frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

The Hazardous Interface: SQL Injection Is a Protocol Defect (2026) [pdf]

https://github.com/opoka-research/the-hazardous-interface/blob/main/The%20Hazardous%20Interface%20%E2%80%94%20Opoka.pdf
3•opoka•1h ago

Comments

opoka•1h ago
Hi HN. We analyzed 1,374 CVEs across MySQL, PostgreSQL, MariaDB, MongoDB, and SQLite.

Key findings:

- Interface Hazards (design-transferred risks) outnumber Implementation Defects 3:1 - 79% of SQL injection occurs downstream of the database engine - ORMs—built specifically to fix this—still fail at 88%

The formal proof (Section 1.1) shows string concatenation is non-composable with parsing. Injection isn't a bug to patch; it's a mathematical property of the interface.

Section 1.2 makes the comparison to W^X: operating systems enforce code/data separation at the hardware level. Databases violate it at the application level. We regressed.

Full methodology is auditable via API. Data and code in the repo.

Happy to answer questions.

fiedzia•1h ago
> ORMs—built specifically to fix this—still fail at 88%

How so? The only way to do anything dangerous using any orm I've used was when I needed to do something orm doesn't support and I had to extend it, operating at a text layer (custom db syntax or non-standard sql extension). 99% of sql users wouldn't event know how to get there.

Show HN: Shelvy Books

https://shelvybooks.com
1•tekkie00•7m ago•0 comments

Declassifying JUMPSEAT: an American pioneer in space

https://www.nro.gov/news-media-featured-stories/news-media-archive/News-Article/Article/4392223/d...
1•mkmk•9m ago•1 comments

Video of man believed to be Alex Pretti with feds 11 days before his death [video]

https://www.youtube.com/watch?v=7q12M7iHUTI
5•Bender•11m ago•0 comments

When and why agent systems work

https://research.google/blog/towards-a-science-of-scaling-agent-systems-when-and-why-agent-system...
1•The_Gray•12m ago•0 comments

BGP Vortex: Update Message Floods Can Create Internet Instabilities [video]

https://www.youtube.com/watch?v=dd6L1mdQLmk
1•maltalex•13m ago•0 comments

Semiconductors will see an end of history (eventually)

https://splittinginfinity.substack.com/p/semiconductors-will-see-an-end-of
1•paulpauper•14m ago•0 comments

Parall v2.0: A New Era of macOS Dock Customization Begins

https://parall.app/
1•IGHOR•18m ago•1 comments

Show HN: A linear-time approach to P vs. NP via Information Noise Subtraction

https://zenodo.org/records/18188972
1•alemonti06•20m ago•1 comments

The AI bubble doesn't *require* AI

1•cadabrabra•20m ago•0 comments

IonQ Acquires Seed Innovations to Make Quantum Computing Act Like Software

https://www.siliconsnark.com/ionq-acquires-seed-innovations-to-make-quantum-computing-act-like-so...
1•SaaSasaurus•22m ago•0 comments

Poll: Trump voters support military intervention in more countries

https://www.politico.com/news/2026/01/28/trump-is-threatening-strike-iran-his-supporters-wouldnt-...
3•JumpCrisscross•23m ago•1 comments

Signs god is saying soon

https://applygodsword.com/3-signs-god-is-saying-soon/
1•marysminefnuf•23m ago•0 comments

It's incredible. It's terrifying. It's MoltBot

https://1password.com/blog/its-moltbot
1•duck•23m ago•0 comments

Death of an Indian Tech Worker

https://restofworld.org/2026/india-tech-workers-crisis-suicide/
4•adrianwaj•24m ago•0 comments

US Company Ubiquiti Aids Russian Military [video]

https://www.youtube.com/watch?v=8KyMY9i__Ks
4•tacheiordache•25m ago•0 comments

Show HN: Lexiso – Authorization layer for AI agents that spend money

1•Deonnroberts•25m ago•0 comments

Show HN: Vietnam Elections (open, source-linked datasets and site)

https://bamboo-filing-cabinet.github.io/vietnam-elections/
1•vietthan•25m ago•0 comments

Coding agents are a new infrastructure primitive

https://www.mesa.dev/blog/coding-agents-are-infra
1•remolacha•25m ago•0 comments

Fork and Make

https://github.com/gabrilend/ai-stuff
1•meldowin•26m ago•1 comments

Show HN: Ignite – Run Firecracker Micro-VMs with a Docker-Like CLI (Rust)

https://github.com/Subeshrock/micro-vm-ecosystem
1•Subesh•28m ago•1 comments

The Artificial Man

https://jack-bradshaw.com/journal/item/the-artificial-man/
1•jackbradshaw•30m ago•0 comments

Ask HN: Feature request: include the second path segment for GitHub URLs

3•rbalicki•35m ago•1 comments

LLMs sabotage existing programming practices by privatizing a public good

https://michiel.buddingh.eu/enclosure-feedback-loop
2•encyclopedism•37m ago•0 comments

Show HN: Fast, private image compression in the browser using WASM

https://img-compress.pages.dev/
1•sethyl•38m ago•1 comments

Web inventor Tim Berners-Lee says he is in a battle for the soul of the internet

https://www.theguardian.com/technology/2026/jan/29/internet-inventor-tim-berners-lee-interview-ba...
6•emptybits•39m ago•2 comments

Open Gaming Collective – Unified gaming-focused components for Linux ecosystem

https://opengamingcollective.org/
4•embedding-shape•40m ago•0 comments

Genesis Designed a Body-on-Frame Truck for the US

https://www.thedrive.com/news/genesis-designed-a-body-on-frame-truck-for-the-us
1•PaulHoule•40m ago•0 comments

Kamaji: Containerized Control Planes for K8s

https://kamaji.clastix.io/
1•asaiacai•41m ago•0 comments

Maybe code was never the point

https://subintp.substack.com/p/maybe-code-was-never-the-point
2•datafloyd•42m ago•0 comments

AlphaGenome

https://github.com/google-deepmind/alphagenome_research
1•logannyeMD•45m ago•0 comments