frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

DataTables CDN Outage – post incident review

https://datatables.net/blog/2025/july-29-outage
18•cristoperb•16h ago

Comments

h1fra•1h ago
The takeover due to the lack of response to an email is worrying
theallan•1h ago
Yeah, I really wasn't happy about that. I did put it to the registrar that such a policy is wrong and open to such an attack. I got the impression that they weren't going to change their policy though. Such policies are something I'm going to be looking at when considering a new registrar.
theallan•1h ago
Didn't expect to see this here, it was over a month ago this incident happened! Happy to answer any questions about it (author of DataTables here). It was a super stressful event to say the least, and I've been reading along with the recent npm incidents wondering what I can do to make sure my OpSec is as good as it reasonably can be.
shaunpud•46m ago
Maybe because your Blog RSS [1] shows releases only, it doesn't seem to show these interesting tidbits?

[1] <link rel="alternate" type="application/rss+xml" title="RSS 2.0" href="http://datatables.net/feeds/releases.xml">

theallan•33m ago
The blog feed is here: https://datatables.net/feeds/blog.xml . It is advertised on the landing page, but it looks like I've missed having it on the blog page! As you say, that has the releases feed - thanks for pointing that out.
SOLAR_FIELDS•2m ago
It would be helpful if you would share the name of the registrar so that other people could be aware that this policy exists if you work with that registrar.
DoctorOW•1h ago
> The fact that someone would attack an open source product such as DataTables sickens me. I release by far the majority of my work as free open source software, host a free to use CDN, and support the software.

Seriously, no idea what could motivate this, unless a paid datatables vendor felt you were undercutting their business. We all like to think that attacks are beneath them, but stuff like that has happened before.

itopaloglu83•1h ago
It’s still a complicated attack and I can understand the registrar being confused, though they should’ve called you for sure.

> They used an email address intentionally crafted to look like it could be mine and submitted a fake driver's license and utility bill with information that could only have been from leaked WHOIS data. The registrar accepted this as proof of identity and started the transfer process. That included sending an email to me to confirm the transfer, an email which I never saw due to the flood of emails (which it is now easy to say was the start of the attack).

Edit: Cloudflare blocking the attackers code with a 1000 error is interesting. Could you share some information about it?

theallan•1h ago
Yeah - it was a well set up attack. What I don't understand is that there was no obvious follow on. I can only guess that it was a proof that it could be done. Maybe?

Regarding the 1000 error - I didn't have any 1:1 support contact with CloudFlare - the first I knew was they were returning 1000 errors, which I presume they were doing due to a blacklisted IP being used for the DNS resolving. I'm really not sure though.

Apple Photos App Corrupts Images

https://tenderlovemaking.com/2025/09/17/apple-photos-app-corrupts-images/
77•pattyj•44m ago•12 comments

Oh no, not again a meditation on NPM supply chain attacks

https://tane.dev/2025/09/oh-no-not-again...-a-meditation-on-npm-supply-chain-attacks/
76•theycameback•1h ago•60 comments

Alibaba's New AI Chip Unveiled: Key Specifications Comparable to H20

https://news.futunn.com/en/post/62202518/alibaba-s-new-ai-chip-unveiled-key-specifications-compar...
37•dworks•2h ago•23 comments

GNU Midnight Commander

https://midnight-commander.org/
331•pykello•7h ago•184 comments

Determination of the fifth Busy Beaver value

https://arxiv.org/abs/2509.12337
30•marvinborner•1h ago•0 comments

Notion API importer, with Databases to Bases conversion bounty

https://github.com/obsidianmd/obsidian-importer/issues/421
126•twapi•6h ago•31 comments

Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised

https://socket.dev/blog/ongoing-supply-chain-attack-targets-crowdstrike-npm-packages
1067•jamesberthoty•1d ago•873 comments

