frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

San Diego overbills sanitation customers due to file copy error

https://voiceofsandiego.org/2026/09/26/how-the-trash-screw-up-happened-and-why-its-not-going-away/
1•leecoursey•37s ago•0 comments

Another World Ported to ZX Spectrum

https://github.com/antirez/anotherworld-zx-spectrum-48k
1•slim•1m ago•0 comments

A list of publications that accept cartoons and their associated payment

https://colemantoons.com/marketlist.php
1•rrjjww•2m ago•0 comments

Turso 0.8: Concurrent writes without SQLite's single-writer bottleneck

https://turso.tech/blog/turso-0.8.0
2•mitchwainer•2m ago•0 comments

The Genius Trick Behind Exile's Impossible Map

https://www.youtube.com/watch?v=MdPz9dLmOtI
1•msephton•3m ago•0 comments

Every model (incl. Jev) we tested inflates security finding severity

https://casco.com/blog/jev-cvss-benchmark
5•brene•3m ago•1 comments

Wikifunctions

https://www.wikifunctions.org/wiki/Wikifunctions:Main_Page
1•caminanteblanco•3m ago•0 comments

Slow running benefits: Boosts in mood and brain function at very light intensity

https://direct.mit.edu/imag/article/doi/10.1162/IMAG.a.1297/137350/Slow-running-benefits-Boosts-i...
1•bookofjoe•3m ago•0 comments

Singularity – design a data model, get the REST API and the MCP server

https://github.com/dantesabatier/Singularity
2•dantesabatier•5m ago•0 comments

Show HN: Squidbrake – self-hosted approval gateway for AI agent tool calls

https://github.com/batrapulkit/squidbrake
1•batrapulkit1103•5m ago•0 comments

Enforce positive security with Cloudflare Application Profiles

https://blog.cloudflare.com/application-profiles/
1•sidcool•5m ago•0 comments

Bootstrapping an Infrastructure [pdf]

https://www.usenix.org/legacy/event/lisa98/full_papers/traugott/traugott.pdf
1•lemonwaterlime•5m ago•0 comments

Author Dropped from Literary Prize over AI Allegations

https://www.plagiarismtoday.com/2026/09/28/author-dropped-from-literary-prize-over-ai-allegations/
1•speckx•5m ago•0 comments

Nvidia Donates $12,000 to the Perl and Raku Foundation

https://www.perl.com/article/nvidia-donates-12-000-to-the-perl-and-raku-foundation/
1•oalders•6m ago•0 comments

TLA+ helped us fix and10 issues in our OSS project

https://github.com/desplega-ai/agent-swarm/pulls
1•tarasyarema•6m ago•1 comments

People building AI think it might kill everyone. Hear from them directly.

https://frominside.ai
1•colinhb•9m ago•0 comments

Ciao, Control coding agents from your phone

https://apps.apple.com/us/app/ciaooo-claude-code-codex/id6793695487
1•bojanstef•11m ago•1 comments

SlopOne: Winning the code quality fight with Jev

https://qlty.sh/blog/introducing-slopone
1•brynary•12m ago•0 comments

Have we reached peak Markdown?

https://strata.space/@strataspace/have-we-reached-peak-markdown
1•strataspace•12m ago•0 comments

Does software performance still matter?

https://lemire.me/blog/2017/03/20/does-software-performance-still-matter/
1•ibobev•12m ago•1 comments

AI: Igniting the Spark to End Stagnation

https://lemire.me/blog/2026/02/15/ai-igniting-the-spark-to-end-stagnation/
1•ibobev•13m ago•0 comments

Antifragile Programming and Why AI Won't Steal Your Job

https://lemire.me/blog/2025/11/29/antifragile-programming-and-why-ai-wont-steal-your-job/
1•ibobev•14m ago•0 comments

Fallout: New York

https://fallout.nyc/
1•lilytweed•14m ago•0 comments

Weapons of Mass Decentralization

https://worksinprogress.co/issue/weapons-of-mass-decentralization/
1•surprisetalk•15m ago•0 comments

LeRebot So-101 Crash Course

https://medium.com/@rob.bercik/getting-out-of-the-way-my-robotics-crash-course-fa2a101b037b
1•systemerror•15m ago•0 comments

