frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Radicle: The Sovereign Forge

https://radicle.xyz
58•ibobev•1h ago•28 comments

Booting from a vinyl record (2020)

https://boginjr.com/it/sw/dev/vinyl-boot/
106•yesturi•4h ago•26 comments

AI is a horse (2024)

https://kconner.com/2024/08/02/ai-is-a-horse.html
194•zdw•3d ago•105 comments

Show HN: Whosthere: A LAN discovery tool with a modern TUI, written in Go

https://github.com/ramonvermeulen/whosthere
42•rvermeulen98•3h ago•16 comments

Proton Spam and the AI Consent Problem

https://dbushell.com/2026/01/22/proton-spam/
296•dbushell•8h ago•189 comments

I built a light that reacts to radio waves [video]

https://www.youtube.com/watch?v=moBCOEiqiPs
302•codetheweb•9h ago•68 comments

Updates to our web search products and Programmable Search Engine capabilities

https://programmablesearchengine.googleblog.com/2026/01/updates-to-our-web-search-products.html
135•01jonny01•5h ago•128 comments

What has Docker become?

https://tuananh.net/2026/01/20/what-has-docker-become/
106•tuananh•2h ago•111 comments

Replacing Protobuf with Rust to go 5 times faster

https://pgdog.dev/blog/replace-protobuf-with-rust
99•whiteros_e•6h ago•67 comments

White House Posts Altered Photo Showing Arrested Minnesota Protester Crying

https://www.nytimes.com/2026/01/22/us/politics/nekima-armstrong-photo-white-house.html
47•nicpottier•25m ago•12 comments

The cleaner: One woman’s mission to help Britain’s hoarders

https://www.aljazeera.com/features/2026/1/18/the-cleaner-one-womans-mission-to-help-britains-hoar...
24•Qem•5d ago•19 comments

Flying with Photons: Rendering Novel Views of Propagating Light

https://anaghmalik.com/FlyingWithPhotons/
4•pillars•3d ago•0 comments

AI Usage Policy

https://github.com/ghostty-org/ghostty/blob/main/AI_POLICY.md
332•mefengl•5h ago•162 comments

Show HN: isometric.nyc – giant isometric pixel art map of NYC

https://cannoneyed.com/isometric-nyc/
1091•cannoneyed•22h ago•205 comments

Tesla fined for repeatedly failing to help UK police over driving offences

https://www.bbc.co.uk/news/articles/c0r44zpprg7o
34•6LLvveMx2koXfwn•35m ago•11 comments

GPTZero finds 100 new hallucinations in NeurIPS 2025 accepted papers

https://gptzero.me/news/neurips/
888•segmenta•23h ago•472 comments

Microsoft mishandling example.com

https://tinyapps.org/blog/microsoft-mishandling-example-com.html
104•mrled•2h ago•46 comments

Show HN: S2-lite, an open source Stream Store

https://github.com/s2-streamstore/s2
32•shikhar•1d ago•2 comments

The state of modern AI text to speech systems for screen reader users

https://stuff.interfree.ca/2026/01/05/ai-tts-for-screenreaders.html
50•tuukkao•5h ago•14 comments

Presence in Death

https://rubinmuseum.org/presence-in-death/
30•tock•2h ago•4 comments

Capital One to acquire Brex for $5.15B

https://www.reuters.com/legal/transactional/capital-one-buy-fintech-firm-brex-515-billion-deal-20...
329•personjerry•17h ago•276 comments

I was banned from Claude for scaffolding a Claude.md file?

https://hugodaniel.com/posts/claude-code-banned-me/
619•hugodan•20h ago•549 comments

Variation on Iota

https://www.toolofthought.com/posts/variation-on-iota
10•aebtebeten•4d ago•2 comments

Why does SSH send 100 packets per keystroke?

https://eieio.games/blog/ssh-sends-100-packets-per-keystroke/
561•eieio•19h ago•298 comments

Qwen3-TTS family is now open sourced: Voice design, clone, and generation

https://qwen.ai/blog?id=qwen3tts-0115
655•Palmik•1d ago•205 comments

Douglas Adams on the English–American cultural divide over "heroes"

https://shreevatsa.net/post/douglas-adams-cultural-divide/
492•speckx•1d ago•496 comments

Why medieval city-builder video games are historically inaccurate (2020)

https://www.leidenmedievalistsblog.nl/articles/why-medieval-city-builder-video-games-are-historic...
177•benbreen•14h ago•115 comments

TI-99/4A: Leaning More on the Firmware

https://bumbershootsoft.wordpress.com/2026/01/17/ti-99-4a-leaning-more-heavily-on-the-firmware/
58•ibobev•4d ago•24 comments

Your app subscription is now my weekend project

https://rselbach.com/your-sub-is-now-my-weekend-project
447•robteix•4d ago•314 comments

Scaling PostgreSQL to power 800M ChatGPT users

https://openai.com/index/scaling-postgresql/
255•mustaphah•17h ago•108 comments
Open in hackernews

Microsoft mishandling example.com

https://tinyapps.org/blog/microsoft-mishandling-example-com.html
104•mrled•2h ago

Comments

godzillabrennus•1h ago
This is the same company that mishandled the Office brand (abandoned it) and is mishandling the Xbox brand (what even is an Xbox anymore?). Are we surprised?
rurban•1h ago
NSA probably. Gives them plausible deniability.

