frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Cloudflare acquires Astro

https://astro.build/blog/joining-cloudflare/
359•todotask2•3h ago•191 comments

6-Day and IP Address Certificates Are Generally Available

https://letsencrypt.org/2026/01/15/6day-and-ip-general-availability
116•jaas•1h ago•37 comments

Michelangelo's first painting, created when he was 12 or 13

https://www.openculture.com/2026/01/discover-michelangelos-first-painting.html
155•bookofjoe•3h ago•101 comments

Just the Browser

https://justthebrowser.com/
327•cl3misch•5h ago•173 comments

Launch HN: Indy (YC S21) – A support app designed for ADHD brains

https://www.shimmer.care/indy-redirect
26•christalwang•1h ago•19 comments

Canada slashes 100% tariffs on Chinese EVs to 6%

https://electrek.co/2026/01/16/canada-breaks-with-us-slashes-100-tariffs-chinese-evs/
74•1970-01-01•27m ago•32 comments

Zep AI (Agent Context Engineering, YC W24) Is Hiring Forward Deployed Engineers

https://www.ycombinator.com/companies/zep-ai/jobs/
1•roseway4•32m ago

Lock-Picking Robot

https://github.com/etinaude/Lock-Picking-Robot
110•p44v9n•4d ago•43 comments

Read_once(), Write_once(), but Not for Rust

https://lwn.net/SubscriberLink/1053142/8ec93e58d5d3cc06/
48•todsacerdoti•2h ago•16 comments

Can You Disable Spotlight and Siri in macOS Tahoe?

https://eclecticlight.co/2026/01/16/can-you-disable-spotlight-and-siri-in-macos-tahoe/
32•chmaynard•2h ago•11 comments

psc: The ps utility, with an eBPF twist and container context

https://github.com/loresuso/psc
45•tanelpoder•4h ago•16 comments

Training my smartwatch to track intelligence

https://dmvaldman.github.io/rooklift/
93•dmvaldman•1d ago•38 comments

OpenBSD-current now runs as guest under Apple Hypervisor

https://www.undeadly.org/cgi?action=article;sid=20260115203619
359•gpi•14h ago•46 comments

List of individual trees

https://en.wikipedia.org/wiki/List_of_individual_trees
280•wilson090•17h ago•99 comments

Interactive eBPF

https://ebpf.party/
149•samuel246•9h ago•6 comments

Cursor's latest "browser experiment" implied success without evidence

https://embedding-shapes.github.io/cursor-implied-success-without-evidence/
36•embedding-shape•2h ago•24 comments

Why DuckDB is my first choice for data processing

https://www.robinlinacre.com/recommend_duckdb/
65•tosh•6h ago•25 comments

Pocket TTS: A high quality TTS that gives your CPU a voice

https://kyutai.org/blog/2026-01-13-pocket-tts
570•pain_perdu•1d ago•129 comments

The spectrum of isolation: From bare metal to WebAssembly

https://buildsoftwaresystems.com/post/guide-to-execution-environments/
71•ThierryBuilds•8h ago•24 comments

Exasol Personal – Democratizing Big Data Analytics

https://www.exasol.com/blog/introducing-exasol-personal/
4•astigsen•4d ago•2 comments

Show HN: mdto.page – Turn Markdown into a shareable webpage instantly

https://mdto.page
23•hjinco•4h ago•14 comments

Briar keeps Iran connected via Bluetooth and Wi-Fi when the internet goes dark

https://briarproject.org/manual/fa/
513•us321•21h ago•321 comments

ICE takes back into custody man released for violation of rights

https://apnews.com/article/minnesota-immigration-crackdown-25e46910fcc62fbf5ab341905af9891c
7•willmarch•11m ago•4 comments

Boeing knew of flaw in part linked to UPS plane crash, NTSB report says

https://www.bbc.com/news/articles/cly56w0p9e1o
230•1659447091•13h ago•114 comments

Inside The Internet Archive's Infrastructure

https://hackernoon.com/the-long-now-of-the-web-inside-the-internet-archives-fight-against-forgetting
414•dvrp•2d ago•97 comments

Show HN: pgwire-replication - pure rust client for Postgres CDC

https://github.com/vnvo/pgwire-replication
34•sacs0ni•5d ago•6 comments

Ask HN: How can we solve the loneliness epidemic?

