frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Brookhaven Lab's RHIC Concludes 25-Year Run with Final Collisions

https://www.hpcwire.com/off-the-wire/brookhaven-labs-rhic-concludes-25-year-run-with-final-collis...
1•gnufx•1m ago•0 comments

Transcribe your aunts post cards with Gemini 3 Pro

https://leserli.ch/ocr/
1•nielstron•5m ago•0 comments

.72% Variance Lance

1•mav5431•6m ago•0 comments

ReKindle – web-based operating system designed specifically for E-ink devices

https://rekindle.ink
1•JSLegendDev•7m ago•0 comments

Encrypt It

https://encryptitalready.org/
1•u1hcw9nx•7m ago•1 comments

NextMatch – 5-minute video speed dating to reduce ghosting

https://nextmatchdating.netlify.app/
1•Halinani8•8m ago•1 comments

Personalizing esketamine treatment in TRD and TRBD

https://www.frontiersin.org/articles/10.3389/fpsyt.2025.1736114
1•PaulHoule•10m ago•0 comments

SpaceKit.xyz – a browser‑native VM for decentralized compute

https://spacekit.xyz
1•astorrivera•10m ago•1 comments

NotebookLM: The AI that only learns from you

https://byandrev.dev/en/blog/what-is-notebooklm
1•byandrev•11m ago•1 comments

Show HN: An open-source starter kit for developing with Postgres and ClickHouse

https://github.com/ClickHouse/postgres-clickhouse-stack
1•saisrirampur•11m ago•0 comments

Game Boy Advance d-pad capacitor measurements

https://gekkio.fi/blog/2026/game-boy-advance-d-pad-capacitor-measurements/
1•todsacerdoti•12m ago•0 comments

South Korean crypto firm accidentally sends $44B in bitcoins to users

https://www.reuters.com/world/asia-pacific/crypto-firm-accidentally-sends-44-billion-bitcoins-use...
2•layer8•12m ago•0 comments

Apache Poison Fountain

https://gist.github.com/jwakely/a511a5cab5eb36d088ecd1659fcee1d5
1•atomic128•14m ago•2 comments

Web.whatsapp.com appears to be having issues syncing and sending messages

http://web.whatsapp.com
1•sabujp•15m ago•2 comments

Google in Your Terminal

https://gogcli.sh/
1•johlo•16m ago•0 comments

Shannon: Claude Code for Pen Testing: #1 on Github today

https://github.com/KeygraphHQ/shannon
1•hendler•16m ago•0 comments

Anthropic: Latest Claude model finds more than 500 vulnerabilities

https://www.scworld.com/news/anthropic-latest-claude-model-finds-more-than-500-vulnerabilities
2•Bender•21m ago•0 comments

Brooklyn cemetery plans human composting option, stirring interest and debate

https://www.cbsnews.com/newyork/news/brooklyn-green-wood-cemetery-human-composting/
1•geox•21m ago•0 comments

Why the 'Strivers' Are Right

https://greyenlightenment.com/2026/02/03/the-strivers-were-right-all-along/
1•paulpauper•22m ago•0 comments

Brain Dumps as a Literary Form

https://davegriffith.substack.com/p/brain-dumps-as-a-literary-form
1•gmays•23m ago•0 comments

Agentic Coding and the Problem of Oracles

https://epkconsulting.substack.com/p/agentic-coding-and-the-problem-of
1•qingsworkshop•23m ago•0 comments

Malicious packages for dYdX cryptocurrency exchange empties user wallets

https://arstechnica.com/security/2026/02/malicious-packages-for-dydx-cryptocurrency-exchange-empt...
1•Bender•23m ago•0 comments

Show HN: I built a <400ms latency voice agent that runs on a 4gb vram GTX 1650"

https://github.com/pheonix-delta/axiom-voice-agent
1•shubham-coder•24m ago•0 comments

Penisgate erupts at Olympics; scandal exposes risks of bulking your bulge

https://arstechnica.com/health/2026/02/penisgate-erupts-at-olympics-scandal-exposes-risks-of-bulk...
4•Bender•25m ago•0 comments

Arcan Explained: A browser for different webs

https://arcan-fe.com/2026/01/26/arcan-explained-a-browser-for-different-webs/
1•fanf2•26m ago•0 comments

What did we learn from the AI Village in 2025?

https://theaidigest.org/village/blog/what-we-learned-2025
1•mrkO99•27m ago•0 comments

An open replacement for the IBM 3174 Establishment Controller

https://github.com/lowobservable/oec
1•bri3d•29m ago•0 comments

The P in PGP isn't for pain: encrypting emails in the browser

https://ckardaris.github.io/blog/2026/02/07/encrypted-email.html
2•ckardaris•31m ago•0 comments

Show HN: Mirror Parliament where users vote on top of politicians and draft laws

https://github.com/fokdelafons/lustra
1•fokdelafons•32m ago•1 comments

Ask HN: Opus 4.6 ignoring instructions, how to use 4.5 in Claude Code instead?

