frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Who has the fastest F1 website (2021)

https://jakearchibald.com/2021/f1-perf-part-3/
39•tosh•37m ago•2 comments

Dwl: Dwm for Wayland

https://codeberg.org/dwl/dwl
8•theycallhermax•27m ago•0 comments

Up to date prices for LLM APIs all in one place

https://pricepertoken.com/
54•alexellman•1h ago•40 comments

Show HN: Apple Health MCP Server

https://github.com/neiltron/apple-health-mcp
56•_neil•1d ago•11 comments

Quantitative AI progress needs accurate and transparent evaluation

https://mathstodon.xyz/@tao/114910028356641733
162•bertman•7h ago•75 comments

The future is not self-hosted

https://www.drewlyton.com/story/the-future-is-not-self-hosted/
29•drew_lytle•2h ago•10 comments

Graphene OS: a security-enhanced Android build

https://lwn.net/SubscriberLink/1030004/898017c7953c0946/
566•madars•16h ago•323 comments

Games Look Bad: HDR and Tone Mapping

https://ventspace.wordpress.com/2017/10/20/games-look-bad-part-1-hdr-and-tone-mapping/
112•uncircle•6h ago•86 comments

Celebrating 20 Years of MDN

https://developer.mozilla.org/en-US/blog/mdn-turns-20/
238•soheilpro•12h ago•35 comments

Google spoofed via DKIM replay attack: A technical breakdown

https://easydmarc.com/blog/google-spoofed-via-dkim-replay-attack-a-technical-breakdown/
204•frasermarlow•8h ago•72 comments

3-JSON

https://rgbcu.be/blog/3-json/
63•RGBCube•4d ago•23 comments

Asciinema: Record and share your terminal sessions

https://asciinema.org
184•phendrenad2•11h ago•48 comments

When photography was born, fascination, obsession, and danger followed

https://www.washingtonpost.com/books/2025/07/12/flashes-brilliance-history-early-photography-anika-burgess-review/
11•prismatic•1d ago•4 comments

Brazil central bank to launch Pix installment feature in September

https://www.reuters.com/technology/brazil-central-bank-launch-pix-installment-feature-september-2025-04-03/
44•CXSHNGCB•3d ago•63 comments

Meta to stop running political ads on Facebook and Instagram in the EU

https://www.euractiv.com/section/tech/news/meta-to-stop-running-political-ads-on-facebook-and-instagram/
10•aquir•14m ago•1 comments

Nuclear Reactor SIM by PeteTimesSix

https://petetimessix.itch.io/nuclear-reactors
36•ofrzeta•3d ago•7 comments

Rapidus Starts 2nm Gate All Around Prototype Production at IIM-1

https://www.servethehome.com/rapidus-starts-2nm-gate-all-around-prototype-production-at-iim-1/
14•rbanffy•3d ago•1 comments

Lisp project of the day

https://40ants.com/lisp-project-of-the-day/index.html
10•perihelions•2h ago•0 comments

My website is one binary (2022)

https://j3s.sh/thought/my-website-is-one-binary.html
9•smartmic•3h ago•0 comments

Qwen3-235B-A22B-Thinking-2507

https://huggingface.co/Qwen/Qwen3-235B-A22B-Thinking-2507
82•tosh•3h ago•14 comments

AMD CEO sees chips from TSMC's US plant costing 5%-20% more

https://www.bloomberg.com/news/articles/2025-07-23/amd-ceo-su-sees-chips-from-us-tsmc-plant-costing-5-to-20-more
367•mfiguiere•1d ago•648 comments

Show HN: MCP server for up-to-date Zig standard library documentation

https://github.com/zig-wasm/zig-mcp
11•afirium•4d ago•4 comments

There is no memory safety without thread safety

https://www.ralfj.de/blog/2025/07/24/memory-safety.html
413•tavianator•22h ago•392 comments

I wasted weeks hand optimizing assembly because I benchmarked on random data

https://www.vidarholen.net/contents/blog/?p=1160
360•thunderbong•4d ago•133 comments

Modernish – A library for writing programs for POSIX-based shells and utilities

https://github.com/modernish/modernish
67•sundarurfriend•3d ago•8 comments

Positron – A next-generation data science IDE

https://positron.posit.co/
203•amai•4d ago•77 comments

Developing with Kiro: Amazon's New Agentic IDE

https://yehudacohen.substack.com/p/developing-with-kiro-amazons-new
41•cebert•4d ago•49 comments

