frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Show HN: React Library for Datacentres

https://react-networks-lib.rackout.net/racks
1•matt-p•2m ago•0 comments

Redline: The Universal Reaction Budget

https://travislwatson.com/redline.html
1•airhangerf15•4m ago•0 comments

Show HN: Stonn, a federated civil/terrain viewer

https://stonn3d.com/
1•oscarcp•5m ago•0 comments

The Most AI-Friendly UI Frameworks – Summer 2026

https://twitter.com/sethltx/status/2065105437750337910
2•sethlivingston•5m ago•0 comments

The current impact of AI on engineering velocity

https://newsletter.getdx.com/p/the-current-impact-of-ai-on-engineering
1•gmays•7m ago•0 comments

NASA's X-59 Aircraft Flies Supersonic for First Time

https://www.nasa.gov/aeronautics/x-59-first-supersonic-flight/
1•woodwireandfood•7m ago•0 comments

Windows 1.0 and the WinAPI, 40 Years Later

https://medium.com/@stassaf.uae/windows-1-0-and-the-winapi-40-years-later-abaf64832918
2•jhack•8m ago•0 comments

Claude Fable 5 costs $10/$50M tokens – what that means in production

https://costlens.dev/blog/claude-fable-5-pricing-production-costs
1•j_filipe•8m ago•0 comments

The Fonts of the U.S. Federal Courts

https://daringfireball.net/2026/05/the_fonts_of_the_us_federal_courts
1•rayiner•9m ago•0 comments

Solar generates more energy in US than coal for first time

https://www.theguardian.com/us-news/2026/jun/11/solar-energy-us-coal
15•neilfrndes•13m ago•2 comments

Introducing Waymo Premier, an elevated rider experience

https://waymo.com/blog/2026/06/waymo-premier/
2•boulos•13m ago•0 comments

Fable on Humanity

https://twitter.com/MathiasChu/status/2064493902271262809
1•jger15•13m ago•0 comments

Herzog and de Meuron transforms mountain antenna tower into "iconic sculpture"

https://www.dezeen.com/2026/06/11/herzog-de-meuron-titlis-tower/
2•johanam•14m ago•0 comments

Build a Basic AI Agent from Scratch

https://www.ruxu.dev/articles/ai/build-a-basic-ai-agent/
1•scapecast•14m ago•0 comments

Self-Harness: Harnesses That Improve Themselves

https://arxiv.org/abs/2606.09498
2•0xkvyb•17m ago•1 comments

Show HN: Basepanel, a Postgres, MySQL, and SQLite Editor for iOS and Android

https://www.basepanel.com/
1•rc318•17m ago•0 comments

.NET 11 Preview 5 is now available

https://devblogs.microsoft.com/dotnet/dotnet-11-preview-5/
1•Fervicus•19m ago•0 comments

The RCE that AMD wouldn't fix

https://mrbruh.com/amd2/
7•MrBruh•19m ago•1 comments

Claude Fable 5: mid-tier results on coding tasks

https://www.endorlabs.com/learn/claude-fable-5-mythos-grade-hype
2•bugvader•19m ago•0 comments

How the Heck Do Traffic Lights Work?

https://perthirtysix.com/how-the-heck-do-traffic-lights-work
2•gmays•20m ago•0 comments

Single File Virtualenv-Native Sandboxed Python Execution Environment

https://github.com/nzjrs/sandbubble
1•nzjrs•22m ago•1 comments

Filterin – A LinkedIn Browser Extension

https://github.com/pPyrius/Filterin
1•Balt000•22m ago•1 comments

MTG Bench: Testing how well LLMs can play magic

https://mtgautodeck.com/articles/mtg-bench/
2•CallumFerg•22m ago•0 comments

America's Most Successful Immigrants

https://www.forbes.com/sites/alexknapp/2026/06/10/forbes-250-americas-most-successful-living-immi...
2•shadag•24m ago•3 comments

How to Block Some of the Bots

https://nochan.net/b/Internet-Crap/20260606-How-To-Block-Some-Of-The-Bots/
2•Bender•24m ago•1 comments

Southpay Ledger – self-serve double-entry ledger API for fintech products

https://www.southpay.io/ledger/
1•tommyrsd•24m ago•0 comments

Show HN: Multi Agent World Cup Simulator

https://github.com/tantara/worldcup-sim
1•tantara•24m ago•0 comments

First tablet version of weight-loss jabs to be available in UK in weeks

https://news.sky.com/story/first-tablet-version-of-weight-loss-jabs-to-be-available-in-uk-in-week...
2•austinallegro•25m ago•0 comments

Don't Conflate Intelligence with Value

https://www.christianitytoday.com/2025/07/dont-conflate-intelligence-with-value/
2•thatoneengineer•25m ago•0 comments

Samsung's SSD warranty policy scammed me so I'm taking them to court [video]

https://www.youtube.com/watch?v=WpPIW4aeeag
1•richardboegli•26m ago•0 comments
Open in hackernews

AMD Gaslights Security Researcher, Changes Rules Retroactively [video]

https://www.youtube.com/watch?v=4HjWHNLRMB0
22•SockThief•1h ago

Comments

Bender•1h ago
The discussion the video references [1]

[1] - https://news.ycombinator.com/item?id=46906947

scw•46m ago
The original post [1] now includes an update:

  UPDATE! Within a day of this blowing up on Hacker News, AMD reached back 
  out to me and said they would be looking into the matter after all.
[1] https://mrbruh.com/amd2/
tptacek•1h ago
AMD didn't deny it was a vulnerability; they denied it was in the scope of the bounty program.

Remember that at giant tech companies, the incentive is to pay out bounties --- there are people on the vendor's team whose performance is measured in part by how much the program pays out.

odyssey7•1h ago
What hair is this splitting? The issue was that AMD allowed a known and serious security vulnerability to exist within their customers’ systems, for months, and acted with a lack of candor while doing so.
tptacek•57m ago
It's not hair-splitting; it's central to the idea of a bug bounty. Too many people have weird ideas about what bug bounties are for.
Hizonner•45m ago
Yeah, like the weird idea that those programs are intended to in some way reduce the number of exploitable bugs actually out there.
tptacek•36m ago
That's in fact often not their core purpose!
JumpCrisscross•30m ago
What is it?
Hizonner•21m ago
... which is why the rest of us should give them, and those who operate them, zero respect.

Nobody but AMD gives a fuck about AMD's internal policies or motivations.

sakkura
sakkura•49m ago
Such a bug could have been exploited by certain big state actors.

Those that have access to international network links.

Those that have the ability to generate new firmware that simply passes the CRC32 checksum.

bri3d•36m ago
Actual write-up rather than overwrought YouTube drama: https://mrbruh.com/amd2/

A non-default-installation set of AMD tools (Ryzen Master and probably others) had an auto-updater which used HTTP instead of HTTPS. It's clear this is a feature they'd basically forgotten about; it even pointed to an ATI domain. A third-party bug bounty company rejected it because MITM was out of scope. AMD are incompetent at making software (news at 11), kept asking for extensions, and took an incredible amount of time to deal with it. Eventually they removed this updater entirely and replaced it with one in the app (rather than the installer) that uses HTTPS + a CRC32 (for some reason). The initial vuln was very stupid and should have been fixed faster. As for the current system, if you're mad about HTTPS-protected auto-updaters (which is valid), you've probably got a lot of them to go to war against.

thesuitonym•13m ago
Gaslighting does not mean lying.
•
45m ago
They wanted to keep it quiet. As if they did not mind if it was exploited by those with access to international network links.