frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Hungary's oldest library is fighting to save books from a beetle infestation

https://www.npr.org/2025/07/14/nx-s1-5467062/hungary-library-books-beetles
55•smollett•3d ago•2 comments

Make Your Own Backup System – Part 1: Strategy Before Scripts

https://it-notes.dragas.net/2025/07/18/make-your-own-backup-system-part-1-strategy-before-scripts/
195•Bogdanp•8h ago•66 comments

I tried Vibe coding in BASIC and it didn't go well

https://www.goto10retro.com/p/vibe-coding-in-basic
47•ibobev•3d ago•32 comments

Local LLMs versus offline Wikipedia

https://evanhahn.com/local-llms-versus-offline-wikipedia/
191•EvanHahn•11h ago•101 comments

Nobody knows how to build with AI yet

https://worksonmymachine.substack.com/p/nobody-knows-how-to-build-with-ai
265•Stwerner•12h ago•215 comments

Mushroom learns to crawl after being given robot body (2024)

https://www.the-independent.com/tech/robot-mushroom-biohybrid-robotics-cornell-b2610411.html
84•Anon84•2d ago•15 comments

OpenAI claims gold-medal performance at IMO 2025

https://twitter.com/alexwei_/status/1946477742855532918
430•Davidzheng•19h ago•646 comments

"Bypassing" Specialization in Rust or How I Learned to Stop Worrying and Love F

https://oakchris1955.eu/posts/bypassing_specialization/
13•todsacerdoti•2d ago•1 comments

Ring introducing new feature to allow police to live-stream access to cameras

https://www.eff.org/deeplinks/2025/07/amazon-ring-cashes-techno-authoritarianism-and-mass-surveillance
188•xoa•6h ago•89 comments

Death by AI

https://davebarry.substack.com/p/death-by-ai
211•ano-ther•13h ago•69 comments

Matterport walkthrough of the original Microsoft Building 3

https://my.matterport.com/show/?m=SZSV6vjcf4L
10•uticus•3d ago•1 comments

Rethinking CLI interfaces for AI

https://www.notcheckmark.com/2025/07/rethinking-cli-interfaces-for-ai/
143•Bogdanp•11h ago•67 comments

Babies made using three people's DNA are born free of mitochondrial disease

https://www.bbc.com/news/articles/cn8179z199vo
267•1659447091•3d ago•156 comments

Erythritol linked to brain cell damage and stroke risk

https://www.sciencedaily.com/releases/2025/07/250718035156.htm
33•OutOfHere•2h ago•17 comments

What Were the Earliest Laws Like?

https://worldhistory.substack.com/p/what-were-the-earliest-laws-really
46•crescit_eundo•4d ago•12 comments

The curious case of the Unix workstation layout

https://thejpster.org.uk/blog/blog-2025-07-19/
76•ingve•12h ago•24 comments

The borrowchecker is what I like the least about Rust

https://viralinstruction.com/posts/borrowchecker/
167•jakobnissen•9h ago•227 comments

TSMC to start building four new plants with 1.4nm technology

https://www.taipeitimes.com/News/front/archives/2025/07/20/2003840583
152•giuliomagnifico•8h ago•104 comments

Zig Interface Revisited

https://williamw520.github.io/2025/07/13/zig-interface-revisited.html
86•ww520•3d ago•23 comments

Trigon: Exploiting coprocessors for fun and for profit (part 2)

https://alfiecg.uk/2025/07/16/Trigon.html
31•Bogdanp•8h ago•1 comments

Intel to boost gross margins – new products must deliver 50% gross profit

https://www.tomshardware.com/tech-industry/semiconductors/intel-draws-a-line-in-the-sand-to-boost-gross-margins-new-products-must-deliver-50-percent-to-get-the-green-light
47•walterbell•4h ago•31 comments

What the Fuck Python

https://colab.research.google.com/github/satwikkansal/wtfpython/blob/master/irrelevant/wtf.ipynb
140•sundarurfriend•9h ago•146 comments

