frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

MongoBleed Explained Simply

https://bigdata.2minutestreaming.com/p/mongobleed-explained-simply
42•todsacerdoti•2h ago

Comments

maxrmk•1h ago
How often are mongo instances exposed to the internet? I'm more of an SQL person and for those I know it's pretty uncommon, but does happen.
wood_spirit•1h ago
The article links to a shodan scan reporting 213K exposed instances https://www.shodan.io/search?query=Product%3A%22MongoDB%22
hahahacorn•1h ago
A highly cited reason for using mongo is that people would rather not figure out a schema. (N=3/3 for “serious” orgs I know using mongo).

That sort of inclination to push off doing the right thing now to save yourself a headache down the line probably overlaps with “let’s just make the db publicly exposed” instead of doing the work of setting up an internal network to save yourself a headache down the line.

TZubiri•30m ago
I would have hoped that there would be no important data in mongoDB.

But now we can at least be rest assured that the important data in mongoDB is just very hard to read with the lack of schemas.

Probably all of that nasty "schema" work and tech debt will finally be done by hackers trying to make use of that information.

petcat•39m ago
From my experience, Mongo DB's entire raison d'etre is "laziness".

* Don't worry about a schema.

* Don't worry about persistence or durability.

* Don't worry about reads or writes.

* Don't worry about connectivity.

This is basically the entire philosophy, so it's not surprising at all that users would also not worry about basic security.

whynotmaybe•32m ago
I'm still thinking about the hypothetical optimism brought by OWASP top 10 hoping that major flaws will be solved and that buffer overflow has been there since the beginning... in 2003.

Show HN: Golazo – Live soccer updates in your terminal

https://github.com/0xjuanma/golazo
1•rocajuanma•29s ago•0 comments

Slaughtering Competition Problems with Quantifier Elimination

https://grossack.site/2021/12/22/qe-competition.html
1•todsacerdoti•58s ago•0 comments

Airlines call in psychologists to stop passengers risking their lives for bags

https://www.telegraph.co.uk/business/2025/12/27/airlines-call-psychologists-passengers-risking-li...
1•elsewhen•1m ago•0 comments

62 years in the making: NYC's newest water tunnel nears the finish line

https://ny1.com/nyc/all-boroughs/news/2025/11/09/water--dep--tunnels-
3•eatonphil•5m ago•0 comments

Show HN: Upload a song and get a finished music video (no editing, no prompts)

https://musicvideogenerator.app/
1•hexadecimal•9m ago•1 comments

Halifax video game workers form first Ubisoft union in North America

https://www.cbc.ca/news/canada/nova-scotia/ubisoft-forms-first-union-north-america-halifax-9.7028674
2•cf100clunk•11m ago•0 comments

Two strangers. A terrorist bomb. An extraordinary tale of courage

https://bungalow-magazine.com/p/the-bench-2f5e
1•rmason•13m ago•0 comments

Show HN: Thingo

https://thingoboard.com
1•jryan49•15m ago•0 comments

As AI gobbles up chips, prices for devices may rise

https://www.npr.org/2025/12/28/nx-s1-5656190/ai-chips-memory-prices-ram
6•geox•18m ago•1 comments

Boost.MultiIndex Refactored

http://bannalia.blogspot.com/2025/12/boostmultiindex-refactored.html
1•ibobev•20m ago•0 comments

Mercury: The planet that shouldn't exist

https://www.bbc.com/future/article/20251223-mercury-the-planet-that-shouldnt-exist
1•1659447091•21m ago•0 comments

Why Your AI Characters Turn To Mush (and how I fixed it)

https://ghostintheweights.substack.com/p/why-your-ai-characters-turn-to-mush
1•llamataboot•23m ago•1 comments

Controlling Blood Sugar Cut Heart Disease Risk in Half, Study Says

https://www.nytimes.com/2025/12/15/well/blood-sugar-heart-disease-risk.html
4•brandonb•24m ago•1 comments

The Detection of Wash Trading

https://rajivsethi.substack.com/p/the-detection-of-wash-trading
5•neehao•27m ago•0 comments

Parsing IP addresses quickly (portably, without SIMD magic)

https://lemire.me/blog/2025/12/27/parsing-ip-addresses-quickly-portably-without-simd-magic/
3•ibobev•30m ago•0 comments

Grasshopper Docs

https://grasshopperdocs.com/
1•downboots•33m ago•0 comments

A Profit-Based Measure of Lending Discrimination

https://arxiv.org/abs/2512.20753
3•neehao•33m ago•0 comments

Doom in Django: testing the limits of LiveView at 600.000 divs/segundo

https://en.andros.dev/blog/7b1b607b/doom-in-django-testing-the-limits-of-liveview-at-600000-divss...
2•ibobev•35m ago•0 comments

What an unprocessed photo looks like

https://maurycyz.com/misc/raw_photo/
9•zdw•36m ago•1 comments

The Internet Is a Net Negative

https://kennethreitz.org/essays/2025-12-28-the_internet_is_a_net_negative
8•zdw•43m ago•6 comments

A metagenome-derived, planetary-scale virome resource with environmental context

https://academic.oup.com/nar/advance-article/doi/10.1093/nar/gkaf1225/8356007?login=false
1•PaulHoule•47m ago•0 comments

Researchers Discover Molecular Difference in Autistic Brains

https://medicine.yale.edu/news-article/molecular-difference-in-autistic-brains/
3•amichail•47m ago•0 comments

An Experiment in Vibe Coding

https://nolanlawson.com/2025/12/28/an-experiment-in-vibe-coding/
1•todsacerdoti•49m ago•0 comments

Show HN: Built a waifu AI generator in 4 hours

https://waifupixel.com
1•smakosh•54m ago•0 comments

Software Ate the World, Skills Will Eat Work

https://gist.github.com/Felo-Sparticle/c8dd67b52c8727277de453c94d62f589
4•jinfeng79•55m ago•2 comments

Julie – an open-source, screen-aware multimodal desktop AI assistant

https://github.com/Luthiraa/julie
1•luthiraabeykoon•55m ago•1 comments

Show HN: Mini-vLLM in ~500 lines of Python

https://github.com/ubermenchh/mini-vllm
1•ubermenchh•58m ago•0 comments

The Asymmetry of Fraud: Why $1.50 "Fullz" Defeat Corporate Security

https://paragraph.com/@info_sec0/hackers-rob-security-reads-the-manual
3•ScottCarrig•1h ago•0 comments

Engineering coffee producing vs. climate change, high demand, speculation

https://english.elpais.com/economy-and-business/2025-12-28/why-the-price-of-coffee-has-skyrockete...
2•dxs•1h ago•0 comments

KDE – Highlights from 2025

https://pointieststick.com/2025/12/28/highlights-from-2025/
2•Lunar5227•1h ago•0 comments