frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

What new cat ownership data says about Americans

https://www.washingtonpost.com/opinions/interactive/2026/10/04/what-new-cat-ownership-data-says-a...
1•pseudolus•46s ago•1 comments

Recly – turn your watch into a Plaud-style AI recorder

https://recly.dev/
1•rokrokss•1m ago•0 comments

Gold Steadies as Softer Inflation Cuts Fed Hike Bets

https://coinmarketcap.com/community/post/379792617/
1•joeymabia1•2m ago•0 comments

Full-fabric VHDL LLM inference engine. Runs Qwen3.5-class transformer inference

https://github.com/Nero7991/llm.vhdl
1•jacquesm•5m ago•0 comments

The Unspoken Arithmetic of the Alto Line

https://melvynschobel.substack.com/p/the-unspoken-arithmetic-of-the-alto
1•dorygold•8m ago•0 comments

Let's compete with China on AI social impact

https://www.machinesociety.ai/p/lets-compete-with-china-on-ai-social
1•mikelgan•9m ago•0 comments

Linear Exponential Scaling in Non-Abelian Groups: A Universal Map

https://zenodo.org/records/23138998
1•GeometryKernel•11m ago•0 comments

Iran is going after America's debt it's targeting the $40T America owes

https://jaymartin.substack.com/p/iran-is-going-after-americas-debt
3•robaato•12m ago•0 comments

We Built an Independent DNS Cache Edge

https://blog.dnsimple.com/2026/08/building-our-fully-independent-dns-edge/
1•unixfg•15m ago•0 comments

Google freezes open-source bug bounty program amid flood of invalid AI slop

https://www.tomshardware.com/tech-industry/artificial-intelligence/google-suspends-part-of-the-os...
4•rdmuser•16m ago•0 comments

How many humans does it take to make tech seem human?

https://blog.computationalcomplexity.org/2026/10/how-many-humans-does-it-take-to-make.html
2•ilreb•18m ago•0 comments

Show HN: Mathness – printable math worksheets, pre-K to grade 5

https://mathness.app/
1•zubink•19m ago•0 comments

Live vote counting for Brazilian Presidential elections

https://resultados.tse.jus.br/oficial/app/index.html#/eleicao/6257/uf/br/cargo/1/vis/nominal/resu...
3•frozenlettuce•23m ago•1 comments

Your Right to Privacy Doesn't Disappear When You're in Public

https://reason.com/2026/09/30/your-right-to-privacy-doesnt-disappear-when-youre-in-public/
3•iamnothere•25m ago•0 comments

AI is making ambition feel pointless [video]

https://www.youtube.com/watch?v=nc8UBme3XLQ
3•dumindunuwan•26m ago•1 comments

Asteroid-mining company to launch first autonomous space mission in 2027

https://www.space.com/technology/without-a-single-command-from-the-ground-asteroid-mining-company...
1•simonebrunozzi•29m ago•0 comments

Mellon Foundation Releases the First National Study of Community-Based Archives

https://www.mellon.org/news/mellon-foundation-releases-the-first-national-study-of-community-base...
1•rdmuser•31m ago•0 comments

Memelang: Token-Terse Query Language

https://memelang.net/11/
1•bri-holt•32m ago•0 comments

Remote-Jobs-Api.tten.no

https://remote-jobs-api.tten.no
1•earnnovadev•33m ago•0 comments

Show HN: Web Analytics Focused on Revenue

https://revscope.co/demo/
1•slashdev•33m ago•0 comments

The Inner Worlds of Neon Genesis Evangelion

https://www.criterion.com/current/posts/9281-the-inner-worlds-of-neon-genesis-evangelion
1•FinnLobsien•34m ago•0 comments

Google Tells Sites to Fact-Check AI Content Before Publishing

https://www.searchenginejournal.com/google-fact-check-ai-content-before-publishing/591782/
2•rdmuser•34m ago•0 comments

Local models on 27,489 CVEs: 4.2% omit security impact (ex-kernel)

https://jerrygamblin.com/2026/10/04/decision-models-vs-cve-data/
1•ilreb•36m ago•0 comments

