frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Freelancer.svoxx.com – A freelancer marketplace for international projects

https://freelancer.svoxx.com/int/en
1•kilincarslan•1m ago•0 comments

Emacs Liquid Glass

https://github.com/larrasket/emacs-liquid-glass
1•lr0•1m ago•0 comments

Whatnot Live Boost: Seller Analytics, CRM and Tools

https://leliveboost.com
1•listvore•1m ago•1 comments

The dynamics of narcissism in founding teams

https://doi.org/10.1016/j.jbusvent.2025.106569
1•toomuchtodo•2m ago•1 comments

Make AI Boring Again

https://charitydotwtf.substack.com/p/make-ai-boring-again
2•cyndunlop•6m ago•0 comments

The Intercept Sues to Uncover Secretive Government Anti-Protester Database

https://theintercept.com/2026/06/24/intercept-lawsuit-ice-protesters-surveillance-travel/
4•petethomas•6m ago•0 comments

Connect Your AI Agent to Google Sheets

https://quickchat.ai/post/connect-ai-agent-to-google-sheets
1•piotrgrudzien•8m ago•0 comments

Show HN: In-App Events ASO Guide (with 2025 search integration)

https://launchshots.app/blog/app-store-in-app-events-aso-2026
1•okutan•8m ago•0 comments

Jeff Kaplan: World of Warcraft, Overwatch, Blizzard and Future of Gaming [video]

https://www.youtube.com/watch?v=H9rF1CSSh-w
1•tehnub•9m ago•0 comments

Dow Faces Parkinson's Lawsuit over Chlorpyrifos Safety Claims

https://finance.yahoo.com/markets/stocks/articles/dow-dow-faces-parkinson-lawsuit-101415713.html
2•Teever•12m ago•0 comments

Word choice is the most granular level of writing craft

https://medium.com/@thesuperrepemail/the-psychology-of-word-choice-news-and-blogs-af4c1c377762
1•mssblogs•12m ago•0 comments

A Tesla Crashed Through a Harris County Home. Is the Car to Blame?

https://www.readponder.com/essay/a-tesla-crashed-through-a-harris-county-home-is-the-car-to-blame
2•wingdiction•12m ago•0 comments

AI enthusiasts in a race against time, AI skeptics in a race against entropy

https://charity.wtf/2026/06/15/ai-demands-more-engineering-discipline-not-less-xpost/
2•The_Fox•15m ago•1 comments

Show HN: An LLM agent that emits typed intent

https://github.com/gabert/ontocortex
1•gabert•17m ago•0 comments

Straw: Compress big infra into one md file – 99.5% LLM token reduction

https://github.com/ilyesarf/straw/
1•ilyesarf•18m ago•0 comments

U.S. health spending on pace to hit $6T

https://www.statnews.com/2026/06/24/health-care-spending-up-7-point-3-percent-6-trillion-dollars-...
5•brandonb•18m ago•2 comments

Jest/Vitest interactive course (runs in the browser)

https://howtotestfrontend.com/courses/jest-vitest-fundamentals
1•howToTestFE•20m ago•1 comments

Show HN: Dspyer – self-correcting, optimizable LLM steps for DSPy and LangGraph

https://github.com/theramkm/dspyer
1•ramkm•20m ago•0 comments

You Increased Your Prices – Did It Help or Hurt?

1•kingmailer•26m ago•0 comments

Lost Indiana Jones Adventure Discovered [video]

https://www.youtube.com/watch?v=HhTUUmQKmFU
1•austinallegro•27m ago•0 comments

Taiwan Chip Firm ASE Expands for AI Boom

https://fivetakes.news/taiwans-ase-expands-capacity-to-meet-ai-demand
1•mmeirovich•27m ago•0 comments

Bitwarden icons bidirectional C2 channel

https://thecontractor.io/bitwarden-c2/
1•bialyalibaba•27m ago•0 comments

Slop Paralysis

https://elijahpotter.dev/articles/slop-paralysis
2•chilipepperhott•28m ago•0 comments

Show HN: Slick, a desktop client mod for Slack

https://github.com/3kh0/slick
1•Agreed3750•29m ago•0 comments

Astryx – open-source design system customizable and agent ready

https://astryx.atmeta.com/
6•peterhunt•30m ago•0 comments

TopoGlyph: A dual-encoding topological language

https://topoglyph.net
1•zwyld•30m ago•1 comments

Earth to Cosmic Clusters

https://www.facebook.com/share/r/14kyEg4LWNd/
1•Asheed•30m ago•0 comments

Export controls for Fable are too late to slow proliferation

https://dualuse.dev/posts/export-controls-on-fable
1•lebovic•34m ago•1 comments

How your generosity made Weblate better for everyone

https://antennapod.org/de/blog/2026/06/weblate
1•ericdanielski•36m ago•0 comments

I built a fleet-scale inference control plane using Crossplane

https://blog.crossplane.io/building-modelplane/
1•negz•37m ago•1 comments
Open in hackernews

You can see T-Mobile's acquisitions by where its logins are hosted

https://neobotnet.com/blog/cotw-t-mobile
3•caffeinedoom•1h ago

Comments

caffeinedoom•1h ago
Neobotnet runs web reconnaissance data for public bug bounty programs. Each week it reads one public bug-bounty program's surface top-down — DNS, HTTP, JS bundles, URL params — and writes up what the architecture gives away.

The T-Mobile scope isn't one company. It's four acquisitions plus an ad arm, and you can read how far each integration actually got purely from where the login pages are hosted:

    t-mobile-bounty-scope/
    │
    ├── t-mobile.com  ← own apps · MERGED (single Entra tenant)
    │   ├── account.t-mobile.com        Entra / Azure AD · edge Akamai
    │   ├── *.docs.t-mobile.com ×24     Entra — MS "Sign in" page
    │   ├── alm · billerdirect ·
    │   │   dealerorder · phys-access    Azure AD App Proxy (msappproxy.net)
    │   └── sts.t-mobile.com            ADFS — legacy fed · on-net, no CDN
    │
    ├── metrobyt-mobile.com  ← MetroPCS · folded into T-Mobile prepaid
    │
    ├── sprint.com  ← Sprint (merged 2020) · NOT merged
    │   ├── idam.sprintdrive.sprint.com OAuth · still issuing, 5 yrs on
    │   ├── autodiscover.sprint.com     Exchange autodiscover · Outlook
    │   └── assurancewireless.com       Lifeline prepaid · via Sprint
    │
    ├── uscellular.com / uscc.com  ← US Cellular (acq. 2024) · NOT merged
    │   ├── login.uscellular.com        SAML /idp/SSO.saml2 · Cloudflare
    │   └── login-sqa.uscellular.com    QA SAML, public · same edge as prod
    │
    └── blis.com + *.audience.com ×7  ← T-Mobile Advertising / Blis
        ├── imply.t-ads.blis.com        Imply login · T-Mobile Ads
        └── imply.publicis.blis.com     Imply login · Publicis agency
T-Mobile's own apps merged onto one Entra tenant; the companies it bought each kept their own IdP on their own edge, still running side by side. Sprint's identity service is still issuing OAuth flows five years after the merger, and autodiscover.sprint.com still answers with an Outlook title.

Worth stating plainly: across all 107,899 indexed URLs there were no creds, no cloud keys, no PII in parameters. Pretty clean infra so far.

There's a verify-it-yourself deep link under every claim in the writeup. Happy to get into the method, or where the detector's still noisy.

jerlam•1h ago
I think as late as last year, AT&T Prepaid was still using the "paygoonline.com" domain which was an acquisition in 1995.
caffeinedoom•1h ago
fun fact!