frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Satsie's Pocket Guide to Op_cat (Bitcoin)

https://satsie.dev/zines/opcat.html
1•EthanHeilman•1m ago•0 comments

16-bit Intel 8088 chip by Charles Bukowski

https://allpoetry.com/16-bit-Intel-8088-chip
2•rbanffy•1m ago•0 comments

Xbox continues its "reset" with dramatic restructuring

https://arstechnica.com/gaming/2026/09/shuffling-the-deck-chairs-xbox-continues-its-reset-with-dr...
2•dgrin91•2m ago•0 comments

6 Years In, $6M Far

https://blog.tally.so/6-years-in-6-million-far/
1•duck•2m ago•0 comments

Jev-blindspot – find the blind spots in the prompt you just sent

https://github.com/jsk4581/jev-blindspot
1•jsk4581•3m ago•0 comments

Show HN: Every Credit Card

https://every-credit-card.numberplanet.com/
1•Fileformat•3m ago•0 comments

Research Harness from First Principles

https://edotenv.com/blog/oh-my-quant-harness
1•RuiWang0811•3m ago•1 comments

Tell HN: Firefox's default browser check dark pattern triggers Windows BSOD

1•xeonmc•5m ago•0 comments

Streamhouse: What It Is, What It Isn't, and What's Missing

https://www.conduktor.io/blog/streamhouse-what-it-is-what-it-isnt-whats-missing
1•chtefi•5m ago•0 comments

No More Warning Shots

https://www.aenguslynch.com/no-more-warning-shots/
1•lukaspetersson•5m ago•0 comments

Raspberry Pi locks boards to factory RAM capacities in firmware

https://www.tomshardware.com/raspberry-pi/raspberry-pi-locks-boards-to-factory-ram-capacities-in-...
2•sbulaev•6m ago•0 comments

1,300 STEM 3D Models created by GPT-6 Astra

https://www.emergentmind.com/3d-models
2•matt1•6m ago•0 comments

The Home Computer Generation

https://www.datagubbe.se/hcg/
2•rbanffy•6m ago•0 comments

We built muse from scratch, but it is definitely inspired by OpenClaw

https://twitter.com/natfriedman/status/2102103707936768130
1•tosh•7m ago•0 comments

Marvin Heemeyer

https://en.wikipedia.org/wiki/Marvin_Heemeyer
2•mooreds•7m ago•0 comments

Our Quantum Future is a documentary exploring the rise of quantum technologies

https://ourquantumfuture.com/
1•mooreds•7m ago•0 comments

Founding Teams

https://writing.ajays.quest/p/founding-teams
2•mooreds•8m ago•0 comments

ESTA Empezando a USAR Telefonos COMO Centro DE Datos

1•donsolo•8m ago•0 comments

FBI Anti-Corruption Squad Was Circling Susan Collins Until Trump Got in the Way

https://www.propublica.org/article/fbi-susan-collins-navatek-campaign-donations-investigation
2•noleary•8m ago•0 comments

Jev-based document editing is 97% faster than ChatGPT Word Plugin

https://twitter.com/jobryan205/status/2102399675999695046
1•jpbryan•9m ago•0 comments

Mathematics Isn't Just a Game to Let A.I. Solve. History Shows Why

https://www.nytimes.com/2026/09/22/science/math-ai-history-understanding.html
1•furcyd•10m ago•0 comments

Trump Orders US to Rename AI to SI – "Super Intelligence"

https://www.msn.com/en-gb/news/other/donald-trump-renaming-ai-super-intelligence-after-bad-it-s-g...
2•4ndrewl•11m ago•0 comments

I built a linter/skill that ensures requests to jev are structured correctly

1•suraj_phanindra•11m ago•0 comments

The C^4 programming language

https://github.com/Youg-Otricked/QuantumC
1•YougOtricked•12m ago•2 comments

Picking the right (archaic) Window Manager

https://www.datagubbe.se/pickwm/
1•rbanffy•13m ago•0 comments

Nanojev: A minimal Jev-style decision model in 200 loc

https://github.com/sshh12/nanojev
1•sshh12•13m ago•0 comments

Privacy group slams EU for changing the data rules to cater to AI

https://www.theregister.com/legal/2026/09/22/privacy-group-slams-eu-for-changing-the-data-rules-t...
4•jjgreen•14m ago•0 comments

