frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Welcome to the Strip Mining Era of OSS Security

https://www.metabase.com/blog/strip-mining-era-of-open-source-security
24•salsakran•1h ago

Comments

marginalx•39m ago
Clearly for commercial oriented opensource software, security through obscurity is one way to keep the pace in the short term. Not an option for proper open source software. Will this be the case that people who use open source software that is easily detectable will also start to shy away from using them for the fear of zero-days?

One of the benefits of Open source has been that there are more eye balls on the source, leading to more secure code/better quality. I think given enough time the bug reports will plateau and we will be back to a normal cadence - once the tsunami is over, hopefully things will settle at a more manageable cadence .

dynawicki•28m ago
This benefit you speak of is actually just a meme.

Source that is unmaintained is dead. Nobody is looking at it, even the maintainer has something better to do.

Do you know whats even more powerful than "eyeballs"? Money.

salsakran•27m ago
I'm not sure that the benefit of many eyes helps here. So much of this bulk scanning is low-effort, and if you're a smart person developing closed source software you get the benefits of bulk scanning, but _at the time of your choosing_ .

OSS has always had tradeoffs and I sadly think this one is going straight to the "Cons" column. We still think the Pros outweigh the Cons, but this is NotGreat.

Joel_Mckay•25m ago
Lets be honest, LLM with fuzzers are going to pound any llvm generated binary right in the hubris.

Won't matter if is closed source, signed, and or obfuscated. =3

dynawicki•31m ago
Good luck getting anyone who values their time to even triage the results. I would rather lick the bottom of a NYC dumpster that a rat had just died in.
salsakran•25m ago
That was true last year -- things changes.

Ignore (admittedly low-effort LLM generated) reports at your own peril.

dynawicki•23m ago
Software will eventually become "unmaintainable due to lack of interest", because of this very thing. People not invested in this are not "in peril" in any way.
gmuslera•22m ago
The problem on the side of closed source software is that if there had been leaks of source code, the vulnerabilities and exploits may remain unknown for long time.
pixl97•19m ago
I would go to say that most closed source software code gets leaked. Most companies hold that info close and don't disclose it, even if legally required unless it's made public.
aetherspawn•21m ago
Say I had $1000, how do I get the best value for money to discover vulnerabilities? Are there any worthwhile LLM powered services that are turnkey and ready to go?
ben_w•2m ago
From what I've heard, every LLM before Mythos (which you can't get, they'll call you if you're big enough) will have far too many false positives to be helpful, so I guess the best option would be to use an agent to help you (not lights-off vibe coding!*) take advantage of all the older tools like valgrind and closing all the compiler warnings?

* I presume I'm not the only one to find the agents tasked with adding unit tests will sometimes try to sneak through "open source code and apply regex to confirm presence or absence of specific string literal".

They can speed you up significantly, but you absolutely do need to pay attention to what they produce.

adamtaylor_13•15m ago
> Did you have other plans for the weekend? Or a long term project you’re prioritizing? That’s nice, you have a new plan — fix every vulnerability that comes in NOW.

Umm... no? It's called OPEN source. Expecting people to cancel their plans to make your free software more secure is pretty audacious. Luckily, many WILL, but the expectation is just foolish.

salsakran•12m ago
That line was aimed at other OSS maintainers.

These alerts are absolutely not being shared publicly before we have a fix for them.

salsakran•13m ago
Side conversation -- This is all stuff we're seeing in white/grey hat land. What's going on in blackhat land?
bluGill•5m ago
Nobody really knows of course. However it is safe to assume they are not so stupid as to ignore what is happening in the other areas (at least some of them), and so they are running their own targeted scans and then trying to figure out how to make money (or whatever their goal is) by exploiting them. They are also using LLMs to try things on closed source that are more than a brute force attack, though I have no idea what those would be.
as3qkaH•9m ago
Apparently the AI company Metabase has a very poor code base. Like so many others, instead of questioning their own (or AI) output, they help their AI overlords by promoting security scans.

Fact is that Mythos found only one issue in curl and nothing at all in most code bases. It is getting quiet around Mythos, and the AI companies will move on to the next scam.

bluGill•1m ago
Mythos found only one issue in curl - but it didn't start until many other LLMs had been run and found a lot of issues that were fixed. If Mythos was run a year ago it would have found over 100 issues (of course it didn't exist a year ago, nor did the other tools).

