frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Story of XZ Backdoor [video]

https://www.youtube.com/watch?v=aoag03mSuXQ
39•Ulf950•1h ago

Comments

forinti•1h ago
Ireland recently created a Basic Income scheme for artists.

Europe should have an equivalent scheme for programmers of important Open Source projects such as this one.

anarazel•1h ago
Just German, not European, but still a start: https://en.wikipedia.org/wiki/Sovereign_Tech_Agency
mc32•39m ago
The problem was more than remuneration. It was burnout and mental health issues. They may have been moderated by income but we don’t know.

Also today as I understand it much of OSS is done in-house by major companies (red hat, Ubuntu, ibm, Google, etc)

coldpie•1h ago
This is IMO one of the coolest tech stories to ever happen, seriously amazing spycraft & hacking skills, but I haven't been keeping up with new developments from this story since it broke. Last I heard, the best guess at what happened was some state-sponsored actor worked very hard to get this merged, and it was caught luckily at the last minute. But no one had any smoking gun as to who did it or why or who they were targeting. Any new developments since then? Are we still just totally in the dark about what was going on here?
nerevarthelame•1h ago
Still no smoking gun, but possibly Russia. From the video https://youtu.be/aoag03mSuXQ?t=2883:

> A lot of the aliases, like Jia Tan, they sound like Asian names, and the published changes are all timestamped in UTC+8, Beijing time. So the signs point to China. And that's why it's probably not China. I mean, why would they make it that obvious? Every other part of the operation has been so meticulous, so cautious.

> And they also worked on Chinese New Year, but not on Christmas. And over the years, there were nine changes that fall outside of the Beijing time into UTC+2, which is a time zone that includes Israel and parts of Western Russia. That's why some experts have speculated that this could be the work of APT29, a Russian-state-backed hacker group also known as Cozy Bear. But again, do we know? No, of course we don't know who it is, and we likely will never know.

gosub100•38m ago
Russians don't celebrate Christmas on the 25th.
mc32•35m ago
Those anecdotes don’t mean anything. If I were China and wanted plausible deniability I would work on CNY and take off on foreign holidays. Of course that leaves Beijing time as a weird oversight though it’s always Beijing time anywhere in China.
ginko•4m ago
>And that's why it's probably not China. I mean, why would they make it that obvious?

That's just what they want you to think!

mbauman•1h ago
I'm still floored that Andres both found this and didn't ignore it. It's such a testament to an incredible engineer.

(But also, my conspiratorially-inclined mind is quite entertained by the thought of some sort of parallel construction or tip from a TLA.)

II2II•9m ago
Even though the video is somewhat sensationalized at some points, it is well worth a watch for people who are interested in computers but don't have a background in it. There is a nice mixture of everything from history (e.g. the founding of the FSF) to a clear explanation of a compression algorithm (clear enough that one should be able to implement it). It also makes claims that should make some people stop and think about the industry as a whole (such as Linux being the most important contemporary operating system).

I'm not sure if it is HN-crowd type material since it is easy enough information for most of us to dig up, assuming we didn't already know it. Yet it does not simplify things to the point of, "technology is magic."

New AirSnitch attack breaks Wi-Fi encryption in homes, offices, and enterprises

https://arstechnica.com/security/2026/02/new-airsnitch-attack-breaks-wi-fi-encryption-in-homes-of...
19•DamnInteresting•19m ago•5 comments

Show HN: Terminal Phone – E2EE Walkie Talkie from the Command Line

https://gitlab.com/here_forawhile/terminalphone
190•smalltorch•5h ago•50 comments

Anthropic ditches its core safety promise

https://www.cnn.com/2026/02/25/tech/anthropic-safety-policy-change
358•motbus3•3h ago•189 comments

