frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

MCP-Scanner – Scan MCP Servers for vulnerabilities

https://github.com/cisco-ai-defense/mcp-scanner
51•hsanthan•3h ago

Comments

cyberax•1h ago
The MCP landscape is a huge frothing septic tank. Go on, try to create a simple MCP server that is protected by a password and connect it to ChatGPT or Claude. Or even the one that uses your local SSO system for authentication.

I tried and failed after about 3 days of dealing with AI-slop-generated nonsense that has _never_ been worked. The MCP spec was created probably by brainless AI agents, so it defines two authentication methods: no authentication whatsoever, and OAuth that requires bleeding-edge features (dynamic client registration) not implemented by Google or Microsoft.

The easiest way for that right now is to ask users to download a random NodeJS package that runs locally on their machines with minimal confinement.

zingababba•1h ago
Lol yeah, lots going on that will hopefully make it better though.

https://github.com/modelcontextprotocol/modelcontextprotocol... https://github.com/modelcontextprotocol/modelcontextprotocol... https://github.com/modelcontextprotocol/modelcontextprotocol... https://aaronparecki.com/2025/05/12/27/enterprise-ready-mcp https://github.com/modelcontextprotocol/modelcontextprotocol... https://www.okta.com/newsroom/press-releases/okta-introduces... https://github.com/modelcontextprotocol/ext-auth/blob/main/s... https://github.com/modelcontextprotocol/modelcontextprotocol... https://github.com/modelcontextprotocol/modelcontextprotocol... https://github.com/modelcontextprotocol/modelcontextprotocol...

cyberax•32m ago
No, it won't. It's just more of AI slop.
dang•22m ago
Can you please stop posting unsubstantive/fulminatey comments? We've already asked you this multiple times:

https://news.ycombinator.com/item?id=45022004 (Aug 2025)

https://news.ycombinator.com/item?id=44396920 (June 2025)

https://news.ycombinator.com/item?id=43028401 (Feb 2025)

https://news.ycombinator.com/item?id=39337678 (Feb 2024)

You've obviously got some substantive points to make here, which is great, but indignant putdown rhetoric has a destructive effect on the threads. If you could just make your substantive points thoughtfully, we'd appreciate it.

https://news.ycombinator.com/newsguidelines.html

fasbiner•1h ago
Had an almost identical experience. Even if you don’t need anything with auth, no one has yet made an mcp that wasn’t ultimately worse or the same as a cli but with a lot more song and dance. Security is also a bit of a joke when half the time it’s installing docker and phoning home. I wanted to like mcp and vend out remote mcp but this spec is not ready.
bootsmann•1h ago
“Ok, how do we do customer auth” has become my go-to question to kill MCP projects. There is no working solution which makes any kind of enterprise exploration into the space pointless.
dorkypunk•1h ago
I'm still laughing on how the error handling for tools is done, it's just a boolean field IsError.

https://modelcontextprotocol.io/specification/2025-06-18/ser...

throwaway314155•1h ago
MCP works best for tool calling that doesn't require auth (so tools that are trusted on your own machine). The whole pitch that you should be using it for business facing tools and things that require auth is a terrible idea.

Even if you're doing local only - MCP tools can mostly be covered by simply asking Claude Code (or whatever) to use the bash equivalent.

cyberax•30m ago
> MCP works best for tool calling that doesn't require auth (so tools that are trusted on your own machine).

In other words, downloading random crap that runs unconfined and requires a shitty app like Claude Desktop.

BTW, Claude Desktop is ALSO an example of AI slop. It barely works, constantly just closing chats, taking 10 seconds to switch between conversations, etc.

In my case, I wanted to connect our CRM with ChatGPT and ask it to organize our customer notes. And also make this available as a service to users, so they won't have to be AI experts with subscriptions to Claude.

