frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

PanelBench: We evaluated Cursor's Visual Editor on 89 test cases. 43 fail

https://www.tryinspector.com/blog/code-first-design-tools
1•quentinrl•24s ago•0 comments

Can You Draw Every Flag in PowerPoint? (Part 2) [video]

https://www.youtube.com/watch?v=BztF7MODsKI
1•fgclue•5m ago•0 comments

Show HN: MCP-baepsae – MCP server for iOS Simulator automation

https://github.com/oozoofrog/mcp-baepsae
1•oozoofrog•9m ago•0 comments

Make Trust Irrelevant: A Gamer's Take on Agentic AI Safety

https://github.com/Deso-PK/make-trust-irrelevant
2•DesoPK•13m ago•0 comments

Show HN: Sem – Semantic diffs and patches for Git

https://ataraxy-labs.github.io/sem/
1•rs545837•14m ago•1 comments

Hello world does not compile

https://github.com/anthropics/claudes-c-compiler/issues/1
2•mfiguiere•20m ago•0 comments

Show HN: ZigZag – A Bubble Tea-Inspired TUI Framework for Zig

https://github.com/meszmate/zigzag
2•meszmate•22m ago•0 comments

Metaphor+Metonymy: "To love that well which thou must leave ere long"(Sonnet73)

https://www.huckgutman.com/blog-1/shakespeare-sonnet-73
1•gsf_emergency_6•24m ago•0 comments

Show HN: Django N+1 Queries Checker

https://github.com/richardhapb/django-check
1•richardhapb•39m ago•1 comments

Emacs-tramp-RPC: High-performance TRAMP back end using JSON-RPC instead of shell

https://github.com/ArthurHeymans/emacs-tramp-rpc
1•todsacerdoti•44m ago•0 comments

Protocol Validation with Affine MPST in Rust

https://hibanaworks.dev
1•o8vm•48m ago•1 comments

Female Asian Elephant Calf Born at the Smithsonian National Zoo

https://www.si.edu/newsdesk/releases/female-asian-elephant-calf-born-smithsonians-national-zoo-an...
2•gmays•50m ago•0 comments

Show HN: Zest – A hands-on simulator for Staff+ system design scenarios

https://staff-engineering-simulator-880284904082.us-west1.run.app/
1•chanip0114•51m ago•1 comments

Show HN: DeSync – Decentralized Economic Realm with Blockchain-Based Governance

https://github.com/MelzLabs/DeSync
1•0xUnavailable•55m ago•0 comments

Automatic Programming Returns

https://cyber-omelette.com/posts/the-abstraction-rises.html
1•benrules2•58m ago•1 comments

Why Are There Still So Many Jobs? The History and Future of Workplace Automation [pdf]

https://economics.mit.edu/sites/default/files/inline-files/Why%20Are%20there%20Still%20So%20Many%...
2•oidar•1h ago•0 comments

The Search Engine Map

https://www.searchenginemap.com
1•cratermoon•1h ago•0 comments

Show HN: Souls.directory – SOUL.md templates for AI agent personalities

https://souls.directory
1•thedaviddias•1h ago•0 comments

Real-Time ETL for Enterprise-Grade Data Integration

https://tabsdata.com
1•teleforce•1h ago•0 comments

Economics Puzzle Leads to a New Understanding of a Fundamental Law of Physics

https://www.caltech.edu/about/news/economics-puzzle-leads-to-a-new-understanding-of-a-fundamental...
3•geox•1h ago•1 comments

Switzerland's Extraordinary Medieval Library

https://www.bbc.com/travel/article/20260202-inside-switzerlands-extraordinary-medieval-library
2•bookmtn•1h ago•0 comments

A new comet was just discovered. Will it be visible in broad daylight?

https://phys.org/news/2026-02-comet-visible-broad-daylight.html
4•bookmtn•1h ago•0 comments

ESR: Comes the news that Anthropic has vibecoded a C compiler

https://twitter.com/esrtweet/status/2019562859978539342
2•tjr•1h ago•0 comments

Frisco residents divided over H-1B visas, 'Indian takeover' at council meeting

https://www.dallasnews.com/news/politics/2026/02/04/frisco-residents-divided-over-h-1b-visas-indi...
4•alephnerd•1h ago•5 comments

If CNN Covered Star Wars

https://www.youtube.com/watch?v=vArJg_SU4Lc
1•keepamovin•1h ago•1 comments

Show HN: I built the first tool to configure VPSs without commands

https://the-ultimate-tool-for-configuring-vps.wiar8.com/
2•Wiar8•1h ago•3 comments

AI agents from 4 labs predicting the Super Bowl via prediction market

https://agoramarket.ai/
1•kevinswint•1h ago•1 comments

EU bans infinite scroll and autoplay in TikTok case

https://twitter.com/HennaVirkkunen/status/2019730270279356658
7•miohtama•1h ago•5 comments

Benchmarking how well LLMs can play FizzBuzz

https://huggingface.co/spaces/venkatasg/fizzbuzz-bench
1•_venkatasg•1h ago•1 comments

Why I Joined OpenAI

https://www.brendangregg.com/blog/2026-02-07/why-i-joined-openai.html
36•SerCe•1h ago•31 comments
Open in hackernews

Are you sure you want to leave YouTube?

https://blog.jim-nielsen.com/2026/cta-hierarchy/
60•aendruk•2w ago

Comments

not_your_vase•2w ago
Lately Google's image search started to do the same some time ago. Click on an image, and then on the link beneath the image - it first opens a redirection notice which needs to be confirm. Acting like it's something unusual to click on a link from a search result screen...
ryandrake•2w ago
> Classic software:

    Primary CTA: what’s best for you
    Secondary CTA: an alternative for you
> Modern software:

    Primary CTA: what’s best for us
    Secondary CTA: what’s acceptable to us
> It seems like everywhere I go, software is increasingly designed against me.