The Asus Gaming Laptop ACPI Firmware Bug: A Deep Technical Investigation

https://github.com/Zephkek/Asus-ROG-Aml-Deep-Dive
246•signa11•7h ago•109 comments

EU Chat Control: Germany's position has been reverted to UNDECIDED

https://mastodon.social/@chatcontrol/115215006562371435
112•doener•1h ago•64 comments

Why We're Building Stategraph: Terraform State as a Distributed Systems Problem

https://stategraph.dev/blog/why-stategraph/
25•lawnchair•3h ago•25 comments

PureVPN IPv6 Leak

https://anagogistis.com/posts/purevpn-ipv6-leak/
15•todsacerdoti•1h ago•0 comments

Things you can do with a Software Defined Radio (2024)

https://blinry.org/50-things-with-sdr/
832•mihau•21h ago•136 comments

You can't test if quantum uses complex numbers

https://algassert.com/post/2501
4•EvgeniyZh•1d ago•0 comments

Murex – An intuitive and content aware shell for a modern command line

https://murex.rocks/
53•modinfo•5h ago•20 comments

Doom crash after 2.5 years of real-world runtime confirmed on real hardware

https://lenowo.org/viewtopic.php?t=31
300•minki_the_avali•14h ago•84 comments

How to make the Framework Desktop run even quieter

https://noctua.at/en/how-to-make-the-framework-desktop-run-even-quieter
287•lwhsiao•17h ago•96 comments

I got the highest score on ARC-AGI again swapping Python for English

https://jeremyberman.substack.com/p/how-i-got-the-highest-score-on-arc-agi-again
104•freediver•9h ago•33 comments

Denmark close to wiping out cancer-causing HPV strains after vaccine roll-out

https://www.gavi.org/vaccineswork/denmark-close-wiping-out-leading-cancer-causing-hpv-strains-aft...
798•slu•17h ago•304 comments

Normal-order syntax-rules and proving the fix-point of call/cc

https://okmij.org/ftp/Scheme/callcc-calc-page.html
30•Bogdanp•3d ago•0 comments

DataTables CDN Outage – post incident review

https://datatables.net/blog/2025/july-29-outage
18•cristoperb•16h ago•9 comments

Algebraic Types are not Scary

https://blog.aiono.dev/posts/algebraic-types-are-not-scary,-actually.html
11•Bogdanp•2d ago•3 comments

A dumb introduction to z3

https://asibahi.github.io/thoughts/a-gentle-introduction-to-z3/
215•kfl•2d ago•30 comments

AMD Open Source Driver for Vulkan project is discontinued

https://github.com/GPUOpen-Drivers/AMDVLK/discussions/416
98•haunter•11h ago•26 comments

Samsung 870 QVO 4TB SATA SSD-s: how are they doing after 4 years of use?

https://ounapuu.ee/posts/2025/09/15/samsung-870-qvo/
45•furkansahin•2d ago•16 comments

Waymo has received our pilot permit allowing for commercial operations at SFO

https://waymo.com/blog/#short-all-systems-go-at-sfo-waymo-has-received-our-pilot-permit
645•ChrisArchitect•19h ago•654 comments

In Praise of Idleness (1932)

https://harpers.org/archive/1932/10/in-praise-of-idleness/
74•awanderingmind•5h ago•10 comments

I built my own phone because innovation is sad rn [video]

https://www.youtube.com/watch?v=qy_9w_c2ub0
264•Timothee•2d ago•47 comments

About the security content of iOS 15.8.5 and iPadOS 15.8.5

https://support.apple.com/en-us/125142
324•jerlam•11h ago•140 comments

Bertrand Russell to Oswald Mosley (1962)

https://lettersofnote.com/2016/02/02/every-ounce-of-my-energy/
236•giraffe_lady•19h ago•115 comments

CubeSats are fascinating learning tools for space

https://www.jeffgeerling.com/blog/2025/cubesats-are-fascinating-learning-tools-space
54•calcifer•3d ago•3 comments