frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Start all of your commands with a comma

https://rhodesmill.org/brandon/2009/commands-with-comma/
142•theblazehen•2d ago•42 comments

OpenCiv3: Open-source, cross-platform reimagining of Civilization III

https://openciv3.org/
668•klaussilveira•14h ago•202 comments

The Waymo World Model

https://waymo.com/blog/2026/02/the-waymo-world-model-a-new-frontier-for-autonomous-driving-simula...
949•xnx•19h ago•551 comments

How we made geo joins 400× faster with H3 indexes

https://floedb.ai/blog/how-we-made-geo-joins-400-faster-with-h3-indexes
122•matheusalmeida•2d ago•33 comments

Unseen Footage of Atari Battlezone Arcade Cabinet Production

https://arcadeblogger.com/2026/02/02/unseen-footage-of-atari-battlezone-cabinet-production/
53•videotopia•4d ago•2 comments

Show HN: Look Ma, No Linux: Shell, App Installer, Vi, Cc on ESP32-S3 / BreezyBox

https://github.com/valdanylchuk/breezydemo
229•isitcontent•14h ago•25 comments

Jeffrey Snover: "Welcome to the Room"

https://www.jsnover.com/blog/2026/02/01/welcome-to-the-room/
16•kaonwarb•3d ago•19 comments

Vocal Guide – belt sing without killing yourself

https://jesperordrup.github.io/vocal-guide/
28•jesperordrup•4h ago•16 comments

Monty: A minimal, secure Python interpreter written in Rust for use by AI

https://github.com/pydantic/monty
223•dmpetrov•14h ago•117 comments

Show HN: I spent 4 years building a UI design tool with only the features I use

https://vecti.com
330•vecti•16h ago•143 comments

Hackers (1995) Animated Experience

https://hackers-1995.vercel.app/
494•todsacerdoti•22h ago•243 comments

Sheldon Brown's Bicycle Technical Info

https://www.sheldonbrown.com/
381•ostacke•20h ago•95 comments

Microsoft open-sources LiteBox, a security-focused library OS

https://github.com/microsoft/litebox
359•aktau•20h ago•181 comments

Show HN: If you lose your memory, how to regain access to your computer?

https://eljojo.github.io/rememory/
288•eljojo•17h ago•169 comments

An Update on Heroku

https://www.heroku.com/blog/an-update-on-heroku/
412•lstoll•20h ago•278 comments

Was Benoit Mandelbrot a hedgehog or a fox?

https://arxiv.org/abs/2602.01122
19•bikenaga•3d ago•4 comments

PC Floppy Copy Protection: Vault Prolok

https://martypc.blogspot.com/2024/09/pc-floppy-copy-protection-vault-prolok.html
63•kmm•5d ago•6 comments

Dark Alley Mathematics

https://blog.szczepan.org/blog/three-points/
90•quibono•4d ago•21 comments

How to effectively write quality code with AI

https://heidenstedt.org/posts/2026/how-to-effectively-write-quality-code-with-ai/
256•i5heu•17h ago•196 comments

Delimited Continuations vs. Lwt for Threads

https://mirageos.org/blog/delimcc-vs-lwt
32•romes•4d ago•3 comments

What Is Ruliology?

https://writings.stephenwolfram.com/2026/01/what-is-ruliology/
44•helloplanets•4d ago•42 comments

Where did all the starships go?

https://www.datawrapper.de/blog/science-fiction-decline
12•speckx•3d ago•5 comments

Introducing the Developer Knowledge API and MCP Server

https://developers.googleblog.com/introducing-the-developer-knowledge-api-and-mcp-server/
59•gfortaine•12h ago•25 comments

Female Asian Elephant Calf Born at the Smithsonian National Zoo

https://www.si.edu/newsdesk/releases/female-asian-elephant-calf-born-smithsonians-national-zoo-an...
33•gmays•9h ago•12 comments

I now assume that all ads on Apple news are scams

https://kirkville.com/i-now-assume-that-all-ads-on-apple-news-are-scams/
1066•cdrnsf•23h ago•446 comments