Show HN: Native Rust rewrites of Electron apps, starting with Slack

https://nothq.github.io
1•tartavull•37m ago•0 comments

Vinix is an effort to write a modern, fast, and useful operating system

https://github.com/vlang/vinix
2•tosh•38m ago•0 comments

Monoswan – a pleasant TS monorepo linter

https://github.com/pelicanonical/monoswan
1•pelicanonical•41m ago•1 comments

Deterministic Simulation Testing in Celld

https://celld.dev/blog/deterministic-simulation-testing/
2•anorak27•43m ago•0 comments

Nikola Tesla – The Laboratory of Lightning

https://ideas.lego.com/product-ideas/c8529e3c-4fd2-43ca-9e78-513d33c7c04e
3•taubek•43m ago•0 comments

I've had agents implement and optimize the Campfire web app in Elixir, Go, Rust

https://twitter.com/dhh/status/2106810173683851564
3•tosh•45m ago•0 comments

The Illusion of AI Productivity: Go Frame the House

https://medium.com/@kevinwhite88/the-illusion-of-ai-productivity-e36f4af6ba38
3•kaydub•48m ago•2 comments
Open in hackernews

Remove and Disable Apple Macos27 AI Models Tool

https://github.com/omlahore/RemoveMacAI
71•privacyisntdead•1h ago

Comments

arialdomartini•37m ago
Stop the curl | bash insanity.

https://nocurlbash.com/#en

demibabs•35m ago
Good message but AI generated text is so grating to read.
shujito•35m ago
there's a homebrew alternative
1over137•29m ago
“You wouldn't run a stranger's code without reading it.” Yes I would. We all do it all the time. macOS itself is closed source, and even if it weren't, there’s way too much code to read.
jtrueb•25m ago
Lol, thinking the exact same thing. No, we don’t read next to 0.0001% of the code we run.
tmpz22•21m ago
Don’t be obtuse, the intended audience is developers with enterprise credentials sprinkled throughout their environment.

Its a different threat model. You should not curl bash.

aaomidi•17m ago
This isn’t really that much of an issue when we have tls tbh.

Like I get why it’s bad, but also homebrew package installation is a more organized version of this.

Hashes are cool but also in a lot of systems you’re trusting the hash to be provided by the same website you don’t trust the binaries from…

packeted•16m ago
Great initiative. I recently got stung by an advert on reddit for "HBO Max for MacOS, 6 months free" from the official HBO user (don't get me started on how that slipped through). Front and center was a curl | bash copy to clipboard that obfuscated the payload source in base10. I knew better, but I think we've made this kind of thing way too acceptable. Of course it was malware and I realized the instant I pressed enter. Thankfully I didn't give it my password and immediately disconnected from the internet and killed the machine. I'm genuinely concerned these kind of attacks are going to become much more commonplace with AI, plus the ability to inject malicious code in to things that get run by trusted scripted installers.
swozey•13m ago
They all dump env and ship it off so check for any keys you might have had in there if anything was able to send at all.
hypeatei•15m ago
> If the project publishes a SHA-256 hash, use it. Non-negotiable on production machines.

They're pushing FUD around downloading a file but then suggest that we trust the same chain of complex things to display the right hash value? Integrity != authentication.

mogwire•15m ago
I bet this is the guy on the call who has to correct someone who calls them SSL certs.

Excuse me, they are TLS certs.

Thanks Arialdomartini, as I was saying… we need to renew the SSL Certs

maccard•13m ago
What’s your suggested installation method instead? Unless it’s “download and read the source before running it” this is no worse than npm install, or pip install, or clicking “trust” on a git repo in VSCode
mingus88•4m ago
It is actually worse than those examples. Pip and npm may be insecure, and that is a fault of those tools, but most user expect secure package managers and should demand it

Telling users it’s fine to raw dog arbitrary commands directly into their shell is dangerous and lowers the bar for all security. In fact by even making this comparison you are communicating that you are complacent with pip and npm’s issues and why shouldn’t you just execute arbitrary commands without even a second glance? Security doesn’t matter!

