frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

How First Wap tracks phones around the world

https://www.lighthousereports.com/methodology/surveillance-secrets-explainer/
62•mattboulos•3h ago

Comments

octagons•2h ago
SS7 strikes again!
rikafurude21•2h ago
At some point you have to wonder how privacy and security wasnt a factor at all in the minds of engineers designing these systems- it has to be intentional, right? Did no one stop to consider how the system theyre building could be abused against the general public? Did they just not care?
ewuhic•2h ago
They were and still are dumb and naive. This comment is going to be downvoted.
rangerelf•1h ago
You're not wrong.

I've seen so many things announced that make me ask myself "But, why?".

hsbauauvhabzb•1h ago
I doubt it’s the engineers. They just build what someone else has requested, they can provide suggestions and suggestions can be ignored.
defrost•1h ago
It starts as a shoehorn to solve a relatively (initially at least) uncommon bridging problem.

Later such things are grandfathered in having never been properly designed or funded for security, etc.

  Signalling System 7, or SS7, is a decades-old set of protocols that allows phone networks to communicate with one another, routing messages and calls across borders.

  It was never designed with security in mind, and while operators have moved to more secure evolutions with 4G and 5G, they still need to maintain backwards compatibility with SS7. This is likely to remain the case for years if not decades to come.

  Phone networks need to know where users are in order to route text messages and phone calls.

  Operators exchange signalling messages to request, and respond with, user location information. The existence of these signalling messages is not in itself a vulnerability.

  The issue is rather that networks process commands, such as location requests, from other networks, without being able to verify who is actually sending them and for what purpose.
CharlesW•1h ago
> At some point you have to wonder how privacy and security wasnt a factor at all in the minds of engineers designing these systems- it has to be intentional, right?

Yes. SS7 is a half-century old, designed for a world of state telecom monopolies and a handful of tightly-peered carriers. The threat model could safely assume that only vetted operators could connect. It's unlikely that anyone involved believed that SS7 would still exist in 2000, much less 2025.

https://www.eff.org/deeplinks/2024/07/eff-fcc-ss7-vulnerable...

decimalenough•1h ago
Almost as crazy as email and HTTP being designed without encryption, amirite?

SS7 dates from the early 1980s, as do SMTP (1981) and HTTP (1989). In all three cases people build the simplest thing that works and then hacked on it as new requirements arose. The main problem is that the telco world is very conservative and closed-source, so while we've had HTTPS and encrypted IMAP etc for a while now, SS7 hasn't gotten similar upgrades.

numpad0•2h ago
dupe: https://news.ycombinator.com/item?id=45584498
baobun•59m ago
related, not dupe
bendouglas•1h ago
Is there anything a common person can do to help reduce the likelihood of their phone being tracked via SS7? (other than not carrying a phone or disabling the mobile network)

IRS Open Sources its Fact Graph

https://github.com/IRS-Public/fact-graph
142•ronbenton•2h ago•40 comments

I'm recomming my customers switch to Linux rather that Upgrade to Windows 11

https://www.scottrlarson.com/publications/publication-windows-move-towards-surveillance/
49•trinsic2•39m ago•22 comments

Apple M5 chip

https://www.apple.com/newsroom/2025/10/apple-unleashes-m5-the-next-big-leap-in-ai-performance-for...
941•mihau•12h ago•1040 comments

Claude Haiku 4.5

https://www.anthropic.com/news/claude-haiku-4-5
430•adocomplete•8h ago•179 comments

Writing an LLM from scratch, part 22 – training our LLM

https://www.gilesthomas.com/2025/10/llm-from-scratch-22-finally-training-our-llm
60•gpjt•1h ago•1 comments

Next Steps for the Caddy Project Maintainership

https://caddy.community/t/next-steps-for-the-caddy-project-maintainership/33076
98•francislavoie•4h ago•17 comments

