frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Show HN: MCP to get latest dependency package and tool versions

https://github.com/MShekow/package-version-check-mcp
1•mshekow•2m ago•0 comments

The better you get at something, the harder it becomes to do

https://seekingtrust.substack.com/p/improving-at-writing-made-me-almost
2•FinnLobsien•4m ago•0 comments

Show HN: WP Float – Archive WordPress blogs to free static hosting

https://wpfloat.netlify.app/
1•zizoulegrande•5m ago•0 comments

Show HN: I Hacked My Family's Meal Planning with an App

https://mealjar.app
1•melvinzammit•5m ago•0 comments

Sony BMG copy protection rootkit scandal

https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootkit_scandal
1•basilikum•8m ago•0 comments

The Future of Systems

https://novlabs.ai/mission/
2•tekbog•9m ago•1 comments

NASA now allowing astronauts to bring their smartphones on space missions

https://twitter.com/NASAAdmin/status/2019259382962307393
2•gbugniot•13m ago•0 comments

Claude Code Is the Inflection Point

https://newsletter.semianalysis.com/p/claude-code-is-the-inflection-point
3•throwaw12•15m ago•1 comments

Show HN: MicroClaw – Agentic AI Assistant for Telegram, Built in Rust

https://github.com/microclaw/microclaw
1•everettjf•15m ago•2 comments

Show HN: Omni-BLAS – 4x faster matrix multiplication via Monte Carlo sampling

https://github.com/AleatorAI/OMNI-BLAS
1•LowSpecEng•16m ago•1 comments

The AI-Ready Software Developer: Conclusion – Same Game, Different Dice

https://codemanship.wordpress.com/2026/01/05/the-ai-ready-software-developer-conclusion-same-game...
1•lifeisstillgood•18m ago•0 comments

AI Agent Automates Google Stock Analysis from Financial Reports

https://pardusai.org/view/54c6646b9e273bbe103b76256a91a7f30da624062a8a6eeb16febfe403efd078
1•JasonHEIN•21m ago•0 comments

Voxtral Realtime 4B Pure C Implementation

https://github.com/antirez/voxtral.c
2•andreabat•23m ago•1 comments

I Was Trapped in Chinese Mafia Crypto Slavery [video]

https://www.youtube.com/watch?v=zOcNaWmmn0A
2•mgh2•30m ago•0 comments

U.S. CBP Reported Employee Arrests (FY2020 – FYTD)

https://www.cbp.gov/newsroom/stats/reported-employee-arrests
1•ludicrousdispla•31m ago•0 comments

Show HN: I built a free UCP checker – see if AI agents can find your store

https://ucphub.ai/ucp-store-check/
2•vladeta•36m ago•1 comments

Show HN: SVGV – A Real-Time Vector Video Format for Budget Hardware

https://github.com/thealidev/VectorVision-SVGV
1•thealidev•38m ago•0 comments

Study of 150 developers shows AI generated code no harder to maintain long term

https://www.youtube.com/watch?v=b9EbCb5A408
1•lifeisstillgood•38m ago•0 comments

Spotify now requires premium accounts for developer mode API access

https://www.neowin.net/news/spotify-now-requires-premium-accounts-for-developer-mode-api-access/
1•bundie•41m ago•0 comments

When Albert Einstein Moved to Princeton

https://twitter.com/Math_files/status/2020017485815456224
1•keepamovin•43m ago•0 comments

Agents.md as a Dark Signal

https://joshmock.com/post/2026-agents-md-as-a-dark-signal/
2•birdculture•44m ago•0 comments

System time, clocks, and their syncing in macOS

https://eclecticlight.co/2025/05/21/system-time-clocks-and-their-syncing-in-macos/
1•fanf2•46m ago•0 comments

McCLIM and 7GUIs – Part 1: The Counter

https://turtleware.eu/posts/McCLIM-and-7GUIs---Part-1-The-Counter.html
2•ramenbytes•48m ago•0 comments

So whats the next word, then? Almost-no-math intro to transformer models

https://matthias-kainer.de/blog/posts/so-whats-the-next-word-then-/
1•oesimania•50m ago•0 comments

Ed Zitron: The Hater's Guide to Microsoft

https://bsky.app/profile/edzitron.com/post/3me7ibeym2c2n
2•vintagedave•53m ago•1 comments

UK infants ill after drinking contaminated baby formula of Nestle and Danone

https://www.bbc.com/news/articles/c931rxnwn3lo
1•__natty__•53m ago•0 comments

Show HN: Android-based audio player for seniors – Homer Audio Player

https://homeraudioplayer.app
3•cinusek•54m ago•2 comments

Starter Template for Ory Kratos

https://github.com/Samuelk0nrad/docker-ory
1•samuel_0xK•55m ago•0 comments

LLMs are powerful, but enterprises are deterministic by nature

2•prateekdalal•59m ago•0 comments

Make your iPad 3 a touchscreen for your computer

https://github.com/lemonjesus/ipad-touch-screen
2•0y•1h ago•1 comments
Open in hackernews

North Korean infiltrator caught at Amazon due to 110ms keystroke lag

https://www.tomshardware.com/tech-industry/cyber-security/north-korean-infiltrator-caught-working-in-amazon-it-department-thanks-to-lag-110ms-keystroke-input-raises-red-flags-over-true-location
80•bns•1mo ago

Comments

belter•1mo ago
A employee of an Amazon contractor...

