frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Where is Silver Spring? It depends who you ask (2018)

https://ggwash.org/view/103217/big-silver-spring-or-little-silver-spring-it-depends-who-you-ask
1•mooreds•46s ago•0 comments

I won my FOIA against Twelve South to open up the electrical for the PlugBug 120

https://archive.org/details/pb120-us
1•reesericci•1m ago•0 comments

Nobody wants to read your shit

https://viverricious.substack.com/p/nobody-wants-to-read-your-shit
1•eatitraw•2m ago•0 comments

National Science Board eviscerated; Trump admin fires all 22 members

https://arstechnica.com/science/2026/04/national-science-board-eviscerated-trump-admin-fires-all-...
1•codezero•2m ago•0 comments

If Claude Feels Worse, Fix Your Harness

https://mdelcaro.substack.com/p/if-claude-feels-worse-fix-your-harness
1•fathermarz•2m ago•0 comments

New Phishing Scam: Fake Invitations

https://www.nytimes.com/2026/04/23/style/invitation-phishing-scam.html
1•speckx•2m ago•0 comments

The Enshittification Multiverse

https://pluralistic.net/2026/04/27/analogs-and-analogies/
1•hn_acker•3m ago•0 comments

Microsoft to invest $18B in Australia to expand AI, cloud infrastructure

https://seekingalpha.com/news/4578419-microsoft-to-invest-18b-in-australia-to-expand-ai-cloud-and...
1•gmays•4m ago•0 comments

The disappearing AI middle class

https://thenewstack.io/disappearing-ai-middle-class/
1•Brajeshwar•4m ago•0 comments

Show HN: Qumulator – quantum circuit simulator, 1000 qubits, no GPU

https://github.com/qumulator/qumulator-sdk
1•nnoorbakhsh•5m ago•0 comments

Show HN: Happy Horse Video Generator

https://happyhorse-ai.site/
1•mixfox•7m ago•0 comments

Agent Auth: Why OAuth Wasn't Built for This

https://www.apideck.com/blog/agent-auth-oauth-ai-agents
2•zacian•8m ago•0 comments

Mixing numeric attributes into text search for better first-stage relevance

https://turbopuffer.com/blog/rank-by-attribute
1•_peregrine_•8m ago•0 comments

GPT 5.5: The System Card

https://thezvi.substack.com/p/gpt-55-the-system-card
2•7777777phil•10m ago•0 comments

Long-running Claude for scientific computing

https://www.anthropic.com/research/long-running-Claude
2•theorchid•10m ago•0 comments

Poisoning RAG document corpora: 32 vectors tested, 19 succeeded

https://corrupted.io/2026/04/24/Poisoned-Rags.html
1•kusuriya•10m ago•0 comments

Humans haven't outsourced all their thinking. They're thinking on a lag

https://dheer.co/the-lag-effect/
1•bushido•10m ago•0 comments

WenWare

https://wen-ware.com/
1•bdlowery•10m ago•0 comments

Percona Live 2026 – Deep dives into Postgres internals, MySQL scaling,and Valkey

https://perconalive.com/2026-usa/agenda/
1•czajkowski•11m ago•1 comments

Can Kafka Queues Make Consumers Faster?

https://www.streamingdata.tech/p/can-kafka-queues-make-consumers-faster
1•sap1enz•12m ago•0 comments

Claude Architect Plugin

https://willhennessy.io/writing/introducing-architect.html
1•hennessywill•12m ago•1 comments

The One-Person Stack

https://www.ivan.codes/blog/the-one-person-stack
1•andout_•12m ago•0 comments

Ask HN: Claude Code usage changing (max 20x)

1•uptownhr•12m ago•0 comments

Supreme Court to Hear Arguments in Landmark Roundup Weedkiller Case

https://www.nytimes.com/2026/04/26/climate/supreme-court-bayer-monsanto-roundup-glyphosate.html
5•mikhael•16m ago•0 comments

Smart Files

https://theolincke.com/blog/10_smart_files_release
1•eatonphil•16m ago•0 comments

LLW 2026: opening legal conversations at the heart of Berlin

https://fsfe.org/news/2026/news-20260427-01.html
1•Tomte•16m ago•0 comments

AI Usage Analytics – Real-time budget enforcement and PII redaction for LLM

1•abdulmdev•17m ago•0 comments

Pure Business Capital Inc. Mark Shelton

https://purebusinesscapital.com/
1•purbiz•19m ago•1 comments

Fresh 2.3: Zero JavaScript by Default, View Transitions, and Temporal Support

https://deno.com/blog/fresh-2.3
1•ms7892•23m ago•0 comments

Clickup.com page source contains hardcoded Split.io API key – data leak

https://twitter.com/weezerOSINT/status/2048662702957134199
2•nazgulsenpai•23m ago•0 comments
Open in hackernews

Ask HN: My project made news as a "Scam", what can I do?

https://www.kitv.com/video/news/state-warns-of-cybersecurity-phishing-threat-from-website-impersonating-state-government/video_c6f491c6-1fb9-58b9-9e21-055b727ec380.html
1•arionhardison•1h ago

Comments

arionhardison•1h ago
TL;DR: Hawaii's SOC mislabeled my civic-tech staging subdomains as a phishing scam, then pushed it as a press release — multiple outlets ran it. I'm about to launch the city-tier version (Miami, Boston, NYC, LA, Vegas) and want HN's advice on correcting the record before then.

