frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

The Claude Code Source Leak: fake tools, frustration regexes, undercover mode

https://alex000kim.com/posts/2026-03-31-claude-code-source-leak/
947•alex000kim•15h ago•374 comments

Neanderthals survived on a knife's edge for 350k years

https://www.science.org/content/article/neanderthals-survived-knife-s-edge-350-000-years
46•Hooke•3h ago•4 comments

TinyLoRA – Learning to Reason in 13 Parameters

https://arxiv.org/abs/2602.04118
111•sorenjan•4d ago•12 comments

TruffleRuby

https://chrisseaton.com/truffleruby/
71•tosh•3d ago•4 comments

Show HN: 1-Bit Bonsai, the First Commercially Viable 1-Bit LLMs

https://prismml.com/
157•PrismML•7h ago•66 comments

Ministack (Replacement for LocalStack)

https://ministack.org/
167•kerblang•7h ago•32 comments

I built a 516-panel financial terminal in 3 weeks using AI

https://neuberg.ai/
3•saratsai•17m ago•2 comments

A dot a day keeps the clutter away

https://scottlawsonbc.com/post/dot-system
204•scottlawson•7h ago•68 comments

Analyzing Geekbench 6 under Intel's BOT

https://www.geekbench.com/blog/2026/03/analyzing-geekbench-6-under-intels-bot/
9•hajile•50m ago•0 comments

We intercepted the White House app's network traffic

https://www.atomic.computer/blog/white-house-app-network-traffic-analysis/
167•donutpepperoni•2h ago•50 comments

OpenAI closes funding round at an $852B valuation

https://www.cnbc.com/2026/03/31/openai-funding-round-ipo.html
376•surprisetalk•8h ago•316 comments

Use string views instead of passing std:wstring by const&

https://giodicanio.com/2024/05/14/why-dont-you-use-string-views-like-std-wstring_view-instead-of-...
19•Orochikaku•2d ago•10 comments

4D Doom

https://github.com/danieldugas/HYPERHELL
153•chronolitus•4d ago•34 comments

Ordinary Lab Gloves May Have Skewed Microplastic Data

https://nautil.us/ordinary-lab-gloves-may-have-skewed-microplastic-data-1279386
79•WaitWaitWha•6h ago•19 comments

Bring Back MiniDV with This Raspberry Pi FireWire Hat

https://www.jeffgeerling.com/blog/2026/minidv-with-raspberry-pi-firewire-hat/
4•ingve•3d ago•0 comments

Slop is not necessarily the future

https://www.greptile.com/blog/ai-slopware-future
193•dakshgupta•13h ago•347 comments

Back to FreeBSD – Part 2 – Jails

https://hypha.pub/back-to-freebsd-part-2
62•vermaden•4d ago•11 comments

Open source CAD in the browser (Solvespace)

https://solvespace.com/webver.pl
305•phkahler•15h ago•99 comments

Teenage Engineering's PO-32 acoustic modem and synth implementation

https://github.com/ericlewis/libpo32
92•ericlewis•4d ago•22 comments

I Traced My Traffic Through a Home Tailscale Exit Node

https://tech.stonecharioteer.com/posts/2026/tailscale-exit-nodes/
94•stonecharioteer•8h ago•41 comments

Cohere Transcribe: Speech Recognition

https://cohere.com/blog/transcribe
170•gmays•11h ago•54 comments

OkCupid gave 3M dating-app photos to facial recognition firm, FTC says

https://arstechnica.com/tech-policy/2026/03/okcupid-match-pay-no-fine-for-sharing-user-photos-wit...
420•whiteboardr•10h ago•87 comments

Why the US Navy won't blast the Iranians and 'open' Strait of Hormuz

https://responsiblestatecraft.org/iran-strait-of-hormuz/
221•KoftaBob•18h ago•569 comments

