frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

UK could force phone companies to add 'anti-theft protections'

https://www.bbc.com/news/articles/ckqxvy98x578o
1•electrum•30s ago•0 comments

Using jev to improve product experiences is pretty crazy

https://www.elvex.com/blog/early-experimentation-using-jev-to-rethink-harness-ux
3•sak84•4m ago•2 comments

What I learned from using FreeBSD as a main OS for a summer

https://divanv.com/post/adventures-in-bsd/
1•divanvisagie•4m ago•0 comments

A Lack of Honesty Is the Ultimate Killer

https://phillipspobrien.substack.com/p/a-lack-of-honesty-is-the-ultimate
1•JumpCrisscross•6m ago•0 comments

Ask HN: What do you think of Noul, a new decision primitive

1•hbarka•7m ago•0 comments

Wealth Taxes Can Make Capital Markets More Efficient

https://www.promarket.org/2026/09/14/wealth-taxes-can-make-capital-markets-more-efficient/
4•paimapi•7m ago•0 comments

German Hospitals Prepare for War, Drones and Mass Casualties

https://www.bloomberg.com/news/features/2026-09-16/germany-s-hospitals-prepare-for-war-and-mass-c...
1•vrganj•8m ago•1 comments

Meta Muse Hits #1 in Apple App Store

https://www.businessinsider.com/meta-muse-personal-ai-agent-top-app-store-charts-2026-9
2•pizzathyme•9m ago•0 comments

You need more than just vanilla RAG

https://medium.com/@NikoZero11/your-rag-pipeline-doesnt-need-more-retrieval-it-needs-better-decis...
2•Savanjj•10m ago•0 comments

Claude Code now reads AGENTS.md if there is no Claude.md

https://code.claude.com/docs/en/changelog
4•datadrivenangel•10m ago•2 comments

Your 401(k) Is Propping Up the AI Bubble

https://www.promarket.org/2026/05/05/your-401k-is-propping-up-the-ai-bubble/
2•paimapi•10m ago•0 comments

PHP, on a Whim #2: Stop Calling Everything an Array

https://carthage.software/en/blog/article/PHP-on-a-Whim-2-Stop-Calling-Everything-an-Array
1•spacebuffer•10m ago•0 comments

Fat Bear Week 2026

https://explore.org/fat-bear-week
1•slater•13m ago•0 comments

Automattic names interim CFO after exec departures

https://techcrunch.com/2026/09/18/automattic-names-interim-cfo-after-exec-departures/
1•cdrnsf•14m ago•0 comments

What is a System One model and why we need it?

https://stackness.dev/blog/what-is-a-system-one-model-and-where-does-it-go-in-your-stack
1•gosen•15m ago•0 comments

Show HN: ReacherX – Open-source platform to find and reach the right people

https://github.com/VecterAI/reacher-x
1•noobships•15m ago•0 comments

Sam Altman to brief UN Security Council next week

https://www.reuters.com/business/openais-sam-altman-to-brief-un-security-council-next-week-during...
1•vertigoruntime•15m ago•1 comments

Silex: Laser Enrichment Between Promise and Proliferation Risk

https://nuclearnetwork.csis.org/silex-laser-enrichment-between-promise-and-proliferation-risk/
2•looofooo0•19m ago•0 comments

Quantum computers will not be that different

https://arxiv.org/abs/2609.19639
1•bober132•20m ago•0 comments

Single player games require age verification if they use Steam under EU KIDS Act

https://www.rockpapershotgun.com/single-player-games-might-require-age-verification-if-they-use-s...
2•righthand•21m ago•1 comments

A solo founder runs a five-continent tender platform on AlloyDB and MCP

https://cloud.google.com/blog/products/databases/solo-founder-runs-a-global-tender-platform-on-al...
1•Davorjerkovic•22m ago•0 comments

Trump Announces Ban of CNN, Politico and MS Now from White House

https://time.com/article/2026/09/18/trump-bans-3-news-organizations-from-white-house/
9•throw0101c•24m ago•2 comments

Using Cyber Decoys to Strengthen Detection and Response

https://www.cisa.gov/resources-tools/resources/using-cyber-decoys-strengthen-detection-and-response
2•mr_hedrick•24m ago•1 comments

Show HN: 3D World Explorer and Location Guesser Game

https://explorer.tadget.net/
1•ramzis•24m ago•0 comments

Saying Goodbye to Firebug (2017)

https://hacks.mozilla.org/2017/10/saying-goodbye-to-firebug/
1•mohamedmohey•28m ago•1 comments

Jev's Architecture Unmasked

https://archerhume.com/posts/jevs-architecture-unmasked/
2•adamveld12•28m ago•0 comments

Senior Engineers Are the Next DRAM Shortage

https://blog.herlein.com/post/build-another-engineer/
15•gherlein•30m ago•9 comments

