frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Show HN: Mermaid Formatter – CLI and library to auto-format Mermaid diagrams

https://github.com/chenyanchen/mermaid-formatter
1•astm•15m ago•0 comments

RFCs vs. READMEs: The Evolution of Protocols

https://h3manth.com/scribe/rfcs-vs-readmes/
2•init0•22m ago•1 comments

Kanchipuram Saris and Thinking Machines

https://altermag.com/articles/kanchipuram-saris-and-thinking-machines
1•trojanalert•22m ago•0 comments

Chinese chemical supplier causes global baby formula recall

https://www.reuters.com/business/healthcare-pharmaceuticals/nestle-widens-french-infant-formula-r...
1•fkdk•25m ago•0 comments

I've used AI to write 100% of my code for a year as an engineer

https://old.reddit.com/r/ClaudeCode/comments/1qxvobt/ive_used_ai_to_write_100_of_my_code_for_1_ye...
1•ukuina•27m ago•1 comments

Looking for 4 Autistic Co-Founders for AI Startup (Equity-Based)

1•au-ai-aisl•37m ago•1 comments

AI-native capabilities, a new API Catalog, and updated plans and pricing

https://blog.postman.com/new-capabilities-march-2026/
1•thunderbong•38m ago•0 comments

What changed in tech from 2010 to 2020?

https://www.tedsanders.com/what-changed-in-tech-from-2010-to-2020/
2•endorphine•43m ago•0 comments

From Human Ergonomics to Agent Ergonomics

https://wesmckinney.com/blog/agent-ergonomics/
1•Anon84•46m ago•0 comments

Advanced Inertial Reference Sphere

https://en.wikipedia.org/wiki/Advanced_Inertial_Reference_Sphere
1•cyanf•48m ago•0 comments

Toyota Developing a Console-Grade, Open-Source Game Engine with Flutter and Dart

https://www.phoronix.com/news/Fluorite-Toyota-Game-Engine
1•computer23•50m ago•0 comments

Typing for Love or Money: The Hidden Labor Behind Modern Literary Masterpieces

https://publicdomainreview.org/essay/typing-for-love-or-money/
1•prismatic•51m ago•0 comments

Show HN: A longitudinal health record built from fragmented medical data

https://myaether.live
1•takmak007•53m ago•0 comments

CoreWeave's $30B Bet on GPU Market Infrastructure

https://davefriedman.substack.com/p/coreweaves-30-billion-bet-on-gpu
1•gmays•1h ago•0 comments

Creating and Hosting a Static Website on Cloudflare for Free

https://benjaminsmallwood.com/blog/creating-and-hosting-a-static-website-on-cloudflare-for-free/
1•bensmallwood•1h ago•1 comments

"The Stanford scam proves America is becoming a nation of grifters"

https://www.thetimes.com/us/news-today/article/students-stanford-grifters-ivy-league-w2g5z768z
3•cwwc•1h ago•0 comments

Elon Musk on Space GPUs, AI, Optimus, and His Manufacturing Method

https://cheekypint.substack.com/p/elon-musk-on-space-gpus-ai-optimus
2•simonebrunozzi•1h ago•0 comments

X (Twitter) is back with a new X API Pay-Per-Use model

https://developer.x.com/
3•eeko_systems•1h ago•0 comments

Zlob.h 100% POSIX and glibc compatible globbing lib that is faste and better

https://github.com/dmtrKovalenko/zlob
3•neogoose•1h ago•1 comments

Show HN: Deterministic signal triangulation using a fixed .72% variance constant

https://github.com/mabrucker85-prog/Project_Lance_Core
2•mav5431•1h ago•1 comments

Scientists Discover Levitating Time Crystals You Can Hold, Defy Newton’s 3rd Law

https://phys.org/news/2026-02-scientists-levitating-crystals.html
3•sizzle•1h ago•0 comments

