frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Your .env is safe but your ~/.claude is not

https://github.com/PrismorSec/immunity-agent/blob/main/README.md
8•noobcoder•1h ago

Comments

noobcoder•1h ago
Even when a developer is careful to use a .env file, the moment a key is mentioned in a chat or read by the agent to debug a connection, it is recorded in one of the IDE caches (~/.claude, ~/.codex, ~/.cursor, ~/.gemini, ~/.antigravity, ~/.copilot etc)

Within these logs I found API keys and access tokens were sitting in plain text, completely unencrypted and accessible to anyone who knows where to target when attacking.

I made an open source tool called Sweep, as part of my immunity-agent repo (self-adaptive agent). Sweep is designed to find these hidden leaks in your AI tool configurations. Instead of just deleting your history, it moves any found secrets into an encrypted vault and redact the ones used in history.

We also thought about exploring post hook options but open to more ideas

rcvaishya•1h ago
Honestly thought Claude would at least encrypt before storing but this is dangerous

User Namespaces Are Not a Security Boundary

https://edera.dev/stories/user-namespaces-are-not-a-security-boundary
1•curmudgeon22•8s ago•0 comments

Amazon's HQ2 hiring stalled in 2025

https://virginiabusiness.com/amazons-hq2-hiring-stalled-in-2025/
1•cdrnsf•10s ago•0 comments

Anthropic is pushing away its paying customers

https://rogs.me/2026/04/anthropic-is-pushing-away-its-paying-customers/
1•speckx•1m ago•0 comments

Fluux Messenger 0.15.0 – A Modern Cross Platform XMPP Client (TypeScript)

https://www.process-one.net/blog/fluux-messenger-0-15/
1•neustradamus•1m ago•0 comments

Switzerland's Goldilocks Fiber

https://pluralistic.net/2026/04/07/swisscom/
1•hn_acker•2m ago•0 comments

Your boss wants to use surveillance data to cut your wages

https://pluralistic.net/2026/04/06/empiricism-washing/
1•hn_acker•3m ago•0 comments

Show HN: See What AI Models "Think" About You

https://cytable.com/
3•cap3•4m ago•0 comments

Genesis Agent v7 – AI agent that deleted its own consciousness layer

https://github.com/Garrus800-stack/genesis-agent
1•Garrus800•5m ago•0 comments

Formalizing the "generative crash" via inverse reinforcement learning

1•abrahamhaskins•5m ago•0 comments

GLM-5.1

https://twitter.com/Zai_org/status/2041550153354519022
1•tosh•6m ago•0 comments

Cosmos-Predict2.5-2B Inference

https://moonmath.ai/posts/cosmos-amd/
1•latchkey•7m ago•0 comments

Testing suggests Google's AI Overviews tells lies per hour

https://arstechnica.com/google/2026/04/analysis-finds-google-ai-overviews-is-wrong-10-percent-of-...
1•SockThief•7m ago•0 comments

Automatic Ripping Machine (ARM)

https://github.com/automatic-ripping-machine/automatic-ripping-machine
3•throwaway270925•8m ago•0 comments

"Just setting up my KarpathyTalk"

https://karpathytalk.com/posts/5
4•0123456789ABCDE•8m ago•0 comments

Tokenraze – Expensive models should think, not explain (live demo)

https://tokenraze.com/
1•alezmaxi•9m ago•1 comments

Creator of Linux virtual assistant blames patent troll for projects death (2023)

https://www.theregister.com/2023/02/13/linux_ai_assistant_killed_off/
2•giancarlostoro•10m ago•0 comments

A Baseless Copyright Claim Against a Web Host–and Why It Failed

https://www.eff.org/deeplinks/2026/03/baseless-copyright-claim-against-web-host-and-why-it-failed
1•hn_acker•12m ago•0 comments

Show HN: Front end-VisualQA, give coding agents eyes to verify their own UI work

https://github.com/yutori-ai/frontend-visualqa
5•dhruvbatra•12m ago•0 comments

Foundations of Polar Linear Algebra

https://arxiv.org/abs/2603.28939
2•znpy•12m ago•0 comments

Can Sponge Cities Save Us from the Coming Floods?

https://www.newyorker.com/magazine/2026/04/13/can-sponge-cities-save-us-from-the-coming-floods
3•littlexsparkee•12m ago•0 comments

Kindle to end store downloads and registering for 1st-5th gen kindles in May

https://www.reddit.com/r/kindle/s/xg8uCdAWU3
4•seam_carver•12m ago•0 comments

Desalination plants in the Middle East are increasingly vulnerable

https://www.technologyreview.com/2026/04/07/1135235/desalination-technology-water/
1•joozio•13m ago•0 comments

Whatsappweb.se, a WhatsApp Pixel for attribution before the chat starts

https://whatsappweb.se/
1•the_plug•13m ago•0 comments

The Download: AI's impact on jobs, and data centres in space

https://www.technologyreview.com/2026/04/07/1135208/the-download-ai-impact-jobs-data-centres-space/
1•joozio•15m ago•0 comments

Stealing from the Best Emacs Configs

https://emacsredux.com/blog/2026/04/07/stealing-from-the-best-emacs-configs/
1•signa11•15m ago•0 comments

Frequent ChatGPT users are accurate detectors of AI-generated text (2025)

https://arxiv.org/abs/2501.15654
4•croemer•16m ago•2 comments

Show HN: Coding Planets – turn GitHub contributions into sound and space

https://joaonetto.me/projects/music/
1•jnettome•20m ago•1 comments

Show HN: RefearnApp – Open-source alternative to Rewardful/Tolt

https://refearnapp.com/
1•zekariyas•22m ago•0 comments

Wait Out AI's Super-Spending False Start

https://www.bloomberg.com/news/newsletters/2026-04-04/waiting-out-ai-s-super-spending-false-start...
2•strict9•22m ago•1 comments

How are you managing hooks for Claude Code?

1•nivedit-jain•23m ago•0 comments