frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Altered states of consciousness induced by breathwork accompanied by music

https://journals.plos.org/plosone/article?id=10.1371/journal.pone.0329411
140•gnabgib•4h ago•46 comments

Yamanot.es: A music box of train station melodies from the JR Yamanote Line

https://yamanot.es/
164•zdw•7h ago•47 comments

Researchers find evidence of ChatGPT buzzwords turning up in everyday speech

https://news.fsu.edu/news/education-society/2025/08/26/on-screen-and-now-irl-fsu-researchers-find...
112•giuliomagnifico•7h ago•183 comments

Malicious versions of Nx and some supporting plugins were published

https://github.com/nrwl/nx/security/advisories/GHSA-cxm3-wv7p-598c
331•longcat•1d ago•378 comments

Toyota is recycling old EV batteries to help power Mazda's production line

https://www.thedrive.com/news/toyota-is-recycling-old-ev-batteries-to-help-power-mazdas-productio...
217•computerliker•4d ago•102 comments

Bookmarks.txt is a concept of keeping URLs in plain text files

https://github.com/soulim/bookmarks.txt
19•secwang•2h ago•9 comments

About Containers and VMs

https://linuxcontainers.org/incus/docs/main/explanation/containers_and_vms/
50•Bogdanp•2d ago•26 comments

Canaries in the Coal Mine? Recent Employment Effects of AI [pdf]

https://digitaleconomy.stanford.edu/wp-content/uploads/2025/08/Canaries_BrynjolfssonChandarChen.pdf
7•p1esk•1h ago•1 comments

Nvidia DGX Spark

https://www.nvidia.com/en-us/products/workstations/dgx-spark/
60•janandonly•3d ago•76 comments

Unexpected productivity boost of Rust

https://lubeno.dev/blog/rusts-productivity-curve
324•bkolobara•12h ago•302 comments

Google has eliminated 35% of managers overseeing small teams in past year

https://www.cnbc.com/2025/08/27/google-executive-says-company-has-cut-a-third-of-its-managers.html
330•frays•7h ago•153 comments

VIM Master

https://github.com/renzorlive/vimmaster
233•Fluffyrnz•12h ago•80 comments

Launch HN: Bitrig (YC S25) – Build Swift apps on your iPhone

119•kylemacomber•12h ago•85 comments

Show HN: Meetup.com and eventribe alternative to small groups

https://github.com/polaroi8d/cactoide
64•orbanlevi•7h ago•22 comments

Will Bardenwerper on Baseball's Betrayal of Its Minor League Roots

https://lithub.com/will-bardenwerper-on-baseballs-betrayal-of-its-minor-league-roots/
4•PaulHoule•2d ago•0 comments

GMP damaging Zen 5 CPUs?

https://gmplib.org/gmp-zen5
170•sequin•12h ago•134 comments

The GitHub website is slow on Safari

https://github.com/orgs/community/discussions/170758
301•talboren•18h ago•234 comments

The Therac-25 Incident (2021)

https://thedailywtf.com/articles/the-therac-25-incident
412•lemper•21h ago•244 comments

Areal, Are.na's new typeface

https://www.are.na/editorial/introducing-areal-are-nas-new-typeface
114•g0xA52A2A•2d ago•77 comments

On the screen, Libyans learned about everything but themselves (2021)

https://newlinesmag.com/argument/on-the-screen-libyans-learned-about-everything-but-themselves/
16•thomassmith65•2d ago•0 comments

Beginning 1 September, we will need to geoblock Mississippi IPs

https://dw-news.dreamwidth.org/44429.html
164•AndrewDucker•8h ago•193 comments

Object-oriented design patterns in C and kernel development

https://oshub.org/projects/retros-32/posts/object-oriented-design-patterns-in-osdev
206•joexbayer•1d ago•130 comments

A mini-book on AWS networking

https://www.ducktyped.org/p/a-mini-book-on-aws-networking-introduction
29•crescit_eundo•2d ago•3 comments

A failure of security systems at PayPal is causing concern for German banks

https://www.nordbayern.de/news-in-english/paypal-security-systems-down-german-banks-block-payment...
222•tietjens•10h ago•155 comments

Implementing Forth in Go and C

https://eli.thegreenplace.net/2025/implementing-forth-in-go-and-c/
139•Bogdanp•15h ago•17 comments

Using information theory to solve Mastermind

https://www.goranssongaspar.com/mastermind
92•SchwKatze•4d ago•29 comments

You shouldn't salt a leech that's sucking your blood (2019)

https://www.cbc.ca/news/science/bloodsuckers-1.5361074
74•pabs3•4d ago•52 comments

Lago – Open-Source Usage Based Billing – Is Hiring in Sales, Eng, Ops (EU, US)

https://www.ycombinator.com/companies/lago/jobs
1•AnhTho_FR•11h ago

How to slow down a program and why it can be useful

https://stefan-marr.de/2025/08/how-to-slow-down-a-program/
141•todsacerdoti•16h ago•50 comments

'Rocks as big as cars' are flying down the Dolomites

https://www.bbc.com/future/article/20250819-why-italys-beloved-ancient-monolith-is-falling
96•bookofjoe•3d ago•51 comments
Open in hackernews

About Containers and VMs

https://linuxcontainers.org/incus/docs/main/explanation/containers_and_vms/
50•Bogdanp•2d ago

Comments

jiggawatts•2h ago
It's a bad sign that the first table on the page is full of errors.

