frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

South Korean crypto firm accidentally sends $44B in bitcoins to users

https://www.reuters.com/world/asia-pacific/crypto-firm-accidentally-sends-44-billion-bitcoins-use...
1•layer8•1m ago•0 comments

Apache Poison Fountain

https://gist.github.com/jwakely/a511a5cab5eb36d088ecd1659fcee1d5
1•atomic128•3m ago•0 comments

Web.whatsapp.com appears to be having issues syncing and sending messages

http://web.whatsapp.com
1•sabujp•3m ago•1 comments

Google in Your Terminal

https://gogcli.sh/
1•johlo•4m ago•0 comments

Shannon: Claude Code for Pen Testing

https://github.com/KeygraphHQ/shannon
1•hendler•5m ago•0 comments

Anthropic: Latest Claude model finds more than 500 vulnerabilities

https://www.scworld.com/news/anthropic-latest-claude-model-finds-more-than-500-vulnerabilities
1•Bender•9m ago•0 comments

Brooklyn cemetery plans human composting option, stirring interest and debate

https://www.cbsnews.com/newyork/news/brooklyn-green-wood-cemetery-human-composting/
1•geox•9m ago•0 comments

Why the 'Strivers' Are Right

https://greyenlightenment.com/2026/02/03/the-strivers-were-right-all-along/
1•paulpauper•11m ago•0 comments

Brain Dumps as a Literary Form

https://davegriffith.substack.com/p/brain-dumps-as-a-literary-form
1•gmays•11m ago•0 comments

Agentic Coding and the Problem of Oracles

https://epkconsulting.substack.com/p/agentic-coding-and-the-problem-of
1•qingsworkshop•12m ago•0 comments

Malicious packages for dYdX cryptocurrency exchange empties user wallets

https://arstechnica.com/security/2026/02/malicious-packages-for-dydx-cryptocurrency-exchange-empt...
1•Bender•12m ago•0 comments

Show HN: I built a <400ms latency voice agent that runs on a 4gb vram GTX 1650"

https://github.com/pheonix-delta/axiom-voice-agent
1•shubham-coder•12m ago•0 comments

Penisgate erupts at Olympics; scandal exposes risks of bulking your bulge

https://arstechnica.com/health/2026/02/penisgate-erupts-at-olympics-scandal-exposes-risks-of-bulk...
4•Bender•13m ago•0 comments

Arcan Explained: A browser for different webs

https://arcan-fe.com/2026/01/26/arcan-explained-a-browser-for-different-webs/
1•fanf2•15m ago•0 comments

What did we learn from the AI Village in 2025?

https://theaidigest.org/village/blog/what-we-learned-2025
1•mrkO99•15m ago•0 comments

An open replacement for the IBM 3174 Establishment Controller

https://github.com/lowobservable/oec
1•bri3d•17m ago•0 comments

The P in PGP isn't for pain: encrypting emails in the browser

https://ckardaris.github.io/blog/2026/02/07/encrypted-email.html
2•ckardaris•20m ago•0 comments

Show HN: Mirror Parliament where users vote on top of politicians and draft laws

https://github.com/fokdelafons/lustra
1•fokdelafons•20m ago•1 comments

Ask HN: Opus 4.6 ignoring instructions, how to use 4.5 in Claude Code instead?

1•Chance-Device•22m ago•0 comments

We Mourn Our Craft

https://nolanlawson.com/2026/02/07/we-mourn-our-craft/
1•ColinWright•24m ago•0 comments

Jim Fan calls pixels the ultimate motor controller

https://robotsandstartups.substack.com/p/humanoids-platform-urdf-kitchen-nvidias
1•robotlaunch•28m ago•0 comments

Exploring a Modern SMTPE 2110 Broadcast Truck with My Dad

https://www.jeffgeerling.com/blog/2026/exploring-a-modern-smpte-2110-broadcast-truck-with-my-dad/
1•HotGarbage•28m ago•0 comments

