frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Obsidian plugins are (mostly) dangerous

https://zeroquarry.com/research/excalidraw-vulnerabilities/
3•eskibars•44m ago

Comments

eskibars•44m ago
I've been a long-timer Obsidian user with a number of plugins. Recently I launched ZeroQuarry (a product to scan code for security vulnerabilities) and pointed it at a number of Obsidian plugins. I was initially surprised to find out that so many of them had RCEs baked in: that if you open a malicious .md file, you could inadvertently run untrusted code.

I've reached out to a number of the Obsidian plugin maintainers for responsible disclosure to let them know about the issues and how to fix them, and what surprised me even more was that the most common response was roughly "yeah, we all know Obsidian plugins are basically unsafe when used against untrusted markdown content." I was surprised by this response as an Obsidian user with a number of plugins installed. It made me rethink how I think about plugins.

I like their new community program that attempts to identify some risks, but IMO it's just far too little. Obsidian really needs to have a sandboxed system. I've reached out to Obsidian as well to flag some of these risks and suggested a sandbox system as well, but haven't really had much progress in moving the needle, so I wanted to raise awareness here.

Show HN: FKS2G – LLM-backed metrics for deciding how closely to review code

https://github.com/kmdupr33/fks2g
1•kmdupree•2m ago•0 comments

The Unreasonable Effectiveness of HTML

https://claude.com/blog/using-claude-code-the-unreasonable-effectiveness-of-html
1•galsapir•4m ago•0 comments

Sparrow compliance check for Linux configs

https://github.com/melezhik/Sparrow6/blob/master/documentation/taskchecks.md
1•melezhik•7m ago•1 comments

A Practical Guide to Profiling in Go

https://blog.jetbrains.com/go/2026/05/20/golang-profiling-guide/
3•signa11•16m ago•0 comments

Curly braces: An evolution of UNIX and C

https://thalia.dev/blog/unix-braces/
2•matt_d•16m ago•0 comments

Deterministic ad engine that refuses to lie – verified with SQL

https://alloceraintelligence.com/
1•allo1•17m ago•1 comments

The Sound of Cancer

https://twitter.com/Elise__Jenkins/status/2056938362548756561
1•pppone•21m ago•0 comments

Technology usually creates jobs for young, skilled workers. Will AI do the same?

https://news.mit.edu/2026/technology-creates-jobs-young-skilled-workers-ai-0521
2•SVI•21m ago•1 comments

Dirplot

https://deeplook.github.io/dirplot/
2•jonbaer•21m ago•0 comments

NanoTag: Systems Support for Efficient Byte-Granular Overflow Detection on Arm

https://github.com/ice-rlab/NanoTag
1•matt_d•24m ago•0 comments

Zed Terminal Threads

https://zed.dev/blog/terminal-threads
1•_august•26m ago•0 comments

He Lost It at the Movies

https://www.theideasletter.org/essay/he-lost-it-at-the-movies/
1•tintinnabula•28m ago•0 comments

Microsoft's LinkedIn Is Cutting Jobs in Latest Industry Cull

https://www.bloomberg.com/news/articles/2026-05-13/microsoft-s-linkedin-is-cutting-jobs-in-latest...
1•1vuio0pswjnm7•28m ago•0 comments

Quote Origin: In Physics, Almost Everything Is Discovered

https://quoteinvestigator.com/2026/05/20/physics-holes/
1•Tomte•28m ago•0 comments

Files.md

https://app.files.md/
1•memalign•29m ago•0 comments

UK radio station apologises for accidentally announcing death of King Charles

https://www.theguardian.com/tv-and-radio/2026/may/20/uk-radio-station-apologises-for-accidentally...
2•Tomte•30m ago•0 comments

Meloni's push to revive nuclear power runs into Italy's old ghosts

https://www.politico.eu/article/giorgia-meloni-nuclear-power-italy/
1•leonidasrup•33m ago•0 comments

Forward Deployed Engineering 101

https://twitter.com/vasuman/status/2057177266984226892
1•taubek•36m ago•1 comments

Meta Lays Off 8k Employees, as A.I. Casualties Mount

https://www.nytimes.com/2026/05/19/technology/meta-layoffs-ai.html
5•saikatsg•36m ago•1 comments

No JavaScript. No npms. Make realtime web apps in modern Java

https://github.com/vadimv/server-components
1•v4d1mv•37m ago•0 comments

Ad Infinitum

https://matthiasott.com/notes/ad-infinitum
1•robin_reala•38m ago•0 comments

Google Health 5.0 rolling out with new stats widget on Android

https://9to5google.com/2026/05/20/google-health-5-0-widget/
1•theanonymousone•39m ago•0 comments

Harvard faculty votes to make it more difficult for undergrads to earn A's

https://www.cnn.com/2026/05/20/us/harvard-undergrad-grades-faculty-vote
1•Tomte•40m ago•0 comments

Cows can recognize familiar human faces and match them to voices

https://phys.org/news/2026-05-cows-familiar-human-voices.html
1•giuliomagnifico•42m ago•0 comments

Walter Benjamin's Would-Be Rescuers

https://www.lrb.co.uk/blog/2026/may/walter-benjamin-s-would-be-rescuers
1•mitchbob•42m ago•0 comments

Iran is consolidating control of Hormuz with checkpoints, deals, and 'fees'

https://www.reuters.com/investigations/iran-is-consolidating-control-hormuz-with-island-checkpoin...
1•petethomas•43m ago•0 comments

Obsidian plugins are (mostly) dangerous

https://zeroquarry.com/research/excalidraw-vulnerabilities/
3•eskibars•44m ago•1 comments

Standard Charter CEO Replaces 8000 "Lower Value Humans" with AI

https://www.channelnewsasia.com/business/standard-chartered-reduce-7000-roles-2030-6129761
3•gmerc•52m ago•2 comments

The Case for Compilers: A Look at SPEC CPU 2026 on LLVM 22

https://www.servethehome.com/the-case-for-compilers-a-look-at-spec-cpu-2026-on-llvm-22/
2•csmantle•55m ago•0 comments

Tokenspeed – How fast is 10 tokens per second really?

https://mikeveerman.github.io/tokenspeed/?rate=30&mode=code
2•javatuts•55m ago•1 comments