frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

GPT-5.3-Codex System Card [pdf]

https://cdn.openai.com/pdf/23eca107-a9b1-4d2c-b156-7deb4fbc697c/GPT-5-3-Codex-System-Card-02.pdf
1•tosh•5m ago•0 comments

Atlas: Manage your database schema as code

https://github.com/ariga/atlas
1•quectophoton•8m ago•0 comments

Geist Pixel

https://vercel.com/blog/introducing-geist-pixel
1•helloplanets•10m ago•0 comments

Show HN: MCP to get latest dependency package and tool versions

https://github.com/MShekow/package-version-check-mcp
1•mshekow•18m ago•0 comments

The better you get at something, the harder it becomes to do

https://seekingtrust.substack.com/p/improving-at-writing-made-me-almost
2•FinnLobsien•20m ago•0 comments

Show HN: WP Float – Archive WordPress blogs to free static hosting

https://wpfloat.netlify.app/
1•zizoulegrande•21m ago•0 comments

Show HN: I Hacked My Family's Meal Planning with an App

https://mealjar.app
1•melvinzammit•21m ago•0 comments

Sony BMG copy protection rootkit scandal

https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootkit_scandal
1•basilikum•24m ago•0 comments

The Future of Systems

https://novlabs.ai/mission/
2•tekbog•25m ago•1 comments

NASA now allowing astronauts to bring their smartphones on space missions

https://twitter.com/NASAAdmin/status/2019259382962307393
2•gbugniot•29m ago•0 comments

Claude Code Is the Inflection Point

https://newsletter.semianalysis.com/p/claude-code-is-the-inflection-point
3•throwaw12•31m ago•1 comments

Show HN: MicroClaw – Agentic AI Assistant for Telegram, Built in Rust

https://github.com/microclaw/microclaw
1•everettjf•31m ago•2 comments

Show HN: Omni-BLAS – 4x faster matrix multiplication via Monte Carlo sampling

https://github.com/AleatorAI/OMNI-BLAS
1•LowSpecEng•32m ago•1 comments

The AI-Ready Software Developer: Conclusion – Same Game, Different Dice

https://codemanship.wordpress.com/2026/01/05/the-ai-ready-software-developer-conclusion-same-game...
1•lifeisstillgood•34m ago•0 comments

AI Agent Automates Google Stock Analysis from Financial Reports

https://pardusai.org/view/54c6646b9e273bbe103b76256a91a7f30da624062a8a6eeb16febfe403efd078
1•JasonHEIN•37m ago•0 comments

Voxtral Realtime 4B Pure C Implementation

https://github.com/antirez/voxtral.c
2•andreabat•39m ago•1 comments

I Was Trapped in Chinese Mafia Crypto Slavery [video]

https://www.youtube.com/watch?v=zOcNaWmmn0A
2•mgh2•46m ago•0 comments

U.S. CBP Reported Employee Arrests (FY2020 – FYTD)

https://www.cbp.gov/newsroom/stats/reported-employee-arrests
1•ludicrousdispla•47m ago•0 comments

Show HN: I built a free UCP checker – see if AI agents can find your store

https://ucphub.ai/ucp-store-check/
2•vladeta•53m ago•1 comments

Show HN: SVGV – A Real-Time Vector Video Format for Budget Hardware

https://github.com/thealidev/VectorVision-SVGV
1•thealidev•54m ago•0 comments

Study of 150 developers shows AI generated code no harder to maintain long term

https://www.youtube.com/watch?v=b9EbCb5A408
1•lifeisstillgood•54m ago•0 comments

Spotify now requires premium accounts for developer mode API access

https://www.neowin.net/news/spotify-now-requires-premium-accounts-for-developer-mode-api-access/
1•bundie•57m ago•0 comments

When Albert Einstein Moved to Princeton

https://twitter.com/Math_files/status/2020017485815456224
1•keepamovin•59m ago•0 comments

Agents.md as a Dark Signal

https://joshmock.com/post/2026-agents-md-as-a-dark-signal/
2•birdculture•1h ago•0 comments

System time, clocks, and their syncing in macOS

https://eclecticlight.co/2025/05/21/system-time-clocks-and-their-syncing-in-macos/
1•fanf2•1h ago•0 comments

McCLIM and 7GUIs – Part 1: The Counter

https://turtleware.eu/posts/McCLIM-and-7GUIs---Part-1-The-Counter.html
2•ramenbytes•1h ago•0 comments

So whats the next word, then? Almost-no-math intro to transformer models

https://matthias-kainer.de/blog/posts/so-whats-the-next-word-then-/
1•oesimania•1h ago•0 comments