AI UX Playground: Real-world examples of AI interaction design

https://www.aiuxplayground.com/
1•javiercr•29m ago•0 comments

The Field Guide to Design Futures

https://designfutures.guide/
1•andyjohnson0•29m ago•0 comments

The Other Leverage in Software and AI

https://tomtunguz.com/the-other-leverage-in-software-and-ai/
1•gmays•31m ago•0 comments

AUR malware scanner written in Rust

https://github.com/Sohimaster/traur
3•sohimaster•33m ago•1 comments

Free FFmpeg API [video]

https://www.youtube.com/watch?v=6RAuSVa4MLI
3•harshalone•33m ago•1 comments

Are AI agents ready for the workplace? A new benchmark raises doubts

https://techcrunch.com/2026/01/22/are-ai-agents-ready-for-the-workplace-a-new-benchmark-raises-do...
2•PaulHoule•38m ago•0 comments

Show HN: AI Watermark and Stego Scanner

https://ulrischa.github.io/AIWatermarkDetector/
1•ulrischa•39m ago•0 comments

Clarity vs. complexity: the invisible work of subtraction

https://www.alexscamp.com/p/clarity-vs-complexity-the-invisible
1•dovhyi•40m ago•0 comments
Open in hackernews

ARIN Public Incident Report – 4.10 Misissuance Error

https://www.arin.net/announcements/20251212/
146•immibis•1mo ago

Comments

gbil•1mo ago
A couple of years ago ARIN increased their fees considerably - way higher than fees paid to RIPE for way less resources - and had a call with their management to express my frustration, not because I was paying from my pocket but because of the high discrepancy of the what they wanted to get and the quantity/quality of their services. Now I can see that their backbone services haven't really improved while their income for sure has.

On a sidenote, what I appreciate in both RIPE and ARIN is that you can have at least a proper discussion when you have valid arguments with their support teams.

rmoriz•1mo ago
Now ARIN is much cheaper than RIPE for small entities.
rmoriz•1mo ago
fee schedules FYI

- ARIN 2026 PDF: https://www.arin.net/resources/fees/images/2026feeschedule.p...

- RIPE 2026 : https://www.ripe.net/membership/payment/

Enthusiasts, trainees and small orgs are paying a lot more with RIPE.

icedchai•1mo ago
Not necessarily. Many have their RIPE registrations through an existing, “sponsoring” LIR. They’re not paying that 1800 Euro, the LIR is.
rmoriz•1mo ago
A single AS resource and a single PI assignment cost more than the ARIN fee.
icedchai•1mo ago
Are you sure? For RIPE I see a 50 ASN plus 75 euro PI fee. ARIN is $275. Maybe I’m looking at it wrong.

It’s cheaper as a hobbyist to use a RIPE LIR. Even in the US. That’s what I’ve been doing for years.

rmoriz•1mo ago
afaik that's +VAT and also for LIRs only. LIRs apply markup, see https://www.lir.services/lir-sponsoring/ they charge 200€ per resource, so ASN + PI would be at last 400€/year that's way above the price of ARIN and you have a middleman.

You must have a sponsoring LIR for your resources or become a LIR yourself. The only exception is LEGACY resources (IPv4, no ASN) but that's a different story.

icedchai•1mo ago
There are more competitive LIRs out there. Example: https://lagrange.cloud/products/lir

It’s also cheaper for me because I have legacy ARIN space. All I really needed was an ASN. The LIR gives me some PA v6 space for cheap, too.

rmoriz•1mo ago
Okay, but that is not enough to operate independently. PA v6 is another dependency. With ARIN you get your personal IPv6 assignment.
icedchai•1mo ago
For a hobbyist, the difference is academic. You can announce PA space with your own ASN, which is what I do. If I change LIRs I’ll have to renumber my IPv6 space.
rmoriz•1mo ago
Companies offering LIR services to hobbyists are probably not going to stay in business forever, as many of them are 1 person companies, too. Also keep in mind that they may change pricing. I understand, that with IPv6 the numbering strategy is almost always automatic and a renumbering can be done in a couple of hours, but it's still an inconvenience, especially when you have to update a lot of AAAA records.

