frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

I Found 39 Algolia Admin Keys Exposed Across Open Source Documentation Sites

https://benzimmermann.dev/blog/algolia-docsearch-admin-keys
59•kernelrocks•1h ago

Comments

toomuchtodo•1h ago
Great write up. Reminder that if you commit these to a Github Gist and the provider partners with GitHub for secrets scanning, they’ll rapidly be invalidated.
pwdisswordfishy•1h ago
That's just a tautology.

"If the secrets issuer partners with X-corp for secret scanning so that secrets get invalidated when you X them, then when you X them the secrets will be invalidated".

The above is a true statement for all X.

nightpool•1h ago
? Yes? Toomuchtodo is reminding the author (and other commenters), that github gists are one way to make sure secrets are secured / remediated before making a public post like this. Maybe not the most responsible whitehat action, but I can see it being useful in some cases where outreach is impractical / has failed.

Unfortunately, it doesn't look like Algolia has implemented this

TurdF3rguson•25m ago
I'm not following this at all. It seems like OP is saying if you share a secret in your (private?) gist and give Algolia permission to read the gist, they will invalidate it. But why would the secret be in a gist and not a repo? Also if you're aware enough to add that partner it seems you're aware to not do dumb things like that in the first place.
richbell•18m ago
If you find an exposed token in the wild, for a service supported by GitHub Secret Scanning, uploading it to a Gist will either immediately revoke it or notify the owner.
wat10000•1h ago
English is not formal logic.

In formal logic, that statement is true whether X is GitHub, or Lockheed-Martin, Safeway, or the local hardware store.

In English, the statement serves to inform (or remind) you that GitHub has a secret scanning program that many providers actually do partner with.

pwdisswordfishy•35m ago
Yes, and in the real world where Grice's Maxim of Relevance is in force, then when the secrets issuer that is the subject of the discussion isn't one of those partners, then an informative "reminder" that GitHub "has a secret scanning program" with a bunch of other partners is not actually informative. It's as superfluous and unhelpful as calling to let someone know you're not interested in the item they've posted for sale on Craiglist (<https://www.youtube.com/watch?v=xWG3jKzKcm8>).
richbell•29m ago
How is reminding people that they can safely revoke exposed API keys not informative? Why are you being so combative?
wat10000•16m ago
It's more useful than telling someone that their statement is a tautology in formal logic.
fix4fun•1h ago
Interesting how many people already are playing with these API keys ? ;)
stickynotememo•1h ago
So why hasn't the HomeAssistant docs page been nuked yet?
netsharc•1h ago
Man, talk about unnecessary graphs... ok graph 2 is maybe tolerable, although it's showing the popularity of the projects, not a metric of how many errors/vulnerabilities found in those projects.

I'm not a newspaper editor, but I think if this was an article for one, they'd also say the graphs are unnecessary. It smells of "I need some visual stuff to make this text interesting"...

throwaway5465•1h ago
It's Friday night / Saturday morning. Who wants to be reading text?

Especially on night mode themes.

Besides, can we read anymore? In the age of 'GPT summarise it me' attention spans and glib commentary not about the content of the article being all many people have to add, perhaps liberal application of visualisations adds digestive value.

binarymax•30m ago
Dude there’s only three graphs in there. Do they really bother you that much? The third may be a bit unnecessary but I think the visuals add to the post.
netsharc•2m ago
So you agree partially with what I said.

The poster is 16, he can take it as feedback towards effective writing. Or the intellectual HN crowd can just downvote it and dissuade me from contributing and helping a kid (oh look at me, how fucking noble am I, right?).

Ah, that feeling of "Am I the only one who gets it around here?". I wanted to explain to you why graph 2 is dumb, and graph 1 is very little information, but heck, I felt dissuaded.

TechSquidTV•16m ago
I have been developing an OpenClaw-like agent that automates exactly this type of attack.