Show HN: Postgres MCP server with a context file the agent can add to

https://github.com/contextflo/postgres-mcp
1•depthfirst•15m ago•1 comments

PocketCI – Monitor your CircleCI builds from your iPhone

https://apps.apple.com/us/app/pocketci/id6811967565
1•doughlass•16m ago•0 comments

Neoserver – A multi-workspace geospatial server in Go

https://neoserver.cloud/
1•tobilg•17m ago•0 comments

Hacking SimCity 2000 saved games

https://log.schemescape.com/posts/memoir/dos.html
2•speckx•17m ago•0 comments

Mercedes-Benz wants employees in the office four days a week

https://www.marketscreener.com/news/mercedes-benz-wants-employees-in-the-office-four-days-a-week-...
2•Tomte•18m ago•1 comments
Open in hackernews

Unsurprisingly, Meta's new Muse AI agent blatantly ignores users permissions

https://appleinsider.com/articles/26/09/28/metas-new-ai-agent-blatantly-ignores-users-permissions
60•dkobia•59m ago

Comments

ParanoidShroom•33m ago
How is this possible? Apple messages are just free for anyone to read?
daishi55•26m ago
It’s not possible. User error lol
ryandrake•23m ago
At least on Unix-like systems, if it's free for you to read, then it's free for any process you run as you to read. Sure, macOS has grafted its own weird "permissions" layer on top of the existing OS level permissions, but at the end of the day, when you run an app on Unix, you're allowing it to act as you, with all the powers your user has.

This used to work when you could trust the software you ran on your system to have access to everything you have access to on your computer. I'd argue that time has largely passed, for most third-party commercial developers and even for some OS vendors.

Best solution is to simply not run software made by blatantly untrustworthy developers. Second best solution would be to run such software as a severely sandboxed user who basically doesn't have access to anything important on your system.

graemep•12m ago
I do not know about all Unix like OSes, but Linux has sandboxes you can run as you main user. Not as safe as running as a separate user and sandboxing, or running in a VM, but reasonably solid.

> I'd argue that time has largely passed, for most third-party commercial developers and even for some OS vendors.

Agreed, but what can you do about your OS vendor?

VCFundedGenYer•32m ago
I think what’s more alarming is the macOS nannying UAC-like toggles to block disk access and other “protections” are apparently all UX reducing flash and no actual functionality.

I’d argue this is a five alarm fire for macOS and Meta simply exploited it.

PaulHoule•10m ago
Personally that stuff drives me up the wall, it's the Mac wanting to become the iPhone and close off everything but the App Economy. They'll geofence XCode to the Bay Area or something so only "professionals" can develop software and eventually ban web browsers.
dec0dedab0de•4m ago
I think we need more granular permissions, and built in ways to trick apps into thinking they have permissions they do not.
jkingsman•31m ago
I'm no evangelist for LLM assistants, but this seems incredibly improbable and represents a failure of MacOS security if so. If full disk access isn't granted, Mac blocks it from the Downloads folder, to say nothing of actually sensitive paths. I would expect a far more likely case of an accidentally granted permission on another device or a permission that was on and then turned off.

Permissionless action is about to skyrocket as an issue, but this particular scenario strikes me as incredibly unlikely. Would be interested to know if Muse can provide more meaningful data provenance/logs.

Scanning iMessage dbs as a passive part of full disk access (and not a messages grant), if true, is a little sketchy, regardless.

bethekidyouwant•29m ago
How is this a story anybody who knows how a computer works knows this is nonsense.
lapcat•12m ago
> After doing a little digging, Aten says Muse synced 187,000 lines from his Messages database, despite Full Disk Access being off.

This is absolutely untrue, and impossible.

I haven't spoken directly with Aten, but I have second-hand information from someone who has spoken directly with Aten, and it turns out that he has two Macs and may have allowed Full Disk Access to Muse on one of them.

iamacyborg•4m ago
The story from Hunterbrook is also pretty crazy with Muse having much more access to Meta’s social graphs than I suspect most users would hope.

https://hntrbrk.com/breaking-news/muse-doxxing