713•publicdebates•1d ago•1112 comments

Linux boxes via SSH: suspended when disconected

https://shellbox.dev/
271•messh•21h ago•141 comments

Bringing the Predators to Life in MAME

https://lysiwyg.mataroa.blog/blog/bringing-the-predators-to-life-in-mame/
55•msephton•2d ago•9 comments

Altaid 8800 (2024)

https://sunrise-ev.com/8080.htm
31•exvi•4d ago•5 comments
Open in hackernews

Cyberattack in Venezuela Demonstrated Precision of U.S. Capabilities

https://www.nytimes.com/2026/01/15/us/politics/cyberattack-venezuela-military.html
63•7402•2h ago

Comments

sylware•2h ago
javascript only
fidotron•1h ago
They can only do JS cyberattacks?

Maybe they need to use RISC-V assembly ;).

zarflax•1h ago
https://archive.is/rUYS4
deanc•45m ago
I’m stuck Ina captcha loop with this site today
flipped•1h ago
Third world countries lack the resources to secure their ICS and SCADA. Corrupted US govt doesn't even need NSA's capabilities for this.
toomuchtodo•1h ago
China should help them.

Beijing tells Chinese firms to stop using US and Israeli cybersecurity software - https://news.ycombinator.com/item?id=46618949 - January 2026

alephnerd•1h ago
It's a performative announcement - most American and Israeli cybersecurity vendors either don't sell in China or white label a Chinese product for the Chinese market.

I know 2 companies in that list that have done that very thing because otherwise it would have put their FedRAMP and CMMC pipelines at risk.

trollbridge•1h ago
I worked at a place that faced exactly that.

I initially was in the Huawei client engagement where they wanted copies of all of our source code. We said “no, nobody gets that”. They just keep asking over and over.

bee_rider•1h ago
On one hand, that seems like a sure way to get your product copied. On the other, they’d be totally nuts to run a cybersecurity product without the source code, right?

Seems like a situation where getting the interests to align is just very difficult.

bflesch•1h ago
Even with white labeled products so they stay legally compliant, is it really justifiable to increase the risk? They're having people flying in and out for "sales meetings", shared office spaces, devices, maybe even staff overlap.

I understand it's a good way to make money but it comes with some tail risk.

alephnerd•1h ago
Basically, a Chinese MSSP or SI is selected and given the American/Israeli company's logo and makes a revenue share agreement, and an airgapped environment using a distinct fork is deployed.

That said, most companies decide not to operate in the Chinese market - the TAM is too small for the headaches that it entails (losing Gov and NATO+ defense procurement opportunities).

bflesch•20m ago
Makes sense, thanks for elaborating. Just the logistics of it sound like a lot of overhead.
victor106•1h ago
> Corrupted US govt

and Venezuela govt is not corrupt?

flipped•1h ago
Every govt is. But whoever has most power is most corrupted.
bflesch•1h ago
You're using "false equivalence" bias. Not every government is bad, especially if you still have russia, iran, and others as ongoing contenders for worst crimes against humanity.

So saying "every government is bad" is simply a bad faith argument and you should shamefully sink towards the planet core for using it. Andorra is not as bad as russia or iran.

Just yesterday there was a video where russian soldiers tie an anti tank mine around the torso of a black African mercenary soldier from Mali before forcing him on a suicide meat assault towards Ukrainian positions. Some countries are evil on another level.

ceejayoz•1h ago
"Murder is bad!"

"So rape isn't?!"

Come on.

bschne•1h ago
unlike rich countries, which only lack the will and care to secure their ICS and SCADA /s
marcosdumay•57m ago
Or the US in particular that applies a lot of resources into willfully keeping every ICS and SCADA out there insecure, including their own.
baxtr•1h ago
Not sure if that’s the right way to divide the world.

Actually, poor countries can leverage cyber to pose a much bigger threat than they could traditionally.

Or in other words: Cyber can be used for asymmetric warfare. In relative terms, poor countries cause a lot more damage than rich ones.

alephnerd•1h ago
This. Also do not underestimate developing countries internal security budgets. Most middle income countries can now afford DACH sized cybersecurity procurement deals.
hojofpodge•1h ago
There's also great potential to build misattribution in. Just pause between combining the attacks from the Internet and renaming variables to watch a Dolph Lundgren movie.
barbazoo•1h ago
> In 2019, the Maduro government accused the United States of conducting a cyberattack on a hydropower plant that plunged much of the country into darkness for a week.

