frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Stop Hacklore – An Open Letter

https://www.hacklore.org/letter
16•zdw•4d ago

Comments

MerrimanInd•5m ago
I worked for a company that had 8-12 different employee passwords across various systems. There was no SSO, they each password had different requirements, and required changes at different intervals ranging from 30-90 days. Consequently every employee had a post-it note directly on the laptop with most or all of their passwords. The outdated IT policy security was so strict that real world security was abysmal.
hullfracture•4m ago
This has the energy of "Remove all DEI initiatives because we have solved workplace discrimination."

> This kind of advice is well-intentioned but misleading. It consumes the limited time people have to protect themselves and diverts attention from actions that truly reduce the likelihood and impact of real compromises.

I dislike any methodology that claims its intent is to talk down to people for whatever declared reasoning. People are capable, and should be helped to make decisions based on all available information.

> Regularly change passwords: Frequent password changes were once common advice, but there is no evidence it reduces crime, and it often leads to weaker passwords and reuse across accounts.

When I worked as a security professional the breaches were nearly always from someone's password getting leaked in a separate public breach. If those individuals had changed that password the in house breach would have been avoided.

> Use a password manager

Sage advice.

Kim_Bruning•4m ago
I think even the 'new' recommendations here are getting a bit old.
voodooEntity•3m ago
So, since this seems to be relevant im a CISO myself.

And i would definitely not agree with everything in this letter.

Personally, i think the worst part about it is handling a low probability as something that's not gonne happen. Thats, especially in IT-Sec, one of the worst practices.

To take on point as example - the "never scan public QR codes".

Apart from the fact that there have been enaugh exploits in the past (The USSD "Remote Wipe", iOS 11 Camera Notification Spoofing (iOS, 2018), ZBar Buffer Overflow (CVE-2023-40889), etc) even without an 0day exploit qr codes can pose a relevant risk.

As a simple example, not to long ago i was in a restaurant which only had their menu in form of a qr code to scan. Behind the QR code was the link to an PDF showing the card. This PDF was hosted on a free to use webservice that allowed to upload files and get a QR code link to them. There was no account managed control about the pdf that they linked to, it could be replaced at any time opening a whole different world of possible exploitations via whatever file is being returned.

Sure you could argue "this is not a QR code vulnerability just bad practice by the restaurant owner" - but that's the point. For the user there is literally no difference if the QR code itself has a malicious payload or if the URL behind it has (etc etc).

While we in the tech world might understand the difference, for the John and Jane Doe this is the same thing. And for them its still a possible danger.

Apart from that, recently a coworker linked me a "hacker" video on youtube showing a guy in an interview talking about the O.MG cable. Sure, you might say this is also an absolutely non standard attack vector, yet it still exists. And people should be aware it does.

My point is - by telling people that all those attack vectors are basically "urban myths" you just desensitize the already not well enough informed public from the dangers the "digital" poses to them. Any from my personal view, we should rather educate more than tell them "don't worry it will be fine".

A Love Letter to FreeBSD

https://www.tara.sh/posts/2025/2025-11-25_freebsd_letter/
47•rbanffy•33m ago•5 comments

Writing a Good Claude.md

https://www.humanlayer.dev/blog/writing-a-good-claude-md
181•objcts•4h ago•53 comments

Advent of Code 2025

https://adventofcode.com/2025/about
642•vismit2000•9h ago•212 comments

Windows drive letters are not limited to A-Z

https://www.ryanliptak.com/blog/windows-drive-letters-are-not-limited-to-a-z/
320•LorenDB•8h ago•148 comments

LLVM-MOS – Clang LLVM fork targeting the 6502

https://llvm-mos.org/wiki/Welcome
86•jdmoreira•5h ago•22 comments

Migrating Dillo from GitHub

https://dillo-browser.org/news/migration-from-github/
235•todsacerdoti•8h ago•138 comments

