frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

AI will compromise your cybersecurity posture

https://rys.io/en/181.html
23•gmays•2h ago

Comments

abicklefitch•2h ago
No shit Sherlock
senectus1•11m ago
we're just waking up to a flood of browser extensions with "AI integration" that are harvesting content and ex-filtrating it.

The only solution is to tighten the nuts down and block all but approved extensions. not a super popular position.

venturecruelty•1h ago
lights cigarette Not mine, directly, but I'm sure I'll be part of the next 150-million-strong data breach because some suit shouted, red-faced, "WE NEED AI" into a Teams meeting, and several people with mortgages and children made it happen.
dasil003•46m ago
I'm sorry you have to use Teams, but at least they let you smoke
chroma205•42m ago
> and several people with mortgages and children made it happen.

Solution seems to be don’t have kids.

Then the employees are less scared of losing their jobs and can push back against management’s idiotic AI requests.

112233•56m ago
Has anyone noticed how poorly tools like claude code (the main one I tried) themselves are working? You'd expect software from company with an infinite AI allowance to be unattainably excellent, instead it lags, hangs, flickers, and feels like unpleasant mvp mess.

I hear at every corner people telling, how they can 100x now, and if my AI use is not laying prime code it's my skill issue. But where is this excellent AI generated software? Do you maybe have some examples you can share?

steve1977•43m ago
> Do you maybe have some examples you can share?

Microsoft 365 Copilot /s

rainonmoon•32m ago
A lot of good information for infra teams to internalise, although I worry that it gets a bit lost in the structure of the piece (there's kind of like 3-5 separate essays here but nothing a good edit couldn't fix.) One thing I'll add (or at least crystallise because I think the pieces are there) is that attack surface management is critical. A lot of the issues here are relevant in exactly the same scenario as exposing web applications. I have reported vulnerabilities in a lot of AI applications in prod and the issues aren't magic or even novel. They're typically the same authorisation and injection issues people have been talking about for decades. The methods of securing them are the same. Unfortunately it's not uncommon for companies to get compromised via a good old fashioned REST API on an exposed dev domain, but I probably wouldn't go so far as to say "REST APIs will compromise your cybersecurity posture." I would just say companies have found another tool to flex their indifference towards protecting user and company data.
112233•23m ago
Properly securing LLMs goes agains branding, I guess. "this tool is like getting new intern every 15 minutes! they read and write fast and know a lot of stuff, but can accidentally attack or sabotage you if they get distracted! oh, and they work remotely only!" doesn't sound like a good pitch
NitpickLawyer•24m ago
This is a trendy article, rehashing themes that were prevalent over the last year, and, like those themes, will age like milk.

If you look at the past 3 years and plot capabilities in 3 key areas, the conclusions will be vastly different.

Code completion was "awww, how cute, this almost looks like python" in early 2023. It's now at the level of "oh my, this actually looks decent".

Then there's e2e "agentic" stuff, where you needed tons of glue 2 years ago to have a decent workflow working 50% of the time. Now you have agents taking a spec, working for 2h uninterrupted, and delivering working, tested, linted code. Unattended.

Lastly, these capabilities have led to CTF challenges going from 0 - 80% since RL was used to train these things. The first one was ~2y ago when a popular CTF site saw the first <10s capture on a new task. Now, several companies are selling CTF as a service, with more and more competitions being dominated by said agents.

So yeah, rehashing all the old "arguments" is a futile attempt. This thing is getting better and better. RL does something really interesting, unlocking an interesting fixation with task completion. Give it a verifiable reward (i.e. capture a flag), and it will bang its head against the wall until it gets that flag. And what's more important, in security stuff you don't need perfect accuracy, nor maj@n. What you're looking for is pass@n, which usually gives 20-30% more on any benchmark. So, yeah, all your flags are belong to AI.

----

AI will compromise your cybersecurity posture, but that's because our postures have been bad all along. It will find more and more exploits, and the value in red-blue teams will be much more than the "bugs" and "exploits" LLM-assisted coding will "bring". Those will get automatically caught as well. But there's vastly more grass-fed guaranteed human-wrote good old fashion bugs out there.