"Can only host Linux" -- Windows Containers are a thing too: https://learn.microsoft.com/en-us/virtualization/windowscont...

"Can host a single app" -- not true either. It's just bad practice to host multiple apps in a single container, but it's definitely possible.

IMHO it's not very nice to use the generic-sounding "linuxcontainers.org" domain exclusively for LXC-related content there.

weikju•2h ago
On incus/lxd is true there containers can only be Linux..

Not sure about the one app thing but that’s the general design of those ad well I suppose.

jiggawatts•2h ago
Which just validates my point that a generic-sounding domain is the wrong place to host content that even within the Linux ecosystem is a relatively minor player.
chucky_z•2h ago
lxc is used really frequently in the home space (jellyfin/plex for instance). A lot of Proxmox use cases as well which is growing in popularity extremely rapidly.
jiggawatts•2h ago
Which is small in the scope of things when Docker Desktop and containerd are both used at far larger scales.
esseph•25m ago
I really wish I could just run regular docker or oci containers in Proxmox.
cyberge99•2h ago
I’m not sure I follow. Are you suggesting OP has an incorrect apex domain name?
9dev•2h ago
It’s like selling Pepsi exclusively on soda.org.
weikju•1h ago
Don’t give them any ideas!!!
TrueDuality•1h ago
LXC far predates docker regardless of size or impact. It's not disingenuous if you were literally the foundation docker was able to package into a shiny accessible tool.
wutwutwat•2h ago
linux containers, be it a lxd container, or a containerd/dockerd one, only run on linux hosts.

windows containers, only run on windows hosts.

when you run a linux container on a windows host, you're actually running a linux container inside of a linux vm on top of a windows host.

containers share the host operating system's kernel. it is impossible for a linux container (which is just a linux process) to execute and share the windows kernel. the reverse is true, a windows container (which is just a process) cannot execute and share the linux kernel

the article is correct, linux containers can only execute on a linux host

hliyan•2h ago
As I always say: a VM makes an OS believe that it has the machine to itself; a container makes a process believe that it has the OS to itself.
weikju•1h ago
I'll have to remember that one!
fulafel•55m ago
I think they linuxcontainers.org people would disagree. Like the table is trying to communicate, in contrast to eg Docker, this is not about application containerization.
skywhopper•2h ago
What is this? Docker containers can host more than one process/service/app. And why is some product called “Incus” using “linuxcontainers.org” as a domain name?
paulhart•1h ago
According to their Github page, they _are_ linuxcontainers (in a way), and Incus is Apache licensed:

Incus, which is named after the Cumulonimbus incus or anvil cloud started as a community fork of Canonical's LXD following Canonical's takeover of the LXD project from the Linux Containers community.

The project was then adopted by the Linux Containers community, taking back the spot left empty by LXD's departure.

Incus is a true open source community project, free of any CLA and remains released under the Apache 2.0 license. It's maintained by the same team of developers that first created LXD.

LXD users wishing to migrate to Incus can easily do so through a migration tool called lxd-to-incus.

https://github.com/lxc/incus

xrd•1h ago
incus is the truly open source version of lxc/lxd. It is stable and incredible. I manage dozens of machines and want for nothing, and most importantly, pay nothing for that luxury.
SirGiggles•16m ago
Linux Containers, or LXC, came before Docker and OCI standardization.

As the others have mentioned, Incus is the community fork led by former members of the LXD team.

worik•2h ago
Very cool...

In my experience it has gotta be Docker. For these reasons:

1. I said so

2. I'm the boss

3. Goto 1.

mappu•48m ago
VMs also don't always require hardware virtualization - Alibaba's PVM https://lkml.org/lkml/2024/2/26/1263 didn't get upstreamed, but, theoretically the MMU is all you need for complete isolation. This kind of idea is also how VM software worked before VT-x was introduced. And of course QEMU has the TCG which works with no kernel support at all.
SirGiggles•18m ago
I think you could also add Xen to that list. IIRC, the old Xen PV mode was purely paravirtualized without using any hardware extensions.
01HNNWZ0MV43FF•1m ago
In my experience TCG (or any method that doesn't require root / admin power) is pretty slow. But I'd be happy to be wrong about that, for an odd project I have
reilly3000•47m ago
Can someone explain how a system container is more secure than an application container, if that is indeed the case?
SirGiggles•18m ago
In the context of Incus, they are the same.

Incus and LXC internally use umoci to manipulate the OCI tarball to conform to how LXC runs containers.

See: - https://umo.ci/ - https://github.com/lxc/lxc/blob/lxc-4.0.2/templates/lxc-oci....

thundergolfer•13m ago
The article is pretty useless at explaining the difference, I agree. It makes claims about Docker that aren't true (e.g. single container) while making inadequate reference to the OS features likely involved in making "system containers" what they are (SECCOMP, capabilities, network namespaces, nftables).

As an engineer this page has a real "trust me bro" feel to it. Maybe fine as a marketing and product positioning thing, but not interesting for HN.

zie•8m ago
It generally is more secure just because the system container virtualization system is "more complete", so it's harder to get out from under it.

My understanding with Incus(the OP link) it's the same virtualization system, so there is no real difference, security wise between the two.

The question then becomes can they get out from under the virtualization and can they get access to other machines, containers, etc.

Docker's virtualization system has been very weak security wise. So a system container would be more secure than docker's virtualization system.