Inside the 'self-driving' lab revolution

https://www.nature.com/articles/d41586-026-00974-2
19•salkahfi•1d ago•2 comments

Learn Something Old Every Day, Part XVIII: How Does FPU Detection Work?

https://www.os2museum.com/wp/learn-something-old-every-day-part-xviii-how-does-fpu-detection-work/
33•kencausey•3d ago•2 comments

Axios compromised on NPM – Malicious versions drop remote access trojan

https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-t...
1797•mtud•1d ago•729 comments

From 300KB to 69KB per Token: How LLM Architectures Solve the KV Cache Problem

https://news.future-shock.ai/the-weight-of-remembering/
97•future-shock-ai•3d ago•7 comments

Show HN: Forkrun – NUMA-aware shell parallelizer (50×–400× faster than parallel)

https://github.com/jkool702/forkrun
125•jkool702•4d ago•30 comments

Show HN: Postgres extension for BM25 relevance-ranked full-text search

https://github.com/timescale/pg_textsearch
114•tjgreen•11h ago•34 comments

GitHub's Historic Uptime

https://damrnelson.github.io/github-historical-uptime/
434•todsacerdoti•9h ago•106 comments
Open in hackernews

We intercepted the White House app's network traffic

https://www.atomic.computer/blog/white-house-app-network-traffic-analysis/
166•donutpepperoni•2h ago

Comments

gruez•1h ago
So like... most b2c apps out there? I checked app privacy report for a few such apps I have installed and also got a very high proportion of third party domains. Maybe not as high as 77% but definitely above 50% (ie. more domains are third party than first party). The most surprising part here is them refusing to put correct info in the "data collected" section of the app store listing.

edit: they seemed to have updated the store listing, so the "data collected" section is correct.

iterateoften•1h ago
A government app being built like b2c is exactly the problem
gruez•1h ago
I'm sure that HN's preferred app would be <5MB, and has zero third party SDKs or telemetry, but half a dozen SDKs and third party domains is basically most mass market apps these days. Is it bad? Yes, but the whitehouse isn't being egregiously bad, but "whitehouse app is bad, just like most other apps" isn't going to get clicks.
aplummer•1h ago
See gov.uk for a good example
SV_BubbleTime•1h ago
Oh, sorry you missed Exlir and WASM, and rust and programming socks of course. Half credit.
abustamam•1h ago
"everything else sucks too" is not a great defense for the US govt.
gruez•1h ago
If only. It would be a far better state of of affairs if the US government sucks like every other first world country. No other first country are waging war in the middle east, having paramilitary forces terrorize residents, or are undergoing a partial government shutdown.
charcircuit•35m ago
Just because an app embeds YouTube instead of creating their own video hosting solution that does not mean that does not mean that the app sucks.
tr_user•1h ago
Are you also the type of person who thinks the government should be run like a business?
jmalicki•1h ago
The government should outsource way more of their traffic to third parties than a business should, since the government is inefficient, right?
amazingman•1h ago
Poe's Law strikes again. I legitimately can't tell if this is sarcasm.
jmalicki•15m ago
It is sarcasm. I always get screwed by Poe's law, since dry sarcastic parodies of extremist views is one of my favorite methodologies for producing humor.
gruez•1h ago
No. Stop putting words in my mouth.
mattbuilds•1h ago
No one put words in your mouth, they asked you a question. You are the one who made the initial comparison to B2C apps, so it seems like a fair question to me. Your comment implies that its standard and the app isn't doing anything out of the ordinary when I think most people would except an official government app to be held to a higher standard than the average B2C app.
gruez•1h ago
>You are the one who made the initial comparison to B2C apps, so it seems like a fair question to me.

The relevant part of B2C is the 2C part, not the B. Mass market apps are generally ridden with telemetry and SDKs. Moreover I'm not sure how you think it's a "fair question" to go from a remark about how other apps are equally bad, to thinking I want the US government to operate as a business. It's like doing:

A: "I called the IRS and was put on hold for 2 hours, can you believe that?"

