frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

OpenAI Parameter Golf Challenge

https://openai.com/index/parameter-golf/
1•mellosouls•1m ago•0 comments

I built a free web tool to generate Kubernetes YAML for Podman play kube

https://podman-generator.rzen.at/
1•Garfieldttt•8m ago•1 comments

Ask HN: Depending on AI for anything important is a horrible idea, agree?

1•roschdal•9m ago•0 comments

Porting Doom to ESP32-P4 Using Doom Generic

https://github.com/alexkid77/ESP32P4DOOM
1•alexkid777•12m ago•1 comments

Show HN: VeilVault – an Android password manager built to stay local

https://veilvault.codeveil.de/index.en.html
1•codeveil•12m ago•1 comments

Someone has publicly leaked an exploit kit that can hack iPhones

https://techcrunch.com/2026/03/23/someone-has-publicly-leaked-an-exploit-kit-that-can-hack-millio...
1•simonebrunozzi•14m ago•0 comments

Show HN: I built the modern, clean and AI native linktree app

https://linkroot.space
1•IsruAlpha2•15m ago•0 comments

Russian Authorities Block Archive.today

https://techcrunch.com/2026/03/23/russian-authorities-block-paywall-removal-site-archive-today/
1•treebrained•18m ago•0 comments

Show HN: Overlay map tiles onto Autodesk's 3D BIM Viewer

https://github.com/infra-plan/bim-tile-overlay
1•gubets•19m ago•0 comments

Have You Paid Your "Intuit Tax"?

https://www.thenation.com/article/politics/tax-season-income-wealth-data/
1•petethomas•23m ago•0 comments

The US government just banned consumer routers made outside the US

https://www.theverge.com/news/899172/fcc-foreign-router-ban
4•bennett_dev•26m ago•0 comments

An end-to-end AI drug discovery platform – accessible to anyone

https://orac-nt-core.onrender.com/
3•DREDREG•27m ago•0 comments

23,464 Stock Trades Cross-Referenced Against 12,350 Breach Signals

https://ciphercue.com/blog/stock-transactions-breach-signals-cross-reference
3•adulion•28m ago•0 comments

Gasoline prices around the world, 16-Mar-2026 – GlobalPetrolPrices.com

https://www.globalpetrolprices.com/gasoline_prices/
3•janandonly•33m ago•0 comments

Native Instant Space Switching on macOS

https://arhan.sh/blog/native-instant-space-switching-on-macos/
2•signa11•42m ago•0 comments

You can now enable Claude to use your computer to complete tasks

https://twitter.com/i/status/2036195789601374705
2•matthieu_bl•43m ago•0 comments

Apple is set to put ads in Apple Maps in services push

https://www.msn.com/en-us/money/other/apple-is-set-to-put-ads-in-apple-maps-in-services-push/ar-A...
2•01-_-•44m ago•0 comments

The Homework Machine

https://insightfultroll.com/blog/2025/12/30/homework-machine/
1•vparikh•45m ago•1 comments

Is TrustMRR the right place to sell a SaaS?

https://trustmrr.com/startup/picx-studio
1•Yash16•46m ago•0 comments

Tangent Tree for ChatGPT Conversations

https://www.getaiworkspace.com/
2•Strikeh•48m ago•0 comments

The Death of OpenAI's Whistleblower Makes No Sense: What Happened to Suchir[video]

https://www.youtube.com/watch?v=v5WgQHCPB8Q
1•Imustaskforhelp•49m ago•0 comments

We're burning the future to simulate intelligence. Aether is the alternative

https://github.com/stillsilent22-spec/Aether-
2•Trybetter•53m ago•0 comments

OCP – Use your Claude Pro/Max subscription as an OpenAI-compatible API($0 extra)

https://github.com/dtzp555-max/openclaw-claude-proxy
3•dtzp555-max•54m ago•2 comments

PicoZ80 Is a Drop-In Replacement for Everyone's Favorite Zilog CPU

https://hackaday.com/2026/03/23/picoz80-is-a-drop-in-replacement-for-everyones-favorite-zilog-cpu/
2•neomech•1h ago•0 comments

March, 19-21: God is a comedian

https://no01.substack.com/p/march-19-21-god-is-a-comedian
8•tastyface•1h ago•1 comments