SR-71's "R2-D2" Could Be Key to Winning Future Fights in GPS Denied Environments

https://www.twz.com/17207/sr-71s-r2-d2-could-be-the-key-to-winning-future-fights-in-gps-denied-en...
3•monomania•34m ago•1 comments

Terence Tao: SAIR's Open Math Model Initiative [video]

https://www.youtube.com/watch?v=PZRb6NIki2w
1•looofooo0•36m ago•0 comments

California governor signs order to explore AI kill switch

https://techxplore.com/news/2026-09-california-governor-explore-ai.html
2•mdp2021•36m ago•1 comments
Open in hackernews

Korea raises data breach fines to 10% of revenue

https://www.koreajoongangdaily.com/business/korea-raises-data-breach-fines-to-10-of-revenue/12869899
143•throw7•1h ago

Comments

quickthrowman•43m ago
I would like to make a wager on this law being ignored the first time Samsung or another chaebol violates it and is facing a fine equal to 10% of revenue. I can almost guarantee it, it’s a high enough fine to turn some low-margin businesses from profitable to unprofitable for the year and there’s no such thing as a secure computer system. The only way to guarantee compliance is to not store any data which isn’t exactly reasonable for some business models.
buellerbueller•39m ago
Maybe those specific business models shouldn't exist, if they consistently risk harm to 3rd parties.
google234123•38m ago
You legally have to hold transactions for years yk as a business
google234123•39m ago
Probably a law targeted at foreign companies
Retro_Dev•5m ago
I especially hope this holds true, because I don't want my information being leaked by anyone.
Retro_Dev•7m ago
> there’s no such thing as a secure computer system

Where is your source for this? It is entirely possible to make a secure computer system, though it does require effort. The article specifically mentions "up to" 10% and the fines applying to companies leaking data on purpose or through negligence. I doubt the fines will be nearly as high for a company that tries to secure a system (and thus prevents more leaks) rather than a company that does not try to secure a system (assuming that leaks will occur), if the same breach happens.

Computers are deterministic (excluding cases where practically impossible cosmic ray events occur), so while we have the power to ensure system security, we should ensure system security. Heck, even just encrypting consumer information and protecting just the keys to this data would already decrease the effectiveness of many data breaches.

prologic•40m ago
Wow! :O Finally, a legislator with enough balls to put up something that _might_ (just might) make corporations _actually_ care about security and privacy! I can't wait for this to start being adopted in other countries. It's about time!
augment_me•35m ago
Or you get some shell firm/subsidiary to hold your data and no difference is made
jmclnx•38m ago
Sounds great if all the following is true.

* Before Tax Revenue

* If the company is owned by another company, the revenue is the total of all companies owned by the highest level parent.

* Includes Worldwide Revenue

* Includes companies based in all other Countries.

I would have went for 20%, but if he above applies I wish the US would do the same.

augment_me•38m ago
You can just do what my university did, hire a small shell firm with 3 employees to hold all your data, and when it got hacked they just went bankrupt and we switched to a new shell firm with similar form and function.

Minimizes money usage and does not require any security investments

louthy•35m ago
Or … and hear me out on this one … care?
augment_me•34m ago
Sounds like something that costs money, if a university doesn't care I don't think most companies will.
louthy•32m ago
Yes, being competent requires effort.

It certainly feels much better being an proactive member of society rather than a self-serving arsehole though.

So, there is that.

nostrademons•25m ago
It feels better only as long as everybody else cares too. Being the only one competent in a room of imbeciles is a terrible feeling.

Hmm, this is perhaps why we get socially-negative businesses that often have very friendly (and driven, and hard-working, and intelligent) internal cultures. Competency becomes a fault line. When it becomes obvious that a large fraction of humanity just doesn't give a shit, a small group of people who are competent and driven turn their efforts to taking advantage of people who don't give a shit. Thus creating industries like market-makers, cryptocurrency, advertising, and AI.

SoftTalker•36m ago
"through intent or gross negligence"

I'm not familiar with Korean law but that seems a rather high bar. I don't think we'll see many fines actually levied.

bluGill•8m ago
The hope is they levy few fines. When you want to make money you set the fines such that they are "a cost of doing business". Most often you don't even call them fines, you call them a permit/license fee (though fines are also common). When you want to prevent a behavior you make the costs high enough that it is worth the effort to not pay them in the first place.

(I'm assuming here that 10% is high enough that nobody would call it a cost of doing business - I could be wrong)

rectang•32m ago
It's childish of me I know, but if this actually goes through I will feel a twinge of delight at the refutation of all the HN commenters who have argued that such enforcement is unrealistic.
esafak•12m ago
The EU AI Act already levies 7% global annual turnover penalties for prohibited AI practices.
ggarnhart•15m ago
This feels like a really odd way to incentivize data breaches and/or not reporting data breaches.
Retro_Dev•11m ago
Um, I think it does the opposite of what you are suggesting - this aims to reduce data breaches and incentivize people to prevent these breaches.
happytoexplain•13m ago
Higher.
louthy•15m ago
> It feels better only as long as everybody else cares too.

