frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Evolution Mail Users Easily Trackable Part 2

https://www.grepular.com/Evolution%20Mail%20Users%20Easily%20Trackable%20Part%202
23•zdw•6h ago

Comments

like_any_other•5h ago
Most devs are entirely too casual about making network requests. Do they not share users' expectation that the software won't rat them out to random servers?
drdaeman•3h ago
> Evolution probably does not require any changes whatsoever to fix this. This problem is not specific to Evolution; it very probably affects Balsa and Geary at least, and all other applications using WebKitGTK that wish to audit outgoing HTTP requests. The problem is that WebKitGTK is making HTTP requests that bypass its API for blocking HTTP requests, which Evolution relies on.

https://gitlab.gnome.org/GNOME/evolution/-/issues/3095#note_...

tetromino_•3h ago
Summary: there is a long-standing bug in Webkit which causes network connection from (probably?) any tag that sets a `rel` attribute to be non-auditable and non-blockable by client code using Webkit.

Mike Cardwell stumbled on the manifestation of this bug in Evolution (which uses Webkit for rendering html mail). His proposal was for Evolution to filter html content before passing it to Webkit for rendering. Evolution devs' counterproposal was to ask Mike to write a patch to fix the Webkit bug, so not just Evolution but all other applications built on top of Webkit benefit.

Instead of writing a patch for Webkit (or at least further investigating the Webkit bug), Mike responded by writing two blogposts denouncing Evolution devs.

Evolution devs responded by locking the bug thread and threatening to ban Mike.

TL;DR drama due to cultural difference.

veeti•3h ago
This reflects of a failure in security "culture" within the GNOME project. Whether the issue boils down to a bug in WebKit or Evolution code, it is ultimately the Evolution developer's responsibility to not ship an end product with known security issues. Whether that is achieved by changes upstream or in the Evolution project is of no relevance to the end users or general public at large.
tetromino_•3h ago
> it is ultimately the Evolution developer's responsibility to not ship an end product with known security issues

Is it? One could argue that Evolution developers do not ship an end product, and that it's distros - Debian, Fedora, etc. - who ship the end product by combining Evolution at version X with Webkit at version Y, and possibly patching both.

Mr Browser – Macintosh Repository file downloader that runs directly on 68k Macs

https://www.macintoshrepository.org/44146-mr-browser
20•zdw•1h ago•1 comments

Asynchrony is not concurrency

https://kristoff.it/blog/asynchrony-is-not-concurrency/
172•kristoff_it•6h ago•116 comments

How to write Rust in the Linux kernel: part 3

https://lwn.net/SubscriberLink/1026694/3413f4b43c862629/
49•chmaynard•3h ago•0 comments

Debcraft – Easiest way to modify and build Debian packages

https://optimizedbyotto.com/post/debcraft-easy-debian-packaging/
15•pabs3•1h ago•1 comments

Silence Is a Commons by Ivan Illich (1983)

http://www.davidtinapple.com/illich/1983_silence_commons.html
85•entaloneralie•4h ago•12 comments

Ccusage: A CLI tool for analyzing Claude Code usage from local JSONL files

https://github.com/ryoppippi/ccusage
28•kristianp•2h ago•20 comments

C++: zero-cost static initialization

https://cofault.com/zero-cost-static.html
15•oecumena•3d ago•4 comments

Valve confirms credit card companies pressured it to delist certain adult games

https://www.pcgamer.com/software/platforms/valve-confirms-credit-card-companies-pressured-it-to-delist-certain-adult-games-from-steam/
202•freedomben•10h ago•221 comments

Meta says it wont sign Europe AI agreement, calling it growth stunting overreach

https://www.cnbc.com/2025/07/18/meta-europe-ai-code.html
111•rntn•7h ago•159 comments

Multiplatform Matrix Multiplication Kernels

https://burn.dev/blog/sota-multiplatform-matmul/
53•homarp•5h ago•19 comments

lsr: ls with io_uring

https://rockorager.dev/log/lsr-ls-but-with-io-uring/
303•mpweiher•13h ago•152 comments

Broadcom to discontinue free Bitnami Helm charts

https://github.com/bitnami/charts/issues/35164
96•mmoogle•6h ago•60 comments

Wii U SDBoot1 Exploit “paid the beak”

https://consolebytes.com/wii-u-sdboot1-exploit-paid-the-beak/
82•sjuut•5h ago•11 comments

Shutting Down Clear Linux OS

https://community.clearlinux.org/t/all-good-things-come-to-an-end-shutting-down-clear-linux-os/10716
84•todsacerdoti•2h ago•61 comments

Trying Guix: A Nixer's impressions

https://tazj.in/blog/trying-guix
143•todsacerdoti•3d ago•42 comments

AI capex is so big that it's affecting economic statistics

https://paulkedrosky.com/honey-ai-capex-ate-the-economy/
207•throw0101c•5h ago•225 comments

The year of peak might and magic

https://www.filfre.net/2025/07/the-year-of-peak-might-and-magic/
81•cybersoyuz•8h ago•41 comments

Replication of Quantum Factorisation Records with a VIC-20, an Abacus, and a Dog

https://eprint.iacr.org/2025/1237
64•teddyh•6h ago•19 comments

CP/M creator Gary Kildall's memoirs released as free download

https://spectrum.ieee.org/cpm-creator-gary-kildalls-memoirs-released-as-free-download
235•rbanffy•15h ago•123 comments

Show HN: I built library management app for those who outgrew spreadsheets

https://www.librari.io/
53•hmkoyan•6h ago•30 comments

Mango Health (YC W24) Is Hiring

https://www.ycombinator.com/companies/mango-health/jobs/3bjIHus-founding-engineer
1•zachgitt•7h ago

I'm Rebelling Against the Algorithm

https://varunraghu.com/im-rebelling-against-the-algorithm/
24•Varun08•3h ago•7 comments

Show HN: Molab, a cloud-hosted Marimo notebook workspace

https://molab.marimo.io/notebooks
71•akshayka•7h ago•11 comments

Converting Integers to Floats Using Hyperfocus (2022)

https://blog.m-ou.se/floats/
3•gus_massa•1d ago•0 comments

A New Geometry for Einstein's Theory of Relativity

https://www.quantamagazine.org/a-new-geometry-for-einsteins-theory-of-relativity-20250716/
84•jandrewrogers•10h ago•3 comments

Sage: An atomic bomb kicked off the biggest computing project in history

https://www.ibm.com/history/sage
20•rawgabbit•3d ago•4 comments

Cancer DNA is detectable in blood years before diagnosis

https://www.sciencenews.org/article/cancer-tumor-dna-blood-test-screening
177•bookofjoe•7h ago•103 comments

Intel Announces It's Shutting Down Clear Linux

https://www.phoronix.com/news/Intel-Ends-Clear-Linux
17•gpi•1h ago•5 comments

How I keep up with AI progress

https://blog.nilenso.com/blog/2025/06/23/how-i-keep-up-with-ai-progress/
190•itzlambda•7h ago•93 comments

Show HN: Simulating autonomous drone formations

https://github.com/sushrut141/ketu
15•wanderinglight•3d ago•3 comments