Show HN: Knitting – shared-memory function calls for JavaScript workers

https://knittingdocs.netlify.app/
1•mimiMonads•1h ago•0 comments

MagicAudio – Free Noise, Echo and Background Music Remover

https://magicaudio.pro/
9•polayan•1h ago•4 comments

Mixing Post-Quantum KEMs into Noise

https://runxiyu.org/comp/nkem1/
1•runxiyu•1h ago•0 comments

Modular 26.2: Image Generation and Upgraded AI Coding with Mojo

https://www.modular.com/blog/modular-26-2-state-of-the-art-image-generation-and-upgraded-ai-codin...
2•tosh•1h ago•0 comments

A Billionaire-Backed Startup Wants to Grow 'Organ Sacks' to Replace Animal Test

https://www.wired.com/story/a-billionaire-backed-startup-wants-to-grow-organ-sacks-to-replace-ani...
2•joozio•1h ago•0 comments
Open in hackernews

Vibe Coding Is a Security Disaster That Is About to Happen

https://medium.com/@jostfaganel/vibe-coding-is-a-security-disaster-that-is-about-to-happen-9f72f39756e9
9•jfaganel99•1d ago

Comments

jfaganel99•1d ago
Author here. The finding that surprised me most while writing this wasn’t the breach numbers. It was the Stanford result: developers with AI assistance introduced more flaws than those without, and felt more confident about their code. The confidence gap is the problem, not just the code quality.

The LLM secret predictability angle is something I’m still digging into and will be a separate article. There’s a lot more to it than I could cover here.

Genuinely curious: for anyone shipping vibe-coded projects, are you actually running any kind of security check before it goes live? Prompting the AI for a review, using a scanner, doing it manually, or just crossing your fingers? And if you are using an agent workflow for it, what does that look like? Any specific agent skills or tools you’ve found useful versus just adding noise?

fhouser•1d ago
I recently shipped a "vibe-coded" project. You raise a good point: I hadn't considered the confidence gap. If it is true that LLM generated code produces more vulnerabilities in addition to there being more code overall, all while at the same time the developer feels better about their results, then that is concerning.

This is how I go about ensuring there is little to no chaos (your mileage may vary based on project size and characteristics): - Plan your project manually, do not outsource thinking to the LLM. This includes being intentional about architecture, tech-stack, dependencies, etc.. - I have planning, orchestrating, coding, and reviewing agents. These should be self-explanatory, but there's a catch: the workflow is automated. OpenCode allows you to define "subagents" which can be called by "primary" agents. I will write a detailed Gitlab issue that my planning agent can fetch and read. It will create a detailed resolution plan that I can point the orchestration agent to. The orchestrator then delegates implementation to one or more coding agents simultaneously. Results are in turn delegated to reviewer agents. If the reviewer agents don't complain, then the results are ready for human review in an MR. - Changes that pass all review are documented in the project spec. E.g., if new modules are added that require an auth guard pattern implementation that is already documented in the spec, they will be listed as relevant sites for that auth guard pattern, etc..

I feel like the LLM agents have been more thorough and consistent than I could have been without them. This goes for refactors too: Since the entire project is essentially mapped out in the spec.md file(s), it's hard for the agent to miss a relevant site in the code. Human review is key. Don't merge code you don't understand.

jfaganel99•1d ago
This is one of the most practical breakdowns I’ve seen for a while. The spec.md as a living architecture map is smart, and documenting auth guard pattern sites as new modules get added is exactly the kind of thing that prevents issues creeping in.

The bit I’d push on: do your reviewer agents catch logic errors… things like a double negative auth check or a race condition in a payment flow. Those usually pass a check because code looks intentional and clean. Curious whether your reviewers are prompted specifically for security logic or more for spec conformance?

“Don’t merge code you don’t understand” is the right closer. Most setups don’t force that discipline cause people dont have the knowledge :)

fhouser•1d ago
Opus 4.6 usually doesn't disappoint .. No double negative auth checks or race conditions to report on, but I can say that introducing new functionality and patterns mostly requires a few cycles before the "repeatable pattern" is cleanly documented in the spec. When bugs do come up, the agent is quite good at finding the root cause and implementing a fix.
jfaganel99•1d ago
Working on a model benchmark focused on which model is good for these tasks. Keep you posted
fhouser•1d ago
Thanks,that would be great.