frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

War.gov/UFO/ UFO file download reference repo

https://github.com/dopper/nts-ufos
1•dopper•2m ago•0 comments

London's BT Tower to get rooftop swimming pool

https://www.theregister.com/offbeat/2026/05/09/londons-bt-tower-to-get-rooftop-swimming-pool/5237337
1•samizdis•3m ago•0 comments

The 90 Day disclosure policy is dead

https://blog.himanshuanand.com/2026/05/the-90-day-disclosure-policy-is-dead/
1•unknownhad•3m ago•0 comments

Blog Post Tells the Time

https://alexsci.com/blog/this-blog-post-tells-the-time/
1•saeedesmaili•7m ago•0 comments

Show HN: Free OSS transcription app I made and found it's faster than wispr flow

https://mumbli.app/
1•fireharp•9m ago•0 comments

The Rise of Emotional Surveillance

https://www.theatlantic.com/culture/2026/05/worker-surveillance-emotion-ai/687029/
4•iugtmkbdfil834•13m ago•1 comments

Web Server on a Nintendo Wii

http://wii.sjmulder.nl/
1•adunk•14m ago•0 comments

Hugging Face's Clem Delangue: Stop Comparing Engines to Cars

https://www.turingpost.com/p/clem-delangue-hugging-face-ai-builders
1•gmays•14m ago•0 comments

Japan is deploying ultra-cheap cardboard drones built for swarm warfare

https://www.tomshardware.com/tech-industry/japan-is-deploying-ultra-cheap-cardboard-drones-built-...
1•_____k•15m ago•1 comments

Geography Is Four-Dimensional

https://sive.rs/4d
1•ColinWright•22m ago•0 comments

Feedback on my local-first AI assistant project?

https://github.com/joshuatic/voxel
1•joshuatic•25m ago•1 comments

Lies, damned lies, and Elastic's benchmarks

https://www.gouthamve.dev/lies-damned-lies-and-elastics-benchmarks/
1•gouthamve•31m ago•0 comments

A hacker ran me over with a robot lawn mower

https://www.theverge.com/tech/925696/yarbo-robot-lawn-mower-hack-remote-control-camera-access-mqtt
2•gnabgib•31m ago•0 comments

Does it scale? Who cares (2011)

https://jacquesmattheij.com/does-it-scale-who-cares/
1•downbad_•35m ago•1 comments

IRGC to generate revenue from undersea internet cables in Strait of Hormu

https://twitter.com/IranIntl_En/status/2053206979330392414
1•us321•36m ago•0 comments

Trump Media and Technology Group lost $406M in first three months of 2026

https://www.theguardian.com/us-news/2026/may/09/trump-media-and-technology-group-loses-406m-first...
4•vinni2•38m ago•2 comments

An Excerpt from "Go the Fuck to College" by Adam Mansbach

https://www.fatherly.com/parenting/go-the-fck-to-college-essay-adam-mansbach
1•johntfella•42m ago•1 comments

Consumer AI's ARPU Problem

https://twitter.com/SashaKaletsky/status/2051366803897766236
1•gmays•42m ago•0 comments

Can I Copyright a Song I Made with AI?

https://www.musicologize.com/can-i-copyright-a-song-i-made-with-ai/
2•speckx•45m ago•1 comments

ScalaTimes – A Free, Once-Weekly Scala News Flash

https://scalatimes.com
1•TheWiggles•45m ago•0 comments

Show HN: Sigma Guard – deterministic contradiction checks for graph memory

1•invariantjason•48m ago•0 comments

RustChat is a minimal team messenger, alternative to Slack, Mattermost, Zulip

https://rustchat.io/
2•xvilka•49m ago•0 comments

PostgresBench: A Reproducible Benchmark for Postgres Services

https://clickhouse.com/blog/postgresbench
1•saisrirampur•50m ago•0 comments

Show HN: AI Design Taste – Design.md Generator

https://chromewebstore.google.com/detail/ai-design-taste-designmd/peclkdlolmcclhhgpoehpikgknbmkknc
1•novateg•53m ago•0 comments

The Mismeasure of Open Source

https://nesbitt.io/2026/05/09/the-mismeasure-of-open-source.html
1•bmitch3020•55m ago•0 comments

