frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Working with the EPA to Secure Exposed Water HMIs

https://censys.com/blog/turning-off-the-information-flow-working-with-the-epa-to-secure-hundreds-of-exposed-water-hmis
33•doener•3d ago

Comments

katzenversteher•14h ago
In general the whole industrial and SCADA world is pretty endangered from my experience. They are ususually very conservative which often means the SCADA stations are stuck to very old OS Versions (often Windows or even DOS).

One reason is OPC DA, a legacy communication protocol based on DCOM. Another is that at least some of the operator stations are often also used as engineering station, so they have to support the controller engineering software for the often also ancient PLCs.

As long as nothing is connected or exposed to the internet that's fine but nowadays companies try use edge computing and machine learning and so on to optimize running costs. Also predictive maintenance etc. is used to automatically trigger service when e.g. vibration sensors show patterns that indicate damage (e.g. bearing damage).

oasisbob•13h ago
> This is all just a long-winded way of saying: you don’t just stumble across insecure critical infrastructure every day, and when you do, it’s usually just a one-off host with a misconfiguration, and not an issue that affects a large number of hosts. But if you do find yourself in a situation where there seems to be some widespread security issue in actual critical infrastructure, you should be encouraged to reevaluate and reassess because in all probability, it’s not what you think it is.

... or in this case, it is what you think it is.

This article could have benefited from some stern and constructive editing. In the age of AI, I find myself with very little patience for verbose and vapid writing.

Launch HN: Vassar Robotics (YC X25) – $219 robot arm that learns new skills

81•charleszyong•1h ago•44 comments

OpenAI o3-pro

https://help.openai.com/en/articles/9624314-model-release-notes
31•mfiguiere•16m ago•7 comments

Magistral — the first reasoning model by Mistral AI

https://mistral.ai/news/magistral
536•meetpateltech•6h ago•221 comments

Low-background Steel: content without AI contamination

https://blog.jgc.org/2025/06/low-background-steel-content-without-ai.html
102•jgrahamc•2h ago•61 comments

A Blacklisted American Magician Became a Hero in Brazil

https://www.wsj.com/lifestyle/careers/magician-brazil-national-celebrity-d31f547a
57•bookofjoe•3h ago•24 comments

Show HN: Chili3d – A open-source, browser-based 3D CAD application

169•xiange•4h ago•46 comments

Malleable software: Restoring user agency in a world of locked-down apps

https://www.inkandswitch.com/essay/malleable-software/
105•jessmartin•5h ago•42 comments

You Can Drive but Not Hide: Detection of Hidden Cellular GPS Vehicle Trackers

https://www.researchgate.net/publication/391704077_You_Can_Drive_But_You_Cannot_Hide_Detection_of_Hidden_Cellular_GPS_Vehicle_Trackers
15•gnabgib•1h ago•1 comments

Denuvo Analysis

https://connorjaydunn.github.io/blog/posts/denuvo-analysis/
159•StefanBatory•1d ago•75 comments

Dubious Math in Infinite Jest (2009)

https://www.thehowlingfantods.com/dfw/dubious-math-in-infinite-jest.html
66•rafaepta•5h ago•46 comments

Android 16 Is Here

https://blog.google/products/android/android-16/
107•nsriv•2h ago•85 comments

Mikeal Rogers has died

https://b.h4x.zip/mikeal/
84•neom•6h ago•8 comments

Launch HN: BitBoard (YC X25) – AI agents for healthcare back-offices

25•arcb•5h ago•14 comments

Spoofing OpenPGP.js signature verification

https://codeanlabs.com/blog/research/cve-2025-47934-spoofing-openpgp-js-signatures/
71•ThomasRinsma•6h ago•20 comments

Another Crack in the Chain of Trust: Uncovering (Yet Another) Secure Boot Bypass

https://www.binarly.io/blog/another-crack-in-the-chain-of-trust
4•vitplister•37m ago•0 comments

Faster, easier 2D vector rendering [video]

https://www.youtube.com/watch?v=_sv8K190Zps
94•raphlinus•7h ago•24 comments

Xeneva Operating System

https://github.com/manaskamal/XenevaOS
9•psnehanshu•1h ago•0 comments

Show HN: High End Color Quantizer

https://github.com/big-nacho/patolette
94•big-nacho•8h ago•27 comments

OpenAI dropped the price of o3 by 80%

https://twitter.com/sama/status/1932434606558462459
177•mfiguiere•2h ago•163 comments

Show HN: PyDoll – Async Python scraping engine with native CAPTCHA bypass

https://github.com/autoscrape-labs/pydoll
99•thalissonvs•6h ago•25 comments

The Concurrency Trap: How an Atomic Counter Stalled a Pipeline

https://www.conviva.com/platform/the-concurrency-trap-how-an-atomic-counter-stalled-a-pipeline/
24•delifue•3d ago•14 comments

Show HN: MidWord – A Word-Guessing Game

https://midword.com/
6•minaguib•1h ago•2 comments

Onlook (YC W25) Is Hiring an engineer in SF

1•D_R_Farrell•8h ago

Containerization is a Swift package for running Linux containers on macOS

https://github.com/apple/containerization
710•gok•23h ago•379 comments

Teaching National Security Policy with AI

https://steveblank.com/2025/06/10/teaching-national-security-policy-with-ai/
31•enescakir•6h ago•19 comments

Reinforcement Pre-Training

https://arxiv.org/abs/2506.08007
47•frozenseven•15h ago•16 comments

Wharton Esherick and the Armstrong Linoleum Company

https://whartonesherickmuseum.org/wharton-esherick-and-armstrong-linoleum/
17•thomasjb•7h ago•2 comments

A Primer on Molecular Dynamics

https://www.owlposting.com/p/a-primer-on-molecular-dynamics
68•EvgeniyZh•4d ago•14 comments

"Localhost tracking" explained. It could cost Meta €32B

https://www.zeropartydata.es/p/localhost-tracking-explained-it-could
272•donohoe•9h ago•142 comments

Animate a mesh across a sphere's surface

https://garden.bradwoods.io/notes/javascript/three-js/animate-a-mesh-on-a-spheres-surface
123•surprisetalk•3d ago•14 comments