frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Show HN: LocalGPT – A local-first AI assistant in Rust with persistent memory

https://github.com/localgpt-app/localgpt
144•yi_wang•5h ago•45 comments

Haskell for all: Beyond agentic coding

https://haskellforall.com/2026/02/beyond-agentic-coding
67•RebelPotato•4h ago•16 comments

Bye Bye Humanity: The Potential AMOC Collapse

https://thatjoescott.com/2026/02/03/bye-bye-humanity-the-potential-amoc-collapse/
50•rolph•3h ago•38 comments

SectorC: A C Compiler in 512 bytes (2023)

https://xorvoid.com/sectorc.html
262•valyala•13h ago•51 comments

Total surface area required to fuel the world with solar (2009)

https://landartgenerator.org/blagi/archives/127
29•robtherobber•4d ago•21 comments

Software factories and the agentic moment

https://factory.strongdm.ai/
205•mellosouls•15h ago•355 comments

Speed up responses with fast mode

https://code.claude.com/docs/en/fast-mode
169•surprisetalk•12h ago•163 comments

LLMs as the new high level language

https://federicopereiro.com/llm-high/
72•swah•4d ago•125 comments

Brookhaven Lab's RHIC concludes 25-year run with final collisions

https://www.hpcwire.com/off-the-wire/brookhaven-labs-rhic-concludes-25-year-run-with-final-collis...
73•gnufx•11h ago•59 comments

Hoot: Scheme on WebAssembly

https://www.spritely.institute/hoot/
182•AlexeyBrin•18h ago•35 comments

Stories from 25 Years of Software Development

https://susam.net/twenty-five-years-of-computing.html
174•vinhnx•15h ago•17 comments

Vocal Guide – belt sing without killing yourself

https://jesperordrup.github.io/vocal-guide/
324•jesperordrup•23h ago•97 comments

Why there is no official statement from Substack about the data leak

https://techcrunch.com/2026/02/05/substack-confirms-data-breach-affecting-email-addresses-and-pho...
22•witnessme•2h ago•6 comments

First Proof

https://arxiv.org/abs/2602.05192
135•samasblack•15h ago•81 comments

Vouch

https://twitter.com/mitchellh/status/2020252149117313349
73•chwtutha•3h ago•17 comments

Wood Gas Vehicles: Firewood in the Fuel Tank (2010)

https://solar.lowtechmagazine.com/2010/01/wood-gas-vehicles-firewood-in-the-fuel-tank/
32•Rygian•2d ago•8 comments

Show HN: I saw this cool navigation reveal, so I made a simple HTML+CSS version

https://github.com/Momciloo/fun-with-clip-path
83•momciloo•12h ago•17 comments

The Architecture of Open Source Applications (Volume 1) Berkeley DB

https://aosabook.org/en/v1/bdb.html
6•grep_it•5d ago•0 comments

Al Lowe on model trains, funny deaths and working with Disney

https://spillhistorie.no/2026/02/06/interview-with-sierra-veteran-al-lowe/
106•thelok•14h ago•24 comments

Start all of your commands with a comma (2009)

https://rhodesmill.org/brandon/2009/commands-with-comma/
586•theblazehen•3d ago•212 comments

Show HN: A luma dependent chroma compression algorithm (image compression)

https://www.bitsnbites.eu/a-spatial-domain-variable-block-size-luma-dependent-chroma-compression-...
40•mbitsnbites•3d ago•5 comments

FDA intends to take action against non-FDA-approved GLP-1 drugs

https://www.fda.gov/news-events/press-announcements/fda-intends-take-action-against-non-fda-appro...
112•randycupertino•8h ago•238 comments

The AI boom is causing shortages everywhere else

https://www.washingtonpost.com/technology/2026/02/07/ai-spending-economy-shortages/
310•1vuio0pswjnm7•19h ago•494 comments

Learning from context is harder than we thought

https://hy.tencent.com/research/100025?langVersion=en
234•limoce•4d ago•125 comments

Where did all the starships go?

https://www.datawrapper.de/blog/science-fiction-decline
158•speckx•4d ago•242 comments

OpenCiv3: Open-source, cross-platform reimagining of Civilization III

https://openciv3.org/
906•klaussilveira•1d ago•277 comments

Microsoft account bugs locked me out of Notepad – Are thin clients ruining PCs?

https://www.windowscentral.com/microsoft/windows-11/windows-locked-me-out-of-notepad-is-the-thin-...
147•josephcsible•10h ago•186 comments

Selection rather than prediction

https://voratiq.com/blog/selection-rather-than-prediction/
35•languid-photic•4d ago•16 comments

Show HN: Look Ma, No Linux: Shell, App Installer, Vi, Cc on ESP32-S3 / BreezyBox

https://github.com/valdanylchuk/breezydemo
304•isitcontent•1d ago•39 comments

An Update on Heroku

https://www.heroku.com/blog/an-update-on-heroku/
497•lstoll•1d ago•331 comments
Open in hackernews

Browser extensions turn nearly 1M browsers into website-scraping bots

https://arstechnica.com/security/2025/07/browser-extensions-turn-nearly-1-million-browsers-into-website-scraping-bots/
34•chha•7mo ago

Comments

paulryanrogers•7mo ago
Extensions and VPNs have been doing this for years, it's not a secret. Where I worked we paid a proxy/scraping company that also offered 'stealth' scraping using residential IPs. They got those IPs using techniques like these extensions.

