frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

A case study in PDF forensics: The Epstein PDFs

https://pdfa.org/a-case-study-in-pdf-forensics-the-epstein-pdfs/
1•DuffJohnson•30s ago•0 comments

Workday, Best in KLAS for ERP for Large Organizations for Ninth Consecutive Year

https://newsroom.workday.com/2026-02-04-Workday-Named-Best-in-KLAS-for-ERP-for-Large-Organization...
1•salkahfi•55s ago•0 comments

Interactive Git

https://inter-git.com
1•maiwand-atssar•1m ago•0 comments

AT&T, Verizon blocking release of Salt Typhoon security assessment reports

https://www.reuters.com/business/media-telecom/senator-says-att-verizon-blocking-release-salt-typ...
1•toomuchtodo•1m ago•1 comments

Nextcloud improves performance with new data access architecture

https://nextcloud.com/blog/a-new-data-access-architecture-for-nextcloud-introducing-the-ada-engine/
1•v1ktor•1m ago•0 comments

Going back to the physical world

https://josem.co/going-back-to-the-physical-world/
1•josem•2m ago•0 comments

Writing an RSS reader in 80 lines of bash

https://yobibyte.github.io/yr
1•yobibyte•3m ago•0 comments

PostgreSQL for Update Skip Locked: The One-Liner Job Queue

https://www.dbpro.app/blog/postgresql-skip-locked
1•upmostly•3m ago•0 comments

GLP1 adherence lower in the real world

https://blog.healthverity.com/glp-1-persistence-what-semaglutide-data-reveals-about-patient-behavior
1•getpokedagain•5m ago•1 comments

Show HN: I built a tool for the last working days before an employee leaves

https://www.skillpasspro.com
1•Squissy•5m ago•1 comments

Survey: Developers Hate AI, Want Unions, and Are Abandoning Xbox

https://kotaku.com/gdc-2026-survey-ai-union-layoff-xbox-ps5-trump-2000664245
1•PaulHoule•6m ago•0 comments

I Built an Agent to Fix Context Issues

https://johnoct.github.io/blog/2025/08/18/optimizing-claude-context-with-specialized-agent/
1•baby-yoda•6m ago•0 comments

Company that 'resurrected' dire wolf announces biovault for endangered species

https://www.cnn.com/2026/02/04/science/colossal-dire-wolf-biovault-endangered-species-spc
1•aa_is_op•6m ago•0 comments

Moltbook Mania

https://www.nytimes.com/2026/02/04/podcasts/moltbook-mania-explained.html
1•MintyPyro•7m ago•0 comments

Show HN: Fluid.sh – Claude Code for Infrastructure

https://www.fluid.sh/blog/introducing-fluid
1•aspectrr•7m ago•0 comments

Chrome Extension Manager

https://chromewebstore.google.com/detail/extension-manager-extensi/jafcieombbedhpdkjlhcggagepcgaihp
1•kaporalix•7m ago•0 comments

Positron AI Raises $230M Series B at Over $1B Valuation

https://finance.yahoo.com/news/positron-ai-raises-230-million-130000465.html
1•hasheddan•8m ago•0 comments

How Foursquare scrapped engineering manager titles

https://sfstandard.com/2026/02/03/foursquare-scrapped-engineering-manager-titles/
1•boring-human•10m ago•0 comments

Analysis of Careers in and through Intercollegiate Compliance [pdf] (2025)

https://scholarcommons.sc.edu/cgi/viewcontent.cgi?article=1575&context=jiia
1•mooreds•11m ago•0 comments

Senate GOP debates filibuster reform after Trump call to 'nationalize' elections

https://thehill.com/homenews/senate/5721518-trump-republicans-filibuster-reform/
1•SilverElfin•11m ago•0 comments

What a federal lawyer's comments tell us about the Trump admin

https://www.lawdork.com/p/the-system-sucks-or-what-a-federal
1•mooreds•11m ago•0 comments

Show HN: NovaAccess – SSH access to Tailscale tailnet hosts on iOS without VPN

https://apps.apple.com/us/app/novaaccess-tailnet-tools/id6749938291
1•mintflow•12m ago•0 comments

Agent Trace spec for tracking AI-generated code

https://agent-trace.dev/
1•turadg•12m ago•0 comments

Canary nonprofit helps employers fund financial care for employees

https://www.marketplace.org/story/2026/02/03/canary-nonprofit-helps-employers-fund-financial-care...
1•mooreds•12m ago•0 comments

Dow Chemicals to layoff 4,500 Employees in AI Overhaul

https://www.wsj.com/business/earnings/dow-dow-q4-earnings-report-2025-11f0e814
1•nitin_flanker•12m ago•0 comments

