frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

The Comforting Lie of SHA Pinning

https://www.vaines.org/posts/2026-03-24-the-comforting-lie-of-sha-pinning/
1•g-b-r•1h ago

Comments

g-b-r•51m ago
This was mind-blowing to me.

I disagree with the author, it's not that sha-pinning is dangerous, it's that it is astonishingly broken in GitHub.

If they're unable to guarantee that the hash really belongs to the repository you indicated them, it would be better if they didn't provide the pinning feature at all.

And if they built their systems such that verifying it is unfeasible, they're just broken, and using GitHub should be considered a risk.

Although in truth, you should always carefully check a PR like that; even without referencing a different repository, a malicious user could just make it point to an outdated, vulnerable version.

Five Nights at Epstein's – Game

https://harshulmoon.github.io/fnae.html
1•whatsupdog•1m ago•0 comments

Anti-Islanding and Smart Grid Protection (2015)

https://www.digikey.com/en/articles/anti-islanding-and-smart-grid-protection
1•password4321•1m ago•0 comments

The first A-Corp law is here

https://blog.metalabel.com/the-first-a-corp-law-is-here/
1•exolymph•1m ago•0 comments

Vibe Security Radar: Real CVEs where AI-generated code introduced Bugs

https://vibe-radar-ten.vercel.app/
2•tsgates•2m ago•0 comments

Hegseth's War on Anthropic Encounters the First Amendment

https://www.techdirt.com/2026/03/27/hegseths-war-on-anthropic-encounters-the-first-amendment/
1•cdrnsf•3m ago•0 comments

About the Atmosphere

https://toni.org/2026/03/27/about-the-atmosphere/
1•Kye•4m ago•0 comments

Red Teaming Would Fix Liberalism's Crisis

https://www.bloomberg.com/opinion/articles/2026-03-27/red-teaming-could-save-liberalism-from-its-...
2•petethomas•6m ago•0 comments

US Tech Companies Must Be Liable for Facilitating Persecution and Torture Abroad

https://www.eff.org/press/releases/us-tech-companies-must-be-accountable-us-courts-facilitating-p...
2•hn_acker•7m ago•1 comments

Mount any SEC EDGAR filer's complete filing history as a virtual filesystem

https://github.com/sampagon/edgar-mount
1•sampagon•8m ago•0 comments

CrackArmor: Critical AppArmor Flaws Enable Local Privilege Escalation to Root

https://blog.qualys.com/vulnerabilities-threat-research/2026/03/12/crackarmor-critical-apparmor-f...
1•type0•10m ago•0 comments

Moats, or castles in the air?

https://www.wsj.com/finance/investing/moats-or-castles-in-the-air-c6de3e56
1•hhs•11m ago•0 comments

Malicious IoliteLabs VSCode Extensions Target Solidity Developers with Backdoor

https://www.stepsecurity.io/blog/malicious-iolitelabs-vscode-extensions-target-solidity-developer...
2•kurmiashish•12m ago•0 comments

Alan Cache – the best caching library? (Part 1)

https://medium.com/alan/alan-cache-the-best-caching-library-part-1-e9e68ecf39dd
1•damsieboy•13m ago•0 comments

Show HN: Echoes of Deception

https://deception.madoke.org/
1•madoek•14m ago•0 comments

Building a Firewall via Endpoint Security?

https://objective-see.org/blog/blog_0x86.html
1•sashk•14m ago•0 comments

Researchers use quantum biosensors to peer into the inner workings of cells

https://artsci.washu.edu/ampersand/washu-researchers-use-quantum-biosensors-peer-inner-workings-l...
1•hhs•15m ago•0 comments

Post reporters called the White House. Their phones showed 'Epstein Island.'

https://www.washingtonpost.com/style/power/2026/03/27/white-house-google-database-epstein/
1•doener•17m ago•0 comments

Google warns quantum computers could hack encrypted systems by 2029

https://www.theguardian.com/technology/2026/mar/26/google-quantum-computers-crack-encryption-2029
1•doener•18m ago•0 comments

Exact Geometric Resolution of Cosmological Constant Problem: The Flat 3-Torus

https://zenodo.org/records/19241283
1•avonmach•23m ago•0 comments

Sashiko agentic Linux kernel code review system

https://github.com/sashiko-dev/sashiko
1•_____k•25m ago•0 comments

Engineers do get promoted for writing simple code

https://www.seangoedecke.com/simple-work-gets-rewarded/
1•aidenn0•25m ago•0 comments

SlopCodeBench: Benchmarking How Coding Agents Degrade over Long-Horizon Tasks

https://arxiv.org/abs/2603.24755
1•FiberBundle•29m ago•0 comments

Show HN: Show the ancestry of your code changes visually

https://www.codeboarding.org/diagrams
1•brovatten•30m ago•1 comments

Weak models excel at long context tasks

https://www.together.ai/blog/plan-divide-conquer
1•zagwdt•30m ago•0 comments

Both radiologists and AI struggle to identify 'deepfake' X-rays

https://radiologybusiness.com/topics/artificial-intelligence/both-radiologists-and-ai-struggle-id...
2•hhs•30m ago•0 comments

Ssereload(1) Introduction

https://timmarinin.net/2026/ssereload/
1•birdculture•31m ago•0 comments

Show HN: Multiplayer Local-First OpenClaw Native Mac App

https://clawcoda.com/
1•EthOptimist•32m ago•0 comments

Claude's popularity is forcing it to hit the brakes on users

https://www.businessinsider.com/claude-usage-caps-changes-popularity-anthropic-2026-3
1•almog•33m ago•0 comments

Software Performance Engineering: The Ideas I Keep Coming Back To

https://ricomariani.medium.com/software-performance-engineering-the-ideas-i-keep-coming-back-to-6...
1•cdrnsf•33m ago•0 comments

Dokis – Runtime RAG provenance enforcement without an LLM call

https://github.com/Vbj1808/dokis
1•Vbj1808•35m ago•0 comments