> The power failures caused sporadic outbursts of looting and unrest, bringing the government close to collapse.

bflesch•1h ago
Let's hope those chicken never come home to roost. NSA has a history of losing offensive cyber tools.

IIRC both Texas and California had widespread power outages in the last few years. I am not convinced that US power grid is much better defended than the one in the EU.

ericmay•1h ago
Yes, you're missing that if you mess with the power grid the US will go and kinetically strike back (read: bomb your country) or attack you with its own cyber warfare capabilities, unlike the EU. That's why the EU is experiencing cyber attacks and cyber warfare with clear culpability from Russia, but is unable to do much about it besides give Ukraine more weapons. If Russia launched a cyber attack and shut down JFK the way it did Heathrow, the US would actually do something about it even with all the Trump is a Russian agent stuff aside.
bflesch•1h ago
Sounds too good to be true. I'd love to believe it.

Didn't russia claim to have the full Epstein files, so how did they get them if not by hacking US government?

Attribution of cyber attacks is extremely difficult, and US seems to notoriously under invest into infrastructure. Unlike other countries, most of the power grid is above ground. How can you be so sure that it is safe?

ericmay•43m ago
> Unlike other countries, most of the power grid is above ground. How can you be so sure that it is safe?

I didn't say it was safe by virtue of defensive capabilities, but it's safe by virtue of the US will very likely come bomb you or use its own cyber capabilities if you do something to the US. This is in contrast to the EU which was the comparison point, which is unable and unwilling to do much against cyber attacks.

bflesch•24m ago
My original post was more focused on defensive capabilities, but those things are hard to discern - you need to know about vulnerabilities in order to protect yourself from them.

If the damage is done, of course the US can massively retaliate. But ideally no damage is done :)

ericmay•17m ago
Ideally yes, but there's a cost. All I was saying was that the US is better equipped than the EU because both are vulnerable but the US actually has and is willing to use offensive capabilities, which provide a defensive deterrent to an aggressor.
ASalazarMX•58m ago
Calm down, John Rambo. Even if USA could prove that it wasn't a false flag op, it won't "kinetically strike back" against China, Russia, India, or even small allies like North Korea.

USA is only willing to fight very asymmetrical wars.

ericmay•46m ago
Sure, of course it's not that simple. If China for example did a cyber attack it doesn't necessitate an immediate kinetic response or some sort of gargantuan nation-state level warfare to take place.

But if one of those countries shut down the US power grid we absolutely would respond and you're naive to think that the US would not respond out of some "fear" about only fighting very asymmetric wars.

Amongst some there seems to be this idea that because the US has taken military action in other countries over the years, more recent being more important, and because those countries "couldn't fight back" that the US is unable or unwilling to take further action against other nation states that theoretically could fight back (India could not, for example as a weak military power with nuclear weapons), but instead I'd caution you look at those action with respect to the ability of other countries to take action.

In other words, it feels good to throw in zingers like the US only beats up on weaker countries or something which, let's be frank would be every country or bloc except China, but you're missing the fact that those countries are not even able to project power to or willingness or ability to attack other countries.

bflesch•31m ago
I only remember that if one US state loses power the other states laugh about it because obviously it is because the current governor is a black female democrat. It'd be great progress to actually detect what caused it in a timely manner and then do a proper cyber attribution.

Generally I think you are using a lot of big words to compensate for the fact that the US ignored the Minsk agreement.

The russian government has been publicly joking about Trump, broadcasting nude pictures of the first lady and boasting about possessing the Epstein tapes. Before that was the hack of Hillary's mail server and fake news campaigns. No kinetic repercussions, even red carpet for putin's visit in Alaska.

Apart from all this a modern drone war would be a big problem for the US, and countries like Ukraine, russia and china are much better prepared for such a scenario.

ericmay•18m ago
> I only remember that if one US state loses power the other states laugh about it because obviously it is because the current governor is a black female democrat.

Yea that's obviously dumb, but the difference is you hear about America's problems, but not the problems in other countries. Russia has its oil facilities regularly bombed. China has institutionalized corruption down to the local level. It's not all peaches and rainbows in every country on earth.

> It'd be great progress to actually detect what caused it in a timely manner and then do a proper cyber attribution.

Who says we aren't?

