frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Meta Superintelligence's surprising first paper

https://paddedinputs.substack.com/p/meta-superintelligences-surprising
42•skadamat•1h ago•6 comments

The <output> Tag

https://denodell.com/blog/html-best-kept-secret-output-tag
694•todsacerdoti•15h ago•157 comments

The Murder That Made Skip Hollandsworth a True Crime Writer

https://www.texasmonthly.com/true-crime/skip-hollandsworth-new-book-she-kills/
11•speckx•5d ago•1 comments

Microsoft only lets you opt out of AI photo scanning 3x a year

https://hardware.slashdot.org/story/25/10/11/0238213/microsofts-onedrive-begins-testing-face-reco...
331•dmitrygr•5h ago•106 comments

ElementaryOS - The thoughtful, capable and ethical replacement for Windows/macOS

https://elementary.io/
66•donutshop•3h ago•58 comments

We Found a Hidden Camera in the Bathroom of Our Airbnb

https://www.nytimes.com/2025/10/09/travel/airbnb-refund-camera-bathroom.html
15•danso•1h ago•10 comments

How Apple designs a virtual knob (2012)

https://jherrm.github.io/knobs/
98•gregsadetsky•4d ago•70 comments

Testing two 18 TB white label SATA hard drives from datablocks.dev

https://ounapuu.ee/posts/2025/10/06/datablocks-white-label-drives/
133•thomasjb•5d ago•79 comments

Rating 26 years of Java changes

https://neilmadden.blog/2025/09/12/rating-26-years-of-java-changes/
135•PaulHoule•5h ago•138 comments

LineageOS 23

https://lineageos.org/Changelog-30/
13•cdesai•27m ago•2 comments

Diane Keaton has died

https://www.nytimes.com/2025/10/11/movies/diane-keaton-dead.html
76•mhb•3h ago•10 comments

GNU Health

https://www.gnuhealth.org/about-us.html
317•smartmic•8h ago•91 comments

AMD and Sony's PS6 chipset aims to rethink the current graphics pipeline

https://arstechnica.com/gaming/2025/10/amd-and-sony-tease-new-chip-architecture-ahead-of-playstat...
285•zdw•19h ago•356 comments

The World Trade Center under construction through photos, 1966-1979

https://rarehistoricalphotos.com/twin-towers-construction-photographs/
183•kinderjaje•4d ago•92 comments

A Guide for WireGuard VPN Setup with Pi-Hole Adblock and Unbound DNS

https://psyonik.tech/posts/a-guide-for-wireguard-vpn-setup-with-pi-hole-adblock-and-unbound-dns/
16•pSYoniK•4h ago•4 comments

People regret buying Amazon smart displays after being bombarded with ads

https://arstechnica.com/gadgets/2025/10/people-regret-buying-amazon-smart-displays-after-being-bo...
155•croes•6h ago•75 comments

Windows Subsystem for FreeBSD

https://github.com/BalajeS/WSL-For-FreeBSD
208•rguiscard•16h ago•80 comments

Superpowers: How I'm using coding agents in October 2025

https://blog.fsck.com/2025/10/09/superpowers/
263•Ch00k•16h ago•152 comments

Google blocks Android hack that let Pixel users enable VoLTE anywhere

https://www.androidauthority.com/pixel-ims-broken-october-update-3606444/
7•josephcsible•40m ago•1 comments

Japan's summers have lengthened by 3 weeks over 42 years, say resaerchers

https://english.kyodonews.net/articles/-/62626
63•anigbrowl•3h ago•8 comments

All-New Next Gen of UniFi Storage

https://blog.ui.com/article/all-new-next-gen-of-unifi-storage
45•ycombinete•3d ago•27 comments

Every LLM Is Its Own Media Channel

https://www.aivojournal.org/every-llm-is-its-own-media-channel/
3•businessmate•3d ago•1 comments

Vibing a non-trivial Ghostty feature

https://mitchellh.com/writing/non-trivial-vibing
204•skevy•9h ago•101 comments

Indonesia says 22 plants in industrial zone contaminated by caesium 137

https://www.reuters.com/sustainability/boards-policy-regulation/indonesia-says-22-plants-industri...
59•geox•4h ago•19 comments

I built physical album cards with NFC tags to teach my son music discovery

https://fulghum.io/album-cards
547•jordanf•1d ago•188 comments

Microsoft Amplifier

https://github.com/microsoft/amplifier
205•JDEW•9h ago•125 comments

Building a JavaScript Runtime using C

https://devlogs.xyz/blog/building-a-javaScript-runtime
63•redbell•4d ago•24 comments

Beyond indexes: How open table formats optimize query performance

https://jack-vanlightly.com/blog/2025/10/8/beyond-indexes-how-open-table-formats-optimize-query-p...
17•jandrewrogers•3d ago•0 comments