Chrome web store changed its policy years ago to prohibit these with the rationale that an extension should have a single purpose. Apparently their scanning tools aren't enforcing the policy strictly enough.

mmsc•7mo ago
Indeed, it's not a secret and it's not just extensions and VPNs, but everything you could imagine. Lots of applications that advertise themselves as "ways to make money for your unused internet bandwidth" are available which do this -- openly.

This type of software is bundled into system executables as well - just like the "free antivirus and browser toolbars" of yesterday, these are the new bundled software.

If a company has an "internal network" (lol) that consists of security that can be described as Swiss cheese, then this stuff is a massive gap there.

josephg•7mo ago
> Extensions and VPNs have been doing this for years, it's not a secret.

Its not a secret in the industry, but I bet money that most of your users have no idea this is happening. They almost certainly wouldn't install those web extensions if this information was widely known.

As a rule of thumb, if you need to do something in secret to get away with it, its probably not ethical.

paulryanrogers•7mo ago
It's supposed to be in the terms of service. Otherwise it is indeed fraud/abuse. Though I'd agree that most users don't read the fine print.
josephg•6mo ago
This sort of behaviour isn’t allowed on the extension store at all. There’s no exception for extensions which tell users all their misdeeds in the fine print.
nerdjon•7mo ago
I have to wonder, how long until the browsers just natively do this.

Gets around the AI blockers that CloudFlare is pushing with the added benefit of seeing information that a crawler would never see.

Just hide it behind an "AI Browser" that just sends everything your browser sees to the cloud anyways for processing...

Throw in some vague "privacy" promise for good measure.

(I realize this is being more sneaky and doing stuff in the background, but my question remains)

Cthulhu_•7mo ago
This may already be happening to a point; I forgot what it's called but in Chrome you can opt-in to sharing analytical data, which is used by Google's page speed insights tooling and/or Lighthouse to measure your site's performance by a wide range of devices and internet connections.
xnx•7mo ago
I'd be OK with an open reciprocal crawling network for non-personal/private pages as it would be a distributed force against walled gardens.

I'm very against this being done surreptitiously/deceptively and on private content (emails, chats, etc.)

mdaniel•7mo ago
I ran an extension that automatically submitted pages to the Internet Archive as I browsed them, but managing the allowlist/denylist turned into a major hassle, so I eventually just installed the extension into a "public browsing" profile, but as is often the case it turned into "I don't feel like switching to that profile" and it fell by the wayside

But, in the same vein as your comment, I have long wished for Common Crawl to really lean into their mission, and not just publish monthly snaps of whatever their bots can see but do what you said and accept .har or .warc files from anyone and serve the ... hourly? ... .warc via Bittorrent

riedel•7mo ago
I wonder why nothing like F-Droid did ever take off for browser extensions. Even if tons of stuff is open source, the standard distribution format are zip files with unknown content. And browser vendors never lived up to their promise that they even checked the most basic things. Also the whole manifest mess is rather a means to secure ad revenue and not to protect users.
mdaniel•7mo ago
I can think of 2 pragmatic reasons:

1. If one wished to use .xpi/.crx (akin to F-Droid's install pathway) then the user would have to teach the browser to trust the signature of them. F-Droid doesn't suffer from this because each .apk is self-trusting, meaning it is signed, and that signature conveys lineage (v1.0 is owned by the same publisher as v1.1, so safe to upgrade), but the operating system doesn't have to be informed about any chain of custody for the .apk cert

2. I am not aware of any self-hosting extension registry, even from Mozilla, and extra lol for Chromium. If such a thing existed, the browser would have to allow the user to add "trusted extension registries" (along with their trusted CA chain). It would actually be snazzy if they went the Helm/Homebrew route and just leveraged OCI distribution (aka docker registry) for that, since it would open up almost unlimited self-hosting options, including publishing right from GitHub Actions to ghcr.io

riedel•7mo ago
IMHO it would be rather easy to overcome this by forking. I anyways have used forks like librewolf, betterbird and recently Zen for Mozilla stuff due to all this telemetry (I guess you will need not care about malware if the browser already contains so many trackers)
mdaniel•7mo ago
Rather easy, eh? Well, then great, you can submit your rather easy patch to any one of the named forks and see if they adopt all the non-code stupidity that's required to execute all the PKI star-alignment that I cited
riedel•7mo ago
The fullblown case is difficult, true. But the 'simple' case would be that one of the forks has a repo. Afaik Zen already has its own mods: https://zen-browser.app/mods/ (I did not check the details). Coupled with GitHub attestation packaging more FOSS from trusted sources, would maybe not easy but also not implausible difficult. The difficulty for sure is to set up some trusted moderation community. And I think with mozdev.org, the future was partially already here, before all the browser wars...
mdaniel•7mo ago
I'm shocked that command-f "honey" didn't return any hits