Article is clear as mud, and its sourcing Bloomberg, on who has sketchy reputation on this type of stories.

wmf•1mo ago
I'm not sure how keypress delay is measured but the rest sounds entirely consistent with the documented MO of North Korean hackers.
ivraatiems•1mo ago
The Arizona woman the article refers to was sentenced to 102 months in prison for her role in this scheme: https://www.justice.gov/opa/pr/arizona-woman-sentenced-17m-i...

Pretty fascinating stuff.

channeleaton•1mo ago
I’ve come across two of these in the last few years of running interviews.

All you have to do is ask about where they live and what they like about it. One, when asked about living in a dead-flat suburb of Houston, said he liked the mountains.

vablings•1mo ago
Easy workaround, AI & LLMS can generate you a random area you live and a simple profile from the perspective of people

What do you like about New Jersey?

"I like New Jersey for its proximity to NYC and Philadelphia, the huge variety of food (from diners to boardwalk pizza), and the great beaches and boardwalks like Asbury Park and Cape May."[1]

[1]: gpt5-mini on duck duck ai chat

the_biot•1mo ago
When you work for Amazon, your computer is monitored to the point they check your keyboard typing speed. Dystopian doesn't even begin to describe it.
chatmasta•1mo ago
According to the article (and therefore Amazon, so take it with a grain of salt), they’ve “foiled more than 1,800 DPRK infiltration attempts since April 2024.”

Company laptops are company property, and employees are warned prominently about the privacy implications of this. Endpoint security is the most critical protection against insider threats, which are the highest leverage attack vectors. One bad actor inside your infrastructure can do untold damage to company finances, reputation, trade secrets, etc. Add to this the sensitive data Amazon processes on behalf of clients, and protecting against these threats becomes necessary for survival.

Also, this detection method doesn’t require full key logging. It just requires measuring the latency between some sample of keystrokes and receiving them on the server. It could be implemented in JavaScript on the login page. In fact it’s actually a clever technique that could be used for VPN detection by normal websites… in the case of Amazon it’s probably more complicated since the “client” may be behind a KVM/VNC server, but the same concept works.

farbklang•1mo ago
I fail to understand how you can measure keystroke latency coming from a KVM. Everything behind the KVM is invisible to you, assuming that it is spoofing a legitimate logitech dongle and emulating a legitimate screen edid.

The KVM uses buffering and queues the keystrokes. So the net time between them is the same as if I would type them locally.

What you could measure is the fingerprint of USB initialization and enumeration of keyboard, mouse etc when connecting and starting up.

vablings•1mo ago
It's actually the buffering in this case that will get you dinged. The stated 110ms "lag" is probably the minimum time between keystrokes ever. If you have ever recorded data on the mean time between keystrokes you get a nice even distribution but for someone on a KVM it will look very skewed with most being under 110ms and zero below 110ms which is impossible for a normal human at a machine to replicate

Furthermore, there are a number of other side channel attacks here you could use to make things really inconvenient. Something super powerful would-be having a fido2 key such as a YubiKey and recording the mean time to human press keypress. Your average person who is present at the machine will touch the button in a number of seconds. A remote operator in NK will have to summon the homeowner which could take significantly longer.

Another technique you could use is look at the mouse movement data. You would also see the same truncated. distribution, I think a few people have put together a PoC for detecting cheaters in games based on mouse movements.

I do wonder also if the KVM devices they are using support HDCP. Showing media over HDCP on the screen that instructs the user to write an email or make a phone call instantly would be pretty cool.

inglor_cz•1mo ago
This is a dystopian consequence of an already dystopian fact that "you" might be a bot or someone completely different from what "you" purport to be.

In such a world, impersonation becomes too easy. It would be nigh impossible in the "all back to office" scenario, but people don't like that scenario either.

hulitu•1mo ago
And you have to pee in a bottle. Good luck if you have to do nr. 2.
keyle•1mo ago
Mind boggling. But well done Amazon.

So if I'm reading this right, all the NK perpetrators have to do "next time", is to have a local remote-desktop as a proxy?

deafpolygon•1mo ago
This is kind of dystopian if you think about it — they’re collecting all kinds of data from their workers. They probably can clock you in and out of your bathroom breaks automagically at some point soon.
wh_123•1mo ago
True, something Microsoft wants to do with teams data.
PaulHoule•1mo ago
Reminds me of the Michael Crichton "Mousetrap" story which was published at the top of the Wargames craze:

https://codegolf.stackexchange.com/questions/41417/michael-c...

wh_123•1mo ago
This is a side channel defense.
burnt-resistor•1mo ago
Amazon doesn't care that it hired malnourished slaves in sanctioned countries or that warehouse workers are subjected to extreme screening procedures and lack of accommodations to universal biology that lead to urination in bottles in the US and UK, they only care that it makes them lose profits from boycott blowback from bad PR.