I really think that when you start to operate an AS that you should have a direct RIR membership. And as mentioned above, RIPE has a higher financial entry barrier. I remember they had an object volume based pricing scheme 15 years ago, just like ARIN still has.

icedchai•1mo ago
None of us know what will happen in the future. All I can say is that currently, it is cheaper for a hobbyist to use a RIPE LIR than to use ARIN. If this changes in the future, I'll move to ARIN.

ARIN is lowering their costs gradually. When I first made the RIPE LIR or ARIN decision several years ago, ARIN wanted $500 just to register an ASN, on top of the yearly fees. I see they have removed that requirement.

progbits•1mo ago
I like how frank the report is, no sugarcoating. "We relied on manual error prone verification and made a mistake. We have to automate the process."

As ARIN block owner this situation is kinda scary but reading this actually makes me think it's less likely to happen again .

anonnon•1mo ago
You don't find this part

> We have to automate the process.

to be ominous?

Aurornis•1mo ago
I don’t. The report says part of this process relied on flat files and spreadsheets. Automating that with software is a good idea.

“Automate the process” doesn’t mean feeding everything to an LLM.

aaomidi•1mo ago
Certificate issuance was once only possible manually.
qingcharles•1mo ago
Domains too, well into the 90s.
netfortius•1mo ago
The road to automation is always full of outages.
stefan_•1mo ago
I'm curious how these fellas took something like IP block allocation and turned it into an Excel based workflow.
jonathanlydall•1mo ago
“Workflow” is probably a bit generous to describe how they probably use Excel.

Having worked at a mom and pop ISP a couple of decades ago where we used Excel to track a lot of things, I can see how this might have happened.

To actually know who is allocated what is ultimately just a list.

And when there are only a few people who edit the list (and probably no more than 1 person at a time) you can get by with even a plain text file, but Excel is quite a bit nicer as you can do things like filtering and sorting easily, maybe even some formulas to help with things.

Building a program backed by a database might be nice, but hard to justify when the manual system has never been a problem before.

They’ve probably been thinking for a while they should, but it’s just never been enough of a pain point for them to invest the effort.

Looks like they see this incident as justification that they need a system with hard coded rules and constraints, no more manual checking.

stefan_•1mo ago
It's ARIN, this is essentially their only job
mmooss•1mo ago
The world's financial systems run on Excel, to a great extent.

I'm more surprised that a single person, apparently without seniority, could delete a block. IME deleting user data is usually a significant event; an IP block would especially be a big deal, especially for the IP block issuers. From the OP:

> RSD has implemented additional process controls that require a dual review for all ticketing type workflows that include a network delete.

> Only a limited set of experienced analysts are permitted to perform this function.

Great that they didn't blame the person who deleted it. ARIN seems to have put them in position where a failure was likely, eventually. Without any inside knowledge, I'd hope the culture would have any engineer leary about pressing that button without a second set of eyes reviewing it carefully and without clear authorization; I don't imagine they delete many blocks each day so it shouldn't interfere with productivity.

bigbuppo•1mo ago
They've improved over the decades. At one point the authoritative database was a physical paper notebook.
autoexec•1mo ago
I can't remember a screw up by ARIN this bad before. I'm not too concerned about it. I understand that mistakes can happen. That said, I'm a little surprised at how easy it was to make this one.

I'm entirely unsurprised that this mistake involved an excel spreadsheet. Out of all the databases and IP management software they could be using which would have prevented this the first thing the employee reached for was excel. Almost every company I've worked for has employees using excel for data that would be better managed/stored/presented outside of an office document.

patmorgan23•1mo ago
From the nanog thread it seemed like the IP allocations for the IPv6 transition space (4.10) was the only space using this manual Excel process. That's probably how they initially started managing these allocations with the intention to build it into their automated systems but hadn't gotten around to it. And it sounds like they're prioritizing that work now, and have implemented an additional lay of checks in the mean time.