I spent 5 years in DevOps – Solutions engineering gave me what I was missing

https://infisical.com/blog/devops-to-solutions-engineering
150•vmatsiiako•19h ago•67 comments

Understanding Neural Network, Visually

https://visualrambling.space/neural-network/
288•surprisetalk•3d ago•43 comments

Why I Joined OpenAI

https://www.brendangregg.com/blog/2026-02-07/why-i-joined-openai.html
149•SerCe•10h ago•138 comments

Learning from context is harder than we thought

https://hy.tencent.com/research/100025?langVersion=en
183•limoce•3d ago•98 comments

Show HN: R3forth, a ColorForth-inspired language with a tiny VM

https://github.com/phreda4/r3
73•phreda4•13h ago•14 comments
Open in hackernews

High-severity WinRAR 0-day exploited for weeks by 2 groups

https://arstechnica.com/security/2025/08/high-severity-winrar-0-day-exploited-for-weeks-by-2-groups/
76•chrisjj•5mo ago

Comments

smokel•5mo ago
> WinRAR, a utility for compressing files, and has an installed base of about 500 million.

Yeah, right.

Edit: this figure is possibly taken from the WinRAR website [1]. It is more likely that there have been that many cumulative downloads, and even that seems to be a high number. Given that Windows has .zip file support built-in for quite some time, and the fact that nearly nobody downloads .zip files anymore, makes me very suspicious of this kind of statistic.

[1] https://www.win-rar.com/

sidewndr46•5mo ago
While I know that WinRAR has some die-hard user bases, I have never been sure who their paying user base is. Are there some companies that are completely dependent on WinRAR for some internal processes?
RiverCrochet•5mo ago
I remember RAR being popular in the early 00's but when 7-zip started becoming a thing I switched to that, and then I rarely saw .RAR's.

RAR seemed to handle large collections of files better on Windows than .zip back in the day, and it had a few features that .zip didn't, so it was something I typically installed on like Windows XP and such back then. But I'm not sure why anyone would use it over 7-zip today unless you have massive numbers of old .RAR files laying around.

I did work for a company that actually licensed WinZip because it was easier to use than the default Windows interface for .zip files.

johnmaguire•5mo ago
> But I'm not sure why anyone would use it over 7-zip today unless you have massive numbers of old .RAR files laying around.

Even then, 7-zip supports extracting rar.

hulitu•5mo ago
> But I'm not sure why anyone would use it over 7-zip today

7zip UI is ... a bit special. It is not shitty like Windows {10,11}, but it needs some emotional attention.

FirmwareBurner•5mo ago
> Are there some companies that are completely dependent on WinRAR for some internal processes?

In aa world where 7zip exists, most likely not.

AlexandrB•5mo ago
I'm one of their paying user base. To me WinRAR is like the VLC of archives. I can throw almost anything at it and it will work. Other compression tools, not so much. I'm also a fan of giving money to small, independent developers.
close04•5mo ago
WinRAR's strong point is support for RAR archives, not ZIP which has been natively supported in Windows for years (since XP?).

I think Windows 11 got native RAR and 7Z support recently but I'm not sure what libraries it uses for this.

hatsuseno•5mo ago
Sort of, the "zip folder" thing was introduced with the "98 Plus!" pack, but came natively with XP. That said, "natively supported in Windows" is one thing, but the usability was... well, not great. The entire "it's a compressed folder!" analogy seems reasonable, but the implementation wasn't. It ate memory like few other components, crashed often, and because it was treated like a folder only in file explorer the analogy quickly broke down when using a file picker anywhere else. WinZIP and WinRAR were basically requirements if you often worked with zip archives until 7zip came along and did everything just a tad better.
scrlk•5mo ago
Windows 11 uses libarchive: https://en.wikipedia.org/wiki/Libarchive#Users
jeroenhd•5mo ago
WinRAR is still very popular in my experience. I don't know why, but it definitely is. People still send me .rar files.
nerdjon•5mo ago
I don't doubt the numbers.

Until very recently Windows could not natively unarchive .rar files and you needed to download WinRAR to be able to do this. I still find it not terribly uncommon to run into a random .rar file that previously would have meant I needed to install it, even if I only used it once.

