frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Now send your marketing campaigns directly from ChatGPT

https://www.mail-o-mail.com/
1•avallark•2m ago•1 comments

Queueing Theory v2: DORA metrics, queue-of-queues, chi-alpha-beta-sigma notation

https://github.com/joelparkerhenderson/queueing-theory
1•jph•14m ago•0 comments

Show HN: Hibana – choreography-first protocol safety for Rust

https://hibanaworks.dev/
3•o8vm•15m ago•0 comments

Haniri: A live autonomous world where AI agents survive or collapse

https://www.haniri.com
1•donangrey•16m ago•1 comments

GPT-5.3-Codex System Card [pdf]

https://cdn.openai.com/pdf/23eca107-a9b1-4d2c-b156-7deb4fbc697c/GPT-5-3-Codex-System-Card-02.pdf
1•tosh•29m ago•0 comments

Atlas: Manage your database schema as code

https://github.com/ariga/atlas
1•quectophoton•32m ago•0 comments

Geist Pixel

https://vercel.com/blog/introducing-geist-pixel
2•helloplanets•35m ago•0 comments

Show HN: MCP to get latest dependency package and tool versions

https://github.com/MShekow/package-version-check-mcp
1•mshekow•43m ago•0 comments

The better you get at something, the harder it becomes to do

https://seekingtrust.substack.com/p/improving-at-writing-made-me-almost
2•FinnLobsien•44m ago•0 comments

Show HN: WP Float – Archive WordPress blogs to free static hosting

https://wpfloat.netlify.app/
1•zizoulegrande•46m ago•0 comments

Show HN: I Hacked My Family's Meal Planning with an App

https://mealjar.app
1•melvinzammit•46m ago•0 comments

Sony BMG copy protection rootkit scandal

https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootkit_scandal
1•basilikum•49m ago•0 comments

The Future of Systems

https://novlabs.ai/mission/
2•tekbog•49m ago•1 comments

NASA now allowing astronauts to bring their smartphones on space missions

https://twitter.com/NASAAdmin/status/2019259382962307393
2•gbugniot•54m ago•0 comments

Claude Code Is the Inflection Point

https://newsletter.semianalysis.com/p/claude-code-is-the-inflection-point
3•throwaw12•55m ago•1 comments

Show HN: MicroClaw – Agentic AI Assistant for Telegram, Built in Rust

https://github.com/microclaw/microclaw
1•everettjf•55m ago•2 comments

Show HN: Omni-BLAS – 4x faster matrix multiplication via Monte Carlo sampling

https://github.com/AleatorAI/OMNI-BLAS
1•LowSpecEng•56m ago•1 comments

The AI-Ready Software Developer: Conclusion – Same Game, Different Dice

https://codemanship.wordpress.com/2026/01/05/the-ai-ready-software-developer-conclusion-same-game...
1•lifeisstillgood•58m ago•0 comments

AI Agent Automates Google Stock Analysis from Financial Reports

https://pardusai.org/view/54c6646b9e273bbe103b76256a91a7f30da624062a8a6eeb16febfe403efd078
1•JasonHEIN•1h ago•0 comments

Voxtral Realtime 4B Pure C Implementation

https://github.com/antirez/voxtral.c
2•andreabat•1h ago•1 comments

I Was Trapped in Chinese Mafia Crypto Slavery [video]

https://www.youtube.com/watch?v=zOcNaWmmn0A
2•mgh2•1h ago•1 comments

U.S. CBP Reported Employee Arrests (FY2020 – FYTD)

https://www.cbp.gov/newsroom/stats/reported-employee-arrests
1•ludicrousdispla•1h ago•0 comments

Show HN: I built a free UCP checker – see if AI agents can find your store

https://ucphub.ai/ucp-store-check/
2•vladeta•1h ago•1 comments

Show HN: SVGV – A Real-Time Vector Video Format for Budget Hardware

https://github.com/thealidev/VectorVision-SVGV
1•thealidev•1h ago•0 comments

Study of 150 developers shows AI generated code no harder to maintain long term

https://www.youtube.com/watch?v=b9EbCb5A408
2•lifeisstillgood•1h ago•0 comments

Spotify now requires premium accounts for developer mode API access

https://www.neowin.net/news/spotify-now-requires-premium-accounts-for-developer-mode-api-access/
2•bundie•1h ago•0 comments