B: "To be fair that's the experience calling into most businesses, like banks or the cable company"

A: "Wow so you think we should be running the IRS like a bank?"

>I think most people would except an official government app to be held to a higher standard than the average B2C app.

Is this a "yes, in an ideal world that's how things should be" type of statement, or are you claiming "yes, government agencies have a track record of delivering technical excellence on software projects, and this particular project was especially bad"? The former is basically a meaningless platitude, and I don't think anyone seriously thinks the latter is true.

ryandrake•1h ago
Ok, so then it just sounds like whataboutism. Those other apps are just as bad. The tone of your original post sounded like you were defending the app's bad behavior. A lot of people might have mistaken your intent, which you clarified in [1].

1: https://news.ycombinator.com/item?id=47596187

gruez•53m ago
>Ok, so then it just sounds like whataboutism.

The flip side of "whataboutism" is "isolated demands for rigor"[1]. Going back to the IRS example, is it a fair retort to point out that IRS's hotline only sucks as much as any other large organization's hotline, or is it "whataboutism"?

[1] https://slatestarcodex.com/2014/08/14/beware-isolated-demand...

chirau•37m ago
It's the government, the US government. By far the largest employer and spender in the world. So yes, they are held to a higher standard. Businesses intentionally throttle customer service lines for profit reasons. The government should not. How is this difficult to understand?
gruez•25m ago
>So yes, they are held to a higher standard.

See my earlier comment about how this is a meaningless platitude.

>Businesses intentionally throttle customer service lines for profit reasons. The government should not.

None of this was presupposed in the original comment, only that wait times are long.

neya•1h ago
It's a classic deflection tactic - when they can't refute you by merit, they answer something with a question that is completely different about what was said - BOOM, the discussion is now about something else, completely different from the original issue. I honestly can't tell if it's bots or humans these days doing this a lot, but they're getting pretty good at it.
neya•1h ago
Are you also the type of person who thinks the government isn't being run like a business everywhere in the world?

If so, why do you think lobbying exists?

I'm not saying it should be run like a business, but it is naive to think it isn't run like one.

nkozyra•1h ago
> If so, why do you think lobbying exists?

Specifically because it's not a natural market. There are people who secure a 2-year, consequence-free term to impact U.S. law, at the behest of people with money.

Lobbying is special interests dictating decisions that often are not financially, morally, or otherwise ideal/beneficial to the other party (the United States and its people). This wouldn't fly at any corporation or business because there would be direct impacts on the bottom line or reputation of the company.

lobf•35m ago
> If so, why do you think lobbying exists?

Would you like to be able to ask your representative to focus on a particular issue?

refulgentis•1h ago
Right, the White House is collecting data and sending it to Huawei, and overall collection rate is worse than any other app you’ve seen by a wide margin.

That makes me net more surprised after reading your comment.

You're not surprised the white house is worse than any other app you've seen by 20%?

gruez•1h ago
>to Huawei

???

commoner•1h ago
See: https://news.ycombinator.com/item?id=47581532
dwattttt•1h ago
I'm happy to be against both the white houses' 3rd party telemetry as well as other apps. I can multitask.
Cider9986•1h ago
Some previous discussion. I think this one is worth a read as well, though.

https://news.ycombinator.com/item?id=47555556 https://news.ycombinator.com/item?id=47577761

ddxv•1h ago
Browse the SDKs it's using as well:

https://appgoblin.info/apps/gov.whitehouse.app/sdks

vjvjvjvjghv•38m ago
Ads are coming next.
merek•33m ago
> We installed mitmproxy on a Mac, configured an iPhone to route traffic through it, and installed the mitmproxy CA certificate on the device.

> All HTTPS traffic was decrypted and logged. No modifications were made to the traffic. The app was used as any normal user would use it.

Is it really that simple to inspect network traffic on an iPhone, namely to get it to trust the user-installed cert? I do quite a bit of network inspection on Android and I find it to be painful, even if the apps don't use certificate pinning.

