frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Chromium Browser DoS Attack via Document.title Exploitation

https://github.com/jofpin/brash
12•croes•6h ago

Comments

zb3•4h ago
I remember back in the day you could just use the alert function in a while(true) loop and that would be enough to render Internet Explorer unusable :)
OptionOfT•1h ago
Ha, back then they were native OS dialogs. And one would block the whole window, even when IE6 gained tabs.
julia_j•3h ago
Calling most APIs in a loop will eventually cause the browser to struggle or eventually crash. What is novel here? Repo looks to be entirely AI generated spam
not4uffin•3h ago
Think you might be right, while reading through the README, I noticed some common LLM pattern words.

Also, some sections of the README completely read as generated by an LLM.

compton•3h ago
Well, Firefox and webkit browsers (Safari and friends) are all apparently not affected so it does appear there's something here.
nerdbaggy•3h ago
I can’t think of the wording right now but generally JS trying to crash the browser would say something like this page is taking a long time, do you want to wait. Something like that. In this case the browser just crashes.

It does seem like it’s full of AI. The Attack Scenarios are very suspicious.

kachapopopow•3h ago
This screams AI generated and you can do this in thousands of ways.
porridgeraisin•3h ago
Is it some sort of "hacker" thing to use hexadecimal numbers even in small for loops?

> for (let i = 0x0; i < 0x3; i++) { document.title = t + i; // Each burst performs 3 sequential updates } this.counter += 0x3;

I suppose the thing is AI generated anyways. Oh well

Etheryte•2h ago
This is as much of a DoS as an unterminated while loop is a DoS, is it not?
diath•2h ago
No, when you run something like <script> while(true) {} </script>, it will only freeze the tab where you ran it, the browser UI and other tabs will still be responsible and usable. When you run this DoS, it makes the entire browser unusable, and exhausts your system memory, eventually crashing the entire browser.

Please Support SomaFM

https://somafm.com/support/
1•mkesper•4m ago•0 comments

Rising heat kills one person a minute worldwide, major report reveals

https://www.theguardian.com/environment/2025/oct/29/rising-heat-kills-one-person-a-minute-worldwi...
1•measurablefunc•4m ago•0 comments

Text-Mode Games as First Haskell Projects

http://jackkelly.name/blog/archives/2022/05/28/text-mode_games_as_first_haskell_projects/
1•alabhyajindal•5m ago•0 comments

Show HN: Ü Programming Language

https://github.com/Panzerschrek/U-00DC-Sprache
2•Panzerschrek•7m ago•0 comments

Cellebrite leak highlights how much more secure Pixel phones are with GrapheneOS

https://www.androidauthority.com/cellebrite-leak-google-pixel-grapheneos-security-3611794/
2•jstanley•9m ago•0 comments

You couldn't stop solar from being built if you wanted to

https://bsky.app/profile/solarchase.bsky.social/post/3m3md2uy5jk2v
2•locallost•12m ago•0 comments

Australian influencer family move to UK to avoid social media ban

https://www.bbc.com/news/articles/c8x1ry124eqo
1•aussieguy1234•16m ago•1 comments

Yarn shows progress bar as pumpkins on Halloween

https://github.com/yarnpkg/berry/blob/a592371321068c3d63b0932030ebbdede611610c/packages/yarnpkg-c...
1•trymas•19m ago•1 comments

Cara Menghubungi CS Adakami

1•Perkembangan•19m ago•0 comments

Denmark surprisingly abandons plans for Chat Control

https://www.heise.de/en/news/Denmark-surprisingly-abandons-plans-for-chat-control-10965249.html
1•RonanSoleste•19m ago•1 comments

Per-request isolation in TinyKVM explained

https://fwsgonzo.medium.com/per-request-isolation-in-tinykvm-explained-080e84328ba4
1•ingve•24m ago•0 comments

Anthropic's Pilot Sabotage Risk Report

https://alignment.anthropic.com/2025/sabotage-risk-report/
1•allenleee•26m ago•0 comments

Arrival Time of Tropical-Storm-Force Winds

https://www.nhc.noaa.gov/refresh/graphics_at3+shtml/310543.shtml?mltoa34#contents
1•bariumbitmap•30m ago•0 comments

The Three Christs of Ypsilanti

https://en.wikipedia.org/wiki/The_Three_Christs_of_Ypsilanti
1•thunderbong•36m ago•0 comments

Sam, Jakub, and Wojciech on the future of OpenAI with audience Q&A

https://www.youtube.com/watch?v=ngDCxlZcecw
1•Brysonbw•37m ago•0 comments

The price of mandatory code reviews

https://workweave.dev/blog/the-price-of-mandatory-code-reviews
2•aard•39m ago•0 comments

Academia Lives – On TikTok

https://web.archive.org/web/20200706004410/https://www.nytimes.com/2020/06/30/style/dark-academia...
1•jruohonen•39m ago•0 comments

Cara Menghubungi CS Uatas

1•perkembagan•39m ago•0 comments

Anyone else having AWS STS issues?

3•ahawkins•40m ago•0 comments

Does using LaTex for my resume have any benefits at all?

1•insinteresting•44m ago•2 comments

Hyperlogloglog (2016)

https://carlos.bueno.org/2016/12/hyperlogloglog.html
1•bariumbitmap•49m ago•0 comments

What Nuclear Testing Does to the Earth–and Us

https://nautil.us/heres-what-nuclear-testing-does-to-the-earth-and-us-1245174/
3•billybuckwheat•59m ago•0 comments

Aardvark: OpenAI's agent security researcher

https://openai.com/index/introducing-aardvark/
1•taocp•1h ago•1 comments

aperf: A CLI tool to gather performance data and visualize using HTML graphs

https://github.com/aws/aperf
1•tanelpoder•1h ago•0 comments

Federal judge in Mississippi admits staff used AI to draft inaccurate order

https://apnews.com/article/robert-conrad-chuck-grassley-artificial-intelligence-henry-t-wingate-m...
2•1vuio0pswjnm7•1h ago•0 comments

Market data provider polygon.io rebrands to massive.com

https://massive.com/blog/polygon-is-now-massive
1•rho4•1h ago•0 comments

The Next Era of Social Media Is Coming

https://www.cnn.com/2025/10/11/tech/openai-sora-2-meta-ai-slop-social-media
2•jruohonen•1h ago•1 comments

A Brief History of Terminal Emulators

https://charm.land/blog/intro-to-terminals/
1•allenleee•1h ago•0 comments

Show HN: Anime Last Stand Wiki – The Go-To for Roblox's Anime TD Hit

https://animelaststand.net/
1•aishu001•1h ago•0 comments

RunwayToFlight – Helps founders model startup's runway, breakeven, and funding

https://andiamo.tech/runwaytoflight
1•bmcgoffin•1h ago•0 comments