frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Voxtral Transcribe 2

https://mistral.ai/news/voxtral-transcribe-2
147•meetpateltech•1h ago•36 comments

Attention at Constant Cost per Token via Symmetry-Aware Taylor Approximation

https://arxiv.org/abs/2602.00294
72•fheinsen•2h ago•32 comments

A sane but bull case on Clawdbot / OpenClaw

https://brandon.wang/2026/clawdbot
124•brdd•1d ago•198 comments

Tractor

https://incoherency.co.uk/blog/stories/tractor.html
35•surprisetalk•19h ago•10 comments

A case study in PDF forensics: The Epstein PDFs

https://pdfa.org/a-case-study-in-pdf-forensics-the-epstein-pdfs/
102•DuffJohnson•2h ago•32 comments

Data centers in space makes no sense

https://civai.org/blog/space-data-centers
920•ajyoon•21h ago•1041 comments

Guinea worm on track to be 2nd eradicated human disease; only 10 cases in 2025

https://arstechnica.com/health/2026/02/guinea-worm-on-track-to-be-2nd-eradicated-human-disease-on...
95•bookofjoe•2h ago•32 comments

Lessons learned shipping 500 units of my first hardware product

https://www.simonberens.com/p/lessons-learned-shipping-500-units
735•sberens•2d ago•352 comments

Old Insurance Maps – Georeferencing Sanborn Fire Insurance Maps on Modern Maps

https://oldinsurancemaps.net/
46•lapetitejort•1w ago•11 comments

FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled

https://www.404media.co/fbi-couldnt-get-into-wapo-reporters-iphone-because-it-had-lockdown-mode-e...
320•robin_reala•2h ago•265 comments

Coding Agent VMs on NixOS with Microvm.nix

https://michael.stapelberg.ch/posts/2026-02-01-coding-agent-microvm-nix/
27•secure•3d ago•11 comments

Procedures for Repair of Potholes in Asphalt-Surfaced Pavements

https://highways.dot.gov/media/7941
13•treebrained•3d ago•13 comments

Show HN: Ghidra MCP Server – 110 tools for AI-assisted reverse engineering

https://github.com/bethington/ghidra-mcp
204•xerzes•10h ago•52 comments

Show HN: Craftplan – I built my wife a production management tool for her bakery

https://github.com/puemos/craftplan
477•deofoo•2d ago•142 comments

Brazilian Micro-SaaS Map

https://saas-map.ssr.trapiche.cloud/
67•acfilho•3d ago•3 comments

I miss thinking hard

https://www.jernesto.com/articles/thinking_hard
1045•jernestomg•13h ago•572 comments

New York’s budget bill would require “blocking technology” on all 3D printers

https://blog.adafruit.com/2026/02/03/new-york-wants-to-ctrlaltdelete-your-3d-printer/
594•ptorrone•1d ago•691 comments

Thatcher Effect – Optical Illusion and Explanation

https://optical.toys/thatcher-effect/
33•robin_reala•3h ago•10 comments

Deno Sandbox

https://deno.com/blog/introducing-deno-sandbox
497•johnspurlock•23h ago•152 comments

The fax numbers of the beast, and other mathematical sports

https://cabinetmagazine.org/issues/57/wertheim.php
20•marysminefnuf•1d ago•8 comments

Broken Proofs and Broken Provers

https://lawrencecpaulson.github.io/2026/01/15/Broken_proofs.html
44•RebelPotato•7h ago•8 comments

Microsoft's Pivotal AI Product Is Running into Big Problems

https://www.wsj.com/tech/ai/microsofts-pivotal-ai-product-is-running-into-big-problems-ce235b28
16•fortran77•50m ago•4 comments

Agent Skills

https://agentskills.io/home
500•mooreds•1d ago•241 comments

X offices raided in France as UK opens fresh investigation into Grok

https://www.bbc.com/news/articles/ce3ex92557jo
524•vikaveri•1d ago•992 comments

High-Altitude Adventure with a DIY Pico Balloon

https://spectrum.ieee.org/explore-stratosphere-diy-pico-balloon
83•jnord•3d ago•42 comments