Regardless, it highlights the importance of having control of our own devices, including the ability to easily inspect network traffic. We have the right to know where our data is being sent, and what data is being sent.

I recall during COVID it was discovered that Zoom was sending traffic to China. There was also the recent case of Facebook tracking private mobile browsing activity and sending it to their servers via the FB app. Imagine how much questionable traffic goes unnoticed due to the difficulty in configuring network inspection for apps.

cedws•31m ago
Installing the CA requires jumping through some hoops, but yes, intercepting traffic for apps that don’t use cert pinning isn’t that difficult on iOS.

Apps that do use cert pinning is a whole other matter, I’ve tried unsuccessfully a few times to inspect things like banking apps. Needs a rooted device at the minimum.

varun_ch•30m ago
Yes, it is _a lot_ easier to set up mitmproxy on iOS vs Android. But once you encounter an app with certificate pinning, being on a more open platform that lets you install your own apps can help get around that.
varun_ch•28m ago
that said, mitming stuff even on Android can be a pain, so I use a rooted Android emulator with Frida. Even that can be a hassle sometimes.

https://www.trickster.dev/post/setting-up-rooted-android-emu...

userbinator•3m ago
Regardless, it highlights the importance of having control of our own devices, including the ability to easily inspect network traffic. We have the right to know where our data is being sent, and what data is being sent.

Meanwhile I've always found it amusing that there's a loud, probably corporate-owned/Big-Tech-brainwashed subset of the "security" crowd who complains about MITM proxies.

gnerd00•20m ago
is location tracking part of OneSignal ? no mention of the other location services in this writeup ?
drnick1•20m ago
I filter the vast majority of adware such as doubleclick.net right at the DNS level. Not that I would use the app anyway...

It's shocking how many third party connections an average website opens. It's particularly true for news websites. Interestingly, atomic.computer also attempts to load Cloudflareinsights and some Google fonts, both of which are denied on my network. This is precisely the kind of requests that make it trivially possible for Google to follow people around the Internet, and the vast majority of webmasters are complicit of this.

john_strinlai•17m ago
43% (of the 158 3rd-party requests) is... google. youtube, fonts, and analytics. 55% if you include facebook and twitter.

a government app shouldnt have crazy analytics and tracking and whatever. but i dont think loading google fonts or embedding youtube videos is really all that wild in the grand scheme of things.

given the title, i was half expecting some sort of egregious list with, like, palantir and some ICE domains or something. i dont like the app, but google? facebook? that is pretty boring.

the title probably should focus on nature/severity of the requests. titling it with a % of all requests feels bait-y if google/facebook/twitter isnt off in its own category. they have all sorts of dumb little requests to all sorts of domains that really inflate the numbers.

_heimdall•15m ago
Don't get me wrong, the government requires a high level of scrutiny.

I would be interested to see how this compares to industry standard though, 77% doesn't seem outrageous to me given all the trackers and advertising code I've seen over the years. It wouldn't surprise me if this is inline with many apps people install and don't think twice about.

pratyushsood•6m ago
Government apps should absolutely be held to a higher standard than consumer B2C apps. Loading Google Fonts is one thing — sending telemetry to OneSignal and Facebook from an official government app is a different conversation entirely.

In Australia, apps handling government data must comply with the PSPF (Protective Security Policy Framework) and the ISM, which explicitly restrict data flows to untrusted third parties. A government app routing 77% of requests externally would fail an IRAP assessment on day one.

The fix is straightforward: self-host fonts, use first-party analytics, and treat every external request as a data exfiltration vector. Government digital teams know how to do this — the question is whether anyone is actually reviewing the network behavior post-deployment

JumpCrisscross•3m ago
> Government apps should absolutely be held to a higher standard than consumer B2C apps

Honestly—why? What is in this traffic that mandates heightened scrutiny? It strikes me as simply about brand.