When Michelangelo Met Titian

https://www.wsj.com/arts-culture/books/michelangelo-titian-review-the-renaissances-odd-couple-e34...
1•keiferski•1h ago•0 comments

Solving NYT Pips with DLX

https://github.com/DonoG/NYTPips4Processing
1•impossiblecode•1h ago•1 comments

Baldur's Gate to be turned into TV series – without the game's developers

https://www.bbc.com/news/articles/c24g457y534o
3•vunderba•1h ago•0 comments

Interview with 'Just use a VPS' bro (OpenClaw version) [video]

https://www.youtube.com/watch?v=40SnEd1RWUU
2•dangtony98•1h ago•0 comments

EchoJEPA: Latent Predictive Foundation Model for Echocardiography

https://github.com/bowang-lab/EchoJEPA
1•euvin•1h ago•0 comments

Disablling Go Telemetry

https://go.dev/doc/telemetry
2•1vuio0pswjnm7•1h ago•0 comments

Effective Nihilism

https://www.effectivenihilism.org/
1•abetusk•1h ago•1 comments

The UK government didn't want you to see this report on ecosystem collapse

https://www.theguardian.com/commentisfree/2026/jan/27/uk-government-report-ecosystem-collapse-foi...
5•pabs3•1h ago•0 comments

No 10 blocks report on impact of rainforest collapse on food prices

https://www.thetimes.com/uk/environment/article/no-10-blocks-report-on-impact-of-rainforest-colla...
3•pabs3•1h ago•0 comments
Open in hackernews

Ask HN: Would you trust a new browser security extension in 2025?

4•linklock•2w ago
I'm considering building a privacy-first browser security extension and want to validate the idea with HN's community before committing months to it.

The hypothesis: Current browser security is fragmented. You need multiple extensions (uBlock, Privacy Badger, HTTPS Everywhere) plus something for phishing protection. Most all-in-one options are bloated (Norton, Avira) or have privacy concerns.

What I'm considering: - Zero data collection (no accounts, no telemetry) - Open-source (MIT license) - Phishing detection (local + Safe Browsing API) - HTTPS enforcement - Cookie auto-delete - Pop-up blocking

Questions for HN:

1. Is there actually a gap here? Or is the current extension ecosystem already perfect?

2. What would make you trust a NEW security extension in 2025? Open source alone doesn't seem sufficient - there are sketchy OS extensions too.

3. Would you ever pay for browser security ($3-5/month)? Or should everything be donation-supported?

4. Is Manifest V3's limitations (30k rules, webRequest restrictions) a dealbreaker even for security-focused extensions?

I put together a survey to gather structured feedback: https://forms.gle/CrxiWDFM23wvHT7g9

But honestly more interested in the discussion here. Talk me out of this if it's a bad idea.

Comments

ghostwords•2w ago
>You need multiple extensions

(I develop Privacy Badger.) There are significant benefits to adding PB or uBO to a browser that doesn't already ship with a real built-in ad blocker. While PB and uBO work well together and you may want to use both for various reasons, I wouldn't say you need both. Either one is enough by itself for most people.

>HTTPS Everywhere

HTTPS Everywhere has been deprecated and eventually removed from extension stores a few years ago: https://www.eff.org/deeplinks/2021/09/https-actually-everywh...

>Phishing detection

Why isn't what's built into browsers enough?

>Cookie auto-delete

Why bother when blocking trackers and ads?

>Pop-up blocking

Is that the same as the various "annoyances" ad blocker lists?

linklock•2w ago
First off, thank you for everything you do with Privacy Badger—it's been a staple in my browser for years. I really appreciate you taking the time to poke holes in this.

You’re absolutely right about HTTPS Everywhere; that was a oversight in my initial write-up. Since it's now integrated into the major browsers, that’s one less 'fragment' to worry about.