Goblins: Distributed, Transactional Programming with Racket and Guile

https://spritely.institute/goblins/
96•alhazrod•4d ago•14 comments

AliSQL: Alibaba's open-source MySQL with vector and DuckDB engines

https://github.com/alibaba/AliSQL
269•baotiao•22h ago•40 comments

Xcode 26.3 – Developers can leverage coding agents directly in Xcode

https://www.apple.com/newsroom/2026/02/xcode-26-point-3-unlocks-the-power-of-agentic-coding/
349•davidbarker•22h ago•301 comments

The Mathematics of Tuning Systems

https://math.ucr.edu/home/baez/tuning_talk/
65•u1hcw9nx•4d ago•12 comments

Exploring Different Keyboard Sensing Technologies

https://www.lttlabs.com/articles/2026/01/27/exploring-different-keyboard-sensing-technologies
60•viraptor•1w ago•43 comments
Open in hackernews

Coding Agent VMs on NixOS with Microvm.nix

https://michael.stapelberg.ch/posts/2026-02-01-coding-agent-microvm-nix/
27•secure•3d ago

Comments

clawsyndicate•3d ago
we run ~10k agent pods on k3s and went with gvisor over microvms purely for density. the memory overhead of a dedicated kernel per tenant just doesn't scale when you're trying to pack thousands of instances onto a few nodes. strict network policies and pid limits cover most of the isolation gaps anyway.
secure•3d ago
Yeah, when you run ≈10k agents instead of ≈10, you need a different solution :)

I’m curious what gVisor is getting you in your setup — of course gVisor is good for running untrusted code, but would you say that gVisor prevents issues that would otherwise make the agent break out of the kubernetes pod? Like, do you have examples you’ve observed where gVisor has saved the day?

clawsyndicate•2d ago
since we allow agents to execute arbitrary python, we treat every container as hostile. we've definitely seen logs of agents trying to crawl /proc or hit the k8s metadata api. gvisor intercepts those syscalls so they never actually reach the host kernel.
rootnod3•35m ago
And you see no problem in that at all? Just “throw a box around it and let the potentially malicious code run”?

Wait until they find a hole. Then good luck.

zeroxfe•59m ago
I've used both gVisor and microvms for this (at very large scales), and there are various tradeoffs between the two.

The huge gVisor drawback is that it __drastically_ slows down applications (despite startup time being faster.)

For agents, the startup time latency is less of an issue than the runtime cost, so microvms perform a lot better. If you're doing this in kube, then there's a bunch of other challenges to deal with if you want standard k8s features, but if you're just looking for isolated sandboxes for agents, microvms work really well.

dist-epoch•32m ago
LXC containers inside a VM scales. bonus point that LXC containers feel like a VM.
rootnod3•1h ago
That is quite an involved setup to get a costly autocomplete going.

Is that really where we are at? Just outsource convenience to a few big players that can afford the hardware? Just to save on typing and god forbid…thinking?

“Sorry boss, I can’t write code because cloudflare is down.”

Cyph0n•11m ago
Keep in mind that this setup is a one-time cost. Also, a lot of the code is related to configuring it the way the author (via Home Manager).

Generally speaking, once you have a working NixOS config, incremental changes become extremely trivial, safe, and easy to rollback.

the_harpia_io•1h ago
The sandbox-or-not debate is important but it's only half the picture. Even a perfectly sandboxed agent can still generate code with vulnerabilities that get deployed to production - SQL injection, path traversal, hardcoded secrets, overly permissive package imports.

The execution sandbox stops the agent from breaking out during development, but the real risk is what gets shipped downstream. Seeing more tools now that scan the generated code itself, not just contain the execution environment.

heliumtera•57m ago
Couldn't you replicate all of your setup with qemu microvm?

Without nix I mean

rictic•32m ago
Yep. What nix adds is a declarative and reproducible way to build customized OS images to boot into.