frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Story of XZ Backdoor [video]

https://www.youtube.com/watch?v=aoag03mSuXQ
36•Ulf950•1h ago

Comments

forinti•1h ago
Ireland recently created a Basic Income scheme for artists.

Europe should have an equivalent scheme for programmers of important Open Source projects such as this one.

anarazel•1h ago
Just German, not European, but still a start: https://en.wikipedia.org/wiki/Sovereign_Tech_Agency
mc32•28m ago
The problem was more than remuneration. It was burnout and mental health issues. They may have been moderated by income but we don’t know.

Also today as I understand it much of OSS is done in-house by major companies (red hat, Ubuntu, ibm, Google, etc)

coldpie•1h ago
This is IMO one of the coolest tech stories to ever happen, seriously amazing spycraft & hacking skills, but I haven't been keeping up with new developments from this story since it broke. Last I heard, the best guess at what happened was some state-sponsored actor worked very hard to get this merged, and it was caught luckily at the last minute. But no one had any smoking gun as to who did it or why or who they were targeting. Any new developments since then? Are we still just totally in the dark about what was going on here?
nerevarthelame•52m ago
Still no smoking gun, but possibly Russia. From the video https://youtu.be/aoag03mSuXQ?t=2883:

> A lot of the aliases, like Jia Tan, they sound like Asian names, and the published changes are all timestamped in UTC+8, Beijing time. So the signs point to China. And that's why it's probably not China. I mean, why would they make it that obvious? Every other part of the operation has been so meticulous, so cautious.

> And they also worked on Chinese New Year, but not on Christmas. And over the years, there were nine changes that fall outside of the Beijing time into UTC+2, which is a time zone that includes Israel and parts of Western Russia. That's why some experts have speculated that this could be the work of APT29, a Russian-state-backed hacker group also known as Cozy Bear. But again, do we know? No, of course we don't know who it is, and we likely will never know.

gosub100•28m ago
Russians don't celebrate Christmas on the 25th.
mc32•25m ago
Those anecdotes don’t mean anything. If I were China and wanted plausible deniability I would work on CNY and take off on foreign holidays. Of course that leaves Beijing time as a weird oversight though it’s always Beijing time anywhere in China.
mbauman•50m ago
I'm still floored that Andres both found this and didn't ignore it. It's such a testament to an incredible engineer.

(But also, my conspiratorially-inclined mind is quite entertained by the thought of some sort of parallel construction or tip from a TLA.)

Linux Heterogeneous Memory Management (HMM)

https://www.kernel.org/doc/html/latest/mm/hmm.html
1•teleforce•31s ago•0 comments

CVE-2026-2006 – PostgreSQL Out-of-cycle release

https://wiki.postgresql.org/wiki/2026-02_Regression_Fixes
1•krembo•43s ago•0 comments

I don't need AI to build me a new app. I need it to make Jira bearable

1•niel_hu•47s ago•0 comments

Show HN: Cifer, zero-key custody using threshold cryptography

https://cifer-security.com
1•mikflex•1m ago•0 comments

British Citizenship Applications by US Nationals Hit Record High

https://www.bloomberg.com/news/articles/2026-02-26/british-citizenship-applications-by-us-nationa...
1•helsinkiandrew•1m ago•0 comments

A New Era of Databases: Lakebase

https://www.databricks.com/blog/what-is-a-lakebase
1•mastabadtomm•2m ago•0 comments

Show HN: NotBuiltYet– Open-source library of civilisation problems worth solving

https://shivankar-madaan.github.io/notbuiltyet/
2•mrxlimitless•2m ago•0 comments

Show HN: Ryvos – Autonomous AI assistant in Rust(15MB RAM,50 tools,16 providers)

https://ryvos.dev
1•aayush-mishraaa•3m ago•0 comments

Nano Banana 2: Google's latest AI image generation model

https://blog.google/innovation-and-ai/technology/ai/nano-banana-2/
4•davidbarker•3m ago•1 comments

EHR API Explorer

https://explorer.usecobalt.com/
1•bryanmillstein•3m ago•1 comments

Matrix Inverse Roots with Fixed-Budget GEMM Kernels

https://jiha-kim.github.io/posts/fast-matrix-inverse-roots/
1•ibobev•4m ago•0 comments

Partial Truth vs. Explicit Failure: Designing Honest System Responses

https://www.sandordargo.com/blog/2026/02/25/partial-truth-vs-explicit-failure
1•ibobev•4m ago•0 comments

Memory or mood? Probiotic capsules and powders may affect the brain differently

https://medicalxpress.com/news/2026-02-memory-mood-probiotic-capsules-powders.html
1•PaulHoule•5m ago•0 comments

Linux Foundation's report reveals contributing to open source offers a 2x-5x ROI

https://thenewstack.io/roi-open-source-contribution/
1•CrankyBear•5m ago•0 comments

Speculations Concerning the First Ultraintelligent Machine (1964) [pdf]

https://languagelog.ldc.upenn.edu/myl/Good1964.pdf
1•ZeljkoS•5m ago•0 comments

Rule of Three (Computer Programming)

https://en.wikipedia.org/wiki/Rule_of_three_(computer_programming)
2•thunderbong•6m ago•0 comments

Introduction to Data-Centric Query Compilation

https://duckul.us/blog/data-centric-query-compilation
1•duckulus•6m ago•1 comments

I started a software research company

https://notes.eatonphil.com/2026-02-25-i-started-a-company.html
1•ibobev•7m ago•0 comments

Show HN: I built a minimal distributed tracer from scratch to understand better

https://github.com/td-02/tracelm
1•taeshdas•8m ago•1 comments

Show HN: Gonzales – Self-hosted internet speed monitor with Home Assistant

https://github.com/akustikrausch/gonzales
1•janiskl93•8m ago•0 comments

Nano Banana 2

https://deepmind.google/models/gemini-image/flash/
6•meetpateltech•9m ago•2 comments

New AirSnitch attack breaks Wi-Fi encryption in homes, offices, and enterprises

https://arstechnica.com/security/2026/02/new-airsnitch-attack-breaks-wi-fi-encryption-in-homes-of...
3•DamnInteresting•9m ago•0 comments

My computer got self-hacked because of OpenClaw

https://substack.com/home/post/p-189184829
4•iliaishacked•9m ago•0 comments

Show HN: I'm building TaskWeave, a task orchestrator

https://github.com/spicyPoke/TaskWeave
2•spicypoke•9m ago•0 comments

Did predictability scale better than openness on the web?

https://borisljevar.substack.com/p/once-upon-a-time-the-internet-promised
1•blnlx•11m ago•1 comments

Show HN: BetterDB Cloud – monitor Valkey/Redis in VPCs with a lightweight agent

2•kaliades•11m ago•0 comments

Show HN: Nano banana 2 is coming to nanabanana2.run

https://nanabanana2.run
1•funnycoding•11m ago•0 comments

Why Developers Keep Choosing Claude over Every Other AI

https://www.bhusalmanish.com.np/blog/posts/why-claude-wins-coding.html
2•gmays•12m ago•0 comments

Formal Methods for Rust Unsafe

https://antithesis.com/blog/2026/rust_formal_methods/
1•wwilson•12m ago•0 comments

Show HN: AgentSecrets – Zero-Knowledge Credential Proxy for AI Agents

https://github.com/The-17/agentsecrets
2•steppacodes•15m ago•1 comments