I'm Arion. I'm building Project20x — an AI-native governance platform (policy authoring → codification → delivery as digital public goods). It's the substrate that turns policy into running services. I'm building it across all 50 states and 40+ countries concurrently, because government actually runs on interagency dependencies, not silos — VA hands off to HUD, HHS coordinates with every state Medicaid office, etc.

The subdomain pattern at the time was {agency}.{state}.{country}.codify.inc — so the Hawaii subprojects lived at dlir.hi.usa.codify.inc, health.hi.usa.codify.inc, etc. Real staging environments. Not impersonations. No credential capture, no solicitation of money, no fake state seal.

In late 2025 the Hawaii SOC published an alert flagging those subdomains as phishing impersonating state agencies — and pushed it out as a press release. KITV ran the segment in the URL above. Several other Hawaii outlets ran their own write-ups off the same release. So "scam" is now indexed across multiple sites, not one. The same effort that went into a coordinated press push could have gone into one email to a contact page — but I hadn't published one, and they didn't ask.

Here's what I think is fair, and what I think isn't:

Fair: A citizen unfamiliar with Codify could be thrown by a .inc URL that contains an agency abbreviation as a subdomain label (dlir.hi.usa.codify.inc) — even though the apex is codify.inc not .gov, and every page header read "Codify Inc official portal for [agency name]." The on-page identification was there; the URL itself was the surprise. That's a comms-and-onboarding failure on my part, and the fix is to stop putting agency abbreviations into deep subdomain paths. The new pattern is per-city apex (codify.la, codify.nyc, codify.boston, codify.miami, codify.vegas) — clearly a Codify property at first glance, no nested abbreviations to misread. I've also published a security contact (a@project20x.com) and a public registry listing live vs. staging vs. claimable subprojects. The SOC didn't reach out before the alert because I hadn't published a contact. That's fixed.

Not fair: "Scam" is a factual claim and it's wrong. Every page header on the flagged subdomains read "Official Codify Inc portal" or "Official Project20x portal for [agency name]" — including the screenshots used in the "scam" example. The site never claimed to be the agency, never collected information on the agency's behalf, and never solicited money. This is a civic-tech project in the same spirit as DOGE / USDS / 18F — same DOGE-shaped goal, achieved by compilation rather than chainsaw. Building in public on the open internet has a cost I underestimated, but mislabeling civic-tech as fraud has a cost too.

Why I'm asking now: I'm launching the city-tier version — "DOGE for cities" — for Miami, Boston, NYC, LA, and Las Vegas, on per-city apex domains (codify.miami, codify.la, codify.nyc, codify.boston, codify.vegas). No more nested codify.inc subdomains. Playbook this time: clear "Codify Inc portal" header on every page, published security contact, .gov counterpart links, and CIO/CISO outreach before launch. Rather get it right than clean up again.

So — HN, what would you actually do?

Project: https://project20x.com/about Contact: a@project20x.com

benoau•1h ago
Why are you calling your portals "Official"?

Wouldn't it be more traditional to disclaim you are unofficial and unaffiliated with these agencies?

arionhardison•35m ago
I was doing this because some portals that have been setup are setup by the end users; its a platform. But these were the ones that "I" the developer of Project20x/Codify had setup internally.

This is a really good point though, I think I should remove that.

oopsiremembered•1h ago
Question Number 1 through Infinity: Is this impacting your business? Actually? Today?

I'd suggest keeping an eye on things but not getting too bent out of shape. The video didn't call your company a scam; it said that scammers have been using your domain. And the news has gotten pretty limited reach, mostly in a small news market -- and a bit in the niche market of cybersecurity. Kicking up too much of a stink, especially ineffectually, might create a Streisand Effect.

If it is impacting your business, then the answer you perhaps don't want to hear: This is crisis comms. This is a job for a PR/crisis comms agency.

If you can't afford one, you're going to have to fake your way through some heavy lifting. Press releases, pitching reporters, etc.

I'd focus, in part, on making people comfortable with the idea of your project and your vision as something normal and safe. I wouldn't draw DOGE comparisons. "DOGE" is a four-letter word to a lot of people.

Separately, you may have legal options -- vis-a-vis defamation or other matters: KHON seems to be saying that links ending with codify.inc "always" indicates a scam. If that's not true, that's something probably correctable. (But that doesn't mean you need to necessarily drop a fat retainer on a lawyer's desk if you're not looking to collect $$$. An email to a relevant editor could sort that out.)

arionhardison•1h ago
1. Yes, I have had 3 potential clients mention this to me and initially I was a bit caught off guard. I am also concerned that it could be more and some decided to just not move forward because they believed outright that it was a "Scam".

2. I agree, I think I was a bit too worried because I do not know how to navigate this space "Gov Tech" very well.

Thankyou very much for your response; developing a product in a silo can cause tunnel vision which leads to blowing things out of proportion, your comment has really helped me to put things into perspective.

My biggest concern by far is that they seem to have put codify.inc on a registry so ISP's are blocking or showing the red "this is a scam - go back to safety" page. I really liked and invested a lot into that "branding".