frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Apple security bounties slashed as Mac malware grows

https://9to5mac.com/2025/12/02/apple-security-bounties-slashed-as-mac-malware-grows/
3•latexr•36m ago

Comments

bediger4000•19m ago
We're finally seeing a natural experiment validation of the Market Share Theory of Malware. That is, Windows has a huge, almost unbelievable, share of malware because Windows also has the largest by far market share.
lapcat•34s ago
Despite multiple security update credits from Apple (and perhaps at least one more forthcoming), I've received exactly $0 in bounties from Apple. The reasons:

1. Some reports were prior to the existence of the security bounty program.

2. Sometimes I was not the first person to report a vulnerability, and the program pays only the first reporter, even when there are multiple reports prior to the fix.

3. Apple has a tendency just to sit on reports without addressing them, sometimes for years, and I finally get sick of that crap and publish my findings, which of course makes me ineligible for a bounty. This gives me the feeling that the main purpose of the program is to keep people quiet for a long as possible, with a (possible, eventual) payment dangled as incentive for your silence.

Ultimately I gave up completely on the security bounty program and decided not to bother even to look for vulnerabilities anymore.

My feeling has been for a long time that macOS TCC is security theater, a joke, that causes great difficulty for honest developers but otherwise does not significantly impede malware. Moreover, TCC is simply a bad fit for the Mac, tacked onto an OS not designed for TCC, long after the fact. The number of TCC bypasses is practically endless, as proven by practically endless number of fixes listed in Apple's security update release notes. I can imagine that patient (willing to wait on Apple) Mac security researchers like Csaba Fitzl have made a fortune on TCC bypasses, and you can see his name countless times in the aforementioned release notes.

Twinning: A Simple Jailbreak That Bypasses AI Image Protections

https://anthonymattas.com/articles/twinning-a-simple-jailbreak-that-bypasses-ai-image-protections
1•cloudripper•35s ago•0 comments

Amazon Nova 2 family of models

https://aws.amazon.com/blogs/aws/introducing-amazon-nova-2-lite-a-fast-cost-effective-reasoning-m...
1•sainyam•39s ago•0 comments

I open sourced my AI Research platform after long time of development

1•introlix•58s ago•0 comments

Deep dive into the grounding of 6000 Airbus Planes

https://yvesremmler.substack.com/p/the-airbus-a320-elac-emergency
1•yvesr•1m ago•0 comments

AWS Announces Database Savings Plans for AWS Databases

https://aws.amazon.com/blogs/aws/introducing-database-savings-plans-for-aws-databases/
1•eclo•1m ago•0 comments

I Ported the Web to the Web

https://developer.puter.com/blog/how-I-ported-the-web-to-the-web/
1•coolelectronics•2m ago•0 comments

The Legal Case Against Ring's Face Recognition Feature

https://www.eff.org/deeplinks/2025/11/legal-case-against-rings-face-recognition-feature
1•thinkingemote•3m ago•0 comments

Show HN: Systemdesigner.net – a free interactive system-design learning platform

https://www.systemdesigner.net/
1•alibad•4m ago•0 comments

Asteroid Bennu has all the ingredients for life as we know it

https://www.newscientist.com/article/2506650-asteroid-bennu-carries-all-the-ingredients-for-life-...
1•darth_avocado•5m ago•0 comments

London Internet Exchange had an outage today, why?

1•gbil•5m ago•0 comments

Helldivers 2 cuts its install size from ~154GB to ~23GB

https://store.steampowered.com/news/app/553850/view/491583942944621371
2•HelloUsername•6m ago•0 comments

Southern Annular Mode in most positive state in 1k years

https://phys.org/news/2025-12-southern-annular-mode-positive-state.html
1•bikenaga•7m ago•0 comments

Every Major City as a Tiny Miniature World

https://www.adithyan.io/blog/world-cities-ai
1•adithyan_win•7m ago•0 comments

Tell HN: Neon Inc is billing free users now for $20 subscriptions

2•leetcodewhore•7m ago•0 comments

Amazon removes controversial AI anime dubs

https://animecorner.me/amazon-removes-controversial-ai-english-dubs-for-banana-fish-no-game-no-li...
1•jsheard•7m ago•0 comments

Finger Shadows in Compose

https://www.romainguy.dev/posts/2025/finger-shadows/
1•ibobev•8m ago•0 comments

4.3M Browsers Infected: Inside ShadyPanda's 7-Year Malware Campaign

https://www.koi.ai/blog/4-million-browsers-infected-inside-shadypanda-7-year-malware-campaign
2•janpio•9m ago•0 comments

Replacing a complex Postgres and Memcached and Kafka back end with Rama

https://blog.redplanetlabs.com/2025/12/02/rama-in-five-minutes/
1•nathanmarz•10m ago•0 comments

Removed Rust to Gain Speed

https://www.prisma.io/blog/announcing-prisma-orm-7-0-0
1•2233•11m ago•0 comments

CJEU Ruling may invalidate DSA protections for platfroms

https://bsky.app/profile/daphnek.bsky.social/post/3m6zcavc4y22s
1•jim-greer•11m ago•0 comments

Show HN: I built an automated AI lab that generates and publishes inventions

https://unpatentable.org/innovation/
1•Archivist_Vale•12m ago•6 comments

Show HN: I built an open-source Rust/TS AI agent runtime with a Next.js-style DX

https://docs.trysoma.ai
1•solsol94•14m ago•1 comments

Show HN: PoG – the only open-source, live, privacy-first AI provenance system

https://github.com/TamTunnel/PoG
1•pp10•14m ago•0 comments

3D-printed cornea restores sight in a legally blind patient

https://newatlas.com/medical/3d-printed-cornea-restores-sight-first-time/
1•geox•15m ago•0 comments

Cursor AI for E2E Testing (Vs Claude vs. Autonoma)

https://www.getautonoma.com/blog/cursor-ai-e2e-testing-comparison
1•tomaspiaggio12•15m ago•0 comments

Attention Got So Efficient [GQA/MLA/DSA] [video]

https://www.youtube.com/watch?v=Y-o545eYjXM
1•sameersegal•15m ago•0 comments

Peter Thiel's Apocalyptic Worldview Is a Dangerous Fantasy

https://jacobin.com/2025/11/peter-thiel-palantir-apocalypse-antichrist
25•robtherobber•16m ago•0 comments

Roundabouts in Keene Help Cut Emissions and Air Pollution

https://www.nytimes.com/2025/10/21/climate/roundabout-auto-emissions-new-hampshire.html
1•pavel_lishin•17m ago•0 comments

All I Want for Christmas Is the Right Aspect Ratio

https://perladvent.org/2025/2025-12-02.html
2•oalders•19m ago•1 comments

Processing 99% of U.S. Caselaw for Under $1

https://www.daft.ai/blog/processing-99-of-us-caselaw-for-under-1-in-the-common-pile
1•ykev•19m ago•0 comments