Claude for Excel

https://www.claude.com/claude-for-excel
260•meetpateltech•4h ago•174 comments

Pyrex catalog from from 1938 with hand-drawn lab glassware [pdf]

https://exhibitdb.cmog.org/opacimages/Images/Pyrex/Rakow_1000132877.pdf
210•speckx•5h ago•49 comments

JetKVM – Control any computer remotely

https://jetkvm.com/
156•elashri•3h ago•101 comments

Why Busy Beaver hunters fear the Antihydra

https://benbrubaker.com/why-busy-beaver-hunters-fear-the-antihydra/
88•Bogdanp•3h ago•12 comments

10M people watched a YouTuber shim a lock; the lock company sued him – bad idea

https://arstechnica.com/tech-policy/2025/10/suing-a-popular-youtuber-who-shimmed-a-130-lock-what-...
303•Brajeshwar•7h ago•139 comments

MCP-Scanner – Scan MCP Servers for vulnerabilities

https://github.com/cisco-ai-defense/mcp-scanner
51•hsanthan•3h ago•10 comments

Simplify Your Code: Functional Core, Imperative Shell

https://testing.googleblog.com/2025/10/simplify-your-code-functional-core.html
27•reqo•2d ago•5 comments

Show HN: JSON Query

https://jsonquerylang.org/
75•wofo•3h ago•39 comments

Creating an all-weather driver

https://waymo.com/blog/2025/10/creating-an-all-weather-driver
27•boulos•1h ago•9 comments

Avoid 2:00 and 3:00 am cron jobs (2013)

https://www.endpointdev.com/blog/2013/04/avoid-200-and-300-am-cron-jobs/
172•pera•3h ago•162 comments

Rust cross-platform GPUI components

https://github.com/longbridge/gpui-component
408•xvilka•10h ago•173 comments

Tags to make HTML work like you expect

https://blog.jim-nielsen.com/2025/dont-forget-these-html-tags/
337•FromTheArchives•10h ago•179 comments

Sieve (YC X25) is hiring engineers to build video datasets for frontier AI

https://www.sievedata.com/
1•mvoodarla•3h ago

Eight Million Copies of Moby-Dick (2014)

https://thevoltablog.wordpress.com/2014/01/27/nicolas-mugaveros-eight-million-copies-of-moby-dick...
21•awalias•4d ago•7 comments

A mild mannered Englishman who was the most prolific ghost hunter

https://lithub.com/the-mild-mannered-englishman-who-was-the-worlds-most-prolific-ghost-hunter/
10•tintinnabula•6d ago•1 comments

Solving regex crosswords with Z3

https://blog.nelhage.com/post/regex-crosswords-z3/
19•atilimcetin•6d ago•0 comments

Let the little guys in: A context sharing runtime for the personalised web

https://arjun.md/little-guys
44•louisbarclay•2h ago•5 comments

Show HN: Erdos – open-source, AI data science IDE

https://www.lotas.ai/erdos
33•jorgeoguerra•4h ago•16 comments

Why Nigeria accepted GMOs

https://www.asimov.press/p/nigeria-crops
24•surprisetalk•2h ago•45 comments

Show HN: Git Auto Commit (GAC) – LLM-powered Git commit command line tool

https://github.com/cellwebb/gac
22•merge-conflict•3h ago•22 comments

fnox, a secret manager that pairs well with mise

https://github.com/jdx/mise/discussions/6779
71•bpierre•3h ago•15 comments

Artificial Writing and Automated Detection [pdf]

https://www.nber.org/system/files/working_papers/w34223/w34223.pdf
26•mathattack•3h ago•16 comments

The last European train that travels by sea

https://www.bbc.com/travel/article/20251024-the-last-european-train-that-travels-by-sea
109•1659447091•11h ago•111 comments

Gitworkshop.dev – Collaborate on code over Nostr

https://gitworkshop.dev/
10•sebastix•2d ago•0 comments

Carl Bohland's Auto Wash Bowl (2015)

https://news.wttw.com/2015/07/29/ask-geoffrey
11•thunderbong•2h ago•5 comments

Should LLMs just treat text content as an image?

https://www.seangoedecke.com/text-tokens-as-image-tokens/
117•ingve•6d ago•76 comments

Fingerprint Formation (2004) [pdf]

https://math.arizona.edu/~anewell/publications/Fingerprint_Formation.pdf
6•o4c•2d ago•0 comments

It's insulting to read AI-generated blog posts

https://blog.pabloecortez.com/its-insulting-to-read-your-ai-generated-blog-post/
709•speckx•4h ago•352 comments

Corrosion

https://fly.io/blog/corrosion/
144•cgb_•4d ago•70 comments

Microsoft in court for allegedly misleading Australians over 365 subscriptions

https://www.accc.gov.au/media-release/microsoft-in-court-for-allegedly-misleading-millions-of-aus...
203•edwinjm•5h ago•86 comments