> Generally I think you are using a lot of big words to compensate for the fact that the US ignored the Minsk agreement.

Can you elaborate? What's the broader point you want to get at here?

> The russian government has been publicly joking about Trump, broadcasting nude pictures of the first lady and boasting about possessing the Epstein tapes. Before that was the hack of Hillary's mail server and fake news campaigns. No kinetic repercussions, even red carpet for putin's visit in Alaska.

Yes, totally. The United States should have bombed Russia for publicly joking about Donald Trump. Give me a break. Why even post stuff like this?

> Apart from all this a modern drone war would be a big problem for the US, and countries like Ukraine, russia and china are much better prepared for such a scenario.

Who do you think is operating in Ukraine and advising the Ukrainians and learning from their drone warfare techniques and capabilities? Do you really not know how this stuff works? Are you not aware that the United States is actively testing weapons in Ukraine to prepare for drone warfare? Is that why you're saying stuff like the US should have a kinetic response against Russia for posting pictures and joking about Donald Trump?

mc32•39m ago
Europe had Ukraine sabotage (according to European reports) its gas lines and gave it more weapons as a reward… so I guess the answer is that it’s complicated.
bflesch•29m ago
source: toilet in google headquarters
mc32•26m ago
German intelligence thinks so… maybe they’re garbage. Also “the island” and “the guardian” maybe they’re garbage when they report on this but not on other things.
tokai•53m ago
Russia conduct cyber attacks on US all the time. North Korea did a high profile attack too. China flew a balloon over the whole country, not bothering a single airport, without any response. US never does anything to anyone that can hit back.
ericmay•44m ago
Three points:

1. You don't actually know what actions the US has taken.

2. The only country outside of one using nuclear bombs that could theoretically "hit back" is China.

3. Flying some balloons across the US doesn't necessarily necessitate some sort of massive response. There's levels.

tokai•36m ago
Oh I thought you said the actions would be kinetic.
ericmay•33m ago
No, sorry. I wrote:

> Yes, you're missing that if you mess with the power grid the US will go and kinetically strike back (read: bomb your country) or attack you with its own cyber warfare capabilities, unlike the EU.

Qem•55m ago
> Let's hope those chicken never come home to roost.

Bare minimum it gives chinese tech suppliers a great pitch to convince buyers to choose their products over US suppliers. Even if theirs are also full of backdoors, at least they have no history of taking advantage of them to kidnap heads of state far away.

ericmay•40m ago
> at least they have no history of taking advantage of them to kidnap heads of state far away.

Ha. Someone else wrote:

> USA is only willing to fight very asymmetrical wars.

I say:

> China is only willing to kidnap defenseless people

loeg•1h ago
Is there any particular reason to take this claim from Maduro at face value?
bflesch•1h ago
Good point. It's easier to say you got hacked by nation state actors than to tell your boss you accidentally screwed up a major system with no way to recover. It's not like 99% of the management could tell the difference.
JKCalhoun•44m ago
Agree. In hindsight though the claim gets a little more credibility.
MSFT_Edging•54m ago
In the 2019 book "Sandworm", which discusses cyber warfare against infrastructure like this, but between Russia and Ukraine, the author begs the question in an interview with a US military/intelligence official,

"why doesn't the US go after these hackers and designate targeting civilian infrastructure as a crime?"

To which the response was essentially "The US would like to reserve those types of cyber attacks for their own uses"

These quotes are very loose, I read it last year, but essentially, the US didn't make a stink about older grid attacks in order to save face when the US does it.

Additionally, much of VZ's difficulty was due to the massive sanctions against the nation. Sanctions are effectively attacks on a nation's citizens to pressure the government. Disabling power infrastructure is absolutely in-line with the motives of sanctions and embargos.

GrowingSideways•43m ago
Is there a particular reason to take any state account of anything at all at face value? At some point you either have to accept to play the game or reject all news.

In this case, it fits squarely in with American foreign policy, especially their orientation towards Venezuelan chavismo.

lentil_soup•29m ago
It also fits squarely with corruption in Venezuela, specially regarding energy. Venezuela has been rationing electricity across the country since 2009 and has been involved in countless corruption scandals involving Odebrecht, PDVSA, Derwick Associates.