Google API keys weren't secrets, but then Gemini changed the rules

https://trufflesecurity.com/blog/google-api-keys-werent-secrets-but-then-gemini-changed-the-rules
985•hiisthisthingon•20h ago•237 comments

just-bash: Bash for Agents

https://github.com/vercel-labs/just-bash
31•tosh•2h ago•22 comments

BuildKit: Docker's Hidden Gem That Can Build Almost Anything

https://tuananh.net/2026/02/25/buildkit-docker-hidden-gem/
15•jasonpeacock•2h ago•10 comments

Show HN: Agent Swarm – Multi-agent self-learning teams (OSS)

https://github.com/desplega-ai/agent-swarm
61•tarasyarema•4h ago•39 comments

Tell HN: YC companies scrape GitHub activity, send spam emails to users

341•miki123211•6h ago•111 comments

In 2025, Meta paid an effective federal tax rate of 3.5%

https://bsky.app/profile/rbreich.bsky.social/post/3mfptlfeucn2i
97•doener•1h ago•58 comments

Jimi Hendrix was a systems engineer

https://spectrum.ieee.org/jimi-hendrix-systems-engineer
585•tintinnabula•19h ago•189 comments

Banned in California

https://www.bannedincalifornia.org/
334•pie_flavor•16h ago•390 comments

Hightouch (YC S19) Is Hiring

https://hightouch.com/careers#open-positions
1•joshwget•4h ago

How will OpenAI compete?

https://www.ben-evans.com/benedictevans/2026/2/19/how-will-openai-compete-nkg2x
372•iamskeole•17h ago•522 comments

Fentanyl makeover: Core structural redesign could lead to safer pain medications

https://www.scripps.edu/news-and-events/press-room/2026/20260211-janda-molecule.html
45•littlexsparkee•3h ago•42 comments

Those who can, teach history

https://www.historytoday.com/archive/making-history/those-who-can-teach-history
16•hhs•4d ago•16 comments

Ferret-UI Lite: Lessons from Building Small On-Device GUI Agents

https://machinelearning.apple.com/research/ferret-ui
5•CharlesW•4d ago•1 comments

Story of XZ Backdoor [video]

https://www.youtube.com/watch?v=aoag03mSuXQ
39•Ulf950•1h ago•10 comments

First Website (1992)

https://info.cern.ch
278•shrikaranhanda•17h ago•76 comments

A 26-Gram Butterfly-Inspired Robot Achieving Autonomous Tailless Flight

https://arxiv.org/abs/2602.06811
40•Terretta•4d ago•9 comments

Some silly Z3 scripts I wrote

https://www.hillelwayne.com/post/z3-examples/
15•azhenley•2d ago•3 comments

Making MCP cheaper via CLI

https://kanyilmaz.me/2026/02/23/cli-vs-mcp.html
284•thellimist•19h ago•109 comments

Windows 11 Notepad to support Markdown

https://blogs.windows.com/windows-insider/2026/01/21/notepad-and-paint-updates-begin-rolling-out-...
327•andreynering•23h ago•494 comments

Artist who “paints” portraits on glass by hitting it with a hammer

https://simonbergerart.com
224•cs702•3d ago•96 comments

Time Is Different

https://shkspr.mobi/blog/2026/02/this-time-is-different/
7•speckx•2h ago•0 comments

Bus stop balancing is fast, cheap, and effective

https://worksinprogress.co/issue/the-united-states-needs-fewer-bus-stops/
396•surprisetalk•23h ago•577 comments

Large-Scale Online Deanonymization with LLMs

https://simonlermen.substack.com/p/large-scale-online-deanonymization
320•DalasNoin•1d ago•223 comments

Apple Launch on Monday

https://twitter.com/tim_cook/status/2027020842396475410
5•redox_•27m ago•0 comments

Show HN: Modern Reimplementation of the Speck Molecule Renderer

https://github.com/vangelov/modern-speck
18•vlad_angelov•4d ago•2 comments

Writers and Their Day Jobs

https://lithub.com/the-work-behind-the-writing-on-writers-and-their-day-jobs/
64•simplegeek•4d ago•22 comments

Show HN: Respectify – A comment moderator that teaches people to argue better

https://respectify.org/
201•vintagedave•1d ago•197 comments