Maybe some of their targets did use example.com for some probing, and the NSA had a hand in Sumitomo Electric Industries' mail server.

whizzter•1h ago
Reading the article, there is a huge flaw in the autodiscover protocol by Microsoft.

https://www.akamai.com/blog/security/autodiscovering-the-gre...

According to it, it seems that if someone registers autodiscover.com then example.com lacking autodiscover.example.com will make Outlook try checking if autodiscover.com has an entry.

It's just a braindead system.

irusensei•1h ago
Not surprised. They used to have training material incentivizing professionals to use .local as TLD for Active Directory realms. Thats a reserved domain for Multicast DNS.

Working on Linux automation systems we would need to make sure to disable anything related to Avahi in our images otherwise name resolution would fail for some customers.

szszrk•1h ago
My company used .local for EVERYTHING. I took it as normal at the time, until I got into problems with VMWARE products.

Support patiently explained .local is reserved for something else and kindly provided Wikipedia links.

They never responded why they used .local in their docs, trainings, webinars they provided, though :)

irusensei•58m ago
My impression is that Ballmer IE6 era Microsoft didn't gave a shit about standards.
PcChip•7m ago
I’ve worked with hundreds of customers that use .local internal domains and vmware, what issues are you describing?
EvanAnderson•1m ago
Things from docs making it into production is insidious. There were some early Sun docs that referenced a 129.9.0.0/16 network. Some helpful contractor in my locality, specializing in local government work, configured several police, fire, and city governments with that subnet internally back in the 90s. A few of them are still running that way today. I remember running into some oddball behavior with the Teredo adapter in Windows 7 that I traced back to it behaving differently because the PC's IP address didn't fall into RFC1918 space.
ndriscoll•55m ago
Haven't they been telling people to do that since before it became reserved? If so, the problem is more that you can't "reserve" something that's already in wide use, and mdns should've used something like .mdns.

It's like when .dev became a gTLD, knowingly breaking a bunch of setups for a mix of vanity and a cash grab. Obviously dropped the ball on the engineering side.

p_ing•8m ago
Usage of .local for AD predated mDNS. That advice stopped with the advent of mDNS in favor of 'corp.<registered_domain>.<tld>'.
EvanAnderson•4m ago
The original Windows 2000 guidance for AD was corp.example.com, from my recollection. The silly .local thing (which does predate mDNS) happened as a result of the Small Business Server refresh for Active Directory.
hu3•1h ago
This is why I never use these IANA-reserved domains like .test, .example, .invalid, .localhost.

I always make up some impossible domains like domain.tmptest

Otherwise you're one DNS "misconfiguration" away from sending dev logs and auth tokens to some random server.

> Since at least February 2020, Microsoft's Autodiscover service has incorrectly routed the IANA-reserved example.com to Sumitomo Electric Industries' mail servers at sei.co.jp, potentially sending test credentials there.

whizzter•1h ago
.example is probably far safer than example.com.

https://www.akamai.com/blog/security/autodiscovering-the-gre...

According to it, it seems that if someone registers autodiscover.com then example.com lacking autodiscover.example.com will make Outlook try checking if autodiscover.com has an entry.

It's just a braindead system.

jsheard•1h ago
It's all fun and games until Donuts buys .tmptest for some reason.
wongarsu•1h ago
brb, just filing paperwork to apply for the .tmptest gTLD /s
lagniappe•57m ago
I suspect you'd download a car.
ThePowerOfFuet•35m ago
$100K
Cthulhu_•40m ago
Would that really make a difference in this case? It's a configuration error / bug in Microsoft's discovery server, they could have a fallback that goes "any unknown address, return this .jp address".
tialaramex•36m ago
It so happens that in this very specific case your obviously bad choice didn't make anything worse, that doesn't make it a good choice.

"Aha, the defective trucks only cause injuries to people who have their hands on the wheel at highway speeds, but I've never bothered holding the wheel at high speed, I just YOLO so I wouldn't be affected"

If people had used IANA's reserved TLDs they too would be unaffected because although Windows will stupidly try to talk to for example autodiscover.example that can't exist by policy and so the attempt will always fail.

andreldm•1h ago
That’s why example.com states “Avoid use in operations”, not only that could create unnecessary traffic for them as well as leak information as in situations like this.
binaryturtle•1h ago
Why do you need to send a password when using their Autodiscover API? Would Outlook send the respective passwords for each email account to Microsoft?
philipwhiuk•45m ago
I suspect they try to login and reverse engineer the IMAP config.
GranPC•1h ago
> Microsoft's Autodiscover service misconfiguration can be confirmed via curl -v -u "email@example.com:password" "https://prod.autodetect.outlook.cloud.microsoft/autodetect/d..."

