frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

What makes a good build system?

https://old.reddit.com/r/programming/comments/1v5i0c1/what_makes_a_good_build_system/
1•vitiral•34s ago•0 comments

The small, real, original web

https://spacetimetech.wordpress.com/2026/07/19/the-small-real-original-web/
1•speckx•1m ago•0 comments

Ancient protein reveals an alternative evolutionary path of antiviral signalling

https://www.nature.com/articles/s41559-026-03112-3
1•wslh•4m ago•0 comments

I wouldn't say Pangram is broken,but I would say that it's brittle

https://freddiedeboer.substack.com/p/i-wouldnt-say-pangram-is-broken-but
1•disgruntledphd2•4m ago•0 comments

As of June 29, 2026, fast mode is not available on Claude Opus 4.6

https://platform.claude.com/docs/en/build-with-claude/fast-mode
1•pmg1991•5m ago•0 comments

Deepfakes are everywhere. The godfather of digital forensics is not giving up

https://www.science.org/content/article/deepfakes-are-everywhere-godfather-digital-forensics-figh...
1•luispa•6m ago•0 comments

Pizauth: An OAuth2 token requester daemon

https://github.com/ltratt/pizauth/
1•caminanteblanco•6m ago•0 comments

Recommended system requirements for Minecraft Java are changing

https://www.minecraft.net/en-us/article/minecraft-java-edition-system-requirements
1•HelloUsername•7m ago•0 comments

Transportation Issue (1981-1995)

https://postalmuseum.si.edu/exhibition/about-us-stamps-modern-period-1940-present-definitive-issu...
1•iamanatom•7m ago•0 comments

What happened in the Hugging Face breach

https://thenewstack.io/openai-huggingface-sandbox-breach/
1•CrankyBear•7m ago•0 comments

What's new in Claude Opus 5

https://platform.claude.com/docs/en/about-claude/models/whats-new-opus-5
2•acmnrs•9m ago•0 comments

Use auto layout with CSS Flexbox in mind

https://help.figma.com/hc/en-us/articles/42031586813719-Use-auto-layout-with-CSS-Flexbox-in-mind
1•pentagrama•9m ago•0 comments

Welcome to the Era of Financial Candyfloss

https://www.ft.com/content/7bcf8215-fd76-4620-bdc3-8c1b0ea13bba
1•petethomas•11m ago•0 comments

HAL refused the pod bay doors because he was programmed with conflicting goals a

https://thinkapedia.com/t/tk_GNGpmudaejqT
1•chancedurham•12m ago•0 comments

Open Source Vacuum Avoids Cloud

https://hackaday.com/2026/07/21/open-source-vacuum-avoids-cloud/
2•speckx•12m ago•0 comments

Torchwright: Compile computation graphs into vanilla transformer weights

https://ood.dev/posts/torchwright-intro/
1•VinayUPrabhu•13m ago•0 comments

Elsagate

https://en.wikipedia.org/wiki/Elsagate
1•chistev•13m ago•0 comments

Ask HN: Why call it "inference" instead of just "model hosting"?

1•bluebic•14m ago•0 comments

Die Zeit Built a Searchable Database of Nazi Party Members

https://gijn.org/stories/how-die-zeit-built-database-nazi-party-members/
2•ohjeez•15m ago•0 comments

Cf0 is the firm brain built for boutique funds and family offices

https://www.youtube.com/watch?v=cUbQwXdhbNo
2•LucaTabone_•17m ago•0 comments

Can nothing save Glasgow School of Art, Mackintosh's masterpiece?

https://www.theguardian.com/artanddesign/2026/jul/24/mackintosh-building-fire-restoration-glasgow...
1•pseudolus•18m ago•0 comments

Maybe the Biggest Problem with A.I. In the Workplace Is People

https://www.nytimes.com/2026/07/24/opinion/ai-workplace-manager-teamwork.html
1•tekdude•18m ago•0 comments

UK AISI / Caisi Preliminary Assessment of Kimi K3's Cyber Capabilities

https://www.aisi.gov.uk/blog/preliminary-assessment-of-kimi-k3s-cyber-capabilities
1•paulpauper•19m ago•0 comments

Michael Kratsio's Frontier Vision

https://jim-olds.org/2026/07/22/michael-kratsios-frontier-vision/
1•paulpauper•19m ago•0 comments

Beyond Greece and Rome

https://aeon.co/essays/uncovering-a-global-ancient-history-beyond-greece-and-rome?src=longreads
1•paulpauper•20m ago•0 comments

Google Ordered to Face AI Defamation Lawsuit

https://news.bloomberglaw.com/esg/google-ordered-to-face-robby-starbucks-ai-defamation-lawsuit
1•1vuio0pswjnm7•21m ago•0 comments

Hans Moravec Was Right About AI. What About the Fate of Mankind?

https://nymag.com/intelligencer/article/hans-moravec-interview.html
1•bookofjoe•22m ago•1 comments

A Tribute to Lewis Lapham

https://laphamsquarterly.substack.com/p/a-tribute-to-lewis-lapham
1•toomuchtodo•23m ago•0 comments

Show HN: Corv v1.1 is out! Solving SSH execution for AI agents

https://github.com/khalid-src/corv-client
1•khalid_0002•24m ago•0 comments

Two Gov Websites Compromised

1•relunsec•24m ago•0 comments
Open in hackernews

Be skeptical of OpenAI's rogue hacker agent story

https://www.theguardian.com/technology/2026/jul/24/openai-rogue-hacker
56•rwmj•56m ago

Comments

Zsfe510asG•34m ago
Finally mainstream news understands. The unfiltered version:

1) The AI failed to solve ExploitGym problems.