I understand the US's foreign policy is a global threat, but let's not let that be an excuse for the atrocities and corruption of tyrants in Venezuela and other places.

https://en.wikipedia.org/wiki/Energy_crisis_in_Venezuela

https://en.wikipedia.org/wiki/Odebrecht_case#Venezuela

https://en.wikipedia.org/wiki/Derwick_Associates

lentil_soup•54m ago
Let's not take Maduro at his word, he's great at playing the victim to hide their corruption. Venezuela has been in an energy crisis since 2009 with rationing still happening everywhere in the country except in Caracas [1] big part of it from the Odebrecht corruption scandal [2]

[1] https://en.wikipedia.org/wiki/Energy_crisis_in_Venezuela

[2] https://en.wikipedia.org/wiki/Odebrecht_case#Venezuela

amadeuswoo•1h ago
Stuxnet was 15 years ago. This isn’t crazy news, it’s just the first time it’s being reported openly
nozzlegear•1h ago
I think I just got Mandela-Effected, I had to look this up. For some reason I thought Stuxnet was something that happened in the 90s, not late 2000s.
bflesch•1h ago
It happened to 90s systems which were used in the 2000s so you are still technically correct ;)
ironyman•1h ago
Because cyber is not a flashy capability like a new jet or missile but it's an area where the US has the clear edge: https://www.iiss.org/research-paper/2021/06/cyber-power---ti...
bflesch•55m ago
US cyber capabilities have an edge because they can analyze all of our data stored with US tech companies and they have interception points on all major internet cables.

Their human intelligence is much better prepared to "convince" someone to act against their own interest if they can look at your last ten years of communication, family pictures, and web browsing history before they even meet you.

Imagine working in a foreign country where death penalty is applied to certain crimes, like blasphemy or homosexuality. They just need to find one person in the target organization who has a secret twitter account that talked badly about god and then they hit them up and tell them to plug in a certain USB stick to a certain system. Cyber operation succeeded because they have a shell.

msie•1h ago
Is the US attacking Russia and China and India as well because they’re the biggest threats?
AnimalMuppet•1h ago
The US is almost certainly ready to attack China, Russia, India, and every other country. Currently attacking? No, at least not on this scale.

Also: Why is India on your list? "Biggest", certainly, but in what way are they a threat?

joribu•38m ago
I read GP as a commentary of BRICS. There may/may not be interference there by the US and/or Five Eyes.
bediger4000•1h ago
Almost certainly not. The first impeachment trial revealed that Trump's foreign policy was for his personal benefit. It's pretty obvious Trump has figured out that nations, corporations and oligarchs will pay him for favors. I think the dots are connectable.
Arun2009•1h ago
India has neither the ability nor the desire to attack the US. The very idea is silly.

The country has its hands full enough coping with its state of quasi-chaos and belligerent nuclear-armed neighbors without taking on the worlds leading superpower for absolutely no reason at all.

mosura•47m ago
> India has neither the ability nor the desire to attack the US.

Extraordinarily wrong on the first part.

Some countries have even outsourced some of their cyberattack capability to Indian companies in the past, and not for cost reasons.

IlikeMadison•23m ago
You need to give some details and arguments on your extraordinary claim because what can be asserted without evidence can also be dismissed without evidence.
loloquwowndueo•35m ago
No: 1) big bully only bullies little guys. 2) big guys have nuclear deterrent.
mlacks•31m ago
https://www.cybercom.mil/About/Mission-and-Vision/ This is a 4-star command.
buildbot•1h ago
It would be funny in this case if it was really just an open SCADA for their entire power grid that they clicked “off”, then “on”.
yabones•1h ago
The reality probably isn't far off... I know in the past the "breaches of critical infrastructure" breathlessly reported by the media have actually just been wide-open SNMPv2 services using the default community string. I'm sure something similar happened here. Turns out you can just connect to port 161, press "power off," and be reported in the news as an "advanced persistent threat actor"
KaiserPro•57m ago
I work in electricity, it wouldn't be one, but yeah essentially it's probably an unpatched RDP/vnc/remote desktop exploit. Or the password is contraseña123
bflesch•23m ago
I can see how a team of cyber bureaucrats is required to type in the fancy n you are using in your password. At least it is safe against brute forcing attempts with standard settings.
qingcharles•49m ago
Is it that, or is it more likely they paid some anti-Maduro electric company worker to walk into HQ and shove a dongle in the back of a PC somewhere on their internal network, ala Stuxnet?