frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Allowlisting some Bash commands is often the same as allowlisting all

https://www.joinformal.com/blog/allowlisting-some-bash-commands-is-often-the-same-as-allowlisting-all-with-claude-code/
10•drewgregory•3h ago

Comments

teddyh•2h ago
“…with Claude Code”
adastra22•1h ago
Are there any agent permission systems that do this correctly?
extraduder_ire•54m ago
The same caveats would apply to most kinds of restricted shell environments.
zufallsheld•1h ago
Same thing for allowing specific sudo-commands. Many tools (like vim or the tools mentioned in the article) would have the same problem when allowing them to be run with root privileges.
denysvitali•1h ago
=> https://gtfobins.org/
sadnboxx•1h ago
Allowing a "command" (executable, I believe) that isn't a read-only absolute path is a fool's errand. I will modify PATH and run my own implementation of it.
pimlottc•1h ago
I know they’re just being through but the “go test” part is a bit “Pray, Mr Babbage”… Test code is just code. I know of no language where tests are sandboxed in any meaningful way.
eqvinox•1h ago
everything is a container these days, and yet somehow collective-we don't manage to have AI agents run in a container layer on top of our current work, so we can later commit or rollback?
schneems•2m ago
"Welcome to 'Whose Turing Machine Is It Anyway?', the show where halting is made up and the permissions don't matter"

Somebody used spoofed ADSB signals to raster the meme of JD Vance

https://alecmuffett.com/article/143548
70•wubin•47m ago•20 comments

How London became the rest of the world’s startup capital

https://www.economist.com/britain/2026/01/26/how-london-became-the-rest-of-the-worlds-startup-cap...
61•ellieh•22h ago•33 comments

Trinity large: An open 400B sparse MoE model

https://www.arcee.ai/blog/trinity-large
36•linolevan•21h ago•10 comments

Airfoil (2024)

https://ciechanow.ski/airfoil/
309•brk•8h ago•46 comments

Did a celebrated researcher obscure a baby's poisoning?

https://www.newyorker.com/magazine/2026/02/02/did-a-celebrated-researcher-obscure-a-fatal-poisoning
33•littlexsparkee•22h ago•2 comments

Mousefood – Build embedded terminal UIs for microcontrollers

https://github.com/ratatui/mousefood
121•orhunp_•5h ago•35 comments

Android's desktop interface leaks

https://9to5google.com/2026/01/27/android-desktop-leak/
111•thunderbong•19h ago•193 comments

Oban, the job processing framework from Elixir, has come to Python

https://www.dimamik.com/posts/oban_py/
148•dimamik•6h ago•65 comments

Computer History Museum Launches Digital Portal to Its Collection

https://computerhistory.org/press-releases/computer-history-museum-launches-digital-portal-to-its...
71•ChrisArchitect•4h ago•14 comments

Show HN: A MitM proxy to see what your LLM tools are sending

https://github.com/jmuncor/sherlock
30•jmuncor•3h ago•14 comments

The Five Levels: From spicy autocomplete to the dark factory

https://www.danshapiro.com/blog/2026/01/the-five-levels-from-spicy-autocomplete-to-the-software-f...
27•benwerd•4d ago•25 comments

Jellyfin LLM/"AI" Development Policy

https://jellyfin.org/docs/general/contributing/llm-policies/
75•mmoogle•56m ago•31 comments

Apple to Soon Take Up to 30% Cut from All Patreon Creators in iOS App

https://www.macrumors.com/2026/01/28/patreon-apple-tax/
81•pier25•1h ago•31 comments

How to turn 'sfo-jfk' into a suitable photo

https://www.approachwithalacrity.com/how-to-turn-sfo-jfk-into-a-beautiful-photo/
15•bblcla•3h ago•15 comments

Who sets the Doomsday Clock?

https://www.popularmechanics.com/science/a70162364/setting-the-doomsday-clock/
12•littlexsparkee•2h ago•9 comments

Microsoft forced me to switch to Linux

https://www.himthe.dev/blog/microsoft-to-linux
1455•bobsterlobster•8h ago•1139 comments

Spinning around: Please don't – Common problems with spin locks

https://www.siliceum.com/en/blog/post/spinning-around/
57•bdash•5h ago•23 comments

Show HN: Cursor for Userscripts

https://github.com/chebykinn/browser-code
21•mifydev•2h ago•5 comments

Show HN: The HN Arcade

https://andrewgy8.github.io/hnarcade/
283•yuppiepuppie•11h ago•72 comments

Hellenistic War-Elephants and the Use of Alcohol Before Battle

https://www.cambridge.org/core/journals/classical-quarterly/article/hellenistic-warelephants-and-...
4•perihelions•5d ago•1 comments

In a genre where spoilers are devastating, how do we talk about puzzle games?

https://thinkygames.com/features/in-a-genre-where-information-is-sacred-and-spoilers-are-devastat...
17•tobr•5d ago•7 comments

Native Linux VST plugin directory

https://linuxmusic.rocks
59•Aldipower•2h ago•16 comments

Amazon One palm authentication discontinued

https://amazonone.aws.com/help
47•KerryJones•5h ago•100 comments

Amazon cuts 16k jobs

https://www.reuters.com/legal/litigation/amazon-cuts-16000-jobs-globally-broader-restructuring-20...
414•DGAP•6h ago•571 comments

I overengineered a spinning top [video]

https://www.youtube.com/watch?v=Wp5NodfvvF4
101•bane•5d ago•29 comments

3D-Printed Mathematical Lampshades

https://hessammehr.github.io/blog/posts/2025-12-24-maths-to-lampshade.html
41•hessammehr•4d ago•16 comments

Kyber (YC W23) Is Hiring a Staff Engineer

https://www.ycombinator.com/companies/kyber/jobs/GPJkv5v-staff-engineer-tech-lead
1•asontha•10h ago

Tuning Semantic Search on JFMM.net – Joint Fleet Maintenance Manual

https://carlkolon.com/2026/01/27/jfmm-semantic-search/
9•cckolon•7h ago•0 comments

I have written gemma3 inference in pure C

https://github.com/robitec97/gemma3.c
43•robitec97•2d ago•17 comments

Show HN: SHDL – A minimal hardware description language built from logic gates

https://github.com/rafa-rrayes/SHDL
20•rafa_rrayes•10h ago•9 comments