frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Building my npx business card

https://ashley.dev/posts/turning-feedback-into-features/
8•edent•7mo ago

Comments

steele•7mo ago
Ooh, free real estate, let's colonize and gentrify package management
aabhay•7mo ago
Lmao, gentrify cracked me up
neilv•7mo ago
Do these npx business cards run arbitrary code on your computer?
cypherpunks01•7mo ago
npx

Run a command from a local or remote npm package

Description

This command allows you to run an arbitrary command from an npm package (either one installed locally, or fetched remotely), in a similar context as running it via npm run.

neilv•7mo ago
Yes, then is a "command from an npm package" arbitrary code?

And what is this "similar context as running it via npm run"?

Would it be better to answer the question directly?

joshka•7mo ago
Yeah, this seems like a very smart but inherently flawed idea.
cypherpunks01•7mo ago
Yes I agree! OSS package management ecosystems are a great idea, but allowing submissions without any review or vetting is just asking for supply chain attacks.
Xss3•7mo ago
May as well just release an executable tbh.
theamk•7mo ago
Reminds me of JAPH [0] - a tiny Perl program that was used in email/newsgroup signature to give it personal touch.

[0] https://www.perlmonks.org/?node_id=412464

watusername•7mo ago
Terminal business cards are a nice idea, but RCE business cards are just asking for trouble. Instead of npx, what happened to good'ol curl? Something like

$ curl ashley.dev

Some decades ago, we had finger (https://en.wikipedia.org/wiki/Finger_%28protocol%29) which is designed for this very use case. Sadly it's no longer installed by default with most distros:

$ finger @ashley.dev

queezey•7mo ago
This would be a great advertisement for security consulting.

"I was just able to run arbitrary code on your computer. Here is a sample of your recent browser history. Let me tell you help you mitigate your security vulnerabilities."

TP-Link Tapo C200: Hardcoded Keys, Buffer Overflows and Privacy

https://www.evilsocket.net/2025/12/18/TP-Link-Tapo-C200-Hardcoded-Keys-Buffer-Overflows-and-Priva...
115•sibellavia•1h ago•18 comments

You can now play Grand Theft Auto Vice City in the browser

https://dos.zone/grand-theft-auto-vice-city/
51•Alifatisk•1h ago•15 comments

Garage – An S3 object store so reliable you can run it outside datacenters

https://garagehq.deuxfleurs.fr/
289•ibobev•4h ago•55 comments

GotaTun -- Mullvad's WireGuard Implementation in Rust

https://mullvad.net/en/blog/announcing-gotatun-the-future-of-wireguard-at-mullvad-vpn
450•km•9h ago•98 comments

Amazon will allow ePub and PDF downloads for DRM-free eBooks

https://www.kdpcommunity.com/s/article/New-eBook-Download-Options-for-Readers-Coming-in-2026?lang...
423•captn3m0•10h ago•234 comments

Reverse Engineering US Airline's PNR System and Accessing All Reservations

https://alexschapiro.com/security/vulnerability/2025/11/20/avelo-airline-reservation-api-vulnerab...
46•bearsyankees•2h ago•22 comments

The FreeBSD Foundation's Laptop Support and Usability Project

https://github.com/FreeBSDFoundation/proj-laptop
101•mikece•5h ago•40 comments

Believe the Checkbook

https://robertgreiner.com/believe-the-checkbook/
70•rg81•4h ago•25 comments

Where Is GPT in the Chomsky Hierarchy?

https://fi-le.net/chomsky/
36•fi-le•4d ago•28 comments

Vm.overcommit_memory=2 is always the right setting for servers

https://ariadne.space/2025/12/16/vmovercommitmemory-is-always-the-right.html
9•signa11•2d ago•7 comments

Show HN: Stickerbox, a kid-safe, AI-powered voice to sticker printer

https://stickerbox.com/
6•spydertennis•31m ago•1 comments

Graphite Is Joining Cursor

https://cursor.com/blog/graphite
83•fosterfriends•4h ago•124 comments

Proton Leaves Switzerland

https://www.nzz.ch/technologie/proton-ceo-andy-yen-wer-gesetzgebung-der-polizei-ueberlaesst-sollt...
93•_tk_•1h ago•38 comments

Lite^3, a JSON-compatible zero-copy serialization format

https://github.com/fastserial/lite3
76•cryptonector•6d ago•26 comments

Show HN: I Made Loom for Mobile

https://demoscope.app
37•admtal•3h ago•27 comments

Prepare for That Stupid World

https://ploum.net/2025-12-19-prepare-for-that-world.html
111•speckx•3h ago•61 comments

Wall Street Ruined the Roomba and Then Blamed Lina Khan

https://www.thebignewsletter.com/p/how-wall-street-ruined-the-roomba
69•connor11528•1h ago•37 comments

Building a Transparent Keyserver

https://words.filippo.io/keyserver-tlog/
40•noident•5h ago•14 comments

We pwned X, Vercel, Cursor, and Discord through a supply-chain attack

https://gist.github.com/hackermondev/5e2cdc32849405fff6b46957747a2d28
1071•hackermondev•1d ago•393 comments

Show HN: Stepped Actions – distributed workflow orchestration for Rails

https://github.com/envirobly/stepped
70•klevo•5d ago•10 comments

1.5 TB of VRAM on Mac Studio – RDMA over Thunderbolt 5

https://www.jeffgeerling.com/blog/2025/15-tb-vram-on-mac-studio-rdma-over-thunderbolt-5
561•rbanffy•21h ago•206 comments

Show HN: Linggen – A local-first memory layer for your AI (Cursor, Zed, Claude)

https://github.com/linggen/linggen
9•linggen•2h ago•5 comments

History LLMs: Models trained exclusively on pre-1913 texts

https://github.com/DGoettlich/history-llms
699•iamwil•21h ago•342 comments

Getting bitten by Intel's poor naming schemes

https://lorendb.dev/posts/getting-bitten-by-poor-naming-schemes/
250•LorenDB•14h ago•136 comments

Cycle-accurate YM2149 PSG emulator

https://github.com/slippyex/ym2149-rs
8•todsacerdoti•6d ago•1 comments

Noclip.website – A digital museum of video game levels

https://noclip.website/
417•ivmoreau•17h ago•53 comments

The New Right-Wing Tech Intelligentsia

https://bayareacurrent.com/meet-the-new-right-wing-tech-intelligentsia/
36•counteroptimize•1h ago•14 comments

Beginning January 2026, all ACM publications will be made open access

https://dl.acm.org/openaccess
1943•Kerrick•1d ago•232 comments

How to think about durable execution

https://hatchet.run/blog/durable-execution
84•abelanger•1w ago•29 comments

GPT-5.2-Codex

https://openai.com/index/introducing-gpt-5-2-codex/
565•meetpateltech•1d ago•301 comments