This is a really big egg on face moment for ARIN, but it sounds like they are responding appropriately.

simonjgreen•1mo ago
All the RIRs are, in my experience, a very consistent and safe set of hands. This sort of things is vanishing rare to the point of borderline inconsequence by many providers of major internet infrastructure. The fact they care enough to take it seriously and publish shows how much they care about getting it right.

I just completed a fairly major reorganisation of resources with RIPE, and I’ve interacted with them for two decades, and my experience is they remain as steady and consistent as ever.

Sure, you may not like a particular policy at some moment, or may not agree with the charging structure at some point in time when it’s not advantageous to you, but they do at least do what they say and say what they do.

mlhpdx•1mo ago
So at least a good chunk of the Internet does indeed operate on a spreadsheet. Good to know.
12_throw_away•1mo ago
All data begins life in a spreadsheet and dies in a spreadsheet. Automation is an illusion; databases are illusions. Only Excel is real.
ang_cire•1mo ago
This reads like a joke, but I've known two DBAs who don't use database management tools beyond exporting whole tables to excel, making manual changes, and importing to update the tables. Scary stuff.
aftbit•1mo ago
I've considered setting up an ASN and grabbing an IPv6 block for myself for a while now, but have never had the gumption, time, and funds at the same time.
galaxygate•1mo ago
Affected customer here, if you're curious on our original NANOG post on the whole situation:

Hey NANOG,

After receiving a BGPAlerter notification that one of our subnets (23.150.164.0/24) had been hijacked, I checked and noticed the prefix in question was missing RPKI. Assuming I had fat fingered something and butchered the ROA, I logged into ARIN and found that the prefix was missing from our resource list entirely, and had been reallocated to another organization and announced from their network. I created a ticket in ARIN and called immediately.

They confirmed that our subnet had been accidentally reallocated to another customer, and that they are currently working on returning it to us. After a couple hours, they told us the other organization will stop announcing the prefix, and WHOIS will be returned shortly.

I’m guessing there’s no way to prevent this kind of thing on our side if the RPKI ROA itself is removed along with the allocation? I’m planning on adding checks to look for missing ROAs (in addition to invalid/expiring ones), which I'm guessing would've caught this earlier.

Have any of you had anything like this happen with ARIN or another RIR? I’m especially curious what might have happened if we’d only noticed and reached out a few weeks later instead of within a few minutes.

Titan2189•1mo ago
The original report says

> The incorrect state persisted for approximately seven days before detection

However you're saying you've reached out "within a few minutes" ?

BlueMatt•1mo ago
It was re-allocated to the new/wrong ARIN customer for seven days before they started announcing it, at which point the OP detected the issue. Prior to that their prefix was routing to them just fine, just without RPKI protection.
teraflop•1mo ago
The "incorrect state" being talked about is the IP prefix being misregistered in ARIN's database.

The "hijacking" happened later, when the IP prefix was announced via BGP by the registrant who it was incorrectly assigned to. Those are two different events.

yoan9224•1mo ago
The transparency in this incident report is refreshing. "We relied on manual Excel-based verification and screwed up" - no corporate speak, just honest assessment.

What's scary is that IPv4 allocations are literally internet infrastructure. Having your /24 suddenly reassigned to someone else could be catastrophic for a business.

The fact that RPKI didn't catch this is interesting. The ROA was deleted along with the allocation, so from RPKI's perspective everything was valid. This is a good reminder that RPKI protects against hijacking but not against the RIR itself making mistakes.

Glad they're automating this. Anything involving copy-pasting IP ranges in Excel is an accident waiting to happen.

squigz•1mo ago
This is a bit beyond my paygrade, but... this is as serious as it sounds, right? I'm just a bit surprised/confused by the response in these comments, especially compared to outages like when CF goes down. It's like that Gordon Ramsay meme. Is ARIN the 8 year old in this situation?