frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

CopyFail Was Not Disclosed to Distros

https://www.openwall.com/lists/oss-security/2026/04/30/10
42•ori_b•1h ago

Comments

xeeeeeeeeeeenu•13m ago
For context, the author of the linked post, Sam James, is a Gentoo developer.

Anyway, this is a disaster. It was extremely irresponsible to share the exploit with the world before the distributions shipped the fix. Who knows how many shared hosting providers were hacked with this.

It's also worrying that it seems there's no communication between the kernel security team and distribution maintainers. One would hope that the former would notify the latter, but apparently it's the responsibility of whoever finds the vulnerability.

shimman•10m ago
Expecting people to do the right thing is a fundamental issue here. Why would you ever expect for all of vulnerabilities to be disclosed privately? There's very little actual incentive to do this.

I'm honestly unaware of what systems could be put in place to prevent this but expecting people to always do the right thing is fantasy level thinking. I mean I bet the disclosers that they would during the right thing, hence why it's a bad thing to rely on.

baggy_trough•8m ago
Why wouldn't the linux security team notify the main linux distributions?
ectospheno•10m ago
The Bleeping Computer link below mentions a potential remedy until a patch is ready.

https://www.bleepingcomputer.com/news/security/new-linux-cop...

jayofdoom•6m ago
This workaround only applies to kernels with the impacted code compiled as a module. RHEL, Fedora, and Gentoo (we use a modified Fedora config) all are configured to build this in directly. Without a patch or config change (as Sam from Gentoo was alluding to), those distributions remain vulnerable.
holowoodman•5m ago
The potential remedy doesn't work on RedHat and derivatives because the affected code is not a module there but statically compiled in.
semiquaver•5m ago
> Note that for Linux kernel vulnerabilities, unless the reporter chooses to bring it to the linux-distros ML, there is no heads-up to distributions.

Why would they imply it is incumbent on the reporter to liaise with distributions? That seems an excessively high level of familiarity with the internal structure of Linux to assume. Reporter did more than enough by responsibly disclosing it to linux and waiting for a patch to land.

Aren’t there people in the linux project itself with authority over and responsibility for security vulnerabilities? One would think they would be the ones notifying downstream distros…

Benchmarking Local LLM/Harness Combinations

https://neuralnoise.com///2026/harness-bench-wip/
1•pminervini•1m ago•0 comments

Cyborg Evals

https://www.lesswrong.com/posts/zctBgvzxamFThgc3T/cyborg-evals
1•frmsaul•2m ago•1 comments

Real Linux. In a browser tab. No install. No server. No Docker

https://linuxontab.com/
1•kilian-ai•3m ago•0 comments

The Evolution of Open Source with Kelsey Hightower [video]

https://www.youtube.com/watch?v=a5-zTLJprpU
1•mooreds•3m ago•0 comments

Anthropic wants to be the AWS of agentic AI

https://thenewstack.io/anthropic-agents-managed-aws-claude/
1•Brajeshwar•4m ago•0 comments

Tess Observations

https://tess.mit.edu/
1•mooreds•4m ago•0 comments

What is Windows K2? Inside Microsoft's big plan to save Windows 11

https://www.windowscentral.com/microsoft/windows-11/what-is-windows-k2-everything-you-need-to-kno...
1•robotnikman•4m ago•0 comments

What Happens in the First 24 Hours After a New Asset Goes Live

https://www.bleepingcomputer.com/news/security/what-happens-in-the-first-24-hours-after-a-new-ass...
1•mooreds•5m ago•0 comments

Ukraine Bets on Battlefield AI

https://apnews.com/article/russia-ukraine-war-artificial-intelligence-europe-a7d2cce367f68caa3598...
1•beezle•5m ago•0 comments

Monthly News – April 2026

https://blog.linuxmint.com/?p=5022
1•paulnpace•6m ago•0 comments

Coding agents expose this: same VPS, 3 runs, ~65% drift

https://webbynode.com/articles/coding-agents-infrastructure-vps-benchmarks
1•gsgreen•6m ago•0 comments

The Enhanced Games, Where Athletes Compete on Steroids, HGH, Adderall

https://www.vanityfair.com/news/story/inside-the-enhanced-games
2•zdw•7m ago•0 comments

Difference between good debt and bad debt

https://smartmoneyguides.quora.com/
1•hennix22•9m ago•0 comments

Digging into Claude Code and codex source codes to understand how they work

https://nimasadri11.github.io/random/annotated-agent/
1•nimasadri11•9m ago•0 comments

From items to users: Rebuilding Plaid's API in flight

https://medium.com/plaid-engineering/from-items-to-users-rebuilding-plaids-api-in-flight-8e8aa037...
2•bassoonspinach•9m ago•0 comments

Palantir's Al Targeting System Running the Iran War [video]

https://www.youtube.com/watch?v=CHLFl26p7Po
2•smallerfish•10m ago•0 comments

The Alice and Bob After Dinner Speech

https://hex.ooo/library/alicebob.html
1•tempodox•10m ago•0 comments

IBM Selectric

https://en.wikipedia.org/wiki/IBM_Selectric
2•paulpauper•11m ago•0 comments

A Year on an E-Reader

https://wombat.bearblog.dev/a-year-on-an-e-reader/
1•speckx•11m ago•0 comments

Paraconsistent Logic (Substantive Revision)

https://plato.stanford.edu/entries/logic-paraconsistent/
1•StatsAreFun•12m ago•0 comments

SFO Gate Explorer

https://www.flysfo.com/passengers/services/gate-explorer
1•CaliforniaKarl•12m ago•0 comments

Greptile's New Pricing Is Predatory

https://greptile-fail.vercel.app/
2•not-chatgpt•12m ago•0 comments

Before DevRel Was a Thing

https://meghangill.substack.com/p/before-devrel-was-a-thing
1•meghan•13m ago•0 comments

The invisible force making food less nutritious

https://www.washingtonpost.com/climate-environment/interactive/2026/carbon-pollution-diluting-key...
2•johnbarron•14m ago•0 comments

Introducing Stage: Engineers deserve a better code review platform

https://stagereview.app/blog/introducing-stage
2•cpan22•16m ago•0 comments

More Tokens Isn't More Intelligence

https://briannelee.substack.com/p/more-tokens-isnt-more-intelligence
1•BrianneLee011•18m ago•0 comments

AI On-Call Engineer That Fixes Prod While I Sleep

https://twitter.com/DVremenko/status/2049885593992126682
1•dimavrem22•18m ago•2 comments

Show HN: Milkdrop Visualizations with WASM+WebGPU [TW: flashing lights]

https://milkdrop.mahae.dev/
1•mkoh•22m ago•0 comments

Granite 4.1 LLMs: How They're Built

https://huggingface.co/blog/ibm-granite/granite-4-1
1•Brajeshwar•22m ago•0 comments

Main quests, subquests, side quests and minigames

https://stevepavlina.com/blog/2020/02/main-quest-subquest-side-quest-or-minigame/
1•highfrequency•22m ago•0 comments