To answer your questions on the 'why' behind the other features:

Phishing detection: The main gap I see with built-in Safe Browsing is the telemetry. Most users don't realize that 'Enhanced Protection' often means sending URLs/metadata back to a central server. I’m exploring a local-first approach (using bloom filters or highly optimized local sets) to keep that check entirely on-device.

Cookie auto-delete: While Total Cookie Protection (Firefox) is great, many browsers still only clear data 'on exit.' For users who keep their browser open for weeks, I see value in 'active' cleaning (e.g., clearing site data 15 minutes after a tab is closed) to minimize the session-tracking window.

The 'All-in-one' goal: My hypothesis is actually driven by the fingerprinting concern you've likely seen discussed. Using uBO + PB + a cookie manager creates a very unique extension fingerprint. I'm wondering if a single, consolidated open-source tool could actually help a user 'blend in' better than a stack of three different ones.

I’m still in the 'talking myself out of it' phase, so this technical pushback is exactly what I was hoping for. Thank you again ghostwords!

ghostwords•2w ago
With my cookie question I meant, what's the point of managing cookies if you already do a good job of blocking trackers?

Re fingerprint, similar question: why does this matter if you do a good job of blocking common trackers that perform fingerprinting?

JohnFen•2w ago
> What would make you trust a NEW security extension in 2025?

Time. I wouldn't trust it while it's new. I'd develop trust in it over time as I've observed the results of other people using and examining it.

> Would you ever pay for browser security ($3-5/month)?

I don't rent software, so I wouldn't pay a recurring fee. A one-time fee isn't out of the question, though.

> Is Manifest V3's limitations (30k rules, webRequest restrictions) a dealbreaker even for security-focused extensions?

Pretty much, in that I wouldn't be using a browser with that limitation in the first place.

linklock•2w ago
"Thanks for the honest feedback—this is exactly the kind of 'cold water' I need to make sure I’m not building in a bubble.

On the trust point: You’re 100% right. Trust is the one thing you can’t 'feature-complete' your way into. My goal is to use things like reproducible builds and eventually a third-party audit to bridge that gap, but I recognize that for many, there is no substitute for a proven track record over years.

Regarding subscriptions: I hear you. The 'subscription fatigue' is real, especially for utilities. I’m strongly considering a 'pay-once' model or a 'donation-supported' version for individuals to avoid that 'software rental' feeling.

And on Manifest V3: I share your frustration. It’s a major reason why I’m prioritizing a Firefox-first (and potentially a Brave-optimized) version where those restrictions aren't as crippling as they are in the standard Chrome implementation.

I really appreciate you taking the time to share these perspectives—it helps me refine the roadmap before I write too much code."

0xmattf•2w ago
Yikes. Is ChatGPT also building the extension for you?
hulitu•2w ago
> I'm considering building a privacy-first browser security extension

> What I'm considering: - Zero data collection

...

> Phishing detection (local + Safe Browsing API)

Please, find the contradiction

canhdien_15•2w ago
If you’ve already chosen your path, why come here asking for permission? Is it a lack of confidence, or are you waiting for a miracle? Don’t turn yourself into the man in the fable who carried his donkey just because others told him to. It’s your idea. If you think it’s a waste, then stop. Everything worth doing requires risk. If you’re looking for a 100% guarantee, go back to sleep.
entuno•2w ago
Trust is a about the author, not the code.

Open source is a bare minimum, although even that's not worth as much given how much harder it is now to load extensions that you've compiled yourself.

But those features you're talking about sound like they need extensive privileges within the browser. And while your extension might do what it says today, what's stopping you sticking a load of malware and adverts in there tomorrow? Or selling it to someone else who does?

If the author is an established person whose been known for years to develop good quality extensions and not sell out, then that gives some assurance. If it's an organisation like the EFF, even better?

But a random anonymous person making their first extension? No chance.

runjake•2w ago
Why not build it for yourself first? Post updates about it on a platform like X or another community you enjoy, and gather adventurous testers to provide feedback and help you iterate and maybe even their own pull requests?