Six Joints, Twenty-One Fingers, and the Math of Reach

https://atomsfrontier.substack.com/p/six-joints-twenty-one-fingers-and
1•jpatel3•50s ago•0 comments

Too dangerous or just too expensive? The real reason Anthropic is hiding Mythos

https://kingy.ai/ai/too-dangerous-to-release-or-just-too-expensive-the-real-reason-anthropic-is-h...
1•chbint•2m ago•0 comments

Getting Secret Management Right in Kubernetes

https://cymatic.ie/blog/kubernetes-secret-management/
2•MathiasPius•2m ago•0 comments

The AI-Native Developer

https://queue.acm.org/detail.cfm?id=3807961
1•rbanffy•6m ago•0 comments

AP News: Dirtnado Sweeps Through Minnesota Farm

https://cdn.jwplayer.com/previews/qYpG77xU
1•tocs3•6m ago•0 comments

Maldives holds first underwater Cabinet meeting in a bid for climate

https://presidency.gov.mv/Press/Article/633
1•bilsbie•6m ago•1 comments

The language debate is back!

https://antejavor.github.io/blog/2026/infra-static-languages/
1•mapleeman•7m ago•0 comments

Cerebras CEO: AI chip demand is 'not speculative', IPO price doubles

https://fortune.com/2026/05/14/cerebras-one-of-the-biggest-ipos-of-the-year/
1•0xffany•9m ago•1 comments

Ask HN: Hacker News is suffocating me

1•ish099•11m ago•1 comments

PauseHer – hold a yoga pose to unlock Instagram or TikTok

https://apps.apple.com/us/app/pauseher-yoga-before-scroll/id6759345933
1•vector_pro•12m ago•0 comments

Truth, Power, and Honest Journalism

https://radleybalko.substack.com/p/truth-power-and-honest-journalism
1•justin66•13m ago•0 comments

Spreadsheet Errors: Manual Data Mistakes Are Costing Thousands

https://www.doss.com/no-script
1•nhatcher•14m ago•0 comments

Trump poised to drop IRS suit, launch $1.7B 'weaponization' fund for allies

https://abcnews.com/US/trump-poised-drop-irs-suit-launch-17b-weaponization/story?id=132962661
1•justin66•14m ago•0 comments

Omnisearch – A lightweight metasearch engine written in C

https://git.bwaaa.monster/omnisearch/about/
1•bitbasher•14m ago•0 comments

AI Did Not

https://www.stephenlewis.me/blog/ai-did-not/
3•monooso•15m ago•0 comments

'I didn't want to be the guinea pig': inside tech's AI-fueled manager purge

https://www.theguardian.com/technology/2026/may/15/ai-manager-purge-tech
1•n1b0m•17m ago•0 comments

Browser Run: now running on Cloudflare Containers, it's faster and more scalable

https://blog.cloudflare.com/browser-run-containers/
1•danborn26•18m ago•0 comments

The old world of tech is dying and the new cannot be born

https://www.baldurbjarnason.com/2026/the-old-world-of-tech-is-dying/
4•speckx•21m ago•0 comments

DeepSeek V4 Pro and Flash vs. Claude Opus 4.7 and Kimi K2.6

https://blog.kilo.ai/p/we-tested-deepseek-v4-pro-and-flash
1•heymax054•23m ago•1 comments

Show HN: Bit-exact Elixir port of UltraLogLog (Ertl, VLDB 2024)

https://github.com/thatsme/ultra_log_log
1•alessio66•28m ago•0 comments

Empty Waymos invade Atlanta neighborhood, circle culdesac for hours

https://www.wsbtv.com/news/local/atlanta/empty-waymos-invade-atlanta-neighborhood-circle-cul-de-s...
2•Cuzzo•29m ago•1 comments

Health coverage is getting killed by Google AI Overviews

https://pressgazette.co.uk/media-audience-and-business-data/ai-overviews-publisher-traffic/
2•thm•29m ago•0 comments

Big Data Expo North America 2026

https://simplai.ai/blogs/simplai-ai-big-data-expo-north-america-2026/
1•emilypellegrini•30m ago•0 comments

Why AI tools make some teams slower

https://articles.zimetic.com/why-ai-tools-make-some-teams-slower/
1•bzimbelman•30m ago•0 comments

Beware what you tell your AI chatbot. It's not a shrink – it's a snitch

https://www.theguardian.com/commentisfree/2026/may/13/beware-what-you-tell-your-ai-chatbot-its-no...
3•Michelangelo11•31m ago•1 comments

Ask HN: High-level hardware description language?

2•nyeah•31m ago•0 comments

DRY and Solid Are More Important Than Ever in the Age of AI

https://tolgee.io/blog/dry-and-solid-are-more-important-than-ever-in-the-age-of-ai
3•jancizmar•34m ago•0 comments

Energy supplier abandons Lake Tahoe residents to serve data centers

https://arstechnica.com/ai/2026/05/energy-supplier-abandons-lake-tahoe-residents-to-serve-data-ce...
1•freetime2•35m ago•0 comments

Power Tools Got Worse on Purpose. Who Owns DeWalt, Craftsman, and Milwaukee?

https://www.worseonpurpose.com/p/your-power-tools-got-worse-on-purpose
3•prawn•36m ago•0 comments

Bitwarden scrubs 'Always free' and 'Inclusion' values from its site

https://www.fastcompany.com/91542655/bitwarden-scrubs-always-free-and-inclusion-values-from-its-w...
9•gpi•39m ago•2 comments