ImapGoose

https://whynothugo.nl/journal/2025/10/15/introducing-imapgoose/
31•xarvatium•3h ago•6 comments

Gerald Sussman - An Electrical Engineering View of a Mechanical Watch (2003)

https://techtv.mit.edu/videos/15895-an-electrical-engineering-view-of-a-mechanical-watch
43•o4c•1w ago•8 comments

Bringing NumPy's type-completeness score to nearly 90%

https://pyrefly.org/blog/numpy-type-completeness/
44•todsacerdoti•1w ago•20 comments

Zed is now available on Windows

https://zed.dev/blog/zed-for-windows-is-here
179•meetpateltech•9h ago•60 comments

I almost got hacked by a 'job interview'

https://blog.daviddodda.com/how-i-almost-got-hacked-by-a-job-interview
725•DavidDodda•12h ago•388 comments

Are hard drives getting better?

https://www.backblaze.com/blog/are-hard-drives-getting-better-lets-revisit-the-bathtub-curve/
125•HieronymusBosch•8h ago•56 comments

Show HN: Halloy – Modern IRC client

https://github.com/squidowl/halloy
280•culinary-robot•13h ago•77 comments

Pwning the Nix ecosystem

https://ptrpa.ws/nixpkgs-actions-abuse
237•SuperShibe•11h ago•42 comments

Leaving serverless led to performance improvement and a simplified architecture

https://www.unkey.com/blog/serverless-exit
293•vednig•14h ago•182 comments

F5 says hackers stole undisclosed BIG-IP flaws, source code

https://www.bleepingcomputer.com/news/security/f5-says-hackers-stole-undisclosed-big-ip-flaws-sou...
134•WalterSobchak•12h ago•64 comments

Recursive Language Models (RLMs)

https://alexzhang13.github.io/blog/2025/rlm/
68•talhof8•7h ago•21 comments

US Dept of Interior denies canceling largest solar project after axing review

https://www.utilitydive.com/news/department-interior-cancels-review-nevada-solar-project-trump/80...
53•toomuchtodo•2h ago•24 comments

More About Jumps Than You Wanted to Know

https://gpfault.net/posts/asm-tut-4.html
7•nice_byte•6d ago•0 comments

A kernel stack use-after-free: Exploiting Nvidia's GPU Linux drivers

https://blog.quarkslab.com/./nvidia_gpu_kernel_vmalloc_exploit.html
132•mustache_kimono•11h ago•15 comments

A Gemma model helped discover a new potential cancer therapy pathway

https://blog.google/technology/ai/google-gemma-ai-cancer-therapy-discovery/
37•alexcos•6h ago•5 comments

Princeton Engineering Anomalies Research

https://pearlab.icrl.org/
32•walterbell•1w ago•6 comments

Recreating the Canon Cat document interface

https://lab.alexanderobenauer.com/updates/the-jasper-report
88•tonyg•10h ago•7 comments

How First Wap tracks phones around the world

https://www.lighthousereports.com/methodology/surveillance-secrets-explainer/
62•mattboulos•3h ago•11 comments

Garbage collection for Rust: The finalizer frontier

https://soft-dev.org/pubs/html/hughes_tratt__garbage_collection_for_rust_the_finalizer_frontier/
113•ltratt•13h ago•112 comments

The brain navigates new spaces by 'darting' between reality and mental maps

https://medicine.yale.edu/news-article/brain-navigates-new-spaces-by-flickering-between-reality-a...
140•XzetaU8•1w ago•54 comments

FSF announces Librephone project

https://www.fsf.org/news/librephone-project
1386•g-b-r•1d ago•566 comments

Americans' love of billiards paved the way for synthetic plastics

https://invention.si.edu/invention-stories/imitation-ivory-and-power-play
61•geox•1w ago•34 comments

M5 MacBook Pro

https://www.apple.com/macbook-pro/
311•tambourine_man•12h ago•428 comments

Helpcare AI (YC F24) Is Hiring

1•hsial•13h ago