And for the record, even with pip and npm being the way that they are, they are still better than a curl pipe because they are versioned. In the case I get a compromised deployment I understand immediately if I got hit by the affected package, and the entire repo can then be audited. Not the case when I’m just curling whatever the internet wants to send into my process space

porridgeraisin•3m ago
> Bash starts before the download finishes ... Drop the connection mid-transfer and you get partial execution: a command like rm -r /usr/share/program can truncate to rm -r /usr. Commands ran, cleanup didn’t.

curl | bash scripts all define a function and then call it on the last line. This is a non issue in the real world.

> The server knows you’re piping — and can lie

This is always a cool demo to show freinds yes, but the server can also sneak in malware in a multitude of other ways given you're downloading code and binaries from them.

> You trust DNS, TLS, the CDN, and the origin simultaneously. A compromised CDN or BGP hijack delivers malware silently.

Well yes, that's how the internet works. If TLS of the server is really compromised, then the attacker will replace the checksum as well as the signing key. In real scenarios, you are going to be reading the signing key and checksum from the same domain. [1]

> You can’t reproduce what ran

`| tee inspect.sh | bash`

> Add sudo and it’s game over

Most credentials and important files live in the home directory, root is a red herring. If you're running it on shared server, then well... don't add sudo.

[1] Yes of course there are legitimate usecases for signing software. Common example: linux distros which are mirrored at many domains, but the checksum and signature are hosted on the canonical domain. But if I am curlbashing uv's install.sh from `astral.sh`, then doing signature verification using the public key hosted on the same astral.sh isn't adding much.

bigyabai•36m ago
Something horrible must have happened, if macOS users are curling shell scripts from the internet to make their desktops more like Linux.
nomel•24m ago
Nope. The only people who notice or care about any of this are those who can't accommodate the storage. Outside that, it all just works better now (especially Siri).
behnamoh•22m ago
Saying that Siri "works" is peak Apple fanboism.
trollbridge•12m ago
People with 256GB laptops care when the 27 AI stuff burns up 10-20% of their storage.
GeekyBear•8m ago
So don't install Chrome.
swozey•17m ago
I'm sick of juggling disk space on my 1tb laptop AND I don't want an llm attack vector anywhere near my machine, this things getting nuked from orbit or i'm not updating to golden gate, ever.
trollbridge•12m ago
behnamoh•33m ago
Oh, things are about to get worse with the new macOS "privacy/security" measures. They are going to curb agentic workflows even more. I don't know how Apple just finds new ways to annoy developers, but we're in a minority after all. Of 200 million Mac users, probably just up to 1 million are developers, and the rest are normies who can't tell when they should authorize or cancel the pop-up.
doawoo•29m ago
I'd argue that a lot of developers can't determine if an LLM generated command is actually safe or not.
wartywhoa23•28m ago
Ah, if only that meant that there'll be less slop in the macOS code itself..
NamlchakKhandro•23m ago
Apple hates developers
pjmlp•10m ago
They love the ones that buy Apple hardware to develop apps for iDevices, pay the dev subscription and store fees for apps, or simply because they wanted a shiny UNIX and don't consider BSD/Linux OEMs worth their money.
ultrarunner•4m ago
With LLMs, everyone's a developer now. Welcome to the mainstream.
hypfer•14m ago
This is stuff on the level of O&O ShutUp10. Which is a good tool, but also, a Windows tool for very (back in the day) Windows-specific nonsense.

What's going on at Apple product strategy?

curl|bash is now standard way to install packages on both macOS and Linux. It’s maddening, but it is now.
pjmlp•9m ago
Meanwhile on Windows we mostly use the store or winget, funny times.
drnick1•10m ago
Uncomfortable, but true.

GNOME has reached maturity and hasn't changed significantly in years, while Apple is busy destroying macOS.

fmajid•2m ago
It’s not about privacy, it’s about kneecapping competitors, just like when they blocked the advertising ID but exempted themselves from this because “Apple is not a third-party, we’re a second-party”.

Apple is an advertising company and thus inherently untrustworthy.