Against the censorship of adult content by payment processors

https://soatok.blog/2025/07/24/against-the-censorship-of-adult-content-by-payment-processors/
132•SlackingOff123•10h ago•88 comments

Scientists may have found a way to eliminate chromosome linked to Down syndrome

https://academic.oup.com/pnasnexus/article/4/2/pgaf022/8016019
359•MattSayar•16h ago•350 comments

How Anthropic teams use Claude Code

https://www.anthropic.com/news/how-anthropic-teams-use-claude-code
216•yurivish•12h ago•157 comments
Open in hackernews

Jitsi privacy flaw enables one-click stealth audio and video capture

https://zimzi.substack.com/p/jitsi-privacy-flaw-that-enables-one
210•zielmicha•1d ago

Comments

o11c•1d ago
Does this apply even for iframes, or not?
zimzi•1d ago
Generally no - cross origin iframes don't allow camera/audio by default. Even if the toplevel site allows it (via https://developer.mozilla.org/en-US/docs/Web/API/HTMLIFrameE...), user still needs to grant permissions to toplevel site. Of course you can still use window.open and top.location.href in the iframe and use the same trick as in the article.
3eb7988a1663•1d ago
Not that I use Jitsi, but I suddenly feel more embarrassed about my number of open tabs. Some other exploit could have silently been launched long ago.
capitainenemo•1d ago
At least in Firefox, tabs recording have a pulsing red microphone on the favicon. I feel like you would have noticed, but perhaps you have so many that it is scrolled out of view?
kevin_thibedeau•1d ago
Old tabs aren't reloaded in Firefox until you click on them. With the pace of updates, tab hoarders are mostly safe.
unsnap_biceps•1d ago
Can someone describe the feature that this is used for? I struggle to think of any valid reason for automatic joining with audio/video like that.
ginking•1d ago
I would say it's to reduce friction - only grant permission once, rather than every time you join a jitsi meeting.
morsch•1d ago
It's not so much about the permissions (which is a browser issue) but about the config.prejoinConfig.enabled flag: usually when joining a meeting, you get an interstitial page which let's you check your webcam image and sound settings before hitting join to enter the call. This setting (passed as a request param) skips that screen.

I'm not a fan, either. I'm used to the interstitial page from other services, and in fact would not expect to join a call and stream data before hitting "join".

Jitsi is used in many custom solutions (which may have their own UI for getting user opt-in, like a customer hitting "Next step" in a registration wizard), I expect that's why they added it.

charcircuit•1d ago
Even without that enabled. You now have to keep the domain registered forever else an attacker can register the domain start recording people from it since permissions do not reset when site ownership changes.
dathinab•1d ago
oh yes, that is such a dump design of web permissions

alongside of the abysmal UX for listing/removing them (from a "normal" user POV it's somehwhat usable for someone who understands tech a bit more)

like in general IMHO origin separation over time (e.g. permissions, cache, local storage) should be bound to some public key cryptography schema where the public key is shipped alongside DNS and every time it changes (or disappears) it's treated as a new origin.

So basically HPKP but 1. one key per origin, 2. separate from the TLS key, 3. way less harmful if messed up so actually just fine to use without worry to permanently lock yourself out.

Also maybe 4. crypto likeable to a group of person/company identity public keys detached from TLS and not spoofable by government DNS/TLS takeover attacks. But in a way where this system is added on top instead of being a building block to make it hard for regulators to effectively shut it down. Like I which police all luck to find all the criminals but history non stop shows we can't rely on governments not going crazy and start prosecuting people for just being different without different meaning "actively" hurting other people or entrapping and then persecuting people for having different political (or religious) opinions or other similar nonsense.

jeroenhd•1d ago
Matrix embedded Jitsi as their voice/video calling solution for a while, probably still does depending on what client you use. Automatically joining the call when you click the call button just makes sense from a UX perspective.

That said, I can't think of a reason why you'd want to permit it outside of very specific containers. Useful for integration, but outright bad design for a public instance.

dathinab•1d ago
if it's embedded in another service and you already clicked join etc. through that other service to name one UX flow where an additional pre-join dialog would be not supper wanted

I e.g. would not complain if MS Teams (I have to use for work) would not put me into a pre join dialog every time I click join in Outlook but just joins me with mic muted/camera disabled by default. But then it also wouldn't be a security issue in my case as I put MS Teams and co. into it's own browser window/process/profile (not due to concerns but more as a side effect of them refusing to even trying to work on Firefox and not wanting to miss out on the tab sync + tab group + account container and not being allowed to install arbitrary extensions which add similar functionality to chrome).

firefax•1d ago
Is this understood to be new? I think I got hit with this quite a long time ago.