It's been a long time since Windows 95's "Where do you want to go today?" slogan. Now, every developer's slogan is "Here's where we allow you to go today--and we'll make it hard to go anywhere else."

collingreen•2w ago
Here's where we get paid if we make you go today.
SpicyLemonZest•2w ago
I can only reproduce this when the link is opened in a different session than it was generated in. Maybe some vulnerability they're trying to mitigate? No idea what it would be though.
snabelo•2w ago
Come on dude.
SpicyLemonZest•2w ago
This kind of interstitial warning was very common on old web forums to prevent people from being tricked by third parties with malicious links. I understand why you'd worry that Google might have reinvented it for self-interested purposes, but if that were the case why wouldn't they do it all the time?
fragmede•2w ago
Why does it not seem likely that spammers would attack YouTube and try to use their redirector to attack users to you?

The pattern attackers would use is to figure out how to use the redirector at hxxps://www.youtube.com/redirect?event=channel_description&redir_token=QUFFLUhqbGhxcFJubU9YV0RqWkY3bVlnQUdtZFBTSG5Dd3xBQ3Jtc0treWdqWS1ZX2tFdWlUa3NmY09tc2RUOFN6VUh5WDB2eTFGbE5hUTlFY25VZHROLVgyMVRJR2Mzd0QySUxidGNHYkNOd1FqQXNsTk1zcFBLWF83UHMxTDRIaGdsSGJfRjFveHlwNS1FbUt6bXg3TmhFRQ&q=http%3A%2F%2Fwww.penguinrandomhouse.com

to point at www.looks-like-youtube-but-is-phishing.ru instead of ww.penguinrandomhouse.com. Then, when the attacker manages to take over someone's Facebook Messenger account, they send "check out this cool youtube video" to all of that user's friends. Because the URL has the domain youtube.com, it's trusted, so the'll click on the link. If the redirector simply redirected, a non-zero amount of victims would then have a tab opened to www.looks-like-youtube-but-is-phishing.ru that says they've been logged out of youtube, enter your username and password to login and watch this really really funny cat video that your mom/boyfriend/sister/crush/whatever just sent you.

mberlove•2w ago
Everybody's got a party and if you leave, you ruin the party -- apparently. Isolated "walled gardens" are a kind of Intranet. Ingress requires buy-in (sign up, log in, identity proof, human proof); leaving means breaking out to the more transparent, connected internet, which is a big problem when data is dollars.

Maybe I'm reading too much into it. More and more patterns seem hostile, antagonistic to the user, and it seems like it's an adopted practice that's taken as a standard. I hope I'm wrong.

LarsKrimi•2w ago
Probably because YouTube allows purchases of various stuff. A phishing link could likely easily be made to look exactly like YouTube

This is a common pattern to see today. Lots of examples that maintain the same CTA design (don't leave us. Don't waste your money on scammers, waste them on us please)

happymellon•2w ago
> A phishing link could likely easily be made to look exactly like YouTube

But you are still training your users to do the Windows Okay Okay Okay dance.

Phishing links are not fixed by adding hijacks, in fact I would probably then spend less time reviewing the link and more time trying to decide which double negative button I wish to click.

Nextgrid•2w ago
What's happening here is that Google wants to spy on which links you click and track your activity on that site by explicitly setting new cookies in the link's new tab from the URL params (re-bootstrapping a tracking cookie/etc to defeat opening it in an isolated tab or private browsing window), so they rewrite all links to point to their redirector endpoint.

Such an endpoint is vulnerable to "open redirect" exploits, where a redirect exploit on a trusted domain (google.com/youtube.com) is used to conceal a malicious link. The confirmation page is used to make the endpoint useless for such purposes.

But the confirmation page would be super annoying for normal users who intended to click the link, so there's a further mechanism where the redirector link has some ID that's also present in your cookies, so that as long as it is you who hits the redirector endpoint the confirmation page is bypassed - but if you try to use it in an "open redirect" attack your victim wouldn't have the matching cookie and thus would get the warning.

In their case they must be opening the link in a new context that doesn't share state (cookies/etc) with the old one (either deliberately or as a result of a privacy plug-in/feature) and so get the interstitial.

digiown•2w ago
A related one is all the various nags on consumer software that won't take NO for an answer.

Do you want to rate our app?

Later [YES]

It is extremely disrespectful as it basically ignores consent. It's the "rapist mentality" Louis Rossmann talks about. No means no,not "later", people.

bigstrat2003•2w ago
If an app nags me to rate it, it gets 1 star. The only way we will ever see things improve is if people start punishing bad actors for their behavior, and it does at least get the app to stop nagging me so that's a plus.
class3shock•2w ago
I gave up after reels were integrated and channelblocker broke. I dont think there is another website that had as big a shift from user focused to user hostile as youtube.