frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

`123456' password used in Danish CPR data breach

https://cphpost.dk/2026-10-10/news/round-up/123456-password-used-in-massive-danish-cpr-data-breach/
264•baal80spam•4h ago•156 comments

Lobbying Is Corruption

https://carette.xyz/posts/lobbying_and_corruption/
241•LucidLynx•1h ago•101 comments

Talorys – A self-hosted personal AI agent on Cloudflare's free tier

https://github.com/rociiu/talorys
102•rociiu•3h ago•47 comments

Bitwarden Dual License Model

https://community.bitwarden.com/t/published-version-update-in-app-stores/102750
11•Cider9986•16m ago•1 comments

REA Reverse – Engineer Anything

https://rea.tools/
532•modinfo•14h ago•229 comments

C for Rust Programmers

https://bd103.dev/blog/2026-10-07-c-for-rust-programmers/
63•xyproto•2d ago•37 comments

Cloudflare acquires Deno

https://deno.com/blog/cloudflare
1287•ilreb•1d ago•663 comments

Telegram Desktop vulnerability allowed any user's file to be stolen

https://beaksec.github.io/posts/telegram-desktop-one-click-account-takeover/
265•g-b-r•11h ago•137 comments

Triple-A Minesweeper

https://minesweeper.mikelacher.com/
1146•robin_reala•22h ago•227 comments

WSL3 Performance is about 5-60% faster than WSL2 depending on the workload

https://tonym.us/wsl2-vs-wsl3-benchmarks.html
132•tonymet•2d ago•94 comments

Eye of Sauron: Long-Range Hidden Spy Camera Detection (2024)

https://www.usenix.org/conference/usenixsecurity24/presentation/zhang-qibo
222•ortusdux•2d ago•45 comments

Noto means "no tofu": fixing dotted circles in Myanmar text

https://www.datocms.com/blog/handling-less-common-scripts
29•steffoz•3d ago•18 comments

Apple/macOS silently removed from official Unix registry

https://www.opengroup.org//openbrand/register/
101•john_alan•3h ago•101 comments

Chernobyl particles reveal unexpectedly stable nuclear fuel after 40 years

https://phys.org/news/2026-10-chernobyl-particles-reveal-unexpectedly-stable.html
54•geox•3d ago•14 comments

Can you use autoregressive diffusion to generate market data?

https://blog.janestreet.com/can-you-use-autoregressive-diffusion-to-generate-market-data/
133•jsomers•23h ago•41 comments

Mxc: Microsoft Execution Containers version 1.0.0

https://blogs.windows.com/windowsdeveloper/2026/10/07/microsoft-execution-containers-policy-drive...
7•smokel•1d ago•0 comments

Show HN: Carrier-Explode: iPhone, Pixel and Galaxy carrier settings decoded

https://carrierexplode.com/
366•simplyalec•20h ago•44 comments

Compiling Rust to readable C with Eurydice

https://lwn.net/Articles/1055211/
106•peter_d_sherman•15h ago•32 comments

How to head into VR without wearing a headset

https://www.kyushu-u.ac.jp/en/researches/view/414/
53•Betelbuddy•3d ago•26 comments

Clinical trial of a prion disease drug candidate begins enrolling participants

https://www.broadinstitute.org/news/clinical-trial-prion-disease-drug-candidate-begins-enrolling-...
112•luu•14h ago•27 comments

Timestamping a Giant Record of the Web

https://projecttimestamper.org/blog/common-crawl/
10•arthuredelstein•1d ago•0 comments

Typesafe AI raises $870M at $7.5B

https://typesafe.ai/blog/series-ai
406•tosh•21h ago•320 comments

Pointing AI at archives found a forgotten meteorite, lost rhinos, and more

https://jessewaites.com/blog/post/i-pointed-ai-at-400-years-of-archives/
168•piratebroadcast•1d ago•86 comments

Scam American companies are using to manipulate ingredient lists

https://twitter.com/WallStreetApes/status/2108594998656807078
166•bilsbie•21h ago•183 comments

What mathematicians should know about the Lean Theorem Prover: reliability & AI

https://terrytao.wordpress.com/2026/10/09/what-mathematicians-should-know-about-the-lean-theorem-...
154•matt_d•21h ago•40 comments

Cube Type – Isometric Typography Generator

https://typeincube.com/
37•eustoria•1d ago•9 comments

Computers Cannot Make Decisions

https://wiki.cateat.fish/art:computers_cannot_make_decisions
148•heavensteeth•9h ago•126 comments

Show HN: Proton Drive for Linux

https://oss.lsantos.dev/proton-drive-linux-fs/
104•khaosdoctor•2d ago•38 comments

'Wallace and Gromit,' 90% Alone

https://animationobsessive.substack.com/p/wallace-and-gromit-90-alone
255•vinhnx•1d ago•39 comments

The role of cat eye narrowing movements in cat–human communication (2020)

https://www.nature.com/articles/s41598-020-73426-0
108•bushwart•3d ago•51 comments
Open in hackernews

Building my npx business card

https://ashley.dev/posts/turning-feedback-into-features/
8•edent•1y ago

Comments

steele•1y ago
Ooh, free real estate, let's colonize and gentrify package management
aabhay•1y ago
Lmao, gentrify cracked me up
neilv•1y ago
Do these npx business cards run arbitrary code on your computer?
cypherpunks01•1y ago
npx

Run a command from a local or remote npm package

Description

This command allows you to run an arbitrary command from an npm package (either one installed locally, or fetched remotely), in a similar context as running it via npm run.

neilv•1y ago
Yes, then is a "command from an npm package" arbitrary code?

And what is this "similar context as running it via npm run"?

Would it be better to answer the question directly?

joshka•1y ago
Yeah, this seems like a very smart but inherently flawed idea.
cypherpunks01•1y ago
Yes I agree! OSS package management ecosystems are a great idea, but allowing submissions without any review or vetting is just asking for supply chain attacks.
Xss3•1y ago
May as well just release an executable tbh.
theamk•1y ago
Reminds me of JAPH [0] - a tiny Perl program that was used in email/newsgroup signature to give it personal touch.

[0] https://www.perlmonks.org/?node_id=412464

watusername•1y ago
Terminal business cards are a nice idea, but RCE business cards are just asking for trouble. Instead of npx, what happened to good'ol curl? Something like

$ curl ashley.dev

Some decades ago, we had finger (https://en.wikipedia.org/wiki/Finger_%28protocol%29) which is designed for this very use case. Sadly it's no longer installed by default with most distros:

$ finger @ashley.dev

queezey•1y ago
This would be a great advertisement for security consulting.

"I was just able to run arbitrary code on your computer. Here is a sample of your recent browser history. Let me tell you help you mitigate your security vulnerabilities."