Wait, does their autodetect send email and password to their servers, instead of just domain???

gruez•1h ago
>Microsoft's Autodiscover service misconfiguration can be confirmed via curl -v -u "email@example.com:password" "https://prod.autodetect.outlook.cloud.microsoft/autodetect/d...":

Hold up, does this mean outlook sends your full credentials to Microsoft when you try to set up an outlook account? I'm sure they pinky promise they keep your credentials secure, but this feels like it breaks all sorts of security/privacy expectations.

thedanbob•55m ago
It's more common than you might think. I know of at least one popular email client that stores your credentials on their servers to enable features like multi-account sync and scheduled sending.
spiffyk•48m ago
I would expect such a feature to use end-to-end encryption for the data, so that only the user can see the credentials. It does, right? Right?
gruez•46m ago
>>multi-account sync and scheduled sending

>I would expect such a feature to use end-to-end encryption for the data

How would "end-to-end encryption" when such features by definition require the server to have access to the credentials to perform the required operations? If by "end to end" you actually mean it's encrypted all the way to the server, that's just "encryption in transit".

tom1337•45m ago
Do you mean Spark? I get why they need to do it that way but I also hate that they have to do it that way because it sucks for privacy.
RajT88•11m ago
I bought a hardware password manager a while back and the bulk load tool sent all your creds to a cloud service. I have not used it since, and sent the manufacturer a nasty note.

It was the Ethernom Beamu, company now defunct.

dec0dedab0de•39m ago
I think outlook is pretty much a saas product these days.
tga•36m ago
Most likely, and nobody cares.

Already many years ago I remember installing a firewall on my phone and noticing in surprise that Outlook was not connecting at all to my private mail server, but instead only sending my credentials to their cloud and downloading messages from there.

The only Android mail client not making random calls to cloud servers was (back then) K-9 Mail.

nhinck2•30m ago
Yeah since the Windows 11 2023h2 update.
brulx126•29m ago
Not just that, the new outlook app makes Microsoft a complete man-in-the-middle for your email account.

https://www.xda-developers.com/privacy-implications-new-micr...

koakuma-chan•23m ago
And? Do you think Gmail is end to end encrypted?
brulx126•18m ago
I am talking about the fact that the new default email client on Windows will hand over all your email credentials to Microsoft. This has nothing to do with Gmail.
koakuma-chan•15m ago
Oh you mean even if you don't use Microsoft's email? Now I get it.
gruez•18m ago
My bank isn't end to end encrypted either, but that doesn't mean it's suddenly ok for Microsoft (or any other company) to suddenly start MITMing my online banking connections.
AlexandrB•11m ago
Adding a bunch of middlemen that also see the data increases the risk.
butvacuum•27m ago
Basically everything microsoft makes that touches http will send your username and your password to any server that asks for Basic Authentication.

It looks like Microsoft Edge had the _ability to disable_ this added in 2020 or 2021, but it isn't currently the default and the Group Policy unintuitively only applies to unencrypted HTTP Connections.

gruez•15m ago
>Basically everything microsoft makes that touches http will send your username and your password to any server that asks for Basic Authentication.

Are you talking about NTLM hashes? It's a weak hash, but not the same as "sending your password". The biggest difference is that even a weak hash can't be reversed if the password has high enough entropy.

dspillett•6m ago
> Hold up, does this mean outlook sends your full credentials to Microsoft when you try to set up an outlook account?

Not just an “outlook account” - any account in outlook, with default settings at least.

I run a mail server, mainly for me but a couple of friends have accounts on there too, and a while ago one friend reported apparently being locked out and it turned out that it was due to them switching Outlook versions and it was connecting via a completely different address to those that my whitelists expected sometimes at times when they weren't even actively using Outlook. Not only were active connections due to their interactive activity being proxied, but the IMAP credentials were stored so the MS server could login to check things whenever it wanted (I assume the intended value-add there is being able to send new mail notifications on phones/desktops even when not actively using mail?).

> but this feels like it breaks all sorts of security/privacy expectations.

It most certainly does. The behaviour can be tamed somewhat, but (unless there have been recent changes) is fully enabled by default in newer Outlook variants.

The above-mentioned friend migrated his mail to some other service in a huf as I refused to open my whitelist to “any old host run by MS” and he didn't want to dig in to how to return behaviour back to the previous “local connections only, not sending credentials off elsewhere where they might be stored”.

Thaxll•1h ago
Where does sei.co.jp comes from? Why Microsoft would use that domain in the first place?
irusensei•59m ago
It's not really the domain but the registration in the MS Office Cloud. If you query who owns example.com mail you get that company.
Daviey•59m ago
I'm willing to bet they were the first user to try and add example.com to their Outlook account, and MS then just assigned it to them without verifying they own the domain.
onionisafruit•41m ago
I gather this has little to do with “example.com” and more to do with any domain that doesn’t have an autodiscover subdomain.
butz•3m ago
Nice to see tinyapps.org is still alive.