Attention at Constant Cost per Token via Symmetry-Aware Taylor Approximation

https://arxiv.org/abs/2602.00294
4•fheinsen•13m ago•0 comments

Understanding UI density and designing for real-world usage

https://www.ruixen.com/blog/ui-density
1•srinath693•13m ago•0 comments

Don't Use Passkey

https://deadcode.rip/temp/dont_use_passkey.html
2•minebreaker•13m ago•0 comments

Nearly 900 Nazi-linked accounts discovered at Credit Suisse

https://www.reuters.com/legal/transactional/hundreds-nazi-linked-accounts-discovered-credit-suiss...
2•wslh•14m ago•0 comments

Show HN: Vopal – AI note taker with no meeting bots (real-time, 98% accurate)

https://vopal.ai/?ly=yc
1•genspeed•15m ago•0 comments
Open in hackernews

I prefer to pass secrets between programs through standard input

https://utcc.utoronto.ca/~cks/space/blog/programming/PassingSecretsViaStdin
35•ingve•1h ago

Comments

kevin_thibedeau•1h ago
> Unfortunately you're using a browser (or client library) that my anti-crawler precautions consider suspicious because it's sending inconsistent values for Sec-CH-UA-* HTTP request headers...

The world doesn't exclusively use Chrome. Nice to see even the nerds are contributing to the closed web.

edwcross•50m ago
I'm using Firefox and didn't see that message.
swiftcoder•47m ago
Nor on Safari. I wonder what exotic browser the parent is using?
ErroneousBosh•46m ago
Doesn't appear to be Firefox, Chrome, Chromium, Edge, or Falkon on Linux, doesn't appear to be Falkon on Haiku.

I also wonder what they're using and where can I get some so I can break stuff too?

guerrilla•25m ago
> Falkon

In case anyone is wondering: https://www.falkon.org/about/

efilife•46m ago
I am on ungoogled chromium and I see this
mhitza•40m ago
Also site is not accessible via Mullvad VPN.
figmert•3m ago
I am on Mullvad (at the router), and I am able to connect.
Alex-Programs•3m ago
It's also moaning about me coming from a datacentre IP (proxy) with some vague complaints about load introduced by AI crawlers. I think this guy treats "protecting" his site as a hobby.
Dwedit•1h ago
I haven't actually tested this, but aren't the input and output handles exposed on /proc/? What's stopping another process from seeing everything?
trashb•41m ago
Yes pipes are exposed /proc/$pid/fd/$thePipeFd with user permissions [0].

Additionally command line parameters are always readable /proc/$YOUR_PROCESS_PID/cmdline [1]

There are workarounds but it's fragile. You may accept the risks and in that case it can work for you but I wouldn't recommend it for "general security". Seems it wouldn't be considered secure if everyone did it this way, therefore is it security through obscurity?

[0] https://unix.stackexchange.com/questions/156859/is-the-data-...

[1] https://stackoverflow.com/questions/3830823/hiding-secret-fr...

Lex-2008•40m ago
not a Linux expert, but I believe that at the very least it's time sensitive: after consumer process reads it, it's gone from the pipe. Unlike env vars and cli argument that stay there.
Tajnymag•38m ago
I guess the kernel is stopping that. I don't think permission wise you'd have the privileges to read someone else's stdin/out.
juancn•47m ago
I used to do that, I had a sort of IDE that launched a local server, bound to localhost.

The launching process would send a random password through stdin to the child after launch, and the child would use that to authenticate the further RPC calls.

It's surprisingly hard to intercept a process' stdin stream.

pvtmert•43m ago
Interesting approach. I like Docker/Kubernetes way of secret mounts where you can limit user/group permissions too.

Meanwhile, I was an avid user of the echo secret | ssh consume approach, specifically for the kerberos authentication.

In my workflow, I saved the kerberos password to the macOS keychain, where kinit --use-keychain authenticated me seamlessly. However this wasn't the case for remote machines.

Therefore, I have implemented a quick script that is essentially

    security find-generic-password -a "kerberos" -s "kerberos-password" -w | ssh user@host kinit user@REALM
Which served me really good for the last 4~years.
stale-labs•40m ago
The main practical win is that cmd args show up in `ps aux` for anyone on the system to see, whereas stdin keeps it off that list.

re: the /proc concerns - true, but if someones got same-user access to read your /proc/pid/fd, they can probably ptrace you or read process memory anyway. stdin is more about basic hygiene than stopping sophisticated attackers.

tbh for anything actually sensitive I've been leaning toward tmpfs files with strict perms, or using something like vault/age. stdin is a nice middle ground tho for quick scripts.

blibble•23m ago
linux has a key api that works pretty well

man keyctl

azornathogron•2m ago
For one of my projects my server needs a private key, and it reads this from a file descriptor on startup and then closes the fd. The fd is set up by the systemd unit, which is also configured to restrict filesystem access for the server. So the server reads a key from a file that is never visible in its mount namespace.