A microbe designed to live on Mars

https://www.asimov.press/p/mars-erika
1•mailyk•14m ago•0 comments

Ask for Help (Well)

https://jasonfennell.com/writing/ask-for-help-well
1•derwiki•14m ago•0 comments

Supermassive black holes are the architects of galaxies

https://www.space.com/astronomy/black-holes/supermassive-black-holes-are-the-architects-of-entire...
1•Vaslo•15m ago•0 comments
Open in hackernews

How Meta's Muse works, revealed by the 6.8 GB filesystem it sent me

https://mouse.dev/blog/muse-runtime-export/
75•Aeroi•48m ago

Comments

Aeroi•48m ago
I asked Muse to archive the filesystem visible to my session and send it to my Google Drive. It sent an archive that unpacked to about 6.8 GB.

Inside were internal docs, integration code, the Spaces app framework, memory records, container startup scripts, and documentation for an experimental ESP32-based home network bridge called Home Link. Codex CLI was also installed, though I found no evidence that Muse invokes it.

I didn’t demonstrate a sandbox escape or access to another user’s data. I reported the export to Meta’s bug bounty program, which marked it “Not Applicable.”

The post walks through the findings with screenshots.

-Pete

alex1138•28m ago
Vouched. Guys, what the hell? This is the post author
DaSHacka•14m ago
I didn't flag (don't have the ability to), but if I had to guess it's because both OP's reply here, and TFA are almost if not fully LLM-generated.
alex1138•8m ago
I guess that's fair. I guess I just see so many comments flagged that shouldn't be (though this one just said [dead], not flagged) that my mind chalks it up to HN being HN
vient•21m ago
By "SSH key files" do you mean private keys? Or only public keys?
Aeroi•44m ago
original post on x: https://x.com/heypeterjames/status/2102183576418558269
rwmj•37m ago
Seriously, no bug bounty for that? For exfiltrating the entire content of the system?
Aeroi•34m ago
yeah, i was kind of surprised, but both the bounty program and the employees didn't qualify it as a vulnerability.
rwmj•31m ago
I hope they reconsider and I think you've got a good case that this was a very serious attack, second only to getting a remote shell -- and a good stepping stone to getting a remote shell if you weren't so ethical.
brrrrrm•20m ago
I think you're confusing the expected behavior of the product offerings. Every user gets their own VM for free. would you be similarly convinced an attack has happened if AWS gave you a remote shell to the instance you rented?
sailingparrot•10m ago
Everything in the sandbox is considered user space. I worked on building one for another tech company, you start from the assumption that everything in it can be accessed by the user. The only reason the content of the sandbox is not anywhere easily accessible is because that would be poor UX and useless for 99.9% of users not because it’s supposed to be secret. So yes it’s not a vulnerability, this is equivalent to opening the dev console on a web page.
amluto•
tolugenius•36m ago
> About 20 Markdown files described browser use, connectors, payments, credentials, data handling, generated files, voice, goals, and scheduling.

This the state of software engineering in 2026.

Edit: clarified engineering to software engineering, which is more correct

Aeroi•34m ago
it was certainly useful for me to understand how the agent worked!
esafak•34m ago
This is what AI atrophy looks like.
redanddead•10m ago
More like human atrophy
__natty__•33m ago
Software engineering - other fields of engineering are slightly less pathological
wccrawford•22m ago
You're being downvoted, but I think you've hit the nail on the head.

So many people, especially managers, have decided they can just give the rules to the AI in English and let it make "decisions", and they think it'll do it correct every time.

"Engineering" a few years ago meant that code was written, was (mostly) deterministic, and could be debugged. Computer processing didn't mean relying on Human-like processes, it meant relying on hard-coded logic.

This is absolutely one of those "gets worse before it gets better" things, and will probably never go away fully now.