(As in during the pandemic -- long ago in vuln times.)

I am willing to discuss it, off the record, if someone provides their signal information.

dathinab•1d ago
yes, it's not new

it's probably also not just affecting Jitsi (in a context only looking at "proper" video conference systems)

through its exceedingly simple to archive with Jitsi

Telemakhos•1d ago
Maybe my Mac is set to be paranoid, but can you share video without being asked to give the mic and camera permission to operate? I chat with jitsi all the time and have to give jitsi explicit permission to use the mic/camera each time.
e40•1d ago
If you’re using jitsi already, won’t you have already given those permissions?
victorbjorklund•1d ago
Probably 99% of people clicks "yes, always"
johnisgood•20h ago
I click and tap "Only this time" on Android and in browsers.
dathinab•1d ago
> but can you share video without being asked to give the mic and camera permission to operate?

yes it's a browser setting to "remember mic/camera permission for given site"

to which extend this "remember" is there by default, can be disabled through system config/MDA etc. is probably very

lastly iff that is a default for Safari on Mac I wouldn't be surprised if that was not only placed their to protect your safety but to annoy you and push you to use Mac, it would fit into a sad list of similar things done by Apple to push people to go through their app store. But then more safe is still more better for many users.

dathinab•22h ago
> is probably very [????]

... browser specific

not sure where that words disappeared, too

spaceport•1d ago
Where do I pay to read security research writeups with only cats used in explainer images and examples? This exploit is cute.
markasoftware•1d ago
this sort of vulnerability (stealth audio and video capture) is surprisingly common, see https://googleprojectzero.blogspot.com/2021/01/the-state-of-...
WHA8m•23h ago
Can't spy on me. Linux drivers not working. /s
cornholio•1d ago
This is clearly a major vulnerability and not a feature, it's a permissions/credentials hijack.

The user has given permission for audio and videos recording to the jitsi domain during a previous meeting, and the domain is using those permissions to start an unsolicited meeting initiated by a 3rd party, who is given access to the video and audio of the victim.

graemep•1d ago
Its also much less likely to be an issue if you self host Jitsi. its only really a worry for large public servers.
abdellah123•1d ago
lol, nice feature. 0 Privacy!
dathinab•1d ago
This attack/feature hinges on the

config.prejoinConfig.enabled=false

config (which implicitly decides weather or not a prejoin dialog is shown)

but this makes me wonder

1. why can you set that config in a URL? Allowing users to set it for them-self seems fine, but allowing rooms or URL to use it seems ... off.

2. how many other sites have this attack surface (e.g. MS Teams) just more obscure

3. actually the moment the attacker controls JS probably *all* other video conference systems have the feature, through potentially needing a lot of additional work. In which case maybe just being straightforward and open about it is fine? But the cost of such an attack is just a very bit too low compared to other conference systems.

saghul•1d ago
Jitsi dev here. We are currently revisiting this. It exists because in cases such as when Jitsi Meet is being embdeed there are pre-join pages provided externally by the "host" site. We will be limiting how this can be used going forward.
qualeed•23h ago
Is/will there be any discussion on how initial triage of potential security issues will be handled in the future?

It was disappointing to see the responses in the post. A curt "It's a feature" to a valid security concern & disclosure, and not replying to a request to publish.

Jitsi says "We encourage responsible disclosure for the sake of our users, so please reach out before posting in a public space.". But if no one bothers to reply, why bother to reach out to Jitsi in the first place?

https://jitsi.org/ says, literally in the hero image banner, "More secure" as the first thing you see. The handling of this raises some concerns about that. (If you don't want to be scrutinized as much about privacy & security stuff, I would recommend not advertising "more secure" as the first thing people see on the site)

saghul•17h ago
You are right, we dropped the ball on this one. We'll try and do better.
arm32•16h ago
Instead of trying, just do. Just do better.
zaggynl•21h ago
Have not been able to reproduce with camera, mic however is unmuted: https://github.com/jitsi/jitsi-meet/issues/16262#issuecommen...
iforgotpassword•21h ago
I mean, I get the idea that you want to skip the whole configure step for webcam/mic if it's embedded somewhere, but I still expect cam/mic to be muted on join. Isn't that what most conferencing tools do, no matter whether you get a config dialog after clicking the join link...