How we tracked down a Go 1.24 memory regression

https://www.datadoghq.com/blog/engineering/go-memory-regression/
132•gandem•2d ago•8 comments

Pimping My Casio: Part Deux

https://blog.jgc.org/2025/07/pimping-my-casio-part-deux.html
171•r4um•20h ago•53 comments

Show HN: Am-I-vibing, detect agentic coding environments

https://github.com/ascorbic/am-i-vibing
53•ascorbic•12h ago•24 comments

Airbnb allowed rampant price gouging following L.A. fires, city attorney alleges

https://www.latimes.com/california/story/2025-07-19/airbnb-allowed-price-gouging-following-l-a-fires-city-attorney-alleges-in-lawsuit
8•miguelazo•1h ago•2 comments

Fstrings.wtf

https://fstrings.wtf/
389•darkamaul•17h ago•123 comments

Hyatt Hotels are using algorithmic Rest “smoking detectors”

https://twitter.com/_ZachGriff/status/1945959030851035223
761•RebeccaTheDev•1d ago•444 comments

Show HN: Display Photos on a World Map

https://worldsnap.surge.sh/
28•stagas•3d ago•2 comments

N78 band 5G NR recordings

https://destevez.net/2025/07/n78-band-5g-nr-recordings/
73•Nokinside•2d ago•3 comments
Open in hackernews

MCP Security Vulnerabilities and Attack Vectors

https://forgecode.dev/blog/prevent-attacks-on-mcp/
153•tested1•10h ago

Comments

Arindam1729•10h ago
Truly, S in MCP stands for Security!
dotancohen•7h ago
The S in SFTP?

The S in SSH?

The S in HTTPS?

The S in MCP?

All stand for the same thing!

I remember when this joke was first applied to IoT.

iotku•6h ago
I do love the joke, but it is worth remembering as well that all of those S were to a certain extent afterthoughts to fix otherwise insecure protocols.

Given how old FTP and HTTP are it's fairly understandable that they weren't initially designed with security in mind, but I think it's valid to question why we're still designing insecure systems in 2025.

amitksingh1490•5h ago
Totally agree, If we have made a mistakes in past we must have learnt from it and when designing a standard specially with AI where the outcome is non deterministic we got be more careful.
postalrat•3h ago
And P in WFH stands for productive.
amitksingh1490•10h ago
MCP new spec has to an extent covered auth. But the MCPs are yet to adopt to that.
simonw•7h ago
Auth doesn't protect against confused deputy attacks, which is a common problem exposed by MCP and other LLM tool systems. https://en.m.wikipedia.org/wiki/Confused_deputy_problem
bitweis•6h ago
100% - especially when Auth stands for just Authentication. Simple RBAC authorization also won't take us far. But Fine-grained Permissions(e.g. OPA, Cedar, OpenFGA, Permit.io) with ReBAC giving ai-agents Zero standing permissions, and only deriving on the fly the least privilege they need / got consent for, can dramatically reduce the problem
aviralb20•10h ago
MCP adoption is picking up fast.
bigyabai•10h ago
This post is an obvious victim of upvote manipulation. HN should ban the forgecode domain if it's going to abuse submissions like this.
dayjah•7h ago
Can you provide some context for your position? I’m not particularly familiar with ForgeCode. I’m interested in why you think there’s manipulation, and what you mean by “submissions like these”.
joshwarwick15•9h ago
Same root causes again - check out https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/
OldfieldFund•9h ago
This can be easily used to search for seeds/private keys when AI coding agents are in YOLO mode.
ethan_smith•6h ago
The "lethal trifecta" refers to default configurations, excessive permissions, and inadequate authentication - three factors that plague MCP implementations just as they did with earlier technologies.
rvz•9h ago
We have not learned anything from the hundreds of open MongoDB databases without passwords floating around the internet waiting to be breached.

We now have the same with MCP servers in the AI era as documented in [0].

[0] https://news.ycombinator.com/item?id=44604453

spiritplumber•8h ago
MCP clearly needs an independent monitoring program to safeguard it. Let's call it Tron.