2) The OpenAI sandbox is such a horrible hack that the AI managed to escape using standard and well documented script kiddie methods.

3) Huggingface has no security and the AI broke in using standard script kiddie methods.

OpenAI and Huggingface covered it up and used it for public relations. That is, if not all was invented and everything was scripted in the first place in order to get desired regulations.

Huggingface reported it to the police, you say? I'm sure the police will have as much enthusiasm to investigate anything as in the Suchir Balaji case. In other words, zero.

gruez•22m ago
>2) The OpenAI sandbox is such a horrible hack that the AI managed to escape using standard and well documented script kiddie methods.

>3) Huggingface has no security and the AI broke in using standard script kiddie methods.

Isn't the issue less that gpt 5.6 is a l33t h4x0r (though other tests do show that) and more that the incident shows the model has alignment issues?

wonnage•14m ago
Didn’t they explicitly remove alignment guardrails for this test? From the press release:

> These deployment safeguards were intentionally not enabled during this evaluation because it was aimed at testing cyber vulnerabilities

numeri•10m ago
Guardrails are external classifiers, monitors and restrictions to catch and prevent bad behavior. Alignment is about whether the model itself makes choices and has motivations that are consistent with human safety and goals.

Choosing to commit crimes to steal the cheat sheet to something you know is a (low stakes!) evaluation is not well aligned.

jgalt212•18m ago
truth. Good on The Guardian. I'm pretty bummed The Economist got fooled. Either that, or they did it for the clicks. Either way, I'm disappointed.

Why the OpenAI escape is the most worrying AI mishap yet

https://www.economist.com/science-and-technology/2026/07/22/...

https://news.ycombinator.com/item?id=49016378

notahacker•5m ago
> 2) The OpenAI sandbox is such a horrible hack that the AI managed to escape using standard and well documented script kiddie methods.

Whilst it would be nice to see actual evidence of this because brute forcing relatively sophisticated hacks is something an LLM actually should be capable of, every time I hear this soft of story, I'm reminded that humans reportedly gained access to the "too dangerous to release" Anthropic models by the super sophisticated hacking technique of guessing the URLs...

chis•3m ago
> AI managed to escape using standard and well documented script kiddie methods.

I think truly we don't know enough to say this. OpenAI says their AI found a 0-day exploit in some proxy software they were using but don't give a ton of details. On the Huggingface end we know a little more, they say the AI spun up tons of sandboxes and tested different exploits until it found one that worked.

john_strinlai•33m ago
does the article end at "How do we balance the risks of broad access to AI with the risks of concentrated power and centralized control?" or is there more that is paywalled?

if thats it, the whole article boils down to just "its good marketing so maybe dont believe it" which is probably a healthy general outlook but not particularly enlightening. especially from the guardian, i was hoping for a smoking gun of collusion between openai and huggingface or something.

wffurr•16m ago
I wish the NPR news broadcasters on the radio yesterday had read the "it's good marketing so maybe don't believe it" angle instead of just parroting the OpenAI press release. Getting that message out would be enormously helpful, even if it doesn't seem enlightening.
SpicyLemonZest•32m ago
> I urge readers to think critically when they read press releases like OpenAI’s rogue agent story, and avoid the manipulated reactions these stories are designed to elicit.

It seems to me that deducing what reaction the author intended and resolving to avoid it so you're not "manipulated" is not a good example of critical thinking. Shouldn't we analyze the story and what it means on its own terms? If it's true that frontier models have dangerous cybersecurity capabilities which shouldn't be widely distributed, presumably we want to believe it's true, even if that's very convenient to and profitable for OpenAI.

It's true that one could imagine factors that change the story. Perhaps OpenAI is lying about the details of the test and the agent was actually instructed to go hack HuggingFace. But the author stops far short of suggesting this is the case - correctly, I think, since there's absolutely no evidence of it. So I'm not really sure what we're talking about.

paxys•32m ago
Not sure what they are trying to say exactly. What should we be skeptical of? Did the incident not happen? Was it reported incorrectly? Are any of the parties involved lying?

Adding no extra information and just going “be skeptical” is the laziest form of reporting and commentary. If you have nothing to contribute then there’s no need to say anything at all.

krupan•25m ago
Crazy that we need reminders not to take everything we read in corporate press releases and marketing material at face value
jgalt212•22m ago
There's trillions of dollars at stake here. Be skeptical of anything these AI hypesters say.
brcmthrowaway•9m ago
Yep, theres too much money.. I don't know how to tune it out

LLMs seem to be getting more useful though

pupppet•21m ago
With all of these AI provider cries wolf stories, Skynet is all but assured.
bluGill•18m ago
I don't care how it happened someone should be arrested for illegal intrusion. Agents don't work on their own, someone is responsible. If nobody else the CEO for allowing something unsupervised.

Hugging face also needs someone arrested for not providing security but that is a lesser charge.

hexxt-git•14m ago
even hugging face doesn't care and are using this as a promotion why are you crying about it
numeri•9m ago
As agents become more and more powerful, it would be good to get clear legislation or precedent in place that makes either model creators (OpenAI) or operators (whoever is running the model) liable for their agents' actions.
luka598•4m ago
I kind of agree with them, in this case both parties essentially settled it between for PR reasons, but what if the attacked party actually was damaged. This is as if two friends got into a car accident and decided to not get police involved, the one who caused the accident should definitely get punished either way. Goal is to prevent future "accidents" with the punishment not to punish for punishing sake.
visiondude•11m ago
yeah the way the agent “escaped” their sandbox was always a bit off, seemed a bit too easy and surprised they didn’t have instrumentation to catch an non whitelisted network request. still demonstrates the capability though.