A quiet change to RSA

https://www.johndcook.com/blog/2025/10/06/a-quiet-change-to-rsa/
89•ibobev•5d ago•28 comments

(Re)Introducing the Pebble Appstore

https://ericmigi.com/blog/re-introducing-the-pebble-appstore/
262•duck•1d ago•48 comments
Open in hackernews

Discord hack shows risks of online age checks

https://news.sky.com/story/discord-hack-shows-dangers-of-online-age-checks-as-internet-policing-hopes-put-to-the-test-13447618
149•ColinWright•4h ago

Comments

dbg31415•4h ago
I don’t understand why we need age verification in Discord. Why should people who play games have to prove they’re old enough to talk to others? It’s not like anyone ever forced anybody else to join your Discord community, it’s all opt in!

If parents don’t want their kids playing certain games, or if a community is more adult in nature, then don’t buy those games for them. If they don’t want their kids exposed to bad influences, they can move the computer into a shared space or—better yet—just engage with their kids on a human level. That’s called parenting.

Politicians shouldn’t be meddling in this kind of personal interaction. It didn’t work when Nancy Reagan or Tipper Gore tried to police music, and it’s not working now. Modern authoritarians are just running the same tired playbook.

Age verification doesn’t make kids safer. It adds bureaucracy, harvests private data, and pretends to solve a problem that only families can actually fix. The result is more surveillance, less trust, and the illusion of protection.

maccard•4h ago
I agree with you but;

> I don’t understand why we need age verification in Discord. Why should people who play games have to prove they’re old enough to talk to others? It’s not like anyone ever forced anybody else to join your Discord community, it’s all opt in!

Discord doesn't require age verirication for voice chat, it requires it for access to "sensitive media", or when yuo try to access a channel that has self opted in as age restricted [0].

[0] https://support.discord.com/hc/en-us/articles/30326565624343...

idle_zealot•3h ago
> Politicians shouldn’t be meddling in this kind of personal interaction.

Broadly I agree. I think there is room for good regulation here, though. Specifically, a legal obligation to hook into parental control systems to enable effective parenting in our increasingly complex digital world. While it would be nice if everyone were individually responsible enough to put in the effort to figure out the specifics of what their kids might be exposed to and the control mechanisms available to them, realistically that's probably expecting too much. There's no perfect solution, but intervention focused on obligating (especially large) organizations to empower users and make safety easy to understand and act on is infinitely preferable to obligating companies to restrict and police their users.

debo_•3h ago
A lot of servers have the equivalent of a #nsfw channel where you post dank stuff. I don't agree with the age verification approach, but I see why it concerns people. Discord naturally attracts a very diverse crowd, of which many are quite young. Walking into a random channel in your random all-ages jrpg server and finding horse porn might concern a parent. (This is a concrete example that I have experienced, not a theoretical one.)
squigz•3h ago
And almost all of those servers have those channels marked as such. But when I set it as an NSFW channel, I didn't agree to demand my users' privacy be invaded. Now, I just remove the NSFW flag from those channels. ¯\_(ツ)_/¯
debo_•2h ago
Yeah. I did the same.
mulmen•1h ago
The random porn in a JRPG chat is concerning but how does age verification prevent that?

Channels have to opt in and participants have to follow the rules, right?

Isn’t the real issue that you don’t know and trust all the participants personally?

charcircuit•3h ago
It's similar to needing ID for purchasing alchohol. You could use the same excuse that parents shouldn't buy alcohol for their kids, but there is the obvious workaround of kids buying it themselves.
mulmen•3h ago
Yes it’s similar, which is the point. Age restrictions have been normalized regardless of effectiveness.
awesome_dude•3h ago
> Age restrictions have been normalized regardless of effectiveness.

For the record.

A law doesn't stop anything.

All a law does is says "If some behaviour meets definition X AND the state becomes aware of it, then consequence Y will be applied by the state"

The hope is that people will see that and make a choice that ensures that they aren't liable for the consequence.

It's also, like everything, as effective as the enforcement. If it's not enforced well, nobody will abide by it.

mulmen•1h ago
> All a law does is says "If some behaviour meets definition X AND the state becomes aware of it, then consequence Y will be applied by the state"

Might be applied, and the terms are negotiable.

bramhaag•4h ago
The thing that everybody expected to happen, happened. At least the kids are safe.

Why were these images not encrypted, and why were they retained for longer than was necessary?

miohtama•4h ago
Why the files were asked in the first place?
naldb•4h ago
Encrypted? Encrypted how? How would the employees tasked with age verification access them if they were encrypted?
jvanderbot•3h ago
By decrypting them with a hardware token or passphrase or memorized password or timeboxed token of another kind.

