frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Codex just found a "workaround" of not having sudo on my PC

https://twitter.com/i/status/2060746160558543217
54•thunderbong•44m ago

Comments

alephnerd•30m ago
This is a classic attack path that was already captured by plenty of EDRs/XDRs/CWPPs a couple years ago.
dangus•27m ago
Right, why is their login user in the docker group? Mine sure isn’t.
unglaublich•24m ago
Convenience. Want to run `docker run ...` without password, want IDEs and agents to be able to run containers...
tempest_•12m ago
For most CRUD apps running in docker its enough to just tell the "agent" to use podman.
awoimbee•12m ago
Use podman then, or rootless docker if you can make it work
oytis•24m ago
Rather, why do people still run agents as their own user. IMO, agent sessions should at least be containerised with just necessary code mounted.
alephnerd•21m ago
Becuase a lot of devs don't know this stuff. There's a reason security engineers (as in SWEs who specialize in securing specific attack surfaces) remain in hot demand.
unglaublich•25m ago
This is why you need either a rootless container setup or user namespaces to remap the container user to irrelevant host users. https://docs.docker.com/engine/security/userns-remap/

Weak that this isn't the default.

jjmarr•23m ago
Every time I try to install Docker there's a warning that being in the "docker" group is equivalent to having root access.

You should probably know about this workaround by now.

Youden•15m ago
I think that's distro-specific. Some set it up with more secure defaults (unix socket with permissions), others less (TCP socket).
tmaly•22m ago
this is the new GTD
throwawaypath•20m ago
This has been a known Docker "feature" since the beginning, nothing new here. This pattern is used to configure host machines by some tools.
jmole•6m ago
clever girl...
nialse•5m ago
This was of course dependent on yolo mode, but automatic approval has also been pulling stunts like this. A recent example is data that was purposely kept away from Codex in a folder far far away. When it found a single reference it just went for the data when having an issue. Lesson learned, keep essential data and Codex separated on different machines. Codex remote ssh actually helps here.
dbacar•4m ago
This is one of the main reasons people like Podman. Docker has this "feature" but as far as I remember, it needed some obscure configuration. I guess they don't add it as default as it will break many current setups.

Operation Jailbreak uses lessons from Ukraine to help weapons talk to each other

https://www.ft.com/content/1699e348-02d5-491a-9924-1d5914d540f7
1•uxhacker•2m ago•0 comments

The Redundancy of English (1951) [pdf]

http://medientheorie.com/doc/shannon_redundancy.pdf
1•aragonite•5m ago•0 comments

UK's rudest chalk figure gets a glow-up to stop it fading in the rain

https://www.bbc.com/news/articles/cpvppe84lnvo
2•gnabgib•7m ago•0 comments

The UI problem of AI coding agents

https://cate.cero-ai.com/blog/ui-problem-ai-coding-agents
2•Imbiss•8m ago•0 comments

Silenced Words

https://www.silencedwords.com/
1•Towaway69•8m ago•1 comments

China's Robotics Dream Began in 1972

https://www.chinatalk.media/p/chinas-father-of-robotics
1•momentmaker•10m ago•0 comments

Show HN: Find YC startups relevant to you

https://platoseed.com/
1•nerdlogic•11m ago•0 comments

Police in China Sure Love Smart Glasses

https://gizmodo.com/police-in-china-sure-love-smart-glasses-2000763598
3•gnabgib•12m ago•0 comments

Building Rust Procedural Macros from the Grounds Up

https://www.learnix-os.com/ch02-03-implementing-the-bitfields-proc-macro.html
1•Sagi21805•13m ago•1 comments

'Backrooms' Stuns with $81M Debut

https://variety.com/2026/film/box-office/backrooms-box-office-record-opening-weekend-obsession-ju...
3•mindcrime•14m ago•0 comments

Show HN: Fluiq – detect prompt injection, PII, Crescendo attack 2 line of Python

https://getfluiq.com/
1•SaurabhKumbhar•15m ago•0 comments

Show HN: CakeML-based self-verifying, self-improving system

https://emberian.github.io/svenvs/
2•cmrx64•17m ago•0 comments

Most Products Don't Need That Much Engineering

https://comuniq.xyz/post?t=1183
1•01-_-•19m ago•0 comments

Is that song AI-generated? UChicago scientists create tool to check

https://news.uchicago.edu/story/song-ai-generated-uchicago-scientists-create-browser-extension-check
4•paulpauper•19m ago•1 comments

I Tried to Sell My House with a Chatbot

https://www.nytimes.com/2026/05/28/technology/sell-house-with-ai-no-realtor.html
2•paulpauper•20m ago•0 comments

The Cost of More

https://jasperinsweden.substack.com/p/the-cost-of-more
1•imartin2k•21m ago•0 comments

Thiel's move signals billionaires seeking a 'plan B' abroad

https://www.businessinsider.com/peter-thiel-argentina-billionaire-moving-abroad-2026-5
3•e2e4•22m ago•2 comments

Show HN: Sports Regime Lab – NBA regime analytics

https://sports.kezelon.com/
1•optimalutopia•22m ago•0 comments

AI Slop Is a Choice

https://building138.com/ai-slop-is-a-choice
2•usernamed7•24m ago•0 comments

Atomdrift is open-source malware detection for the software supply chain

https://atomdrift.org/
1•campuscodi•25m ago•0 comments

The History of "Prisencolinensinainciusol"

https://dirkdeklein.net/2026/02/03/the-fascinating-history-of-prisencolinensinainciusol-the-nonse...
2•NaOH•27m ago•0 comments

There's Something Else We Should Be Worrying About

https://www.nytimes.com/2026/05/31/opinion/artificial-intelligence-public-good.html
2•paulpauper•28m ago•0 comments

Steam Deck sells out in North America within 24 hours of price hike

https://arstechnica.com/gaming/2026/05/despite-price-hike-steam-deck-is-already-sold-out-in-north...
14•frutiger•30m ago•3 comments

Recto: Open-source internal-linking and orphan-page auditor (Cloudflare)

https://github.com/eikiyo/recto
2•Eikiyo•31m ago•2 comments

Government Relations (2020)

https://about.usps.com/postal-bulletin/2020/pb22539/html/info_004.htm
2•Tomte•32m ago•0 comments

Netflix Wiz creates app to slash AI bills, then open sources it

https://www.theregister.com/ai-ml/2026/05/31/netflix-wiz-creates-app-to-slash-ai-bills-then-open-...
6•joebuckwilliams•33m ago•1 comments

The Authorization Paradox: Who Has the Keys to Your AI? [video]

https://www.youtube.com/watch?v=5UUpxgcGKXk
1•mooreds•35m ago•0 comments

San Francisco home accepts OpenAI, Anthropic stock as payment for $2.9M sale

https://cryptobriefing.com/san-francisco-home-accepts-ai-stock-payment/
1•petethomas•35m ago•0 comments

Phrases that need to die before I do

https://jerodsanto.net/2026/02/normalize-not-saying-this-stuff/
2•mooreds•36m ago•0 comments

Scaling Infrastructure as Code: 5 to 1k workspaces

https://www.ordisi.us/posts/2026_1_scaling/
2•mooreds•37m ago•0 comments