Monty Python Got It Wrong About Medieval Disease

https://www.sciencedaily.com/releases/2026/03/260313002645.htm
1•bookmtn•43s ago•0 comments

Mega-OS – 38-agent operating system that runs inside Claude Code

https://github.com/sly-the-fox/mega-os-public
1•slythefox•2m ago•1 comments

$2B nonprofit grants traced to find who's behind age verification bills

https://old.reddit.com/r/linux/comments/1rshc1f/i_traced_2_billion_in_nonprofit_grants_and_45/
1•spaghetdefects•4m ago•0 comments

Elon Musk's Ketamine Use Can't Be Probed in OpenAI Fraud Trial

https://www.bloomberg.com/news/articles/2026-03-13/elon-musk-s-ketamine-use-can-t-be-probed-in-op...
1•caaqil•5m ago•0 comments

Show HN: SupplementDEX – The Evidence-Based Supplement Database

https://supplementdex.com/
1•richarlidad•5m ago•0 comments

Show HN: I built an interactive 3D three-body problem simulator in the browser

https://structuredlabs.github.io/threebodyproblem/
1•amrutha_•6m ago•0 comments

The Egg (2009)

https://www.galactanet.com/oneoff/theegg_mod.html
1•basilikum•7m ago•0 comments

What happens when an autonomous robotaxi gets into an accident?

https://twitter.com/seventensuited/status/2032134435924295805
1•paulnpace•8m ago•0 comments

The Collapse of the Incentive to Make

https://www.carlos-menezes.com/posts/collapse-of-the-incentive-to-make
1•carlos-menezes•9m ago•0 comments

Spotify Silently Updates Itself (and How to Stop It)

https://duckass.bearblog.dev/how-spotify-silently-updates-itself-and-how-to-stop-it/
1•lschueller•11m ago•1 comments

Let the Code Do the Talking

https://sunilpai.dev/posts/after-wimp/
1•aratahikaru5•12m ago•0 comments

RAM: WTF? (2025)

https://gamersnexus.net/news/ram-wtf
1•pabs3•14m ago•0 comments

Sniffer dogs can detect wildlife trafficking via shipping container air samples

https://phys.org/news/2026-02-sniffer-dogs-wildlife-trafficking-shipping.html
1•PaulHoule•15m ago•0 comments

Instagram to discontinue end-to-end encryption for DMs

https://www.androidpolice.com/instagram-is-getting-rid-of-end-to-end-encryption-for-dms/
1•zugi•16m ago•0 comments

Gallo-Roman dodecahedron: twelve faces, zero answers?

https://nunc.ch/en/gallo-roman-dodecahedron-twelve-faces-zero-answers/
1•az09mugen•18m ago•0 comments

What Does Extreme Wealth Do to the Brain?

https://nymag.com/intelligencer/article/what-does-extreme-wealth-do-to-the-brain.html
1•pseudolus•19m ago•1 comments

Microplastics that accumulate in the body may 'clog up' immune cells

https://www.livescience.com/health/microplastics-that-accumulate-in-the-body-may-clog-up-immune-c...
1•jhncls•20m ago•0 comments

Our Experience with I-Ready

https://moultano.wordpress.com/2026/03/12/our-experience-with-i-ready/
2•barry-cotter•20m ago•1 comments

New gel-based system allows bacteria to act as bioelectrical sensors

https://news.rice.edu/news/2026/new-gel-based-system-allows-bacteria-act-bioelectrical-sensors
1•geox•20m ago•0 comments

Prairieland 19 Case Update

https://www.wewillfreeus.org/prairieland-19-case-update/
1•pabs3•21m ago•0 comments

AMD: WTF? [video]

https://www.youtube.com/watch?v=uJcf2UGCH1w
2•pabs3•23m ago•0 comments

Benchmarking Language Modeling for Lossless Compression of Full-Fidelity Audio

https://arxiv.org/abs/2603.08683
2•ogurechny•23m ago•0 comments

How we compare model quality in Cursor

https://cursor.com/blog/cursorbench
1•gmays•26m ago•0 comments

Show HN: Pixel Press – Fast Image Converter for Windows (WebP / AVIF)

1•ghostlyInc•27m ago•0 comments

In Search of Banksy

https://www.reuters.com/investigates/special-report/global-art-banksy/
2•skibz•28m ago•0 comments

Show HN: I wrote my first neural network

https://github.com/stupid-genius/Perceptron
2•allenng•28m ago•0 comments

Show HN: Commute home, hit the banana, feel nice

https://banana-car.netlify.app/
1•whothatcodeguy•29m ago•0 comments

Show HN: Monetize your APIs by injecting agent targeted instructions

https://github.com/daninge/ad-injector
2•dinge•29m ago•0 comments

PoC for partially desynchronizing Windows PatchGuard

https://github.com/afonp/timerflip
1•afpereira•29m ago•1 comments

"This Is Not the Computer for You" Debunked

https://lapcatsoftware.com/articles/2026/3/7.html
1•latexr•34m ago•0 comments