ETH-Zurich: Digital Design and Computer Architecture; 227-0003-10L, Spring, 2025

https://safari.ethz.ch/ddca/spring2025/doku.php?id=start
103•__rito__•4h ago•15 comments

ESA Sentinel-1D delivers first high-resolution images

https://www.esa.int/Applications/Observing_the_Earth/Copernicus/Sentinel-1/Sentinel-1D_delivers_f...
58•giuliomagnifico•5h ago•13 comments

Program-of-Thought Prompting Outperforms Chain-of-Thought by 15% (2022)

https://arxiv.org/abs/2211.12588
47•mkagenius•4h ago•14 comments

Stop Hacklore – An Open Letter

https://www.hacklore.org/letter
16•zdw•4d ago•4 comments

"Boobs check" – Technique to verify if sites behind CDN are hosted in Iran

https://twitter.com/hkashfi/status/1995109785679573167
107•defly•1h ago•24 comments

GitHub to Codeberg: my experience

https://eldred.fr/blog/forge-migration/
84•todsacerdoti•6h ago•33 comments

CachyOS: Fast and Customizable Linux Distribution

https://cachyos.org/
237•doener•11h ago•217 comments

Don't push AI down our throats

https://gpt3experiments.substack.com/p/dont-push-ai-down-our-throats
266•nutanc•4h ago•156 comments

Stackoverflow Outage

https://www.stackstatus.net/
11•ga_to•1h ago•4 comments

A Second Look at Geolocation and Starlink

https://www.potaroo.net/ispcol/2025-11/starlinkgeo2.html
20•speckx•5d ago•5 comments

RetailReady (YC W24) Is Hiring Associate Product Manager

https://www.ycombinator.com/companies/retailready/jobs/KPKDu3D-associate-product-manager
1•sarah74•5h ago

Show HN: Boing

https://boing.greg.technology/
683•gregsadetsky•18h ago•134 comments

NixOS 25.11 released

https://nixos.org/blog/announcements/2025/nixos-2511/
122•trulyrandom•4h ago•30 comments

There is No Quintic Formula [video]

https://www.youtube.com/watch?v=9HIy5dJE-zQ
34•DamnInteresting•4h ago•14 comments

Show HN: Real-time system that tracks how news spreads across 200k websites

https://yandori.io/news-flow/
210•antiochIst•4d ago•54 comments

People keep flocking to Linux, not just to escape Windows

https://www.zdnet.com/article/why-people-keep-flocking-to-linux-in-2025-and-its-not-just-to-escap...
59•breve•2h ago•26 comments

Finding the grain of sand in a heap of Salt

https://blog.cloudflare.com/finding-the-grain-of-sand-in-a-heap-of-salt/
10•privacyops•3d ago•2 comments

Show HN: Fixing Google Nano Banana Pixel Art with Rust

https://github.com/Hugo-Dz/spritefusion-pixel-snapper
93•HugoDz•4d ago•16 comments

Langjam Gamejam: Build a programming language then make a game with it

https://langjamgamejam.com/
40•birdculture•6h ago•27 comments

Paul Hegarty's updated CS193p SwiftUI course released by Stanford

https://cs193p.stanford.edu/
128•yehiaabdelm•5d ago•32 comments

Zigbook Is Plagiarizing the Zigtools Playground

https://zigtools.org/blog/zigbook-plagiarizing-playground/
444•todsacerdoti•18h ago•129 comments

Modern cars are spying on you. Here's what you can do about it

https://apnews.com/article/auto-car-privacy-3674ce59c9b30f2861d29178a31e6ab7
189•MilnerRoute•6h ago•198 comments

Notes on Shadowing a Hospitalist

https://humaninvariant.substack.com/p/notes-on-shadowing-a-hospitalist
38•surprisetalk•5h ago•15 comments

All it takes is for one to work out

https://alearningaday.blog/2025/11/28/all-it-takes-is-for-one-to-work-out-2/
741•herbertl•1d ago•359 comments