RL Benchmark "Ant" in Hardware

https://github.com/Openmind-Research-Institute/open-ant
1•lupusorina•56m ago•0 comments

TypeScript checker and language service written in Rust

https://tsz.dev/
2•jcbhmr•57m ago•0 comments

Startup Skills

https://github.com/dhruvhanda15-dev/startupskills
1•dhruvh3•59m ago•0 comments

A happy 150th birthday to the Otto Cycle internal combustion engine

https://twitter.com/iowahawkblog/status/2053100736309809319
1•delichon•1h ago•0 comments

Show HN: Draw Battle

https://vidzert.com/draw-battle
2•vidzert•1h ago•0 comments
Open in hackernews

FreeBSD: Local Privilege Escalation via Execve()

https://www.freebsd.org/security/advisories/FreeBSD-SA-26:13.exec.asc
37•Deeg9rie9usi•1h ago

Comments

rvz•1h ago
> IV. Workaround

> No workaround is available.

Oh dear.

itsthefrank•49m ago
> V. Solution

> Upgrade your vulnerable system to a supported FreeBSD stable or release / security branch (releng) dated after the correction date, and reboot the system.

Not everyone can just freebsd-update and reboot, so yes, "Oh dear." is a good response to this.

epcoa•44m ago
Anyone relying on a 30+ year old monolith kernel written in C to not have some exploitable LPEs lurking should stay in basket weaving and out of sysadmin.
itsthefrank•37m ago
Not sure why the snark but if people are running FreeBSD then they should be...basket weaving instead of using it? Yes, the correct solution is to patch and reboot but not everyone is in a place to jump and do that which is why a temp workaround, if possible, would be welcome
cyberpunk•36m ago
Yep.

You should treat any system where non-admins regularly login as basically insecure/owned and rig your architecture appropriately.

TBH -- I don't have any of these kinds of boxes anymore. Who is really running anything like this in 2026 and for what purpose?

jmspring•16m ago
Stability of ecosystem. No systemd. Native ZFS. Jails over Docker. Been using it for 20+ years and it’s my preferred server OS.
cyberpunk•5m ago
No, I mean do you run FreeBSD boxes where users who should not ever assume root access actually login to do tasks?

My point is that if you do, you probably shouldn't run, for e.g applications which need production db credential, or hold sensitive data on these boxes, or .. whatever.

Edit: I use FreeBSD extensively, for various things -- but shell access to them is restricted to the sysadmins..

icedchai•3m ago
Same. I've been using it since 1996. Initially, we used it at an early ISP for DNS, SMTP, and POP3 for roughly 8K users, and it stuck with me.
skydhash•39m ago
Why can't they? Upgrading and rebooting is kinda the standard response for most security issues. So I would expect something like Ansible's playbooks for this exact scenario. You might also have it setup as a staggered rollout.
doublerabbit•43m ago
Linux is on their second and FreeBSD is on their first. How many is Windows on?
pjmlp•39m ago
Plenty, Microsoft has security teams whose job is to attack Windows.

Naturally they don't do blog posts about what they find.

hnlmorg•32m ago
You talk as if Windows is the only OS that has red teams attacking the system when clearly that isn’t even remotely true.
dwattttt•37m ago
If you think Linux is on their first or second, I'm not sure how or what you're counting.
doublerabbit•21m ago
> I'm not sure how or what you're counting.

The recent two. FailCopy and DirtyFrag and FreeBSD with Execve.

2 - Linux 1 - FreeBSD.

Of course, all OS have had past-time exploits. Three now have made the news.

cyberpunk•39m ago
This is from April 28th, it was patched in 15.0R-p7.
itsthefrank•35m ago
-p8 is the current patch level for 15.0-RELEASE so if people have been keeping on top of patching this is already two reboots in the past.
loeg•24m ago
Just yesterday, cperciva was bragging about the FreeBSD approach to security: https://news.ycombinator.com/item?id=48056853 You can argue the response here was well coordinated, but having an LPE in a core syscall like execve() isn't ideal.
broken-kebab•10m ago
Or in other words, the response is well-coordinated so cperciva's bragging is justified, isn't it?
bch•5m ago
Its like rain on your wedding day - not actually ironic, just unfortunate.