frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Triaging security issues reported by third parties

https://gitlab.gnome.org/GNOME/libxml2/-/issues/913
27•zdw•3d ago

Comments

tptacek•4h ago
Wow, this is a whole thing. Like: absolutely, unpaid volunteers shouldn't feel like they're on deadlines to fix security bugs in open source code. They're not. But you're reading this and assuming, "ok, they're getting a lot of dumb reports from random bounty seekers or whatever", and, nope, he's complaining about GPZ.

Which, again, fair enough! But the bugs he's apparently talking about are presumably very serious.

(If maintainers of projects like libxslt stop fixing bugs, Google will ultimately just fix them.)

mdaniel•4h ago
It took me a second: "Google Project Zero" which I accept responsibility for because I come to the comments before TFA but I hadn't seen that initialism before
ndiddy•3h ago
This library was originally written to parse GNOME configuration XML files. It was never intended for parsing untrusted data. From GNOME's perspective, if you can crash the XML parser with a malformed config file, that's just a regular bug. If an attacker is able to write to arbitrary files in your home directory, he's already won.

I agree with the maintainer's perspective that it's irresponsible for Apple, Microsoft, and Google to rely on this library for parsing untrusted data in products that they make billions of dollars off of, not provide him any monetary or other support, and expect him to prioritize fixing "security bugs" that don't impact security for his use case. If I was the maintainer, I'd make the same decision he made.

tptacek•3h ago
All of us agree!
Aurornis•1h ago
I definitely have empathy for OSS maintainers but getting to the bottom of what was going on here was a rollercoaster.

They mentioned Google Project Zero “breathing down our necks” but then later said Google Project Zero hadn’t even reported anything this year:

> That said, Project Zero has notably reported zero security vulnerabilities in libxml2 since the start of this year.

runningmike•3h ago
“ These organizations are very exclusive clubs and anything but open.” This is so true! Many tests of the OpenSSF Scorecards do not make sense when you e.g do not use github actions and have a one persons project…..
cwillu•2h ago
Proof of work captcha appears to be busted?

Mechanical Watch: Exploded View

https://fellerts.no/projects/epoch.html
572•fellerts•9h ago•86 comments

I wrote my PhD Thesis in Typst

https://fransskarman.com/phd_thesis_in_typst.html
122•todsacerdoti•3h ago•56 comments

Using Home Assistant, adguard home and an $8 smart outlet to avoid brain rot

https://www.romanklasen.com/blog/beating-brainrot-by-button/
80•remuskaos•4h ago•46 comments

Cross-Account and Cross-Region Backups with AWS Backup (and Friends)

https://tylerrussell.dev/2025/06/20/cross-account-and-region-backups-with-aws-backup-and-friends/
9•terussell85•2d ago•1 comments

Finding a billion factorials in 60 ms with SIMD

https://codeforces.com/blog/entry/143279
17•todsacerdoti•1h ago•0 comments

Git Notes: Git's coolest, most unloved­ feature (2022)

https://tylercipriani.com/blog/2022/11/19/git-notes-gits-coolest-most-unloved-feature/
424•Delgan•15h ago•106 comments

Klein Bottle Amazon Brand Hijacking (2021)

https://www.kleinbottle.com/Amazon_Brand_Hijacking.html
71•sebg•5h ago•14 comments

Interview with Francine Prose on early-1970s San Francisco [audio]

https://www.laphamsquarterly.org/content/episode-3-francine-prose
35•keiferski•4h ago•5 comments

Hawaii Highways

http://www.hawaiihighways.com/
7•yakattak•1h ago•0 comments

Kastle (S24) is hiring an engineer

https://www.ycombinator.com/companies/kastle/jobs/ItDVKB7-founding-engineer-at-kastle-s24
1•rishi443•1h ago

Radio Garden

https://radio.garden/?2025
24•LeoPanthera•3h ago•3 comments

2048 with only 64 bits of state

https://github.com/izabera/bitwise-challenge-2048
95•todsacerdoti•3d ago•24 comments

LibRedirect – Redirects popular sites to alternative privacy-friendly frontends

https://libredirect.github.io
375•riffraff•18h ago•92 comments

We’ve had a Denisovan skull since the 1930s—only nobody knew

https://arstechnica.com/science/2025/06/the-controversial-dragon-man-skull-was-a-denisovan/
43•Bluestein•3d ago•11 comments

How to negotiate your salary package

https://www.complexsystemspodcast.com/episodes/how-to-negotiate-your-salary-package/
198•surprisetalk•4d ago•172 comments

FreeBSD Kernel Modules Pkg(8) Repositories

https://vermaden.wordpress.com/2025/06/22/freebsd-kernel-modules-pkg8-repositories/
21•todsacerdoti•4h ago•3 comments

Show HN: Turn a paper's DOI into its full reference list (BibTeX/RIS, etc.)

https://references.mireklzicar.com
29•mireklzicar•6h ago•10 comments

The cultural decline of literary fiction

https://oyyy.substack.com/p/the-cultural-decline-of-literary
103•libraryofbabel•8h ago•201 comments

TPU Deep Dive

https://henryhmko.github.io/posts/tpu/tpu.html
364•transpute•21h ago•71 comments

I was surprised by how simple an allocator is

https://tgmatos.github.io/allocators-are-for-monkeys-with-typewriters/
77•gilgamesh3•3d ago•27 comments

Why do all browsers' user agents start with "Mozilla/"? (2008)

https://stackoverflow.com/questions/1114254/why-do-all-browsers-user-agents-start-with-mozilla
82•nan60•4h ago•41 comments

Kilauea volcano errupts, lava more than 1k feet high [video]

https://www.youtube.com/watch?v=oG5zz9Sjw3E
62•asix66•2d ago•31 comments

How fast are Linux pipes anyway?

https://mazzo.li/posts/fast-pipes.html
181•keepamovin•17h ago•22 comments

Using an $8 smart outlet to avoid brainrot

https://www.neilchen.co/blog/kasa
97•NWChen•12h ago•60 comments

Dynamic YAML with Python computed properties for fusing API workflows and SQL

https://sequor.dev/
6•maxgrinev•2d ago•2 comments

Low-Temperature Additive Manufacturing of Glass

https://www.ll.mit.edu/research-and-development/advanced-technology/microsystems-prototyping-foundry/low-temperature
102•LorenDB•4d ago•18 comments

There's Gold in the Hills

https://longreads.com/2025/06/12/blm-land-enduring-wild-josh-jackson/
19•gmays•3d ago•0 comments

Mbake – A Makefile formatter and linter, that only took 50 years

https://github.com/EbodShojaei/bake
211•rainmans•2d ago•97 comments

Remote MCP Support in Claude Code

https://www.anthropic.com/news/claude-code-remote-mcp?campaignId=13926158&source=i_email&medium=email&content=Oct2024AnalysisTool&messageTypeId=140367
147•surprisetalk•4d ago•69 comments

Show HN: Luna Rail – Treating night trains as a spatial optimization problem

https://luna-rail.com/en/home-2
110•ant6n•4d ago•58 comments