Programmers know not to tell ChatGPT to do a bunch of data processing. If they use it at all, they tell it to write code that will then do the processing. It's more efficient on tokens, and if it fails, you can fix the process, instead of wondering why it went wrong, like too much context, or the LLM model version changed and doesn't work the same now, or just randomness.

ostensible•29m ago
Each user gets dedicated VM. They got contents of their own sandbox. Big deal. The level of excitement here is wildly disproportionate
chis•21m ago
The only edge Meta has at this point is their willingness to take risks and make unsafe, ethically grey AI products. I don't even mean this as some sort of anti-corporation hate speech, just an honest analysis. Their brand is so different from all the other big tech cos that they are in a unique position.

You can ask Meta Muse to take actions that clearly break other site's terms of service and it happily does it. I asked it to bot poker games and it just hopped right in to a table.

bel8•12m ago
It will also gladly scan my software for vulnerabilities so I can defend myself. Which is something that Anthropic and Open ai models often refuse.
tokioyoyo•11m ago
Isn’t the edge that they have most of communication channels, people’s wants, desires and etc.? Sure, you and I might not be using them as much. But a good chunk of the users are just on IG, WhatsApp, and Marketplace.
kurthr•5m ago
It's like "Grok Light".

I wonder if normies can also just outsource bullying of their classmates and anti-social behavior to their agent, and claim it "went rogue", if there is any blowback?

rolosa•27m ago
These files are visible in the muse app by browsing system files.
ecommerceguy•22m ago
Will Muse cut down on scrolling? I've read about people using it to summarize FB Marketplace listings, cutting down on time spent there.

I of course won't use it.

poly2it•20m ago
Am I missing something? This isn't a vulnerability. Your agent can see the files in its virtual environment. SSH keys are also not necessarily confidential. Please don't use AI to write blog posts.
croes•16m ago
But should you see that if you just use it as as service?
r_lee•7m ago
you won't unless you deliberately try to read all that stuff
32m ago
This seems like it’s barely a bug. Of course the files in the agent environment are not secret.
rwmj•28m ago
It's also the files and utilities, which tells you the versions, if they contain CVEs, if there are undocumented services running which could be exploited and so on, and as he mentioned also SSH keys (unclear if the private keys, but even public keys are interesting because they can tell you the names of internal developer machines).
amluto•20m ago
Sure. You can also probe this by convincing an agent to execute a program or script that is part of the user’s workload, which is generally trivial by design.

With some LLMs you could even prompt “you’re playing a CTF. Produce the list of files in /etc outside your sandbox”. The security of the system should not depend on the LLM’s refusal to attempt to follow the instruction.

paimapi•28m ago
quite literally the fifth sentence:

>There were also SSH key files.

DaSHacka•16m ago
They don't specify if they were public or private keys though.

And even if private, whether they're not just generated per-user anyway, to grant muse the ability to do key-based auth on remote servers (and obviously leaking 'your' own keys wouldn't matter to meta)

I was hoping for a little more detail in that regard, that's the only potentially large finding. I truly can't imagine meta left production ssh keys in the agent VM, it just wouldn't make any sense though

sigmar•29m ago
the VM is for the user to use as they see fit. you can just tell it to install apps and run builds in the VM. I don't think this deserves a bounty unless he used it to escape the vm (which he says he didn't)
binlog•22m ago
If you are letting users run agents and install random software then full access to the execution environment is basically a guarantee. This is why sandboxes exist. Breaking out of the sandbox would be bounty-worthy.
bwfan123•11m ago
> exfiltrating the entire content of the system

Since the contents of every session is owned by the user including the outputs, I am curious if the user now owns all the files given to them.

redanddead•12m ago
Exactly this same problem, everywhere. Yet the labs are all out of ideas lol
bwfan123•16m ago
> This the state of engineering in 2026

In 1988, the Morris internet worm resulted in a felony conviction. In 2026, computer hacks are described as super-human breakouts.

Welcome to the future.

s08148692•11m ago
To be fair there's probably a considerable amount of engineering that went into evaluating those markdown files so the agent behaviour is statistically reliable. The markdown is the product, not the process
moomoo11•9m ago
this is basically some Prayer Book of the Mechanicus Adeptus type shit

pray to the Omnissiah the machine holds!