There's a ridiculous amount of tech in a disposable vape

https://blog.jgc.org/2026/01/theres-ridiculous-amount-of-tech-in.html
182•abnercoimbre•1d ago•147 comments

1000 Blank White Cards

https://en.wikipedia.org/wiki/1000_Blank_White_Cards
72•eieio•3h ago•12 comments

ASCII Clouds

https://caidan.dev/portfolio/ascii_clouds/
105•majkinetor•4h ago•18 comments

A 40-line fix eliminated a 400x performance gap

https://questdb.com/blog/jvm-current-thread-user-time/
218•bluestreak•7h ago•45 comments

Every GitHub object has two IDs

https://www.greptile.com/blog/github-ids
181•dakshgupta•14h ago•46 comments

The Gleam Programming Language

https://gleam.run/
49•Alupis•3h ago•13 comments

Show HN: OSS AI agent that indexes and searches the Epstein files

https://epstein.trynia.ai/
50•jellyotsiro•4h ago•14 comments

Show HN: Cachekit – High performance caching policies library in Rust

https://github.com/OxidizeLabs/cachekit
26•failsafe•4h ago•0 comments

vLLM large scale serving: DeepSeek 2.2k tok/s/h200 with wide-ep

https://blog.vllm.ai/2025/12/17/large-scale-serving.html
81•robertnishihara•14h ago•7 comments

The $LANG Programming Language

147•dang•6h ago•27 comments

Show HN: 1D-Pong Game at 39C3

https://github.com/ogermer/1d-pong
7•oger•2d ago•0 comments

Show HN: The Tsonic Programming Language

https://tsonic.org
14•jeswin•13h ago•3 comments

The Emacs Widget Library: A Critique and Case Study

https://www.d12frosted.io/posts/2025-11-26-emacs-widget-library
41•whacked_new•1d ago•9 comments

The truth behind the 2026 J.P. Morgan Healthcare Conference

https://www.owlposting.com/p/the-truth-behind-the-2026-jp-morgan
167•abhishaike•12h ago•34 comments

Stop using natural language interfaces

https://tidepool.leaflet.pub/3mcbegnuf2k2i
40•steveklabnik•4h ago•5 comments

No management needed: anti-patterns in early-stage engineering teams

https://www.ablg.io/blog/no-management-needed
141•tonioab•11h ago•162 comments

Sei (YC W22) Is Hiring a DevOps Engineer (India/In-Office/Chennai/Gurgaon)

https://www.ycombinator.com/companies/sei/jobs/Rn0KPXR-devops-platform-ai-infrastructure-engineer
1•ramkumarvenkat•5h ago

Are two heads better than one?

https://eieio.games/blog/two-heads-arent-better-than-one/
145•evakhoury•14h ago•43 comments

The Tulip Creative Computer

https://github.com/shorepine/tulipcc
206•apitman•13h ago•46 comments

Handling secrets (somewhat) securely in shells

https://linus.schreibt.jetzt/posts/shell-secrets.html
35•todsacerdoti•4d ago•17 comments

AI generated music barred from Bandcamp

https://old.reddit.com/r/BandCamp/comments/1qbw8ba/ai_generated_music_on_bandcamp/
704•cdrnsf•12h ago•496 comments

Agonist-Antagonist Myoneural Interface

https://www.media.mit.edu/projects/agonist-antagonist-myoneural-interface-ami/overview/
51•kaycebasques•5d ago•3 comments

Scott Adams has died

https://www.youtube.com/watch?v=Rs_JrOIo3SE
873•ekianjo•15h ago•1378 comments

How to make a damn website (2024)

https://lmnt.me/blog/how-to-make-a-damn-website.html
172•birdculture•13h ago•54 comments

April 9, 1940 a Dish Best Served Cold

https://todayinhistory.blog/2021/04/09/april-9-1940-a-dish-best-served-cold/
5•vinnyglennon•4d ago•2 comments

Exa-d: How to store the web in S3

https://exa.ai/blog/exa-d
18•willbryk•5h ago•0 comments

Why we built our own background agent

https://builders.ramp.com/post/why-we-built-our-background-agent
84•jrsj•1d ago•10 comments

When hardware goes end-of-life, companies need to open-source the software

https://www.marcia.no/words/eol
248•Marciplan•7h ago•77 comments

Show HN: Nogic – VS Code extension that visualizes your codebase as a graph

https://marketplace.visualstudio.com/items?itemName=Nogic.nogic
99•davelradindra•11h ago•36 comments

We can't have nice things because of AI scrapers

https://blog.metabrainz.org/2025/12/11/we-cant-have-nice-things-because-of-ai-scrapers/
356•LorenDB•8h ago•186 comments