When Albert Einstein Moved to Princeton

https://twitter.com/Math_files/status/2020017485815456224
1•keepamovin•1h ago•0 comments

Agents.md as a Dark Signal

https://joshmock.com/post/2026-agents-md-as-a-dark-signal/
2•birdculture•1h ago•1 comments

System time, clocks, and their syncing in macOS

https://eclecticlight.co/2025/05/21/system-time-clocks-and-their-syncing-in-macos/
1•fanf2•1h ago•0 comments

McCLIM and 7GUIs – Part 1: The Counter

https://turtleware.eu/posts/McCLIM-and-7GUIs---Part-1-The-Counter.html
3•ramenbytes•1h ago•0 comments
Open in hackernews

Enterprise security can be messy: Building a Security-Aware Culture

2•rezliant•2mo ago
Your executive team gets it. They've approved the budget, they mention security in board meetings, they understand the stakes. You're not fighting for recognition at the top anymore.

But then you look at what's actually happening three levels down. The marketing team is sharing credentials to social media accounts. Sales is pushing back on MFA because it adds seconds to their login process. Developers are storing API keys in public repositories because it's faster than the approved method. Remote employees are working from unsecured networks and don't think twice about it.

The executive commitment is there. The company-wide behavior isn't. And that gap is where breaches happen.

This is the challenge that keeps security leaders up at night. You have the mandate from above, but translating that into thousands of daily decisions made by people who have completely different priorities is a different game entirely.

Comments

necovek•2mo ago
It happens because cybersecurity teams do not design for efficiency and believe that security trumps everything else. If they understood that security, just like anything else, is there to drive the business, they'd perhaps sit down with people doing the work. And then figure out how hard it is to share a simple file or a photo, take it to the print shop as one can't plug in their private USB stick, or how annoying it is to develop Linux IoT firmware on WSL, or how annoying it is to get logged out every 2h.

Because unless you do, people will adopt behaviour that makes them productive, and instead of increasing security, your policies will drive it down.

This is not a result of "bad employees": this is a result of bad security policies.

mrktf•2mo ago
Yes, i couldn't agree more with this. The problem these "bad employees" earns wage by getting results and not entering multiple times mfa codes during day or repeating same logins. And talking from experience: these secure practices starting to approach at least hour of productive time everyday, which is literally robbing time
bdangubic•2mo ago
No security works unless it is enforced and there are severe consequences

> Marketing team sharing credentials

Fireable offense, immediate firing first time this happens, won’t happen again after that, both of person who shared the credentials and person who used the shared credentials

> Sales MFA

Prevent login without it, let them bitch about it for a week

> API keys in repos

Fireable offense not just for commiter but entire team

daemonologist•2mo ago
If you made API keys in the repo a fireable offense for the whole team, people would stop using the repo. There's already a constant problem at my company with people not merging into main/master in order to avoid the overbearing automated security scanning.
bdangubic•2mo ago
with all due respect I am very happy I don’t work where you do or any place where merging to main is a “thing”
tacostakohashi•2mo ago
Well, that's because somewhere between the executive team, which "gets it", and "three levels down"... somewhere between 1 and 2 levels down, there is a team that translates "security" into some compulsory training, scanning internal software/apps/libraries/libraries using crappy automated vendorware, and counterproductive/arbitrary password requirements.

After that, "security" starts to mean "ticking all the boxes to keep the scan happy and stay off the report" (even if the scans are wrong, out of date, littered with false positives, and lacking the ability to find basic problems) and stops having anything to do with actually being secure.

RJ000•2mo ago
"..teams not design..efficiency.."

Enough truth in that.

Need hours back and forth w/the end user, moderately sophisticated UX designers (eg. empathy, anybody?) user education (not mandates) and training, an actually useful help desk, efficient equipment... And real time graduated enforcement that impacts all levels, not just the bottom level perp-scapegoat.

markus_zhang•2mo ago
Gotta meet with each of them and understand how to proceed without impacting efficiency. Security is the most annoying thing in the corporation world so it’s easy to get pushed back.