frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

TapTrap: Animation‑Driven Tapjacking on Android

https://taptrap.click/
56•Bogdanp•8h ago

Comments

tehwebguy•5h ago
> independently and confidentially reported by @MG193_7 (ByteDance IES RedTeam) to the Android Security Team in early 2023

I wonder if this is in the wild anywhere, it has to be after 2.5 years right?

SoftTalker•5h ago
Another reason not to install random apps.
subscribed•1h ago
You probably forgot about multiple instances of malware found in the official Google Play store.
qbane•4h ago
This has a long history dating back to the Flash era.

https://owasp.org/www-community/attacks/Clickjacking

> One of the most notorious examples of Clickjacking was an attack against the Adobe Flash plugin settings page. By loading this page into an invisible iframe, an attacker could trick a user into altering the security settings of Flash, giving permission for any Flash animation to utilize the computer’s microphone and camera.

user_7832•4h ago
> If you use an Android phone and haven’t disabled system animations, then yes, you’re likely affected. iPhone users are not affected.

Okay... that was much worse than I expected. Looks like you can get the victim to click anywhere, which looks bad. I thought Android had protections against this?

> It is based on transition animations instead of overlays, so it doesn’t need special permissions and isn’t blocked by Android’s overlay protections.

Oh well. Not sure how that slipped past.

altfredd•3h ago
This might be somewhat less threatening then it sounds, because it requires caller to fully control animations used for entering the targeted Activity.

In particular, this vulnerability might not overcome root permission prompts on rooted devices, because their windows are launched and controlled by the installed su app, not by attacker.

wiseowise•1h ago
Sleek website.
_vere•1h ago
Actually insane that this isn't patched in AOSP yet, literally the only android devices that aren't vulnerable are those running graphene. For companies as big as google, there really ought to be just disgusting financial penalties if they leave something like this unfixed for this amount of time.

Extending Emacs with Fennel (2024)

https://andreyor.st/posts/2024-12-20-extending-emacs-with-fennel/
33•Bogdanp•2h ago•2 comments

Rescuing two PDP-11s from a former British Telecom underground shelter (2023)

https://forum.vcfed.org/index.php?threads/rescuing-two-pdp-11-systems-in-uk-from-a-former-big-british-telecom-underground-shelter-in-central-london.1244723/page-2
39•mhh__•2h ago•6 comments

Qwen3-Coder: Agentic coding in the world

https://qwenlm.github.io/blog/qwen3-coder/
537•danielhanchen•11h ago•181 comments

Mathematics for Computer Science (2024)

https://ocw.mit.edu/courses/6-1200j-mathematics-for-computer-science-spring-2024/
92•vismit2000•4h ago•10 comments

When Is WebAssembly Going to Get DOM Support?

https://queue.acm.org/detail.cfm?id=3746174
33•jazzypants•3h ago•12 comments

Show HN: WTFfmpeg – Natural Language to FFmpeg Translator

https://github.com/scottvr/wtffmpeg
48•ycombiredd•4h ago•28 comments

Org tutorials

https://orgmode.org/worg/org-tutorials/index.html
63•dargscisyhp•5h ago•11 comments

Depot (YC W23) Is Hiring a Technical Content Writer (Remote)

https://www.ycombinator.com/companies/depot/jobs/BzrfAzP-technical-content-writer
1•jacobwg•47m ago

More than you wanted to know about how Game Boy cartridges work

https://abc.decontextualize.com/more-than-you-wanted-to-know/
291•todsacerdoti•13h ago•32 comments

Android Earthquake Alerts: A global system for early warning

https://research.google/blog/android-earthquake-alerts-a-global-system-for-early-warning/
255•michaefe•13h ago•84 comments

Why you can't color calibrate deep space photos

https://maurycyz.com/misc/cc/
124•LorenDB•8h ago•56 comments

Algorithms for Modern Processor Architectures

https://lemire.github.io/talks/2025/sea/sea2025.html
161•matt_d•9h ago•19 comments

Swift-erlang-actor-system

https://forums.swift.org/t/introducing-swift-erlang-actor-system/81248
276•todsacerdoti•13h ago•56 comments

Managing EFI boot loaders for Linux: Controlling secure boot (2015)

https://www.rodsbooks.com/efi-bootloaders/controlling-sb.html
27•CaliforniaKarl•3d ago•0 comments

We built an air-gapped Jira alternative for regulated industries

https://plane.so/blog/everything-you-need-to-know-about-plane-air-gapped
217•viharkurama•13h ago•131 comments

AI coding agents are removing programming language barriers

https://railsatscale.com/2025-07-19-ai-coding-agents-are-removing-programming-language-barriers/
60•Bogdanp•4h ago•44 comments

AI groups spend to replace low-cost 'data labellers' with high-paid experts

https://www.ft.com/content/e17647f0-4c3b-49b4-a031-b56158bbb3b8
9•eisa01•3d ago•3 comments

I watched Gemini CLI hallucinate and delete my files

https://anuraag2601.github.io/gemini_cli_disaster.html
183•anuraag2601•13h ago•196 comments

Countries across the world see food price shocks from climate extremes

https://www.bsc.es/news/bsc-news/countries-across-the-world-see-food-price-shocks-climate-extremes-research-involving-bsc-shows
55•littlexsparkee•4h ago•29 comments

Don't animate height

https://www.granola.ai/blog/dont-animate-height
371•birdculture•3d ago•212 comments

Subliminal learning: Models transmit behaviors via hidden signals in data

https://alignment.anthropic.com/2025/subliminal-learning/
158•treebrained•14h ago•35 comments

TODOs aren't for doing

https://sophiebits.com/2025/07/21/todos-arent-for-doing
339•todsacerdoti•18h ago•200 comments

Fourier lightfield multiview stereoscope for large field-of-view 3D imaging

https://www.spiedigitallibrary.org/journals/advanced-photonics-nexus/volume-4/issue-04/046008/Fourier-lightfield-multiview-stereoscope-for-large-field-of-view-3D/10.1117/1.APN.4.4.046008.full
7•PaulHoule•2d ago•0 comments

TapTrap: Animation‑Driven Tapjacking on Android

https://taptrap.click/
56•Bogdanp•8h ago•8 comments

Font Comparison: Atkinson Hyperlegible Mono vs. JetBrains Mono and Fira Code

https://www.anthes.is/font-comparison-review-atkinson-hyperlegible-mono.html
210•maybebyte•18h ago•135 comments

Show HN: A word of the day that doesn't suck

47•jsomers•20h ago•20 comments

Gemini North telescope discovers long-predicted stellar companion of Betelgeuse

https://www.science.org/content/article/betelgeuse-s-long-predicted-stellar-companion-may-have-been-found-last
124•layer8•15h ago•30 comments

Many lung cancers are now in nonsmokers

https://www.nytimes.com/2025/07/22/well/lung-cancer-nonsmokers.html
155•alexcos•17h ago•192 comments

Show HN: Phind.design – Image editor & design tool powered by 4o / custom models

https://phind.design
56•rushingcreek•14h ago•16 comments

Project Lyra – Exploring Interstellar Objects

https://i4is.org/what-we-do/technical/project-lyra/
10•andsoitis•3h ago•0 comments