frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Podman rootless containers and the Copy Fail exploit

https://garrido.io/notes/podman-rootless-containers-copy-fail/
13•ggpsv•1h ago

Comments

raesene9•32m ago
This is kind of an odd article to me. The point that podman may provide better isolation that Docker is made, but copy fail part focuses on the sample exploit (that overwrote su) which is not super applicable to containerised environments, and not the general effect of exploiting the vulnerability, which is to allow the user to overwrite a file that they should only have read-only access to.

https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kuber... - This PoC has a good example of how Copy Fail might have an impact in a container based environment, it's exploiting the shared layers in a pair of container images, to overwrite a file in one image based on the running of an exploit in another.

Whilst I've not directly tested podman for that kind of attack, I'd be a bit surprised if it stopped it, given how this vuln works.

When Semiconductor Materials Misbehave

https://semiengineering.com/when-semiconductor-materials-misbehave/
1•PaulHoule•33s ago•0 comments

Reggie: Hybrid Compile-Time and Runtime Optimized Regex for Java

https://github.com/DataDog/java-reggie
1•mfiguiere•1m ago•0 comments

(Un)portable defer in C

https://antonz.org/defer-in-c/
2•fanf2•2m ago•0 comments

Show HN: NPM Package that fills forms via voice using Gemini Live API

https://www.npmjs.com/package/audio-forms
1•vaibhavgeek•3m ago•0 comments

Show HN: A near-zero-dependency Java tookit for internal tools and AI flows

https://github.com/vadimv/server-components
1•v4d1mv•4m ago•0 comments

Expansion on DORA report's observation on individual vs. team productivity

https://alokit.substack.com/p/the-dora-paradox-why-adding-ai-makes
1•avikalp•5m ago•0 comments

Echon – Privacy-First Discord Alternative in Rust and Tauri

https://echon-voice.com
1•Phrosen•7m ago•0 comments

Tldraw SDK 5.0

https://tldraw.dev/blog/tldraw-sdk-5-0
1•SpyCoder77•8m ago•0 comments

Metaphors are central to design. AI needs better ones

https://metedata.substack.com/p/011-ai-needs-better-metaphors
1•young_mete•8m ago•0 comments

De-classified Files documenting UFOs, 'extraterrestrial life' released

https://www.foxnews.com/politics/trump-admin-releases-highly-anticipatedfiles-documents-ufos-extr...
2•kokanator•8m ago•0 comments

What Color is Your Function? (2015)

https://journal.stuffwithstuff.com/2015/02/01/what-color-is-your-function/
1•jeremyscanvic•8m ago•0 comments

You're ignoring most of the world – Which countries get attention by the numbers

https://timhirschelburns.substack.com/p/youre-ignoring-most-of-the-world
1•alphabetatango•9m ago•0 comments

Code Red: The Business Impact of Code Quality

https://dl.acm.org/doi/epdf/10.1145/3524843.3528091
1•tacon•9m ago•0 comments

WhyGoAI – AI session recordings that tell you why users left

1•LatifaOuali•10m ago•0 comments

Cognitive Surrender

https://addyosmani.com/blog/cognitive-surrender/
1•tagyro•10m ago•0 comments

GPON vs. EPON vs. XGS-PON: Complete Comparison Guide 2026

https://www.langzhichina.com/gpon-vs-epon-vs-xgs-pon-comparison-guide
1•langzhi•11m ago•0 comments

Telegram Adds Guest AI Bots, Bot-to-Bot Chats, Chat Automation

https://telegram.org/blog/ai-bot-revolution-11-new-features
1•sharpshadow•11m ago•0 comments

Conversation Branching in AI Chat

https://ably.com/blog/conversation-tree-branching-ably-ai-transport
1•zknill•12m ago•0 comments

Tesla's screwup involves making the font size of braking system too small (2024)

https://www.theverge.com/2024/2/2/24059114/tesla-recall-brake-system-font-size-power-steering
2•gurjeet•13m ago•0 comments

Ask HN: How do we handle the rise of low quality "This is LLM" comments?

1•shantnutiwari•15m ago•1 comments

Young and old men are leaving the labor force, fueling a record decline

https://www.washingtonpost.com/business/2026/05/08/men-labor-force-drop-outs/
4•littlexsparkee•15m ago•1 comments

Show HN: Slate – agentic pre-production studio for solo Youtubers

https://useslate.app/
2•jcfontecha•16m ago•0 comments

Why Don't Lowercase Letters Come Right After Uppercase Letters in ASCII?

https://tylerhillery.com/blog/why-dont-lowercase-chars-come-after-upper/
2•SpyCoder77•17m ago•1 comments

Pentagon Releases Files on U.F.O.s (Gift Article)

https://www.nytimes.com/2026/05/08/us/politics/pentagon-ufo-files.html
2•SpyCoder77•18m ago•0 comments

Block Guard: Spam Call Blocker

https://play.google.com/store/apps/details?id=com.radstormtech.blockguard&hl=en_US
2•BlockGuardApp•18m ago•0 comments

People who care are having the hardest time

https://www.rawsignal.ca/newsletter-archive/the-people-who-care-are-having-the-hardest-time/
1•nanderson_•19m ago•0 comments

The Washing-Machine Tragedy (1981)

https://www.newyorker.com/magazine/1981/11/30/the-washing-machine-tragedy
2•chromaton•21m ago•1 comments

How to use food to help your mood (2022)

https://psyche.co/guides/how-to-use-food-to-help-reduce-your-risk-of-depression
1•herbertl•21m ago•0 comments

What If Ed Tech Peaked 200 Years Ago?

https://www.educationdaly.us/p/what-if-peak-ed-tech-was-200-years
1•dan_sbl•21m ago•0 comments

How we made Notion available offline

https://www.notion.com/blog/how-we-made-notion-available-offline
3•birdculture•22m ago•0 comments