Not sure who “everybody else” is in your statement, but as someone who founded a healthcare tech platform (since sold) [1], I spent 20 years caring about the many millions of patient medical records we held and making sure my team cared too. In my mind it wasn’t optional.

I did it because:

* it’s the right thing to do

* for professional pride

* and so I could sleep at night

And, at least at the beginning, I believed a data breach could be the death knell of the company. Over time the laissez faire attitude to data protection by the industry as a whole made it seem like it would be survivable.

I still walked away from it a wealthy man. Being competent and caring about your customers (and being able to sleep at night) doesn’t have to mean failure like it seems everyone here thinks.

[1] https://www.meddbase.com/

pluc•31m ago
Every single tool being released since like 2024 is pushing everyone to care less and less and to let agents handle more and more. We are not trending towards increased quality, resilience and reliability - even though we've been obsessing over these things for the past 20 years.
toomuchtodo•28m ago
Caring is orthogonal to profits and shareholder value. The one who cares the least wins unless economic incentives change this math, which is what these financial penalties work towards. Humans are tricky.

To defend against the threat OP talks about (intentionally under capitalized corporate entity to avoided liability), insurance should be required, and your cyber insurance underwriter will perform an audit as part of underwriting. It's effectively a bond against fuckery in this context.

(cyber consultant and practitioner)

x3n0ph3n3•27m ago
That's not what orthogonal means. Saying they are orthogonal means that you can care and be profitable.
toomuchtodo•26m ago
You can care and be profitable, but it is usually cheaper to not unless regulatory mechanisms exist to internalize this potential externality. Can't rely on humans to do the right thing, some will not unless they feel pain for doing the wrong thing. Ergo, we build systems (legal, regulatory, technical, people) to encourage the desired target outcome(s).

I've worked with very profitable firms who care very little (and it shows in their systems and how they operate in this regard), and barely profitable firms who do everything right. What's the difference? Their culture, people, and internal incentives.

TLDR Security failures and data breach fines must be more expensive than the happy path and doing the right things. This encourages the happy path and doing the right thing, while discouraging doing not enough or nothing.

bluGill•11m ago
There is a lot more than regulations. Reputation is important as well. While you can give up a reputation fairly quickly, it is very hard to get/keep. Many companies are well aware of the value of their reputation - they call it the value of the brand.
my-huge-pony•13m ago
Why the middle man? Can't we make the law so that the University is still liable for the data beach because it's "their" data (collected/stored on their behalf) that is breached?

I think that still aligns the incentives, and University in this case has interest to make sure the data is stored properly.

SoftTalker•7m ago
Insurance only pays for damages, up to the limit of coverage. It does not do anything to remove liability.
augment_me•6m ago
This is already the law, but the shell company signs the ownership of the data and the security responsility. The university in this case is just using APIs to load and store stuff to someone else's servers.

If this is not possible no cloud storage would ever be possible to be liable for anything. Your Google drive got hacked? Your responsibility.

AIiscoming•11m ago
Lets be honest here, this is a business risk which is crazy high. As stupid as this is, I care but i can't guarantee it.

I might suggest a construct like this too.

What do you think how much it cost to do it perfect?

louthy•5m ago
Perfect isn’t required. The bar is “gross negligence”. Perfect is impossible, but proper compliance procedures, proper process, and a commitment to following industry best practice will always see you on the right side of the negligence bar, even if something slipped through the net.

It’s the difference between being a professional and an amateur (or worse, a ‘cowboy’).

augment_me•2m ago
Again this is not priced in. Every rational(in terms of revenue) business would rather be a highly profitable "amateur" compared to a barely profitable "professional".

There is no capitalist incentive for the latter, and you will lose market share to firms that can undercut you because of their lower costs.

ranger_danger•29m ago
Perhaps they should read https://en.wikipedia.org/wiki/Piercing_the_corporate_veil
dmos62•28m ago
That's legal?
micromacrofoot•19m ago
similarly, most AI datacenters aren't directly owned by the frontier labs

guess who holds the bag if capacity needs collapse

EA-3167•13m ago
Sure, but the real question is, "Will a judge not immediately see through this and punish them accordingly in any realistic case?"

Sort of like EULA's a lot of the "value" is incredibly theoretical.

amelius•14m ago
That's like blaming Seagate when your harddisk fails.

No judge will fall for that. You should have made backups. And you are responsible for the data of your clients.

augment_me•9m ago
Not really, the shell company is the owner of the data and is responsible for the security of it by contract, that's the whole point.

Seagate will not in a million years sign anything like this when you buy a HDD.

SoftTalker•5m ago
It's not that easy. Companies are required to do due diligence on stuff like this. If they know (or should have known) that they are outsourcing something to an incompetent provider, they could still be liable.
imnotr0b0t•9m ago
That sounds risky