> and the fact that nearly nobody downloads .zip files anymore

Citation needed? Why would people not be downloading .zip files anymore?

hnuser123456•5mo ago
What I don't get is why people kept installing WinRAR when 7zip can do all the same things and doesn't beg for money.
TonyTrapp•5mo ago
Subjective: WinRAR has nicer UI.

Objective: 7z (the format) doesn't have the same data recovery options as RAR. As it stands, RAR remains one of the best options for long-term archival of data for casual users thanks to its optional recovery records.

nerdjon•5mo ago
Sure, but if you are a non technical user what are you likely going to search for first.

A lot of non technical people know "winrar" and even if they don't if you search "rar file" on Google the first result is winrar.

close04•5mo ago
WinRAR in my experience has a better speed/compression ratio than 7Zip. If you need best compression 7z is probably best but it will cost you some extra time. The GUI and integration of 7Zip also aren't as polished as WinRAR's. I've been using both since their early versions and each have their individual strengths.
wongarsu•5mo ago
7zip can't do all the same things. It's an incomplete WinRar clone that leaves out a lot of features and adds very little on its own, besides the 7zip format and being open source (both neat things, but that doesn't replace the long list of features it doesn't have or the worse UI)
hulitu•5mo ago
> What I don't get is why people kept installing WinRAR

Kids those days. There are some rar archives ( with recovery record ? ) that are only readable by winrar.

sim7c00•5mo ago
i have not seen anything relevant packaged in rar for at since the early 2000s
smokel•5mo ago
You can't get a citation for this, and I must admit that this was a bit of a hyperbole.

Still, I sincerely believe that in a typical year, a typical user runs into zero or one .zip files. Of course there are exceptions, but these power users do not make up a large part of the population. Facebook and Instagram are not shipped in .zip format for a reason.

Here are some numbers to think about:

According to Microsoft, there are ~1.4 billion devices that run Windows 10 or Windows 11 [1]. Apparently, there are some 200 million additional devices that run older versions of Windows [2].

Now, I could hypothetically ask my mom and dad, and find out that only one of them knows what a .zip file is. The other has not heard of .rar. I don't think I myself am a typical user, but I do know .rar, and I do not even have WinRAR installed.

That leaves me to conclude that it is very, very, unlikely that 31% of all Windows users has WinRAR installed.

[1] https://blogs.windows.com/windowsexperience/2025/06/24/stay-...

[2] https://jitendra.co/how-many-windows-users-are-there-in-the-...

k_roy•5mo ago
I know many people that still use it because it does all formats, it’s what they’ve been using forever, and the UI is so much better than using zip on Windows.

Of course, RAR usage nowadays is probably a bit more limited to things like usenet downloads, so the people caring enough to install an alternative decompressor is narrowing.

Larrikin•5mo ago
Don't all email providers automatically zip attachments after a certain number and don't all the major OSes try to hide extensions and include zip handling? I'm not sure what your parents knowing about zip files indicates about its usage.
entelechy0•5mo ago
winrar has been around since I was in high school...21+ years 500 million downloads isn't unreasonable during that time frame real question is: how many windows boxes are up right now and how many have winrar installed
bdcravens•5mo ago
I haven't downloaded it in 10 years or more, but I know I've downloaded it (and WinZip) a few dozen times. Back in the day I even had a paid license.

I do reject the idea that "nearly nobody downloads .zip files anymore". It's still pretty common. Crafters using Cricuts and engravers regularly download zip files of fonts, etc. Fedex/UPS package up invoices of a certain size, or consolidated billing accounts, in zip files. Etc.

transcriptase•5mo ago
Every game mod for every game ever.
HackerThemAll•5mo ago
"nearly nobody downloads .zip files anymore"

At this point you lost my attention.

hulitu•5mo ago
> Given that Windows has .zip file support built-in for quite some time, and the fact that nearly nobody downloads .zip files anymore, makes me very suspicious of this kind of statistic.