1•Chance-Device•33m ago•0 comments
Open in hackernews

GoSign Desktop RCE flaws affecting users in Italy

https://www.ush.it/2025/11/14/multiple-vulnerabilities-gosign-desktop-remote-code-execution/
86•ascii•2mo ago
GoSign is a desktop client used across Italian public administrations and enterprises for qualified electronic signatures, produced by Tinexta InfoCert, one of Europe’s major eIDAS-regulated trust service providers. Researchers found that versions ≤ 2.4.0 disable TLS certificate verification when a proxy is configured and use an unsigned update manifest. Combined, these flaws allow man-in-the-middle attacks and delivery of malicious updates leading to remote code execution.

Comments

gritzko•2mo ago
Paris Cloudflare Error
chasing0entropy•2mo ago
AI scrapes internet from millions of IPs worldwide proving an orchestrated, intelligent, botnet effectually becoming a large percentage of total internet traffic overnight.

Internet responds by retreating to behind a single cloud provider who can mysteriously keep ai at bay... Same provider network is probably responsible for the near instantaneous distribution of AI traffic to begin with.

Internet's last bastion of hope is attacked, rather quickly, and half of the internet is scrambling to remember how to administer DNS (The other half never knew).

agos•2mo ago
Cloudflare was already a thing before AI scrapers
immibis•2mo ago
And they were strongly suspected to DDoS their prospective customers, so they would suddenly have a need to buy DDoS protection.
steelbrain•2mo ago
First I’m hearing of it, got a source?
giancarlostoro•2mo ago
That is a wild claim, got some evidence?
gruez•2mo ago
How does this work given there are many competing DDoS protection providers like Akamai, Azure, or AWS?
amalcon•2mo ago
The claim I think you're referring to is in two parts:

1) They were willing to sell DDoS protection to DDoS services

2) This decision was made specifically because the existence of DDoS services increased the value of their product

This was always a weird claim, because the first part is 100% true -- while the second part was always unfounded speculation. The conclusion is thus most likely false. They just didn't want to incorporate that sort of thing into their ToS or vet their customers in that way, for various understandable reasons.

nullbyte808•2mo ago
what is this "AI" your referring to?
nullbyte808•2mo ago
Bonjour!
VladVladikoff•2mo ago
Cloudflare yet again making the internet a shittier place. I will never understand why so many people willingly allow their website to be MiTM’d by this garbage company.
delichon•2mo ago
Then I suppose you know a better alternative when your site is being effectively DDOSed by a ridiculously high volume of scrapers. Please share.
codingminds•2mo ago
E.g. https://www.fastly.com/

But Cloudflare has the best marketing of all of them ¯\_(ツ)_/¯

ramon156•2mo ago
iirc isn't steam also on fastly? I vaguely remember their stack to either include fastly or they're using fastify. Names...
hofrogs•2mo ago
I think Steam uses akamai, at least for user-generated content
codingminds•2mo ago
Seems to be correct

  store.steampowered.com. 30 IN A 184.31.101.220

  NetRange:       184.24.0.0 - 184.31.255.255
  CIDR:           184.24.0.0/13
  NetName:        AKAMAI
chasing0entropy•2mo ago
There are so many CDNs, they have existed since the internet was just for porn. The problem is they are not as easy to use for today's novice webdev with zero knowledge of how to administer or even research infrastructure beyond the stack specs.
whizzter•2mo ago
I don't think the issue is a skill one but rather giving a sane option.

Going to Akamai's site I don't see a single mention of pricing, I don't want to be smooched by some enterprise salesman to get my pricing options.

Going to Fastly's site I see egress costs that makes me think I could probably be better of just staying on AWS,Azure or smth and have a single bill to care about. (That have their own expensive options).

There's probably other small players with sane options pricing wise, but when it comes to managing DDoS issues people want someone big to handle the bulk.

deaux•2mo ago
LA here.
N19PEDL2•2mo ago
How is this related with the Cloudflare outage? The bug was present in GoSign Desktop <= 2.4.0, so it seems that it was introduced long time ago.
CodesInChaos•2mo ago
I'm a bit confused by the privilege escalation part. Doesn't modifying the settings require the same privileges the application has?
SkiFire13•2mo ago
I suppose the application runs as root (to update the application files) but reads the user settings (which are writable without root priviledges)