equivalent of the CIA, they are not meant to act inside Israel

ta1243•46m ago
> b. The Mossad is the equivalent of the CIA, they are not meant to act inside Israel

For that purpose is Gaza inside or not inside Israel?

2rsf•38m ago
Yes (TBD)
lifestyleguru•36m ago
Israel would probably dispute it, but for most of the world Gaza in relation to Israel is "abroad" and not "domestic".
rgblambda•35m ago
Shin Bet (Israeli internal security service) have an Arab desk that covers the West Bank & Gaza.
smashah•39m ago
They didn't know about the pretense they wanted to spend the following 2+ years making unlimited fallacious justifications for committing a live-streamed holocaust of children? Who told you that?
torginus•1h ago
If your adversary is a state intelligence agency, you're probably a high ranking politician and a boomer who is clueless about computers, and has demonstrably terrible opsec, either through government incompetence of your own agencies, or not following the terribly cumbersome opsec procedures, either because of inconvenience, the policies being terrible or sheer incompetence.

The amount of examples we've seen of this is staggering.

mike_hearn•1h ago
It's hilarious, but the hilarity gets in the way of recognizing how much insight there is also there. It makes serious points. This part about the Mossad is especially astonishing given the pager attack:

> If your adversary is the Mossad, YOU’RE GONNA DIE AND THERE’S NOTHING THAT YOU CAN DO ABOUT IT. The Mossad is not intimidated by the fact that you employ https://. If the Mossad wants your data, they’re going to use a drone to replace your cellphone with a piece of uranium that’s shaped like a cellphone

It's like a Mossad agent read this paper and thought hey that's actually not a bad idea.

But the core rant is about dubious assumptions in academic cryptography papers. I was also reading a lot of academic crypto papers in 2014, and the assumptions got old real fast. Mickens mocks these ideas:

• "There are heroes and villains with fantastic (yet oddly constrained) powers". Totally standard way to get a paper published. Especially annoying were the mathematical proofs that sound rigorous to outsiders but quietly assume that the adversary just can't/won't solve a certain kind of equation, because it would be inconvenient to prove the scheme secure if they did. Or the "exploits" that only worked if nobody had upgraded their software stack for five years. Or the systems that assume a perfect implementation with no way to recover if anything goes wrong.

• "you could enlist a well-known technology company to [run a PKI], but this would offend the refined aesthetics of the vaguely Marxist but comfortably bourgeoisie hacker community who wants everything to be decentralized", lol. This got really tiresome when I worked on Bitcoin. Lots of semi-technical people who had never run any large system constantly attacking every plausible design of implementable complexity because it wasn't decentralized enough for their tastes, sometimes not even proposing anything better.

• "These [social networks] are not the best people in the history of people, yet somehow, I am supposed to stitch these clowns into a rich cryptographic tapestry that supports key revocation and verifiable audit trails" - another variant of believing decentralized cryptography and PKI is easy.

He also talks about security labels like in SELinux but I never read those papers. I think Mickens used humor to try and get people talking about some of the bad patterns in academic cryptography, but if you want a more serious paper that makes some similar points there's one here:

https://eprint.iacr.org/2019/1336.pdf

Yizahi•1h ago
> Lots of semi-technical people who had never run any large system constantly attacking every plausible design of implementable complexity because it wasn't decentralized enough for their tastes, sometimes not even proposing anything better.

And for added fun, that same radical decentralization crowd, finally settling on the extremely centralized Lightning crutch, which is not only centralized but also computationally over complicated and buggy.

ta1243•1h ago
> you could enlist a well-known technology company to [run a PKI],

If you have a single company, then that's easy enough for a group like Mossad to infiltrate. Probably easier than a distributed system.

mike_hearn•27m ago
The best known PKI (webtrust) is many companies, not a single company. So it's distributed but that makes it easier to hack not harder because you have many possible targets instead of just one.
jojobas•57m ago
It is kinda funny, but cost and benefit analysis is not foreign even to Mossad. Mossad would prefer quite a few people's data stolen, but they are not going to carry out a black abroad for most of them.
smashah•1h ago
Very true, unfortunately there's no password strong enough to stop Malaysian Airlines ground crew from loading a pallet full of Mossad-rigged walkie talkies on my flight from Kuala Lumpur to Beijing via conveniently-placed-NATO-AWACS-infested airspace.

2FA isn't going to protect me from cruising altitude walkie talkie detonation and having the debris scattered over an impossibly wide area.

I guess the best thing to do is not take an airline of a country that has recently showed public support for Gaza specifically during a humanitarian visit in the months prior to my flight.

Thankfully none of this is true and everything the mainstream media and governments tell us are true - imagine if things weren't as they seemed?.. Craziness... Back to my password manager!

gjvc•1h ago
this guy's stuff reads like word salad and people lap it up. I've never understood why.
Havoc•47m ago
Despite word salad it is entertaining and the core message is valid
EdwardDiego•24m ago
Because it's a funny rant.
ChrisMarshallNY•46m ago
I've always enjoyed Mikens' writing. He has a great sense of humor.

I like his using Mossad as the extreme. I guess "Mossad'd" is now a verb.

zkmon•44m ago
Security is a problem caused by ownership of some usefulness. Sometimes solution can be around addressing these two causes.
Havoc•42m ago
I see this on reddit a lot in self hosting context.

The range of things people do on security is wild. Everything from publicly expose everything and pray the apps login function some random threw together is solid to elaborate intrusion detection systems.

jones89176•32m ago
I enjoyed "The Night Watch" a lot:

https://scholar.harvard.edu/files/mickens/files/thenightwatc...

> A systems programmer will know what to do when society breaks down, because the systems programmer already lives in a world without law.