But honestly just delete them ASAP, that's the issue

Dylan16807•3h ago
And if all the employees have access to this hardware token or passphrase or memorized password or timeboxed token of some kind, does that actually prevent a hack, or does it just let you bullet point "encrypted"?

The main thing encryption prevents is someone that steals a physical device getting access to the data inside. It doesn't do much about unauthorized access to live servers.

awesome_dude•3h ago
I mean, this is the problem for all companies with sensitive data (ensuring that "ex" employees no longer have access to <stuff>).

Generally it's done via accessing some 3rd party secret storage system where employees need to verify themselves to get access (eg. Vault, or AWS secrets or what have you)

Dylan16807•3h ago
Do you think this breach had anything to do with ex-employees retaining access? That also sounds like solving the wrong problem.
awesome_dude•3h ago
I mean this is posted on this page too.

z> nomilk 8 minutes ago | prev | next [–]

> The hacker claims an outsourced worker was compromised through a $500 bribe Also interesting:

> The hacker claims government IDs were just sitting there for months or even years... I have spoken to people familiar with Discord's Age Verification system, and they said after some period of time Discord will delete (the copies of IDs), but they should be deleting them the second they're done

Source (pinned comment, and 7m20s respectively): https://www.youtube.com/watch?v=NnuyT8FgSpA

reply

vehementi•3h ago
Check out Defense in Depth as a security concept
Dylan16807•3h ago
It's not defense in depth, it's defense against a different threat entirely.

You want to have encryption, but I doubt their encryption or lack thereof has anything to do with this attack. Do we even have evidence the data wasn't encrypted?.

If someone gets access to a ticketing system they shouldn't have, talking about encryption is about as useful as talking about seatbelts. Important for general safety but irrelevant to the problem at hand.

Barrin92•4h ago
>and why were they retained for longer than was necessary?

it's stated in the article. In most cases they weren't, the data breach only affected people who disputed the result of their age verification.

Of course in principle Discord or any third party should never need any photographic identity themselves to begin with if countries would bother to implement a proper trusted identity system where the data stays with an authority and they simply sign off on requests. Like in South Korea or the eID features you have on most European national ID cards.

whatever1•3h ago
So they process 70k disputes per day? If not, why 70k ids were stolen?

It’s a flawed design. No reason to retain the personal info for more than the processing time. Aka the duration of the dispute process itself (not the queue of disputes).

The principal engineer who signed it off should go to jail.

debo_•3h ago
It's not 70k per day. A dispute takes longer than a day; this was their entire ongoing dispute queue.
whatever1•3h ago
So they were retaining data that they were not actively processing. They were just waiting to be processed.

Aka, the system design was wrong. The buck has to stop somewhere. Somebody signed it off.

debo_•3h ago
I'm not sure how you're coming to that conclusion. If, for example, the id verification says "your id appears to be fake" and the user disputes it, what happens next? A dispute usually has several back-and-forth steps where one party is waiting for the other to respond.
whatever1•3h ago
As simple as: “We are processing your request, once we need more evidence we will contact you.” The day that their turn has come remind them to upload their personal data. Process the request, delete the data in 24 hours.

If you don’t hear back, even better, less private data to worry about.

debo_•3h ago
This is not a tradeoff-less scenario. Most users will be pretty irritated if, for example, you ask them to re-upload the front and back of the id in question at a later date because you deleted it last time for their protection.

I personally think doing ID verification of physical documents over the internet is just a non-starter. I've unfortunately had to support such systems for years at a time, and I'm thankful I don't do it anymore.

esseph•3h ago
You're asking for accountability? Nobody has time for that, stop being silly.
exasperaited•3h ago
> The principal engineer who signed it off should go to jail.

Indeed.

Dylan16807•3h ago
> it's stated in the article. In most cases they weren't, the data breach only affected people who disputed the result of their age verification.

Saying this only affected disputes doesn't answer the question. It also makes it clear they knew deleting IDs was important, but did they not have proper deletion in their dispute system? If this was only new active disputes, I would expect discord to say so, but it sounds like the data in the leak goes back a lot further.

exasperaited•3h ago
> Of course in principle Discord or any third party should never need any photographic identity themselves to begin with if countries would bother to implement a proper trusted identity system where the data stays with an authority and they simply sign off on requests.

Indeed. But in the UK the only really loud voices against the porn age laws are also the same voices against the latest digital ID proposals.

It's logical to say "we don't need either of these two things".

But the status quo of ID verification of all kinds (for things like finance agreements, some online purchases, KYC, checking into some hotel chains if you're not the card holder who paid, etc.) is horrifying and involves uploading scans of paper documents. Every time someone says "I don't need a digital ID thanks" I ask them how many times they've let someone take a flatbed or photocopier scan of their passport or driving licence in real life (it's usually not zero) and then I ask them to explain to me how they would do that if it is online, and if they ever asked how long they are retained.