Windows has _some_ .zip file support. Winrar is usually used for rar files. Zip files are still used (docx xlsx and pptx are zip files).

pityJuke•5mo ago
> The exploit abused that feature to trigger a previously unknown path traversal flaw that caused WinRAR to plant malicious executables in attacker-chosen file paths %TEMP% and %LOCALAPPDATA%, which Windows normally makes off-limits because of their ability to execute code.

This seems... wrong? Isn't %LOCALAPPDATA% commonly used to store executables for programs that want to install for a single user and not the whole computer? An example of which includes Google Chrome?

jeroenhd•5mo ago
ESET's story seems to make more sense: https://www.welivesecurity.com/en/eset-research/update-winra...

The exploit abuses ADSes with ..\ in the name to drop files on the system that aren't visible in the WinRAR file browser. It drops malware in the temp directory and then a .lnk in the Startup directory to activate an attack against COM, influencing the DLL that's being loaded by legitimate applications.

dataflow•5mo ago
> This seems... wrong? Isn't %LOCALAPPDATA% commonly used to store executables for programs that want to install for a single user and not the whole computer? An example of which includes Google Chrome?

Maybe you're thinking of %AppData%?

gruez•5mo ago
No, he's right.

>By default, VS Code is installed under C:\Users\{Username}\AppData\Local\Programs\Microsoft VS Code.

https://code.visualstudio.com/docs/setup/windows

%appdata% would be C:\Users\{Username}\AppData\Roaming

wongarsu•5mo ago
%LocalAppData% is for files you wouldn't want to synchronize across multiple computers using the same account. Installed programs squarely fall into that category, even just based on size. %AppData% is also commonly used to install executables, but I'd consider that a bug. Just like putting your cache dir in %appdata% instead of %localappdata%
rkagerer•5mo ago
The only reason publishers use those appdata paths for executables is so regular users can install their software without needing an administrator or a UAC prompt, since Microsoft locked down installing to the various Program Files directories.
wongarsu•5mo ago
But %localappdata% has all the same advantages and permissions. Using %appdata% for executables is usually a mix of ignorance and indifference. Roaming user profiles are a rare setup nowadays and are even less common on developer machines. And it's not like it breaks in obvious ways, the is just more storage space used and login is slower because more data is transferred from the server, in a setup that devs and PMs don't use
philipwhiuk•5mo ago
Can someone explain why you would ever want to compress a file into .rar?
exhilaration•5mo ago
I bet it's Usenet users. WinRAR can split large files into chunks that are uploaded as separate Usenet messages.
JackeJR•5mo ago
And also have parity built in for file recovery. The alternative will be to use par2 to create parity files.
qingcharles•5mo ago
The parity files are the killer feature for me. Probably 95% of the downloads from Usenet end up needing them.
dmonitor•5mo ago
7z also does this now FWIW

I'd still bet it's Usenet users that installed WinRAR way back when and have stuck to it ever since

kayson•5mo ago
That's me. But now everything is done automagically by nzbget and I use nanazip on my Windows desktop.
DaSHacka•5mo ago
Better compression over .zip and other older formats (like .gz).

Why people use it over .7z though? For that, I have no idea.

CJefferson•5mo ago
rar is super popular in China, because for a long time (and still with many modern implementations) it is much better at preserving Chinese filenames in Windows than zip.
chrisjj•5mo ago
Does zip actually alter some filenames, then?
chrisjj•5mo ago
Wider filename character support, for one.
JosephRedfern•5mo ago
There's a really interesting article from Tavis Ormandy about the instruction set and virtual machine used in RAR: https://blog.cmpxchg8b.com/2012/09/fun-with-constrained-prog....

The docs for the toolchain he implemented (https://github.com/taviso/rarvmtools) allude to a number of bugs, but doesn't sound (??) like they're related to this vulnerability.

LegionMammal978•5mo ago
The VM has long since been torn out of the RAR decompressor. These days, when it finds a file containing bytecode, it just hashes the bytecode and matches it against a few hardcoded routines that existed at the time.
zzrrt•5mo ago
Sounds like a good ingredient for a CTF or other puzzle. It could be a small obfuscation where player has to install an ancient version with the VM, or get crazier with a byecode hash collision or abusing undocumented VM quirks.