Ed Zitron: The Hater's Guide to Microsoft

https://bsky.app/profile/edzitron.com/post/3me7ibeym2c2n
2•vintagedave•1h ago•1 comments

UK infants ill after drinking contaminated baby formula of Nestle and Danone

https://www.bbc.com/news/articles/c931rxnwn3lo
1•__natty__•1h ago•0 comments

Show HN: Android-based audio player for seniors – Homer Audio Player

https://homeraudioplayer.app
3•cinusek•1h ago•2 comments
Open in hackernews

Show HN: TypoGuard – A typosquatting monitoring engine with automated reporting

https://typoguard.io/
1•robinbaertschi•1w ago

Comments

robinbaertschi•1w ago
Hi HN,

I’m the creator of TypoGuard. I built this specialized engine to help protect brands against typosquatting and phishing domains before they are used in active attacks.

The Core Logic: Unlike basic permutation tools, TypoGuard uses a multi-factor risk scoring system (High Risk >= 8 points). The scoring is based on:

Domain Metadata: Real-time WHOIS age (domains ≤ 30 days are flagged), MX record presence, and SSL status.

Advanced Permutations: Beyond character swaps, the engine handles Phonetic & Vowel swaps, Dictionary Affixing, and TLD variants.

Homoglyph Detection: Identifying Unicode lookalikes (IDN).

Wildcard DNS Shield: To avoid noise, I implemented logic to detect and filter out parking pages that resolve every random subdomain.

Infrastructure & Automation: The system is designed for passive monitoring rather than just manual lookups:

Backend: Built with FastAPI and PostgreSQL.

Asynchronous Processing: I use Celery with Redis to handle the heavy lifting of scanning thousands of domain permutations.

Automated Reporting: A Celery Beat scheduler manages periodic scans and generates automated email reports. You don't need to manually check the dashboard; the system alerts you only when a high-risk threat is detected.

Deployment: The entire stack is containerized with Docker Compose, running behind an Nginx reverse proxy.

Why not open-source? The project is currently a closed SaaS as I’m focusing on the Phase 3 roadmap, which includes a Public REST API and enterprise SIEM integrations (Splunk/Sentinel). However, I’m very open to discussing the underlying algorithms, the risk scoring weights, or the infrastructure challenges.

I'd love to get your feedback on the scanning logic or the reporting workflow!

Thanks!

alcazar•1w ago
I think this is great idea.

I generated a report for my website and it showed up the domain itself (the true correct one I own and verified) 3 times as a medium risk. It should not be reporting the domain itself as typosquatting and it should be avoiding duplicates.

The onboarding itself could be smoother if I had less options when I sign up. I just want to check the tool by adding a domain (it could default to my email domain) and generating a report (a report should autogenerate when I add a domain, or at least have a button to quickly do that instead of needing to change tab).

When adding a domain, I shouldn't need to verify it if I signed up with an email @thatdomain already.

It was not obvious to me whether the page would refresh automatically or I would receive an email (I did) when the scan would finish. It would be great if the page told me that and also how long will the scan take on average.

This is all honest feedback that I hope helps you. Good luck!

robinbaertschi•1w ago
Thanks so much for the detailed feedback! This is incredibly helpful for our roadmap. I want to address your point about the "duplicates" first, because it’s actually a perfect example of why this tool is necessary.

It’s not your domain—it’s a "Homograph" Take a very close look at the characters in those "Medium" risk rows. While they look identical to your domain, they are actually using Internationalized Domain Names (IDN).

The tool isn't reporting your own domain; it's reporting spoofed versions that use Greek or Cyrillic characters (like a "c" that is actually a Greek "с").

alℭazarseℭ[.]com alcazarseℭ[.]com alℭazarsec[.]com

Why it matters: Phishers use these because they are visually indistinguishable from your real site in a browser address bar. The fact that you thought they were your own site proves exactly why you need to monitor them!

Improving the Onboarding You’re 100% right on the friction points. We’re taking your notes to heart:

Auto-Generation: We agree. Adding a domain should trigger an immediate scan without navigating away.

Smart Defaults: Defaulting to the email domain for the first scan is a great "quick start" idea.

Trust-based Verification: If you’ve verified your email @company.com, we should absolutely fast-track the verification for company.com.

Status Transparency: We’ll add a "Time to Completion" estimate and a clearer "We will email you" notification so you aren't left staring at a static page.

Thank you for the honest feedback—it’s exactly what we need to make this more than just a security tool, but a great user experience.