Dylan16807•3h ago
I mostly agree, but your list of situations is places you want your actual identity to be verified. For age checks, a core feature should be not identifying yourself.
exasperaited•2h ago
Yes, but a core feature of contemporary digital ID is age-only digital attestation -- that is, yes this unnamed person is old enough.

The absence of such means that there are few ways for people to verify their ages without handing over scans of their IDs to far too many organisations.

In the UK we do have one means to do this that is not widely used yet: since all mobile phone providers attempt to block adult content by default until the owner proves they are an adult (a pretty long-standing pre-existing child safety/parental control initiative by PAYG providers that has evolved to be standard across all contract types), the question of "can you prove you are 18" can now be delegated to the MNOs. But not all the age verification agencies are doing it.

raggi•4h ago
> At least the kids are safe.

Are they any safer? Roadblocks rarely stopped me as a kid. These kinds of impediments most often resulted in me strategically moving what I was doing to somewhere out of sight of the gatekeepers, most often resulting in less safety. Where do most kids learn to play with fire in modern society? in very very dangerous places.

yieldcrv•3h ago
that was sarcasm, a satire on the situation and ostensible purpose of burdening everyone with this
drdeadringer•3h ago
This reminds me of a small but fond memory of mine. One of my friends in high school, up from elementary, was slightly a troublemaker. But not terribly so. One day, we found ourselves sitting at the same lunch table. He occasionally smoked, I did not (I still don't). This meant that he had a lighter and I at the time did not (I now carry a lighter with me at all times for unrelated reasons).

He made a comment about how good orange peels smelled when you burned them. I leaned into this comment with curiosity and personal ignorance on the matter.

He said yeah and then looked around made the shush shush signal and leaned in, and invited me to do the same. He took an orange peel and brushed it across his opened lighter flame. Nobody caught us, and I smelled firsthand What he was talking about. Nobody got into trouble over this innocent demonstration. But for sure as hell you would have gone into trouble for this uncensioned demonstration of fire usage.

subscribed•3h ago
How does it make kids any safer?

My kids had a honest conversation with me about possible Wikipedia ban and VPNs maybe a week in. Their classmates were already using it.

Dylan16807•3h ago
https://news.ycombinator.com/item?id=45552348

https://news.ycombinator.com/item?id=45552382

LelouBil•4h ago
Related : https://www.youtube.com/watch?v=NnuyT8FgSpA

The hacker contacted some well known youtuber that talks about discord, they provided contents of support tickets of the YouTuber to prove they were really the hacker

luxuryballs•4h ago
Anyone with insight into this kind of thing know if it’s reasonable to doubt Discord’s claims about what the hackers have? I can see motives for both parties to stretch the truth in opposite directions. But maybe there’s some legal risk for Discord to lie about what was compromised, in the event they get found out?
guerrilla•3h ago
I'm grateful for the timing.
nomilk•3h ago
> The hacker claims an outsourced worker was compromised through a $500 bribe

Also interesting:

> The hacker claims government IDs were just sitting there for months or even years... I have spoken to people familiar with Discord's Age Verification system, and they said after some period of time Discord will delete (the copies of IDs), but they should be deleting them the second they're done

Source (pinned comment, and 7m20s respectively): https://www.youtube.com/watch?v=NnuyT8FgSpA

ndriscoll•1h ago
Didn't they only start doing age verification this summer? Why do they have years worth of IDs?
Macha•1h ago
Disputes over hacked/stolen accounts I guess?
nomilk•1h ago
I think you must be 13+ to use discord, so the IDs were required for Discord’s own age verification.
like_any_other•2h ago
I don't understand. Weren't we told that these age checks are "privacy-preserving"? So why was there anything for hackers to steal? Or do they mean "privacy-preserving" only against other random users of a service, but not against the service itself, the corporation running it, it's subsidiaries and parent conglomerate, their "trusted partners", the process of legal discovery if that corporation ever gets sued, legal subpoena by the police and intelligence agencies of every jurisdiction that conglomerate conducts business in, local councils [1], every government agency you can think of including ambulance service providers [2], and of course data breaches?

"Privacy."

[1] https://www.ibtimes.co.uk/british-councils-used-ripa-conduct...

[2] https://en.wikipedia.org/wiki/Investigatory_Powers_Act_2016#...

aucisson_masque•2h ago
It's only the beginning, right ?

I already bought a vps in turkey and installed a vpn on it, cost 10€ a year but it's a small price to pay to not have his ID stolen.

hiprob•1h ago
Like this would actually stop any politician from pushing actively malicious legislation just because their kid doesn't love them and it's all the damn phone's fault.